The chain that formed while nobody wrote it down
Ultrahuman announced a $70 million raise on 4 September 2026 to expand its health intelligence platform, with Qualcomm Ventures and Verlinvest named among the lead investors in that day's Indian funding roundup. The capital is going into interpretation, not just sensing: rings and bands that already measure heart rate variability, sleep stages, skin temperature and blood oxygen are being pushed toward telling the wearer what those readings mean.
That shift matters because wearables have stopped being a personal purchase. HR teams now bundle rings and bands into corporate wellness programmes, often in the same procurement cycle as the group mediclaim renewal, and increasingly with an insurer willing to discuss a participation-linked credit if enough employees wear the device and share aggregate data.
Four parties are now standing in a line that nobody has drawn on paper:
- The employee acts, or fails to act, on an algorithmic health signal.
- The employer selected, paid for and distributed the device, and framed it as a benefit.
- The insurer offered a premium credit conditioned on device participation.
- The manufacturer disclaims medical use in its terms and positions the output as wellness information.
When the signal is wrong in a way that produces harm, whether that is a missed cardiac event, a false alarm that triggers an expensive and unnecessary hospitalisation, or an employment decision taken on the back of a wellness score, each party's first move will be to point at the party next to it. The contracts that would settle the argument, in most Indian corporate wellness programmes, do not currently address it.
What the device maker carries when the reading is wrong
The Consumer Protection Act, 2019 created a statutory product liability regime covering product manufacturers, sellers and service providers. A manufacturer can be held liable for a manufacturing defect, a design defect, a deviation from manufacturing specifications, non-conformance with an express warranty, or inadequate instructions and warnings. That last limb is the one wearable makers should read closely, because the claim in a wearable dispute is rarely that the hardware failed. It is that the interpretation layer said something misleading, or failed to say something the device had measured.
Every serious brand answers this with a disclaimer: the product is a wellness device, not a medical device, and its outputs are not intended to diagnose, treat, cure or prevent any condition. The disclaimer does real work. It is not a complete answer, for three reasons.
- A disclaimer buried in terms of service sits uneasily against marketing that promises health intelligence and early warning. Indian consumer forums read the representation and the disclaimer together.
- The stronger the interpretation layer becomes, the harder it is to argue the output was never meant to be relied on. A raw heart-rate number is data. A notification saying cardiovascular strain is elevated is advice.
- In a corporate programme, the employee did not read the terms at purchase.
For the device maker, the insurance answer is a product liability programme underwritten for a health-adjacent technology product rather than a generic consumer electronics item, with the recall, defence-cost and inadequate-warning limbs examined line by line. Indian consumer hardware startups routinely find at claim stage that their liability cover was priced as electronics and worded for physical injury from a physical defect. The same gap runs through D2C product liability programmes, where the exposure has moved from the object to the claim made about it.
The employer paid for it, which is where duty of care attaches
An employer that hands an employee a device, tells them it monitors their health, and links it to an insurance benefit has done something more than pass along a consumer gadget. It has made a health-related intervention inside the employment relationship.
Three exposures follow, and they sit in different parts of an insurance programme.
Duty of care and occupational health
Once a wellness programme surfaces a health signal, what the employer did with that signal becomes a live question. Ignoring a flagged risk in a safety-critical role is one problem. Acting on it without clinical validation is a different one. Shift-based manufacturing, logistics and healthcare operations are most exposed, because fatigue and cardiac signals interact directly with rostering decisions.
Employment practices exposure
The moment wellness data reaches a manager, it becomes capable of influencing promotion, appraisal, role allocation and separation decisions. Employment practices liability cover in the Indian market is usually bought as an extension to a directors and officers programme or as a standalone employment practices wording, and its trigger is an employment-related wrongful act. A claim that a role change followed an employee's health score is exactly that. Very few Indian employment practices wordings currently say anything about algorithmically derived health data, which means the argument will be fought on general terms rather than on a drafted allocation.
The third piece is the vendor contract. Most employers sign the vendor's standard master services agreement unamended. Those agreements cap vendor liability at fees paid, exclude indirect loss and disclaim reliance on outputs. An employer who accepts that has taken the residual risk of the whole chain while also paying for the device.
DPDP turns wellness data into a compliance object
India's Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, with full compliance required by 13 May 2027 and penalties reaching up to Rs 250 crore. That timeline is the operative deadline for every corporate wellness programme running today, because a programme designed in 2026 will still be running when the obligations bite.
The Indian statute does not carve out a separate sensitive-data tier for health information the way some foreign regimes do. Health data from a wearable is digital personal data, and the ordinary obligations apply: a clear notice, consent that is free, specific, informed and unconditional, purpose limitation, retention limits, and the ability to withdraw consent as easily as it was given.
Two structural questions decide whether a corporate wellness programme survives review.
Who is the data fiduciary? If the employer specifies what is collected and why, the employer is making purpose decisions and cannot describe itself as a passive beneficiary. If the wearable maker independently uses the data to improve its models, it is a fiduciary for that purpose in its own right. Programmes commonly assume a single fiduciary and a single processor. The reality is often two fiduciaries with overlapping duties and no written allocation between them.
