With more and more sensors being crammed into the consumer devices that many of us wear every day, the question of where medical devices begin and end, and how they should be regulated become ever more pertinent. When a ‘watch’ no longer just shows the time, but can keep track of a dozen vital measurements, and the line between ‘earbud’ and ‘hearing aid’ is a rather fuzzy one, this necessitates that institutions like the US FDA update their medical device rules, as was done recently in its 2026 update.
This determines how exactly these devices are regulated, and in how far their data can be used for medical purposes. An important clarification made in the 2026 update is the distinction between ‘medical information’ and ‘signals/patterns’. Meaning that while a non-calibrated fitness tracker or smart watch does not provide medically valid information, it can be used to detect patterns and events that warrant a closer look, such as indications of arrhythmia or low blood oxygen saturation.
As detailed in the IEEE Spectrum article, these consumer devices are thus ‘general wellness’ devices, and should be marketed as such, without embellished claims. Least of all should they be sold as devices that can provide medical information.
Another major aspect with these general wellness devices is what happens to the data that they generate. While not medical information, it does provide health information about a person that e.g. a marketing company would kill for to obtain. This privacy issue is unresolved in the US market, while other countries prescribe strict requirements about such data handling.
Effectively, this leaves the designers of wearables relatively free to do whatever they want, as long as they do not claim that the medical data being produced from any sensors is medical information. How this data is being handled is strictly regulated in most markets, except for the US, which is quite worrying and something you should definitely be aware of.
As for other medical device purposes like hearing aids, the earbuds capable of this fortunately do not generally collect information. They do need to have local regulatory approval to enable the feature, however, even if you can bypass any geofencing with some creative hacking.

