What IRB and Informed Consent Language Do You Need for Passively Collected, Continuous Sleep Data?

A practical FAQ for clinical researchers, sleep scientists, epidemiologists, and digital health teams designing real-world wearable studies.

You have designed a wearable sleep study. Participants will wear a device every night for weeks or months, and it will stream movement, heart rate, and derived sleep stages in the background without any nightly prompt. Then your Institutional Review Board (IRB) asks the question you were hoping to answer with a single sentence: what does your consent form say about all of this? Passive, continuous physiological sensing does not fit the templates written for one-time blood draws or survey studies, and treating it as though it does is the most common way these protocols stall. This post walks through what the regulations actually require, why continuous passive collection is genuinely different, what the peer-reviewed evidence says about the specific risks, and a staged framework you can follow from design through ongoing governance.

The short version. High-resolution longitudinal biosignals are re-identifiable behavioral fingerprints; participants forget they are being monitored; and wearables routinely capture bed partners and household members. As a result, most well-designed studies of this kind land in expedited or full-board review rather than exempt status, and the consent form has to address continuity, re-identification, incidental findings, and third-party manufacturer data governance on top of the standard elements. The defensible design pattern is data minimization plus layered, dynamic consent: collect the least granular signal that answers your question, decide raw-versus-processed access deliberately, and disclose the real risks in plain language.

The regulatory floor is layered, not singular

There is no single statute that governs a wearable sleep study. Several regimes apply in parallel, and which ones bind you depends on who you are, who your participants are, and what the device is for.

The 2018 Common Rule (45 CFR 46)

For federally supported human-subjects research in the United States, 45 CFR 46.116 sets out the required elements of consent.1 The 2018 revision added two features that matter most for passive sensing. First, consent must “begin with a concise and focused presentation of the key information” (46.116(a)(5)), presented first, so a participant grasps the essentials before wading into detail. Second, a new ninth basic element (46.116(b)(9)) requires a statement about whether identifiers might be stripped and the data re-used or shared for future research without additional consent. That element is written almost precisely for banked biosignal data.

Broad consent (46.116(d)) is a separate, optional pathway for the storage, maintenance, and secondary use of identifiable data. It is attractive for long-lived cohorts but remains legally fragile and is not implemented by every institution, so confirm your IRB supports it before you build a protocol around it. A true waiver of consent runs through the four-part test in 46.116(f); you cannot simply omit inconvenient elements.

On review category: prospective, continuous, identifiable biosignal collection with re-identification and incidental-finding risks frequently exceeds the “minimal risk” threshold, which pushes a study toward expedited-at-best or full-board review. Exemption determinations cannot be self-certified by the investigator, and secondary-data studies still must be submitted to the IRB. If your argument for “exempt” rests on calling the data de-identified, the sections below explain why that argument is weak.

FDA (21 CFR 50 and 56)

When a wearable supports a clinical investigation of a drug, biologic, or device, FDA’s informed-consent (21 CFR 50.25) and IRB (21 CFR 56) regulations apply alongside, and sometimes instead of, the Common Rule. FDA’s final guidance on Digital Health Technologies (DHTs) for remote data acquisition in clinical investigations, issued in December 2023, clarifies that DHTs are defined by function, that consumer wearables and mobile apps count as DHTs, and it addresses technology selection, verification and validation, endpoint use, risk management, and data retention and protection. This is an actively developing area, so check for updated guidance before you submit.

HIPAA is narrower than most participants assume

HIPAA is actor-centered: it protects protected health information held by covered entities (providers, plans, clearinghouses) and their business associates. Consumer wearable and sleep data collected directly from participants through a manufacturer app for your study’s own purposes is generally not HIPAA-protected. It becomes protected health information only when it is created, received, or maintained by a covered entity or a business associate under a business associate agreement. This is a frequent misconception among participants and researchers alike, and your consent form should not imply HIPAA coverage that does not exist. State consumer-health-data laws, such as Washington’s My Health My Data Act, increasingly fill this gap.

