Every paper in this series to this point has documented behavioral participation: what people do, where they go, what they watch, what they search for, what they buy, and what they drive. The data those papers documented is a record of choices. Paper Eight documents something different. The data captured across this domain is not a record of choices. It is a record of physiology, genetics, reproductive function, sleep architecture, cardiac behavior, and metabolic state. It does not describe what a person does. It describes what a person is.
That distinction is not philosophical. It is structural. A behavioral profile can be changed. A person can stop using a platform, delete an account, change their habits, and over time generate a different record. A genetic profile cannot be changed. A cardiac history cannot be unrecorded. Reproductive data, once contributed to a platform, describes a biological reality that existed before the platform captured it and will continue to exist after the platform disposes of it. The commercial systems that capture biological participation data are not assembling a record of behavior that reflects choices the participant made. They are assembling a record of existence that reflects what the participant is, and what their biological relatives are, regardless of any choice any of them made or will make.
The consequences of misclassification in this domain are not limited to advertising revenue or insurance pricing differentials, though they include both. They extend into employment screening, pharmaceutical targeting, reproductive legal exposure, and in the case of genetic data, consequences that extend to family members who never participated at all. The person at the origin of biological participation data is not only unrecognized as its producer. In the systems that hold it, they are the data. It is the person, rendered as a dataset.
There is a further dimension that no prior paper has reached. In every prior domain, the participant's individual contribution was necessary for the platform's commercial model. Here, it is not. Platforms assembling biological datasets at scale do not need any specific individual's data. They need a dataset large enough to be commercially useful. The participant is not irreplaceable. They are substitutable. Their biological contribution is extracted not because they are recognized as its origin but because they are one of the millions of bodies whose aggregate participation produces the asset. That is not a degree of difference from the misclassification documented in prior papers. It is a different condition. The person has no recognized standing in the system that holds them, and the system does not require their standing to function.
This is also why individual consent models are structurally insufficient in this domain: a single person's refusal does not affect the viability of a dataset assembled from millions of bodies, and the system has no incentive to treat individual standing as a meaningful constraint.
The biological participation domain assembles data across four distinct layers, each with different commercial destinations and different regulatory coverage. They are not separate systems. They are entry points into the same one.
The consumer wearable layer generates continuous physiological signals through devices worn on the body: heart rate, heart rate variability, blood oxygen saturation, skin temperature, sleep stages and architecture, activity patterns, menstrual cycle signals, stress indicators derived from physiological proxies, and in newer devices electrocardiogram readings that were previously available only in clinical settings. These signals are not captured episodically. They are generated continuously, across every hour of every day, across years of device ownership. Biological data becomes more valuable and more identifiable the longer it is collected. A person who has worn an Apple Watch for five years has contributed tens of thousands of hours of continuous physiological monitoring to Apple's HealthKit ecosystem. The longitudinal record that produces is not simply larger than a short record. It is qualitatively different: it contains patterns that only emerge over time, whose predictive value for health outcomes, behavioral modeling, and actuarial risk scoring compounds with every additional observation. It is not a record of what the person did during those hours. It is a record of what their body was doing, rendered into a form that grows more commercially precise the longer it accumulates.
The wellness and behavioral layer captures reproductive and psychological state through consumer applications that operate entirely outside the regulatory framework governing clinical health data. Period tracking applications including Flo, Clue, and Glow capture menstrual cycle length and regularity, fertility signals, pregnancy status, sexual behavior, and symptoms reported by users across months and years of continuous use. Mental health applications including Calm, Headspace, and in the case of therapy platforms such as BetterHelp, the content of therapeutic conversations themselves. Nutrition and weight management platforms capture dietary behavior, caloric intake, body weight trajectories, and metabolic signals. Sleep tracking platforms capture sleep architecture, circadian rhythm patterns, and in some cases audio recordings of the sleep environment. Each of these applications generates biological signals whose commercial value extends into insurance underwriting, pharmaceutical targeting, and employer wellness programs, under terms that classify the data as user-contributed content rather than as a biological record with a recognized origin.