Is consent inside an employment relationship free? An employee asked to wear a device to unlock a premium credit is being offered a benefit conditioned on data sharing. Employers who want that to hold should be able to show a real non-wearable route to the same benefit and no manager visibility into who declined.
The practical control is the one that already governs health-screening programmes: the employer receives cohort-level statistics, never individual readings. Insurers running their own DPDP implementation are building consent artefacts, retention schedules and breach playbooks along the same lines, and a broker sitting between the two should be checking that the insurer-side DPDP implementation and the employer-side wellness consent describe the same data flow. Where they do not match, the mismatch is the finding.
Does the premium credit survive a dispute about the data behind it?
Wellness-linked pricing in Indian group health takes three broad shapes, carrying different risk when the underlying data is challenged.
- A soft credit at renewal. The insurer takes wellness participation into account alongside claims experience, without a stated formula. Low risk, low value, and the least likely to be honoured when the claims ratio deteriorates.
- A stated participation threshold tied to a defined credit. The wording names a participation percentage, a verification method and a percentage adjustment. This is where the exposure sits.
- An individual-level reward mechanism. Employees earn wellness points that convert to benefit enhancements, the hardest structure to run cleanly under data-minimisation obligations.
Structure two is the one worth stress-testing. Ask three questions of the policy wording and the credit endorsement:
- Who verifies participation, and against what record? If the answer is the wellness vendor's dashboard, the insurer is pricing on a number produced by a party with a commercial interest in the number being high, and no audit right.
- What happens if participation is later found to be overstated? Silence here does not mean nothing happens. It means the insurer will argue misrepresentation of a material fact, and the dispute will be about disclosure rather than about a stated remedy.
- Is the credit a discount to the premium or an adjustment to the renewal rating? The two behave differently when the account moves to another insurer, and only one survives a mid-term restructure of the covered population.
The cleanest drafting states the participation definition, names the verification source, gives the insurer an audit right over aggregate data, and specifies a proportionate clawback rather than leaving the remedy to general law. A credit tied to a headcount that moves monthly also needs the same endorsement rhythm as any other member movement, so group mediclaim administration discipline has to extend to the wellness endorsement.
Work linking screening participation to group mediclaim loss ratios shows underwriters will credit verified participation trends when the verification is independent. Wearable participation is the same argument with a weaker verification chain, which is why the wording has to carry more weight.
Where the regulator is heading on algorithmic health signals
IRDAI announced a seven-member working group on artificial intelligence on 19 June 2026, chaired by Sandeep Shukla of IIIT Hyderabad, with a three-month deadline to deliver recommendations. Its brief covers governance frameworks, safeguards and an AI audit framework, examining AI's impact on insurers, policyholders and the wider insurance system, with stated emphasis on ethical adoption, transparency and data security. Claims processing and fraud detection were named as the functions warranting closest attention first.
Two things follow for wellness-linked group health.
The first is sequencing. Underwriting inputs derived from consumer wearables are not the working group's opening priority, so an insurer offering a wearable-linked credit today is doing so without a specific framework to point at. That is a commercial freedom now and a retrofit obligation later.
The second is the shape of what is coming. A framework built around transparency, explainability and auditability will eventually reach any algorithm that changes what a policyholder pays or receives. A wellness score produced by a third-party device and fed into a premium adjustment is that kind of algorithm, even though it sits outside the insurer's own systems.
For brokers, the practical reading is to prefer participation-based credits over score-based credits for the next two renewal cycles. Participation is a countable fact. A score is a model output that someone will eventually have to explain.
Mapping the chain before the next renewal
Employers who already run a wearable-linked wellness programme, and brokers who placed the group health account under it, have a narrow window before the DPDP compliance deadline of 13 May 2027 turns drafting questions into regulatory ones. Put the four contracts side by side: the wearable vendor agreement, the wellness programme terms given to employees, the group mediclaim policy with its credit endorsement, and the employer's own liability programme. Then check six things.
- Allocation of liability for output error. Does any document say who carries the loss if the device's interpretation is wrong? If every document is silent, the answer defaults to whoever the employee sues first, which will be the employer.
- Vendor liability cap against programme size. A cap at fees paid on a 2,000-employee deployment is a cap at the device cost. Compare that to a single serious injury claim.
- Medical-device positioning. Confirm in writing what regulatory classification the vendor claims for the product in India and how it markets the interpretation layer here.
- Data flow diagram. One page showing what is collected, who holds it, who sees it identified, who sees it aggregated, and how long it is kept. If nobody can draw it, the DPDP notice is not accurate.
- Employment practices wording. Read the exclusions against a scenario where a manager acted on health information, and check whether privacy-related employment claims sit inside or outside the cover.
- Credit endorsement mechanics. Participation definition, verification source, audit right, clawback, and what happens on a mid-term population change.
The six checks take a working day. The exposure they map has no natural home in any single policy, which is why it is usually found only after a claim has already picked a defendant.
None of this requires anyone to decide whether wearables improve health outcomes. It requires the four parties in the chain to write down which of them carries the loss when the ring on an employee's finger is wrong.