Every benefits leader I meet tells me the same thing: “Our wellness program is fully compliant. HIPAA covers the data, and we only see aggregated reports. We’re fine.”
I get it. That line is comforting. Vendors promise it. Brokers repeat it. And for years, it was mostly true.
But the ground has shifted. Wellness programs have quietly become data ecosystems that few employers truly understand. The new risks aren’t about a lost laptop or a phishing attack. They are structural-baked into how wellness data moves between vendors, stop-loss carriers, and employers.
Let me show you what I mean, starting with a quiet danger that almost no one is talking about.
The Myth of the Safe Aggregate
When an employee completes a health risk assessment or logs a blood pressure reading, the vendor says: “Don’t worry. The employer only sees aggregate data-no individual information.”
This sounds reassuring. But here’s the problem: Aggregation does not equal anonymity.
In a small or mid-sized employer-say, 300 employees-the “aggregate” report might show that two people in the 45-54 age bracket have elevated HbA1c levels. If your company has only one person in that demographic with a known history of prediabetes, their identity can be inferred. This is called re-identification risk, and it is real, measurable, and increasingly targeted by regulators.
The legal standard is not whether the data has a name attached. It is whether a reasonable person could be identified from the data. In many wellness programs, the answer is yes-and no one has told the employee.
The Stop-Loss Handshake Nobody Explains
Here’s where things get even more uncomfortable.
Most employers with self-funded health plans purchase stop-loss insurance to cap catastrophic claims. In recent years, stop-loss carriers have begun asking for clinical data from wellness programs to refine their underwriting. They claim they need “population health trends” to set rates.
Let’s be clear about what that really means.
The stop-loss carrier receives data that includes biometric measurements, health risk scores, and participation patterns. While the data is labeled “de-identified,” the carrier can often cross-reference it with claims data (which they also hold) to pinpoint specific individuals. They then use that information to exclude specific high-risk employees from coverage or to impose rate increases tied to the employer’s wellness outcomes.
The employee’s reality: They filled out a health assessment to earn a $50 gift card, believing it was private. In truth, they have silently helped their employer’s insurer identify them as a cost liability.
This is not a theoretical risk. It is happening today, buried in vendor contracts and plan renewal documents that no one reads until it’s too late.
The Data Perpetuity Problem
Most wellness program consent forms are one-time events. An employee signs a HIPAA authorization at enrollment, and the vendor retains that data-sometimes forever.
What happens when your wellness vendor is acquired by a larger data company? What happens when that company is a pharmacy benefit manager or a life insurer? Your employees’ biometric data now lives in a system they never agreed to, used for purposes they never imagined.
The consent form says “for wellness program administration.” But that phrase is vague. It can be interpreted to include population health research, product development, or even data sales-as long as the data is “de-identified” (see re-identification risk above).
And none of this is communicated to the employee.
The Missing Compliance Layer: Data as Property
We think of privacy as a HIPAA problem. But the emerging legal battleground is not HIPAA-it is property rights.
In Illinois, the Biometric Information Privacy Act (BIPA) has already led to multi-million-dollar settlements against employers who collected fingerprints or facial scans without explicit, ongoing consent. While BIPA targets biometric identifiers like fingerprints, the legal reasoning is spreading to health data. Courts are beginning to ask: Does an employee’s metabolic data belong to them, even if they voluntarily shared it?
If the answer is yes, then every wellness program that retains, shares, or sells that data without granular consent is facing a class-action exposure that dwarfs typical HIPAA fines.
The Bright Line You Need to Draw
None of this means you should kill your wellness program. Wellness initiatives can improve health and reduce costs. But they must be restructured around a new principle: the employee’s data is their asset, not your vendor’s inventory.
Here are five concrete actions you can take starting today:
- Map your data handshakes. Identify every third party that touches wellness data: the vendor, the stop-loss carrier, the TPA, the pharmacy benefit manager. Document exactly what they receive and whether it can be linked back to individuals.
- Audit your vendor contract for data sales. Look for phrases like “de-identified data may be used for research or commercial purposes.” If it exists, demand removal or an explicit opt-in from each employee.
- Limit data retention. Require your vendor to destroy all clinical wellness data (excluding participation records) within 90 days after the incentive period ends. There is no business justification for keeping last year’s HbA1c results.
- Separate participation from results. Pay incentives for completing a health risk assessment, not for achieving a specific biometric target. The moment you reward results, you create a medical examination under the ADA, which triggers a much higher standard of privacy protection.
- Educate employees honestly. Stop telling them “your data is anonymous.” Tell them the truth: “Your data is pseudonymized and used only for program administration. We do not share individual results with your employer or insurer. You have the right to delete your data at any time.”
The Bottom Line
Wellness programs were born with good intentions. But the data infrastructure around them has quietly become a risk machine. The employee who steps on a scale and enters a blood pressure reading believes they are participating in a health improvement program. In reality, they may be feeding a data pipeline that ends in a higher insurance premium, an exclusion notice, or a class action lawsuit.
You have the power to rebuild that pipeline. Start with transparency. End with control.
Because the real wellness outcome we should be measuring is not steps taken. It is trust kept.
This article reflects the views of the author and is not legal advice. Consult your benefits counsel for specific compliance guidance.