The genetic layer is categorically different from the layers above. DNA sequences submitted to consumer testing companies are not behavioral data. They are structural data. They describe what a person is at the molecular level, what diseases they are predisposed to, what medications will or will not work for them, what their ancestors were, and what their descendants will inherit. Genetic data is also not individual in the way that behavioral data is individual. A genetic profile built from one person's DNA contains information about every biological relative of that person. One person's participation expands the dataset for people who never participated at all. A person who submits a sample to 23andMe or AncestryDNA is not only contributing their own biological data to a commercial system. They are contributing partial biological data about every sibling, parent, child, and cousin they have, none of whom submitted a sample, none of whom consented, and none of whom have any recognized standing in the commercial arrangements that profile enables. This is a system property, not an ethical extension. It is a structural consequence of how genetic data is constituted.
The clinical layer sits closest to formal health data regulation but is not fully covered by it. Hospital patient portal behavioral data, remote patient monitoring systems, telehealth platforms, and prescription management applications generate clinical participation data whose commercial value extends beyond the covered entity relationship in which it was produced. The regulatory boundary here is real but porous, and its porousness is structural rather than incidental. The same physiological signal, captured at the same moment, is subject to different legal treatment depending on which system holds it. A heart rate reading transmitted from an Apple Watch to a cardiologist's electronic health record system exists in two regulatory environments simultaneously. Inside the EHR it is protected health information subject to HIPAA. On the Apple Watch it is consumer wellness data subject to no equivalent federal protection. The data did not change. The regulatory coverage did.
23andMe, Inc. offered consumer genetic testing services to approximately 15 million people across its operating history. Customers submitted a saliva sample, paid a fee ranging from $99 to $229 depending on the service level, and received ancestry analysis and health risk assessments derived from their DNA. The company built its commercial model on the proposition that genetic data, aggregated across millions of profiles, had substantial value in pharmaceutical research, drug development partnerships, and health data licensing. In 2018, 23andMe entered into a drug development partnership with GlaxoSmithKline valued at $300 million, in which GSK received access to 23andMe's genetic database for drug target identification and validation. That transaction assigned a specific, disclosed commercial value to the genetic database assembled from customer submissions.
In March 2025, 23andMe filed for Chapter 11 bankruptcy protection. The company's genetic database, containing the profiles of approximately 15 million people built from their biological contributions, was identified as a primary asset of the bankruptcy estate. The sale of that asset was proposed as a mechanism for satisfying creditor claims. The people whose DNA built the asset were not creditors in the proceeding. They were not parties to the proposed sale. They had no recognized standing in the transaction that would determine the disposition of the most intimate data they had ever contributed to any system.
The 23andMe case establishes four things that no prior paper in this series has established.
The first is asset classification. Biological participation data is classified as a corporate asset belonging to the platform rather than to the person who generated it. The customer who submitted a saliva sample to 23andMe contributed the foundational input of the company's primary commercial asset. The asset belongs to the company. The customer is not recognized as its origin.
The second is persistence. Biological participation data persists after the platform's commercial failure. The company that collected the data went bankrupt. The data did not. It remained intact as a transferable asset whose value to a new owner was independent of the commercial failure that preceded the transfer.
The third is transferability. The asset can be transferred to a new owner through bankruptcy proceedings without the consent or notification of the people whose biology constitutes it. The terms of service through which 23andMe's customers agreed to data collection did not contemplate a bankruptcy proceeding that would transfer their genetic profiles to an unknown acquirer operating under different commercial incentives and subject to different governance structures.
The fourth is familial spillover as a system property. The consequences of the transfer extend to people who never participated. A genetic profile built from one person's DNA contains information about their biological relatives. The bankruptcy transfer of 23andMe's database transferred partial genetic profiles of tens of millions of people who never submitted a sample, never agreed to any terms of service, and had no knowledge that their biological data was held by a company that was about to sell it in a bankruptcy proceeding. This is not an incidental harm. It is a structural feature of how genetic data operates as a commercial asset: its value derives precisely from the fact that it encodes information about more people than submitted it.
It should be noted explicitly that the system produced these outcomes regardless of 23andMe's intent as a platform. The company did not intend to go bankrupt. It did not design its consent framework to fail in a bankruptcy proceeding. The consequences documented here are not the product of malicious design. They are the product of a system in which biological participation data is classified as a corporate asset, and corporate assets follow the legal rules governing corporate distress. Intent is not the relevant variable. Classification is.
