InvestigationWestchester Gold Coast, NY

When "Optional" Wellness Wearables Aren't: The Legal Backlash Against Biometric Data in Reviews

See More Like This — Add as Preferred Source

Executive Briefing

Bottom Line: Federal ADA rules require wellness programs to be genuinely voluntary, and the EEOC's own guidance now says a mandatory tracking watch fails that test. State biometric statutes add a second, separate exposure layer on top.

Metric: Illinois BIPA violations carry $1,000 to $5,000 in statutory damages per violation, per 740 ILCS 14/20. Programs commonly involve HRV and step-count tracking.

Access: Review the Breathing Protocol, a device an employee owns and controls outright.

A "voluntary" wellness wearable program is not voluntary if declining it costs an employee money or standing. That is the plain reading federal regulators and Illinois courts have converged on since 2024.

Employers who mandate a step-count or HRV-tracking device, then feed the readouts into HR files, are now sitting on real legal exposure. Three separate bodies of law now touch this practice: the ADA's voluntariness requirement, Illinois's Biometric Information Privacy Act, and newer state biometric statutes in Texas and Washington.

What Counts as "Voluntary" Under Federal Law

The ADA restricts disability-related inquiries and medical examinations to a narrow set of exceptions. One of those exceptions covers voluntary employee health programs reasonably designed to promote health or prevent disease, under 42 U.S.C. 12112(d)(4)(B).

The EEOC's December 2024 fact sheet on workplace wearables applied that standard directly to fitness trackers for the first time. Its own worked example: an employer tells an employee he must wear a company-issued tracking watch that collects vital signs and gait data, and, per the agency, "this mandatory use of the watch does not satisfy the ADA's requirements for employee health programs that are voluntary."

That single sentence reframes a decade of ambiguous wellness-program design. Mandatory participation, even framed as a friendly nudge toward better sleep, can itself be the violation.

The Incentive Gap

No federal rule currently sets a bright-line incentive percentage for wellness programs. A 2016 EEOC rule capped incentives at 30% of self-only coverage, but a federal court vacated that provision effective January 1, 2019, after AARP argued it was coercive rather than voluntary.

Employers have operated without a numeric ceiling since. Source: U.S. District Court for the District of Columbia, AARP v. EEOC.

The BIPA Exposure Employers Underestimate

Illinois's Biometric Information Privacy Act defines a biometric identifier as "a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry," per 740 ILCS 14/10. Biometric information is defined even more broadly, covering any data "based on an individual's biometric identifier used to identify an individual."

Most consumer HRV rings and fitness bands track heart rate and movement, which sit outside that narrow identifier list on their own. The exposure appears when an employer layers biometric login, fingerprint kiosks, or face-scan check-ins onto a wellness program alongside the wearable data.

That combination is exactly what BIPA was written to police, and Illinois plaintiffs' firms have noticed the wellness-adjacent angle. Over 100 new BIPA class actions were filed in 2025 alone, with settlements including a $12.1 million payout from Speedway.

The BIPA Filing Count

BIPA filings fell to roughly 150 cases in 2025, down from 427 in 2024, following a 2024 statutory amendment that narrowed per-scan damage stacking. Even at reduced volume, the law remains a live threat for any employer program touching biometric identifiers.

Source: 2025 Year-in-Review, Privacy World / National Law Review.

Texas and Washington Add State-Level Risk

Illinois is not alone anymore. Texas enacted the Capture or Use of Biometric Identifier Act, and Washington passed its own biometric privacy statute in 2017.

Neither state allows an individual employee to sue directly; enforcement runs through each state's attorney general. That has not made the exposure small.

Texas Attorney General Ken Paxton used CUBI to reach a $1.4 billion settlement with Meta over facial recognition practices, a number that signals how aggressively the statute can be enforced once a regulator takes interest. A wellness vendor's face-scan check-in kiosk or voice-based coaching assistant could draw the same scrutiny.

When Wearable Data Bleeds Into Performance Reviews

The EEOC's fact sheet does not stop at collection. It separately addresses what happens once an employer uses the data collected.

Its listed examples read like a checklist of what not to do: inferring pregnancy from heart rate and temperature patterns and then forcing unpaid leave, or firing an employee over an elevated heart rate caused by an underlying heart condition. Each example ties wearable output directly to an adverse employment decision.

A performance review that references "low recovery scores" or "inconsistent sleep compliance" sits uncomfortably close to those examples. The moment a wellness metric shapes a rating, a raise, or a termination, it stops being wellness data and becomes evidence in an EEO claim.

Is Your Program Actually Voluntary? A Decision Tree

The distinction between a defensible program and an exposed one usually comes down to a small number of yes-or-no questions. Below is a simplified version of the analysis employment counsel typically runs.

