The ONC recently released a report describing privacy and security gaps at non-HIPAA covered entities that collect health data. These entities collect large amounts of personal data from devices like fitness trackers but are not regulated by HIPAA privacy rules. This poses risks to individual privacy as data could be misused. The report also finds a lack of encryption and other security measures protecting this health information. It recommends increasing education about appropriate privacy policies and restrictions on how personal data can be used and shared.