The FTC Health Breach Notification Rule

The gap HIPAA leaves is partly filled by the Federal Trade Commission. Amendments to the Health Breach Notification Rule, published in May 2024 and effective July 29, 2024, clarify that the Rule reaches developers of health apps and connected devices not covered by HIPAA; they broaden the definition of a breach to include unauthorized disclosures, such as sharing data with advertising platforms, rather than only cyber-intrusions; and they require notice to affected individuals and to the FTC. Enforcement actions against consumer health apps have already followed. If your data flow touches a consumer app, this Rule is part of your compliance picture.

GDPR, for any EU participant

Sleep, heart-rate, and heart-rate-variability data are “data concerning health,” which is Article 9 special-category data under the GDPR. Processing is prohibited unless an Article 9(2) condition applies. For research, the two operational routes are explicit consent (9(2)(a)) or the scientific-research derogation (9(2)(j)) with Article 89(1) safeguards, layered on top of an Article 6 lawful basis.5 The European Data Protection Board has noted that for public-interest research, the research derogation may be safer than explicit consent, because a participant who consents can withdraw that consent mid-study. Core principles apply throughout: data minimization and purpose limitation, the right to erasure, and transparency. Legitimate interests cannot justify processing Article 9 health data.

Why passive continuous sensing is genuinely different

The regulations above were not written with months-long background physiological streams in mind. Five features of passive continuous sensing create risks that a standard consent template does not anticipate.

Ongoing awareness fades

Unlike a one-time procedure, continuous passive collection means a participant can genuinely forget they are being monitored for weeks. Consent that was meaningful at enrollment decays. Ethicists recommend periodic re-notification, or just-in-time reminders, so that awareness, and therefore consent, remains live over the life of the study.

Bystanders are captured too

Wearable and ambient sensors capture data about people who never consented: a bed partner’s movement in accelerometry, household members in location or audio. Camille Nebeker’s Connected and Open Research Ethics (CORE) work identified bystander rights as a primary IRB concern for pervasive-sensing studies. Your protocol should include a bystander-mitigation plan, and your consent should tell participants what to expect.

“De-identified” is not “anonymous”

This is the risk most often underestimated. Longitudinal biosignals behave as behavioral fingerprints. The WristPrint study demonstrated user re-identification from wrist-worn accelerometry collected in natural environments, and circadian rest-activity patterns are stable and individually distinctive. High-resolution longitudinal data that has had names removed can still be re-linked to individuals, which is exactly why leaning on de-identification as your sole privacy safeguard is fragile. Say so plainly in your consent form.

Incidental findings are a duty to plan for

Photoplethysmography (PPG), heart-rate-variability, and irregular-pulse algorithms can flag possible atrial fibrillation, arrhythmias, or severe sleep fragmentation. The canonical large-scale example monitored 419,297 participants over a median of 117 days; 2,161 (0.52 percent) received an irregular-pulse notification, and among the 450 who returned analyzable ECG patches, atrial fibrillation was present in 34 percent, with a positive predictive value of 0.84 for the notification.Impressive at scale, but consumer devices are not validated for diagnosis. In a head-to-head evaluation of five consumer devices, the proportion of inconclusive tracings ranged from roughly 17 to 26 percent, and the authors concluded that manual review of tracings was required in about one quarter of cases. Wearable-enabled screening can drive overdiagnosis and unnecessary medicalization. You must pre-specify a findings-management plan: whether, when, and how you will return anything, and what you will tell participants a device notification does and does not mean.

Raw signal versus processed output

Most consumer-grade devices restrict raw-signal access, process signals in black-box firmware, and expose only aggregate outputs. The Sleep Research Society-endorsed state-of-the-science paper on wearables in sleep and circadian research notes that raw accelerometry is rarely provided, the raw PPG signal is rarely accessible, and beat-to-beat intervals are processed directly in firmware outside the researcher’s control.10 This is not only a scientific-reproducibility problem; it is a consent and governance problem. Raw access enables custom analysis and reproducibility but multiplies privacy and re-identification exposure. Processed-only data reduces exposure but surrenders analytic control and traceability. Which side of that trade-off you choose should be a deliberate design decision, disclosed in the consent form, not an accident of whichever device you happened to pick.

