Lawsuit Claims Whoop Fitness Tracker Shared Heart Rate Variability Data With Life Insurers

Whoop, the popular fitness tracking wristband, has faced multiple class action lawsuits alleging unauthorized data sharing with third parties.

Whoop, the popular fitness tracking wristband, has faced multiple class action lawsuits alleging unauthorized data sharing with third parties. However, current legal filings and court documents do not show evidence that Whoop specifically shared health data with life insurance companies. The most significant lawsuit—Lomeli v.

Whoop, filed in August 2025 in the Northern District of California—alleges instead that Whoop embedded a third-party tracker called Segment (owned by Twilio) that collected and transmitted sensitive health metrics including heart rate, blood oxygen, stress levels, and sleep patterns without user consent. The distinction matters because while unauthorized third-party tracking is a serious privacy violation, data sharing with life insurers would involve different legal and practical risks. The confirmed Whoop lawsuits focus on analytics companies gaining access to intimate health information—a problem that could still affect insurance rates, employment decisions, or other sensitive matters downstream, but through different mechanisms than direct insurer partnerships.

Table of Contents

What Does the Whoop Lawsuit Actually Allege?

The primary lawsuit against Whoop centers on Segment, a data collection and customer analytics platform owned by Twilio. According to the Lomeli v. Whoop complaint, Whoop embedded Segment’s tracking code into its mobile app without clearly disclosing that sensitive health data would be collected and transmitted to Twilio and Segment’s network of downstream partners. The lawsuit identifies specific data points captured: heart rate measurements, blood oxygen saturation, stress levels, and sleep duration and quality. This data went far beyond what users might reasonably expect would leave their phones, especially health information that could be considered intimate and sensitive. Whoop users typically download the Whoop app to sync data from their wristband, view their daily metrics, and receive coaching recommendations. They do not consent—or at least not knowingly—to have that health information siphoned off to a third-party analytics platform.

This is the core of the privacy violation alleged in the lawsuit: the data transmission happened in the background without adequate notice, and Whoop’s privacy policy and terms of service did not make it clear that third-party trackers would have this access. The fact that Segment is a corporate analytics tool, not a health app or public database, makes the unauthorized transmission especially troubling. Separate from the Segment tracking issue, a different lawsuit (Sanderson v. Whoop, filed October 2023) targeted Whoop’s automatic renewal practices, alleging deceptive billing. That case achieved class certification in March 2025. A third recent lawsuit (Rowe v. Whoop, November 2025) challenged Whoop’s marketing of “medical-grade” blood pressure insights after the FDA issued a warning letter to the company about overstated health claims.

What Does the Whoop Lawsuit Actually Allege?

The Lomeli lawsuit alleges violations of two major privacy statutes. The first is the Video Privacy Protection Act (VPPA), a federal law originally enacted to prevent unauthorized tracking of people’s video rental habits. Courts have increasingly applied VPPA to any unauthorized tracking of sensitive information, including health data. The second is California’s Confidentiality of Medical Information Act (CIPA), a state law that provides strong protections for medical and health information and requires explicit patient consent before health data can be disclosed to third parties. These aren’t just technical violations of written policies.

The lawsuit argues that Whoop’s conduct violates the fundamental principle of informed consent—the idea that people should know when their sensitive data is being collected and where it’s going. A user who opens the Whoop app to check their sleep score did not sign up to have their heart rate data analyzed by Twilio and Segment. The lack of clear, upfront disclosure makes the violation especially significant legally and ethically. However, if you use Whoop, it’s important to understand that these lawsuits have been filed but not yet resolved. Class certification, settlements, and damage awards typically take months or years to finalize. Some users may be eligible to submit claims once a settlement is reached, but no final judgment or settlement amount has been announced publicly yet.

Whoop Lawsuit TimelineSanderson Renewal Lawsuit (Filed)2023YearRowe False Advertising Lawsuit (Filed)2025YearLomeli Data-Sharing Lawsuit (Filed)2025YearSanderson Class Certification2025YearRowe FDA Warning Letter2025YearSource: Federal court filings and public records

Third-Party Trackers Versus Life Insurance Data Sharing

The distinction between Whoop’s alleged conduct and the title’s reference to life insurers is important. Whoop appears to have shared data with Segment, an analytics and marketing platform. Life insurance companies, by contrast, underwrite insurance policies and make decisions about coverage and pricing based on health information. If Whoop had actually shared data with life insurers, the claim would involve a different set of harms and legal risks. In theory, if a life insurer obtained your detailed heart rate and stress data from Whoop without consent, they could use it to deny coverage, raise your premiums, or decide whether to renew your policy.