The California Attorney General issued an advisory in the period following the bankruptcy filing, recommending that 23andMe customers request deletion of their data before the sale completed. The advisory acknowledged that deletion requests might not be honored by a bankruptcy trustee operating under different legal obligations than the company that originally collected the data. The advisory also did not address the inference permanence problem: even if raw genetic data is deleted from 23andMe's systems, the risk scores, disease predisposition classifications, ancestry inferences, and pharmacogenomic profiles derived from that data and incorporated into research datasets, pharmaceutical models, and third-party analytical systems do not delete with it. Derived inferences persist beyond the deletion of the source data that produced them. The person whose DNA is in the 23andMe database had no remedy that the legal system could guarantee for either the raw data or its derivatives. They had a suggestion.
Apple Watch and Apple's HealthKit ecosystem represent the largest consumer health data collection infrastructure in the United States by active device count. Apple does not disclose HealthKit participation figures or health data revenue as separate line items in its financial reporting. What it discloses is device revenue: Apple Watch is among the top-selling wearable devices globally, with an installed base estimated at over 100 million active devices worldwide. Every one of those devices generates continuous physiological monitoring data that flows into HealthKit, Apple's health data aggregation platform, and from there into the broader Apple ecosystem whose commercial value is embedded in advertising, product development, and AI training infrastructure. The system produces this outcome regardless of Apple's public positioning on privacy. The data flows because the infrastructure exists and the classification of biological participation data as consumer telemetry rather than health data places it outside the regulatory constraints that would otherwise govern its use.
The Google acquisition of Fitbit, completed in January 2021 for $2.1 billion, provides the clearest disclosed valuation of a health data platform available from primary sources. Fitbit had approximately 29 million active users at the time of the acquisition. Dividing the $2.1 billion acquisition price by the active user base produces a per-user asset valuation of approximately $72. This figure is not a revenue figure. It is an acquisition price figure, which means it represents what Google was willing to pay for access to each active user's health behavioral record as a commercial asset. It is not a pure data valuation: the acquisition price reflects brand value, hardware infrastructure, distribution relationships, and engineering capability alongside the data asset. The per-user figure should be read as an acquisition-price proxy for health data asset value, not as a precise measure of what each user's data is worth in isolation. It is included because it is the only disclosed transaction that assigns a specific dollar value to a health data platform's user base from a primary source.
Biological data assembled through wearable devices does not remain within the platform that collected it. Between platform collection and commercial application sits an intermediate market: health data brokers, de-identified dataset aggregators, and pharmaceutical data licensing ecosystems that routinely package, layer, and redistribute biological participation data in forms that are commercially available to insurers, pharmaceutical companies, employers, and researchers. Once biological participation data enters this intermediate market, the original platform relationship becomes irrelevant to its movement. The data does not carry the platform's boundaries with it. It carries only its content. The movement of data through this intermediate market is the mechanism through which platform-collected health data reaches the underwriting and targeting systems that produce the commercial consequences this paper documents. Health data that has been de-identified at the platform level does not remain de-identified through this process. Longitudinal wearable data and genetic data are not merely re-identifiable in theory. In practice, the accumulation of physiological patterns, location signals, and demographic proxies across time produces a fingerprint whose resolution to a specific individual becomes a matter of when, not whether, as cross-dataset linkage capabilities improve and the dataset grows.
Peloton Interactive generates biometric and performance data from connected fitness equipment used by approximately 3 million active subscribers. Every Peloton session captures cardiovascular response, workout intensity, power output, cadence, recovery patterns, and longitudinal fitness trajectory across months and years of use. The resulting dataset is a detailed record of a subscriber's physical capacity, cardiovascular health, and fitness behavior over time. Peloton discloses subscription revenue but does not disclose the commercial value of the behavioral and biometric data its platform assembles. The dual transaction structure is present and undisclosed at the level the formula requires.