Is participation mandatory? Yes Likely NOT voluntary EEOC's own Marco example fails on this fact alone No Does declining cost pay or standing? Yes Coercive incentive risk No safe-harbor % exists since AARP v. EEOC No Does a biometric identifier get captured? Yes BIPA / CUBI / WA exposure Written notice and consent required before capture No Does wellness data reach a manager or review file? Yes EEO adverse-effect risk Data must be kept in a separate confidential file No Defensible design Voluntary, no coercive incentive, data walled off
A simplified legal decision tree, not a substitute for counsel review of a specific program.

What Westchester Employers Should Audit Now

Start with the incentive structure, not the device. If declining the wearable changes an employee's premium, bonus, or standing with a manager, the "voluntary" label will not survive a challenge.

Next, check where the data physically lives. The ADA requires medical information collected through a wellness program to sit in files separate from personnel records, per 42 U.S.C. 12112(d)(4)(C).

Finally, map every biometric touchpoint in the vendor stack. A wellness app's face-scan login or fingerprint-based device pairing can trigger BIPA, CUBI, or Washington's statute independently of the fitness data itself.

Next Move

Watch for the first reported case where wearable HRV or sleep data appears as an exhibit in a wrongful-termination or discrimination suit. None has been publicly confirmed yet, but the EEOC's fact sheet reads like a roadmap for plaintiffs' counsel building exactly that record.

Executives implementing these programs should ask their own HR teams the same four questions in the tree above, before a regulator or a former employee asks them first.

See our related coverage on how boards are requesting CEO HRV data. Also read how life insurers are pricing wearable data.

Last updated September 2026. Not medical, legal, or financial advice. This article is editorial commentary on employment law and wearable data practice.

It is not a substitute for review by employment counsel of any specific wellness program. Statutes, regulations, and case outcomes change; verify current requirements before acting.

Sources

  1. U.S. Equal Employment Opportunity Commission. "Wearables in the Workplace: Using Wearable Technologies Under Federal Employment Discrimination Laws." December 19, 2024. eeoc.gov
  2. Illinois General Assembly. "Biometric Information Privacy Act," 740 ILCS 14/10 (definitions). ilga.gov
  3. Illinois General Assembly. "Biometric Information Privacy Act," 740 ILCS 14/20 (statutory damages). ilga.gov
  4. U.S. Equal Employment Opportunity Commission. "EEOC's Final Rule on Employer Wellness Programs and the Genetic Information Nondiscrimination Act." eeoc.gov
  5. Constangy, Brooks, Smith & Prophete LLP. "Court vacates parts of EEOC wellness rules, effective 1/1/19." constangy.com
  6. Privacy World. "2025 Year-In-Review: Biometric Privacy Litigation." privacyworld.blog
  7. National Law Review. "Review of Major Biometric Privacy Litigation in 2025 Under BIPA." natlawreview.com
  8. Ogletree Deakins. "Employer Alert: Texas Reaches $1.4B Settlement Over Allegations of Violation of Biometric Information Privacy Law." ogletree.com
  9. HR Defense Blog (Akerman LLP). "Fitbits at Work: Navigating the Legal Risks of Wearables in Corporate Wellness Programs." hrdefenseblog.com

Frequently Asked Questions

Yes, under the ADA. Disability-related inquiries or medical examinations are only permitted without a specific safety justification if they are voluntary and part of an employee health program reasonably designed to promote health or prevent disease.

The EEOC's December 2024 wearables fact sheet states that a mandatory tracking watch collecting vital signs does not satisfy that voluntariness requirement.

It can, if the wearable captures a biometric identifier such as a fingerprint, retina scan, or hand or face geometry scan as defined in 740 ILCS 14/10.

Most consumer fitness wearables track heart rate and movement rather than those specific identifiers, but any employer program layering biometric login or scanning onto a wellness device raises BIPA exposure. Violations carry statutory damages of $1,000 to $5,000 per violation.

A federal court vacated the incentive provisions of the EEOC's 2016 ADA and GINA wellness rules, effective January 1, 2019, after AARP challenged the 30% incentive cap as coercive.

No replacement incentive rule has taken effect since, leaving employers without a bright-line percentage for how large a reward or penalty can be before a program stops being voluntary.

Using wearable-generated health data to make an employment decision that has an adverse effect on an employee because of a protected characteristic can violate federal EEO law.

The EEOC's fact sheet gives examples including inferring pregnancy from heart rate patterns or firing someone over an elevated heart rate caused by a disability. Data collected for wellness purposes bleeding into a performance file is the exact scenario regulators are watching.

Texas has the Capture or Use of Biometric Identifier Act (CUBI) and Washington has its own 2017 biometric privacy law.

Both require notice and consent before commercial biometric collection, but neither creates a private right of action; only the state attorney general can enforce them, unlike Illinois BIPA which allows individual lawsuits.

Editorial Integrity

WestChester Zen editorial content is research-based and independently produced. No sponsored placements shaped this article's findings.

Sources include primary statutory text, federal agency guidance and law firm client alerts. Full policy at disclosures.