
A decade ago, corporate wellness programs meant a subsidized gym membership and maybe a step-count challenge with a $50 gift card on the line. Today, the same programs collect heart rate variability, sleep architecture, blood oxygen levels, stress scores, and—increasingly—predictive health flags generated by AI. The data is richer, the insights are sharper, and the liability exposure has grown right along with them.
Executives who wouldn’t dream of emailing unencrypted financial data are, in many cases, wearing devices that transmit a continuous stream of health information to third-party platforms their company doesn’t fully control. That gap between how seriously we treat financial risk and how casually we treat biometric risk is becoming a real problem for legal, HR, and risk-management teams.
The wellness program is now a data pipeline
Most corporate wellness platforms license AI health models rather than building their own. That means an employee’s sleep and recovery data may pass through two, three, or four vendors before it’s turned into a “risk score” that appears on an HR dashboard. Each handoff is a point of exposure: unclear data ownership, inconsistent retention policies, and terms of service that were written for a consumer product, not an employer-sponsored one.
Few companies have mapped this pipeline end to end. Fewer still have asked the harder question: if an AI model infers a health condition an employee never disclosed—early signs of a cardiac issue, a pregnancy, a mental health pattern—who is responsible for what happens to that inference, and who is allowed to see it?
Insurance is paying attention
Group health insurers have wanted better risk data for years, and now wearables and AI scoring are finally giving it to them. That’s a double-edged sword. Aggregated, anonymized data can lower premiums by demonstrating a healthier workforce. However, the more granular and individualized the data becomes, the closer employers get to a line most weren’t planning to approach: using health predictions to shape decisions about a specific person, even indirectly.
The legal exposure here isn’t hypothetical. In the U.S., the ADA and GINA restrict how employers can request, use, or incentivize the collection of health and genetic information, and the EEOC has sued employers —including Honeywell and Flambeau—over wellness programs it viewed as coercive rather than voluntary.
The agency has since gone further, issuing specific guidance on workplace wearables that explicitly names smartwatches, rings, and other biometric-tracking devices as tools that can trigger ADA scrutiny. An AI model that flags an employee as “high risk” based on biometric trends can create a paper trail. That’s something a plaintiff’s attorney would love to have in a wrongful termination or discrimination case, regardless of whether that data ever consciously influenced a decision.
Litigation risk doesn’t wait for a bad outcome
The exposure isn’t limited to obvious misuse. A company that collected biometric data “just for wellness” may find itself explaining, under oath, exactly how that data was stored, who accessed it, and whether any algorithm ever touched it before a promotion or termination decision. Good intentions don’t show up well in a data-retention audit.
There’s also a subtler risk: false confidence. AI wellness scores are probabilistic, not diagnostic, and they’re often built on population data that doesn’t reflect a specific employee’s context. If a manager treats an AI-generated “burnout risk” or “recovery score” as truth in a performance conversation, the company has effectively let an unvalidated model into a decision it was never designed to inform.
The regulatory picture is only getting more fragmented
U.S. employers also can’t assume this is purely a domestic compliance issue. Under Article 9 of the GDPR, health data is a “special category,” processing of which is prohibited by default unless the employer can satisfy one of a narrow set of legal exceptions—explicit, specific consent being the most common route, and a materially higher bar than the consent most U.S. wellness platforms currently obtain. Regulators have shown they’ll enforce this against biometric systems in the workplace. For example, the UK’s Information Commissioner’s Office ordered a leisure-facilities operator to stop all fingerprint-scanning and delete the data it had collected after it couldn’t demonstrate a lawful basis for the processing.
Meanwhile, several U.S. states have passed their own biometric and health-privacy statutes with private rights of action attached — meaning employees, not just regulators, can sue directly. A multinational company running a single global wellness platform may be applying one data-handling standard across a patchwork of jurisdictions that don’t agree on what’s even permissible to collect. That mismatch tends to surface at the worst possible time: during a breach investigation or a lawsuit.
What leadership teams should actually do
None of this means that wearables or AI-driven wellness benefits are too risky; the upside for engagement and genuine health outcomes is real. However, biometric data ought to be treated with the same governance rigor as any other sensitive corporate data asset:
- Separate the vendor’s business model from risk exposure. Understand exactly what a wellness platform does with the data once it leaves the device, and whether “aggregated and anonymized” actually holds up on inspection.
- Firewall wellness data from HR decision-making, formally and technically—and not just by policy, but by making sure the systems literally don’t talk to each other.
- Treat AI health inferences as hypotheses, not facts. Make sure managers are never trained, even implicitly, to read a dashboard score as a personnel signal.
- Loop in legal before procurement, not after. Wellness benefits should be negotiated by HR and benefits teams with the same data-governance review a CRM or analytics tool would get.
The organizations getting ahead of this aren’t the ones with the flashiest wellness perks—they’re the ones who’ve figured out where their biometric data actually goes, and who’s accountable if something goes wrong with it.