Period tracking applications collect reproductive health data from tens of millions of users. Flo Health, one of the largest period tracking platforms, reported over 70 million monthly active users globally as of 2023. Clue, Glow, and Natural Cycles operate at comparable scale in their respective markets. These applications capture menstrual cycle regularity, fertility signals, ovulation timing, pregnancy status, sexual activity, symptom patterns, and in some cases hormone level data from connected testing devices. The data is generated through self-reporting and through behavioral inference, and it accumulates over months and years into a longitudinal reproductive health record whose commercial value extends into fertility treatment targeting, pharmaceutical advertising, and insurance underwriting.
The post-Dobbs legal environment introduced a consequence for reproductive health data that no prior participation domain in this series had faced at the time of Paper Eight's composition. Following the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization in June 2022, which eliminated the federal constitutional right to abortion, multiple states enacted laws criminalizing abortion-related conduct. In those jurisdictions, reproductive health data retained by a period tracking application constitutes potential evidence of conduct that may be subject to criminal prosecution. The person who contributed menstrual cycle and pregnancy data to a wellness application did not contribute it as a legal record. The platform that retained it may be compelled to produce it as one. Several states have enacted specific protections for reproductive health data in response to this risk, including Washington's My Health MY Data Act enacted in 2023. Those protections are not uniform and do not cover every jurisdiction in which the legal risk exists.
Mental health applications including BetterHelp, Talkspace, Calm, and Headspace capture psychological state, therapy session content, stress patterns, and emotional health indicators from users who engage with them specifically because they are experiencing difficulty. BetterHelp reached a settlement with the Federal Trade Commission in March 2023 for $7.8 million, following FTC findings that the company had shared users' mental health data with Facebook and Snapchat for advertising targeting purposes. The users who shared their mental health status with BetterHelp did so in the context of seeking therapeutic support. The platform used that data to target them with advertising. The FTC settlement documented the mechanism on the public record. It did not establish the users as recognized origins of the data whose commercial application the settlement addressed.
The Health Insurance Portability and Accountability Act governs covered entities: hospitals, insurers, and healthcare providers, and their business associates. It does not govern consumer wellness applications, fitness trackers, or direct-to-consumer genetic testing companies unless those companies operate as business associates of covered entities under formal contractual arrangements. The regulatory gap is structural, documented in FTC guidance and academic literature, and consequential for the majority of biological participation data generated through consumer platforms.
The fault line operates as follows. A person who wears an Apple Watch and whose cardiologist uses an Apple Health Records integration has health data in two regulatory environments simultaneously. The cardiac data transmitted to the cardiologist's electronic health record system is protected health information subject to HIPAA's access, retention, and disclosure requirements. The same cardiac data on the Apple Watch is consumer wellness data governed by Apple's privacy policy and subject to no equivalent federal protection. The cardiologist cannot share the EHR data with an advertiser without violating HIPAA. Apple can use the HealthKit data to inform product development, advertising targeting, and AI training under terms that satisfy Apple's privacy policy rather than HIPAA's requirements.
The core failure that this fault line reveals is a system property, not a regulatory oversight: HIPAA attaches regulation to the institution that holds the data, not to the data itself. When the same biological signal moves from a covered institution into a consumer platform, the regulatory protection does not travel with it. The data changes hands. The coverage does not. That is not a loophole that platforms exploit around the margins of a framework designed to cover them. It is the structural consequence of a regulatory framework written in 1996 for a healthcare system in which consumer biological data collection at scale did not exist. HIPAA's coverage was designed around the covered entity relationship because that was where health data lived. Consumer wearables, wellness apps, and direct-to-consumer genetic testing have created an entirely new category of health data that lives outside the covered entity relationship, is generated at greater scale than clinical data, and carries commercial value that the clinical system has never matched.
Remote patient monitoring represents the most acute version of the fault line. A patient with a chronic condition who is monitored remotely through connected devices generates clinical participation data as a condition of their medical care. That data flows through platforms that may be covered entities, business associates, or consumer technology companies depending on the specific architecture of the monitoring system. The regulatory coverage follows the contractual structure rather than the clinical purpose. Data generated in the service of medical care may or may not be protected depending on which company's infrastructure it passes through.
