MFMac is delighted to once again be part of this exciting week-long programme of events when it hosts Innovation, Regulation and Real-Time Health Monitoring on Monday 7 September 2026, a panel discussion bringing together our experts to explore the commercial opportunities and legal risks arising from wearable health technologies.
Healthcare Revolution
Wearable health technology is making real-time monitoring increasingly mainstream. Devices that once sat firmly in the consumer wellness space are increasingly capable of continuous monitoring. This creates exciting opportunities for earlier intervention and personalised care, but also raises a difficult question across the product lifecycle: where is the risk?
Wearables – devices worn on the body to monitor health (such as smart watches, blood glucose sensors and sleep monitors) – sit at the intersection between innovation and healthcare. For businesses developing these tools, the question is not just whether the technology works, but whether there are sufficient safeguards incorporated in its design to nurture public trust and, in turn, allow the product to scale responsibly.
The direction of travel is clear. From diabetes to anxiety, healthcare is moving from reactive treatment towards continuous monitoring where physiological data is extracted from the body via wearable technologies to flag changes before a patient seeks help. That creates commercial opportunity, particularly in remote monitoring, chronic disease management, prevention and NHS redesign.
This is where navigating the legal and regulatory landscape starts to matter. For businesses in this space, regulation is not a brake on innovation: it is often what makes adoption possible. Those that can show robust governance and regulatory awareness will be better placed to build trust with healthcare providers, NHS procurement teams, patients and investors.
This is why adopting a proactive understanding of the regulatory environment is so important, especially given the potential opportunities that may arise through upcoming reforms to boost experimentation and relax certain measures through the Regulation for Growth Bill (as announced in the King's Speech 2026).
Navigating The Regulatory Landscape
MFMac's Innovation, Regulation and Real-Time Health Monitoring event will therefore probe key areas of regulation in the wearables space, giving innovators practical insight into how best to harness the rules governing the sector to develop a successful product.
Product Classification
A foundational issue is establishing the classification of a wearable product in a particular jurisdiction. In the UK, this primarily turns on whether the wearable is classed as a medical device: broadly, a product intended to diagnose, monitor, prevent or treat a medical condition, and therefore regulated by the MHRA.
Should a product be considered a medical device, it will be subject to stricter market-entry checks and certification measures, together with continued market surveillance, by the MHRA. This classification not only creates additional ongoing obligations for the manufacturer of the wearable but permeates throughout the product ecosystem by imposing stricter duties on others including importers, retailers and medical practitioners.
But the line is not always clear. A product that merely records data, rather than delivering medical assessments, may fall outside the medical-device regime. However, that does not mean the legal risk falls away. Whatever the product’s classification, wearable health technologies sit within a wider web of regulatory obligations.
Data Protection
One of the most significant of those obligations is data protection, not least because confidence in a wearable product will often depend on how responsibly it collects, uses and protects health data.
Wearables generate highly sensitive health data, often across connected platforms and third-party integrations. Under the UK GDPR, this will usually be special category data, attracting heightened obligations. Organisations operating in this space must be clear about who controls the data, who can access it, what users understand they are agreeing to and how that data may be used for product development, research, service delivery or clinical decision-making.
What is more, many wearables have an international dimension, with data moving across cloud infrastructure around the world. For businesses seeking healthcare partnerships, particularly with NHS bodies, those cross-border data flows need to be governed properly to demonstrate an awareness of regulatory duties (not least if said data is being used for AI model training).
Cyber Security
Cyber security is also moving from being considered an operational concern to an urgent patient safety issue. If a device or connected platform is hacked, the consequence may not simply be business disruption or data loss: it could affect underlying patient monitoring mechanisms and, more generally, trust in the product itself.
Of course, regulatory oversight of cyber security and data protection is intrinsically linked. The strong multi-jurisdictional response to 23andMe's cyber security breaches a few years ago serves as a stark warning to controllers who fail to protect biological and ancestry data, with the company being the subject of considerable regulatory fines and claims from individuals affected around the world.
That scrutiny is only likely to intensify. As vulnerability-seeking AI models grow more capable of probing and attacking digital infrastructure, connected health technologies will become increasingly attractive targets: not only because of the sensitive data they hold, but because clinical decisions, patient safety and user trust may all depend on their continued security.
Liability
Given the risks associated with holding sensitive data, innovators also need a clear view of what happens when things go wrong. For developers and manufacturers of wearables, understanding rights of redress is a proactive commercial strategy.
It helps businesses anticipate where liability may arise, design safer products and allocate risk across contracts. Potential exposure may cut across consumer rights, product liability, negligence, data protection claims and MHRA scrutiny. For cross-border manufacturers, the EU’s new Product Liability Directive adds another important layer (as explored in our previous article: Medical devices and product liability: Manufacturers, get ready).
Register Your Place
Using wearable healthcare technology as a practical case study, MFMac's Glasgow Tech Week event on Innovation, Regulation and Real-Time Health Monitoring will examine how data protection, cyber security and product liability risks shape innovation across the product lifecycle.
With contributions from Jude McCorry, CEO of Cyber Fraud Centre Scotland, alongside Melissa Hall and Michael Vaughan, Legal Directors at MFMac, this discussion will draw on perspectives from the technology, healthcare and life sciences sectors, exploring key issues including:
Data ownership and governance within connected health ecosystems
Cross-border data protection and information sharing
Cyber security risks and their implications for patient safety
Responsibility and liability when monitoring technologies are defective or cause harm
The role of governance in supporting innovation and adoption
Find out more and register here.
This article has been co-authored by Josh Chambers, Trainee Solicitor.


