Over 60 million records related to wearables and fitness trackers were exposed online from an unsecured database.
See also: Pandemic: How has wearable technology helped athletes?

On Monday, WebsitePlanet, along with cybersecurity researcher Jeremiah Fowler, reported that the database belonged to GetHealth.
GetHealth, described as a “unified solution for accessing health and wellness data from hundreds of wearable medical devices and apps,” is able to pull health-related data from sources such as Fitbit, Misfit Wearables, Microsoft Band, Strava, and Google Fit.
On June 30, 2021, the team discovered a database online that was not password protected.
Researchers said that over 60 million records were included in the data repository and were exposed, including vast amounts of user information, some of which could be considered personal such as their names, dates of birth, weight, height, gender and GPS logs, among other datasets.
See also: Wearable device turns your body into a "biological battery"!

When sampling a set of approximately 20,000 records to verify the data, the team found that the majority of data sources came from Fitbit and Apple.
References to GetHealth in the database indicated that the company was the likely owner, and once the data was validated on the day of the discovery, Fowler privately notified the company of his findings. GetHealth responded quickly and the system was secured within hours. That same day, the company’s CTO reached out, informed him that the security issue had now been resolved, and thanked the researcher.
See also: Europe and America are concerned about Google's purchase of Fitbit
“It is unclear how long these files were exposed or who else may have had access to the dataset,” WebsitePlanet said. “[…] We do not imply any wrongdoing by GetHealth, its customers, or its partners. Nor do we imply that any customer or user data was compromised. We were unable to determine the exact number of individuals affected before the database was restricted from public access.”