The Introduction to this series established four conditions whose simultaneous presence is required for participation to function as voluntary exchange: survivable refusal, recognized standing, transparency of terms, and independent jurisdiction. Paper Eight applies those conditions to a domain where they fail in ways that are specific to biological participation and that no prior paper has documented.
Survivable refusal does not fail uniformly across this domain. A person who declines to use a period tracking application retains survivable refusal for that platform. The social and practical cost of that refusal is low. A person who requires remote patient monitoring as a condition of managing a chronic health condition does not retain survivable refusal in any meaningful sense. Declining monitoring means declining care. A person who submitted a genetic sample to 23andMe exercised a voluntary choice at the moment of submission. After that moment, survivable refusal became structurally unavailable because the data cannot be ungenerated. The sample was processed, the profile was built, and the dataset exists independently of any subsequent decision the contributor makes about their relationship with the platform. In this domain, survivable refusal operates as a window that closes permanently at the moment of biological contribution.
The irreversibility that closes that window operates across three distinct failure modes that should not be conflated. Biological irreversibility means the underlying reality the data describes cannot change: genetic sequences are fixed at birth, and the predispositions, ancestry, and pharmacogenomic profiles they encode exist regardless of whether a dataset holds them. Data persistence means that stored biological datasets outlive the commercial relationship that produced them, surviving platform failure, acquisition, and bankruptcy as transferable assets. Inference permanence is the third and most underappreciated failure mode: even if raw biological data is deleted from a platform's systems, the risk scores, disease classifications, ancestry inferences, and behavioral predictions derived from that data persist in the research systems, actuarial models, and commercial datasets into which they have been incorporated. Deletion of source data does not retract derived inferences. The person who requests deletion of their data from a platform closes one window. The inferences drawn from that data before deletion continue to operate in systems the platform does not control and the person cannot reach.
Recognized standing fails completely and more consequentially than in any prior paper in the series. Behavioral data describes what a person does. Biological data describes what a person is. A platform that holds a person's genetic profile, cardiac history, and reproductive record holds a more complete and more permanent model of that person than any behavioral dataset can produce. The person has no recognized standing as the origin of that model, no claim on the asset their biology constitutes, and as the 23andMe case documents, no ability to prevent that asset from being transferred to an unknown owner in a legal proceeding to which they were never a party.
Transparency of terms fails at the most fundamental level available in this series. No disclosure at the point of biological data collection establishes what that data is worth in insurance underwriting markets, pharmaceutical research partnerships, or the asset valuations of companies that may subsequently go bankrupt. The 23andMe customer who submitted a saliva sample in 2015 was not informed that their genetic profile would be included in a $300 million drug development partnership with GlaxoSmithKline in 2018, or that it would be identified as a primary asset of a bankruptcy estate in 2025. The terms of service they agreed to permitted these uses in language sufficient to satisfy legal disclosure requirements. They did not produce the transparency the PDR framework requires.
Independent jurisdiction is formally present and substantively inadequate. HIPAA provides enforcement mechanisms for covered entities. The FTC provides enforcement authority for consumer wellness platforms under its unfair and deceptive acts and practices authority, as demonstrated in the BetterHelp settlement. State laws including Washington's My Health MY Data Act and the Illinois Genetic Information Privacy Act provide additional protections in specific jurisdictions. None of these frameworks recognize the person as the origin of the biological data they generate or establish any mechanism through which that recognition could produce standing in the commercial arrangements the data enables. They address unauthorized use. They do not address unrecognized origin.
The PDR formula established in the Introduction to this series produces a per-user participation value baseline from disclosed financial data. In the biological participation domain, the formula faces a measurement challenge more acute than in any prior paper. Health data platforms do not disclose per-user data revenue with the granularity the formula requires. This domain requires valuation through transactions rather than operations, because the commercial value of biological participation is not expressed in disclosed operating revenue. It is expressed in acquisitions and research partnerships, where a third party assigns a specific price to access the dataset the platform assembled. What those transactions price is access to the aggregate dataset, not the contribution of any individual whose biology constitutes it. The market has assigned value to the collection while declining to recognize the origin of any single element within it. That methodological shift is not a limitation of the analysis. It is a finding: biological participation data is valued in markets that do not report per-user figures because those markets are structured around dataset access rather than individual contribution.
