My smart watch and I are growing apart. At first, I appreciated that it tracked how much I moved and how long I slept. By now, the watch interferes with my day at the strangest moments. After a walk, it tells me I've been sitting still for too long. Huh? After a bad night, it explains that I slept poorly. Thanks for the confirmation! Not to mention the same notification when I was convinced I had actually slept well.
I do appreciate the insights, but I have less and less need for yet another screen around my wrist. Apparently, I'm not the only one: more and more wearables without screens are appearing. Bracelets and rings continuously collect data, while you view the results in an app. Some providers add an AI coach that looks for patterns and offers advice on its own.
That all sounds quite nice, but the technology is increasingly keeping tabs on you. And what happens to all that data as AI capabilities grow? And what rules actually apply to the providers of such products?
After a few weeks, I receive a message from my watch:
Your heart rate and skin temperature have deviated from your normal pattern for three days now. Get some rest. If the abnormalities persist, contact your doctor.
Do I still have a fun consumer product on my wrist, or a device that is now starting to give medical advice? And does that possibly qualify it as a medical device under European legislation? This question doesn't just apply to what's on my wrist. From our office in Eindhoven, in the heart of Brainport, we increasingly see products where sensors, wearables, and artificial intelligence converge for diagnosis, treatment, and remote care. That's why in this blog I'll examine such a smart wearable through three questions: what kind of product is it actually, what happens to the data it collects, and what changes when a healthcare provider starts monitoring?
The honest lawyer's answer to that question is, of course: it depends. Annoying, I know. But when it comes to whether such a wearable is a medical device, the purpose the manufacturer assigns to it plays a major role. A bracelet that counts how much you move and gives general tips about sleep is not immediately a medical device. That can change when the manufacturer designates the product for, for example, predicting, monitoring, or diagnosing disease, or for providing information used in diagnostic or treatment decisions.
It's not just about what's written somewhere in fine print. The label, user manual, and statements on the website, for example, also determine the manufacturer's intended purpose, as does what the manufacturer specifies in the clinical evaluation. "You slept restlessly" is different from "this pattern may indicate a medical abnormality." Although even the former isn't a free pass: if the product then attaches medical conclusions or advice to it, it can still shift in that direction. The same sensors can therefore receive a very different legal classification.
And then there's the AI coach. If such a wearable uses AI, then in addition to the rules for medical devices, the AI Regulation also comes into play. Not every AI coach is immediately a high-risk system under that regulation. An application for general lifestyle tips doesn't automatically fall into the same category as AI that is part of a medical device and plays a role in decisions related to diagnostics. Although an AI system can also be a high-risk system without MDR qualification. Complicated, I know. The question "what does the AI do?" is in any case insufficient. You also want to know what purpose the provider offers it for, who uses the outcome (yourself or a healthcare provider looking along), and how much depends on that outcome.
Whatever the wearable is legally: it collects data regardless. A wearable without a screen in particular rarely demands your attention, but meanwhile records a lot: sleep, heart rate, temperature, movement, and perhaps even your stress level. Such measurements aren't always automatically health data. They become so when they relate to your physical or mental health and provide information about your state of health. A single heart rate measurement may say little, but a pattern from which AI derives a health risk for you tells a lot more.
Then the next question quickly arises for me: does the provider use my data only to give me advice, or does the model also learn from my data to improve advice for others? Is that allowed and do I actually want that? The answer starts with the type of data: for health data, the GDPR imposes a processing prohibition, which only gives way if an exception applies, such as explicit consent. A provider can process data on behalf of another party, such as a healthcare institution. If they also use the data for their own product development or to train the algorithm, they may be determining a purpose themselves and acquire their own responsibilities under the GDPR. "We use your data to improve our service" still tells me very little.
Until now, this was about me, the manufacturer, and the provider. The final question arises as soon as a third party is watching along. Suppose a healthcare institution uses such a bracelet for patients recovering from surgery at home. Whether the bracelet thereby also becomes a medical device, I deliberately leave open here. Although that does matter for the healthcare institution: a medical device has (among other things) undergone a conformity assessment, a consumer gadget has not. The role of the bracelet changes through its use in healthcare regardless. The bracelet looks the same, but a notification is no longer advice you swipe away at breakfast. The patient can expect that someone is monitoring or will intervene when values deviate.
Against that expectation stands a question for the healthcare institution: what care does it promise by deploying the bracelet? The law holds the healthcare provider responsible for good care: care that is at least safe and timely. Responsibilities and authorities must also be allocated in such a way that this should reasonably lead to good care. This doesn't mean the law prescribes a fixed response time for every notification; that depends on the professional standard and quality standards, and thus in practice on the medical risk. However, it must be clear beforehand who assesses notifications and which signals lead to action.
Such open norms require concrete agreements in practice: clear patient information, internal agreements on who assesses notifications, and an appropriate contract with the provider. That contract is about more than price and duration: you also want to make agreements with the provider on matters such as outages, incorrect notifications, security incidents, and the use of data. A contract that says little about the technology and how the solution serves or supports the care process mainly offers false certainty.
Incidentally, I haven't ordered a screenless tracker yet. My current watch will get another chance for now, although I expect little self-awareness from a device that reproaches me for sitting still too long after a walk.
Especially in Brainport, new technologies, AI, and healthcare come close together. From our office in Eindhoven, we therefore look beyond a single law or standard. Health law, the rules for medical devices, the AI Regulation, privacy, and IT contracts all touch the same application here. A smart wearable rarely fits into a single legal category. That makes our work more complicated, but above all a lot more interesting. So: does your innovation also not fit into a single legal category? We're happy to think along. Schedule an introductory meeting.