This would be especially problematic because insurance is often obtained through employers or family plans where the individual may not have bargaining power to negotiate consent terms. However, the current lawsuits focus on Segment and other third-party analytics platforms—companies in the data brokerage and marketing business—not insurance underwriters. Why doesn’t Whoop’s data reach life insurers based on the available evidence? Segment sells data and audience segments to marketers, advertisers, and data brokers. Life insurers are not typically Segment customers in this context. That said, data can flow through many intermediaries, and it’s possible that some of the downstream recipients of Whoop user data could be insurers or that insurers could eventually purchase aggregated health data from brokers. The lawsuits don’t provide granular detail on every company that received the data, only that Segment was the immediate unauthorized conduit.

Third-Party Trackers Versus Life Insurance Data Sharing

Timeline of Recent Whoop Litigation

Understanding when these lawsuits were filed helps illustrate that Whoop faces multiple independent challenges from different angles. The Sanderson automatic renewal lawsuit came first, filed in October 2023 and certified as a class action in March 2025. This case targets billing practices, not data sharing. The Rowe lawsuit followed in November 2025, alleging false advertising about Whoop’s blood pressure measurement capability after an FDA warning. The Lomeli data-sharing lawsuit is the most recent major claim, filed in August 2025.

This is the suit with the broadest implications for user privacy, alleging that millions of Whoop users had their health information harvested and transmitted without consent. Given that Whoop has millions of active users worldwide, the number of people potentially affected by the unauthorized Segment tracking could be substantial. The suit was filed in the Northern District of California, which is a common venue for tech and privacy class actions. Collectively, these three lawsuits show that Whoop has faced scrutiny from multiple directions: billing practices, marketing claims, and privacy violations. Affected users may potentially be eligible for relief in any of these cases, depending on when they used Whoop and what specific harms they experienced.

What Health Data Is at Risk, and Why Heart Rate Variability Matters

Whoop collects several categories of health data, with heart rate variability (HRV) being one of the most valuable. HRV is the variation in time between heartbeats, measured in milliseconds. It’s considered a marker of nervous system health and stress levels—lower HRV may suggest higher stress or poor recovery, while higher HRV is associated with better fitness and resilience. Athletes and fitness enthusiasts value this metric because it can indicate overtraining or readiness for intense exercise. The problem is that HRV data is deeply personal and revealing. It reflects not just your physical fitness, but your stress levels, anxiety, and overall well-being.

Combined with sleep data, stress measurements, and other metrics Whoop collects, this information creates a detailed health profile. In the hands of an analytics company like Segment, it can be used to build behavioral models, segment users by health status, or sell that information to advertisers and data brokers. Someone with consistently low HRV and poor sleep might be targeted for expensive wellness products, supplements, or services that exploit their apparent health struggles. Beyond Whoop specifically, unauthorized health data sharing is a broader privacy problem. Fitness trackers, smartwatches, and health apps collect continuously, and many users don’t realize how much of that data leaves their devices. The Whoop lawsuit highlights a practice that may be more common than users assume: embedding third-party trackers into apps that ostensibly function for the user’s benefit while secretly feeding data to corporate partners.

What Health Data Is at Risk, and Why Heart Rate Variability Matters

How to Know If You’re Affected and What Steps to Take

If you used Whoop between the dates covered by the Lomeli class definition (typically the entire period since Whoop launched, though the exact dates will be determined in the litigation), you may be a class member and potentially eligible for compensation once a settlement is reached. You don’t need to do anything immediately, but you should watch for settlement notices, which will be sent to the email address associated with your Whoop account. When a settlement is finalized, you’ll typically have a limited window—usually 60 to 120 days—to submit a claim or register for the settlement class.

Claims typically require proof of membership (your account and dates of use) and may offer either cash compensation or some combination of account credits. To stay informed, periodically search for “Whoop class action settlement” or check legal class action settlement databases. You should also review your Whoop privacy settings now: disable data sharing with third parties if the app provides that option, and consider whether you want to continue using the service given the alleged data practices.

The Broader Fitness Tracker Privacy Landscape

The Whoop litigation is part of a larger pattern of privacy challenges facing fitness tracker companies and health app makers. Many wearable devices and health apps embed third-party trackers—including Google Analytics, Amplitude, Mixpanel, and others—that collect far more data than necessary for the app’s core function. Users generally don’t realize this is happening, and many app privacy policies bury disclosures about these trackers in legal jargon.

Looking forward, expect more lawsuits targeting fitness tracker privacy practices, especially as companies face FDA scrutiny over health claims and users become more aware of data collection. The Whoop cases may set important precedents for how courts interpret privacy obligations of health device companies under VPPA and state medical privacy laws. Settlements in these cases will likely drive industry-wide changes, prompting fitness tracker companies to audit their data-sharing practices and provide users with better transparency and control.

You Might Also Like


Leave a Reply