In the Origin Economics framework, Y = λ · f(H, K, T) expresses output as a function of human-origin participation, capital, and technology, multiplied by whether the legitimacy conditions of the exchange were satisfied. Lambda fails before the first heartbeat is recorded. The wearable device begins capturing physiological data the moment it is worn. The genetic testing company begins building a commercial asset the moment the saliva sample is processed. In neither case did the person establish legitimacy conditions before data collection began. In neither case were those conditions on offer.
The Google acquisition of Fitbit for $2.1 billion in January 2021 provides the primary valuation anchor for this paper. Fitbit had approximately 29 million active users at the time of acquisition. The acquisition price divided by the active user base produces a per-user asset valuation of approximately $72. This figure represents what Google paid per active user for access to Fitbit's health behavioral dataset as a commercial asset. It is an acquisition-price proxy, not a revenue measure, and it reflects brand, hardware, and engineering value alongside the data asset. It should be read as a floor indicator of health data asset value per user rather than as a precise measure of what each user's health record is worth in isolation. It is the only disclosed transaction that assigns a specific dollar value to a health data platform's user base from a primary source available for this paper.
The GlaxoSmithKline partnership with 23andMe, valued at $300 million in 2018 and structured around access to 23andMe's genetic database for drug target research, provides a second valuation reference. At the time of the partnership, 23andMe had approximately 5 million genotyped customers. The $300 million partnership value divided across that user base produces a per-profile research value of approximately $60 per customer. This figure represents what a major pharmaceutical company paid for research access to genetic profiles, not what the profiles are worth in the full range of commercial applications they enable. It is a partial measure of a partial transaction. It is included because it is a disclosed, primary-source transaction that assigns a specific value to genetic participation data as a research asset.
The PDR baselines for this paper are anchors rather than floors in the precise sense established in earlier papers. The Fitbit acquisition proxy of approximately $72 per user and the GSK partnership proxy of approximately $60 per profile represent confirmed commercial valuations of biological participation data from disclosed primary source transactions. They do not represent the total value platforms realize from biological participation across insurance underwriting, pharmaceutical targeting, advertising, and AI training. The gap between these figures and the full commercial value of biological participation data is not calculated to precision. It is established as present, substantial, and entirely outside any accounting that recognizes the person as the origin of the data whose value those transactions confirm.
The health benefit objection holds that wearables improve health outcomes, period tracking applications help people understand their bodies, genetic testing provides medically actionable information about disease risk, and remote monitoring enables care for patients who would otherwise lack it. Each of these claims is accurate. None address the misclassification argument. The question the PDR framework asks is not whether biological participation platforms deliver value to their users. It is whether the person is recognized as the origin of the biological data their participation generates and whether they have standing in the commercial arrangements that data enables. A person whose Apple Watch detects an atrial fibrillation episode and prompts them to seek medical care has received genuine health value. They have simultaneously contributed years of continuous cardiac monitoring data to Apple's commercial ecosystem without recognition as its origin. The benefit and the misclassification are not mutually exclusive. They are simultaneous features of the same transaction.
The consent objection holds that users agreed to terms of service governing data collection and use, and that this agreement constitutes sufficient authorization for the commercial applications documented in this paper. The consent objection fails on the same grounds it has failed in every prior paper, with an additional observation specific to biological participation. The 23andMe customer who agreed to terms of service in 2015 agreed to terms that did not contemplate a $300 million pharmaceutical research partnership, a bankruptcy filing, or a proposed sale of their genetic profile to an unknown acquirer. Terms of service that authorize data use in general language sufficient to encompass commercial applications not disclosed at the time of agreement do not constitute the transparency that the PDR framework requires. They constitute legal cover for a transaction the person was never genuinely informed about.
The regulatory protection objection holds that HIPAA protects health data and that existing frameworks are adequate for the participation domain this paper documents. As Section Six establishes, HIPAA provides partial coverage for a portion of the biological participation domain. It does not cover consumer wellness applications, fitness trackers, or direct-to-consumer genetic testing companies outside the covered entity relationship. The majority of biological participation data generated through the platforms documented in this paper is generated outside HIPAA's coverage. Partial coverage of a unified domain is not adequate protection for that domain.
The biological participation domain faces regulatory exposure across several frameworks, none of which addresses the foundational misclassification this paper documents.
The FTC's enforcement action against BetterHelp, resulting in a $7.8 million settlement in March 2023, established that the FTC will pursue consumer wellness platforms for unauthorized disclosure of mental health data to advertising networks. The action documented on the public record that BetterHelp shared users' mental health status with Facebook and Snapchat for advertising targeting purposes, in violation of the company's representations to users about how their data would be used. The settlement addressed the unauthorized disclosure. It did not establish the users as recognized origins of the mental health data whose commercial application the settlement addressed.
The FTC's health breach notification rule, strengthened in 2024, requires health apps and connected device companies to notify users and the FTC when the security of individually identifiable health information is breached. The rule extends notification obligations beyond HIPAA-covered entities to consumer health platforms. It addresses the security of health data after collection. It does not address the misclassification of biological participation data as a corporate asset at the point of collection.
State reproductive health data protection laws enacted post-Dobbs represent the most direct legislative response to a specific biological participation risk documented in this paper. Washington's My Health MY Data Act, enacted in 2023, establishes consent requirements for the collection and sharing of consumer health data including reproductive and sexual health information. California, Connecticut, and Nevada have enacted related protections. These frameworks address consent and disclosure for specific categories of health data in specific jurisdictions. They do not establish a national framework and do not recognize the person as the origin of the biological data they generate.
The Illinois Genetic Information Privacy Act requires informed consent for genetic testing and prohibits the use of genetic information for employment, insurance, and other decisions without consent. It is the most comprehensive state-level genetic data protection framework in the United States. It does not address the asset classification question the 23andMe bankruptcy exposed: that genetic data, once collected under a consent framework, can be transferred through bankruptcy proceedings to entities whose commercial intentions were not part of the original consent.
The 23andMe bankruptcy proceedings prompted the California Attorney General to issue a public advisory recommending that customers delete their data before the sale completed. The advisory acknowledged that deletion requests might not be honored by a bankruptcy trustee whose legal obligations run to creditors rather than to data subjects. It did not address the inference permanence problem: even if raw data is deleted, derived inferences already incorporated into research and commercial systems remain. The advisory is the most direct official acknowledgment available that the legal framework governing biological participation data does not protect the person whose biology constitutes it at the moment when protection is most consequential.
The PDR calculation in this paper rests on the Fitbit acquisition proxy and the GSK partnership proxy as valuation anchors. It does not include the following biological participation categories. Each generates health data whose commercial value is not attributable to individual participants at the level the formula requires. Their exclusion is methodological. Their participation is real.
Employer wellness programs collect biometric data from employees as a condition of health insurance premium reductions. Employees who participate in biometric screening, fitness tracking, or health coaching programs contribute biological data to commercial systems under terms that tie their participation to financial incentives they cannot afford to decline. The participation is nominally voluntary and structurally coerced by the premium differential.
Pharmaceutical company data acquisition programs purchase health behavioral data from consumer platforms, wellness applications, and data brokers to identify patient populations, target clinical trial recruitment, and calibrate marketing for specific drug categories. The person whose health data was purchased for pharmaceutical targeting is not a party to that transaction.
Life insurance underwriting systems use health behavioral data from wearables and wellness applications to assess mortality risk and price policies. John Hancock operates a program called Vitality that offers premium reductions to policyholders who share fitness tracker data. The policyholder who shares that data to receive a discount is generating a longitudinal health behavioral record whose value to the insurer's underwriting model extends beyond the discount they received.
Clinical trial recruitment platforms use health data to identify and target potential participants based on specific biological criteria. The person whose health data was used to identify them as a trial candidate is not recognized as the origin of the data that identified them.
Pharmacy benefit managers and retail pharmacy chains including CVS and Walgreens operate data monetization programs built on prescription purchase behavior, combining medication history with demographic and behavioral data to create commercial health profiles sold to pharmaceutical companies and insurers.
Hospital system behavioral analytics, including patient portal engagement patterns, appointment scheduling behavior, and care navigation data, are sold or licensed to commercial partners for population health management and pharmaceutical marketing purposes under business associate agreements that satisfy HIPAA's technical requirements while enabling commercial applications that patients did not anticipate when they accessed their medical records.
The floor is not the number. It is the portion that has been disclosed.
Every prior paper in this series documented the capture of what people do. Paper Eight documents the capture of what people are. The biological record assembled across this domain is not a profile of behavior that reflects choices the participant made. It is a record of existence: their genetics, their cardiac function, their reproductive state, their psychological patterns, their sleep architecture, their physiological response to exertion and rest. The person who generated that record has no recognized standing in any commercial arrangement it enables, no claim on the asset their biology constitutes, and in the case of 23andMe, no ability to prevent that asset from being transferred to an unknown owner in a bankruptcy proceeding they were never a party to.
The misclassification this series documents reaches its most consequential form in this domain. In Papers One through Seven, the data documented behavior. In Paper Eight, the data is the person. The participant is not unrecognized as the origin of something they produced. They are unrecognized as the origin of something they are. And the system does not require their individual standing to function. It requires only their bodies, in sufficient number, to constitute a dataset worth holding.
Running total after Paper Eight. Add only the lines that apply to you.
If you use a wearable device or health platform
Fitbit acquisition proxy: approximately $72 per active user at time of Google acquisition, January 2021. This is an acquisition-price indicator, not a revenue measure. It represents what Google paid per active user for the health behavioral dataset as a commercial asset.
GSK partnership proxy: approximately $60 per genotyped profile at time of 23andMe partnership, 2018. This is a research access indicator. It represents what a pharmaceutical company paid per profile for drug development research access to genetic participation data.
These figures are valuation anchors, not baselines in the sense established in Papers One through Six. They confirm that biological participation data is valued as a commercial asset in transactions where a third party assigns a specific price to dataset access. They do not represent the full commercial value of biological participation across insurance underwriting, pharmaceutical targeting, advertising, and AI training. The data brokerage layer through which biological participation data reaches those markets operates between platform collection and commercial application and does not disclose per-participant figures at the level the formula requires.
Net effect: unrecognized contribution to commercial systems whose value to acquirers and research partners is confirmed at the transaction level and undisclosed at the individual participation level.23andMe, Inc., Chapter 11 bankruptcy filing, United States Bankruptcy Court, Eastern District of Virginia, March 2025.
California Attorney General, public advisory regarding 23andMe data deletion, March 2025. oag.ca.gov.
GlaxoSmithKline plc and 23andMe, Inc., drug development partnership announcement, July 2018. Value confirmed at $300 million. gsk.com.
Google LLC, acquisition of Fitbit, Inc., completed January 14, 2021. Acquisition price $2.1 billion confirmed from Alphabet Inc. press release and SEC filings.
Federal Trade Commission, In the Matter of BetterHelp, Inc., File No. 2023-0019. Settlement order and $7.8 million redress, March 2, 2023. ftc.gov.
Federal Trade Commission, Health Breach Notification Rule, revised final rule, 2024. ftc.gov.
Washington State Legislature, My Health MY Data Act, Chapter 70.372 RCW, enacted April 2023.
Illinois Genetic Information Privacy Act, 410 ILCS 513, enacted 1998, as amended.
Dobbs v. Jackson Women's Health Organization, 597 U.S. 215, 2022.
Apple Inc., HealthKit developer documentation and privacy framework. developer.apple.com.
Flo Health, Inc., user statistics and platform disclosures, 2023. flo.health.
Insurance Information Institute, usage-based insurance and telematics program data, 2024. iii.org.
Imanol Arrieta-Ibarra, Leonard Goff, Diego Jiménez-Hernández, Jaron Lanier, and E. Glen Weyl, Should We Treat Data as Labor? Moving beyond Free, AEA Papers and Proceedings 108, 2018, pp. 38–42.
Eric Posner and E. Glen Weyl, Radical Markets: Uprooting Capitalism and Democracy for a Just Society, Princeton University Press, 2018.
Shoshana Zuboff, The Age of Surveillance Capitalism, PublicAffairs, 2019.