Consent language and models that fit passive sensing

Beyond the standard 45 CFR 46.116 elements, a consent form for passive continuous sensing should include the following, in plain language:

  • A plain-language inventory of what is collected (movement or accelerometry, heart rate, heart-rate variability, breathing rate, blood oxygen, sleep stages) and whether raw signals or only summaries are stored.
  • A statement that collection is continuous and passive, running in the background day and night without prompts, plus how to pause or stop it.
  • A candid re-identification statement: removing names does not guarantee anonymity, because sleep and movement patterns can be distinctive.
  • A bystander disclosure and practical instructions.
  • An incidental-findings clause stating whether the study will return health alerts, that the device is not a diagnostic tool, and what participants should do with any device-generated notification.
  • A third-party-governance disclosure: data flow through the device manufacturer’s platform or SDK under the manufacturer’s own terms of service, creating layered data governance the research team does not fully control.
  • Retention, sharing, and secondary-use terms, aligned with element 46.116(b)(9).
  • Withdrawal procedures, and explicitly what happens to already-collected passive data on withdrawal (deleted, or retained but not augmented).

Static, one-time consent fits multi-year passive cohorts poorly. Consider models along a spectrum: tiered consent, where participants opt in or out of categories such as commercial re-use versus public-health use; dynamic consent, an interactive digital portal where participants view uses and grant or withdraw permissions over time, as piloted in cohorts such as EXCEED;11 and meta-consent, where participants choose in advance how they wish to be asked about future uses. Digital phenotyping platforms illustrate operational practice, collecting raw passive data continuously under study-specific IRB approval with privacy-protective defaults.

On readability: consent should target an eighth-grade reading level or lower, yet the field falls well short of this in practice. An analysis of 5,239 US informed-consent forms found an average Flesch-Kincaid grade level of 10.99, with 91 percent written above the eighth-grade level, and earlier work found that IRB-provided sample consent text itself averaged grade 10.6, exceeding institutions’ own stated standards by roughly 2.8 grade levels.13 Reaching plain language is therefore a deliberate act of drafting and testing, not a default. Electronic informed consent is expressly permitted, and the joint FDA and OHRP guidance endorses multimedia, interactive formats, hyperlinked definitions, and comprehension checks such as teach-back, all of which suit the job of explaining passive sensing.

A staged decision framework

Design phase

Ask what the minimum signal and granularity are that answer your question. Prefer processed outputs unless raw signals are scientifically necessary; if raw, plan enhanced security and re-identification mitigation. Map the full data flow, including the manufacturer platform or SDK and its terms of service. Decide the incidental-findings policy before submission, not after a participant’s device flags something.

IRB submission

Assume expedited or full-board review; do not assume exempt. Propose concrete protections: encryption in transit and at rest, access controls, data-use agreements, a manufacturer or business-associate analysis, a bystander-mitigation plan, and a findings-management plan. Address HIPAA applicability explicitly, and for EU participants name the Article 9 basis and the Article 89(1) safeguards.

Consent construction

Lead with the key-information summary. Use plain language at an eighth-grade level or lower, delivered through e-consent with comprehension checks. Include the passive-sensing-specific elements listed above, and make the consequences of withdrawal and the data-retention rules explicit.

Ongoing governance

Re-notify participants periodically. Define re-consent triggers for new data types, new secondary uses, new sharing partners, or protocol changes that materially affect risk. Maintain a data-retention and destruction schedule, and keep a breach-response plan aligned with the FTC timelines where they apply.

Where data architecture meets consent

One theme runs through every stage above: the raw-versus-processed decision is not only methodological, it is an ethics-and-consent decision, and it is constrained by the device platform you build on. When a platform exposes only processed outputs, your consent form can promise less exposure, but you also cannot reprocess signals through a common validated pipeline, audit how a sleep stage was derived, or reconstruct what happened when an algorithm changes between firmware versions. When you have raw-signal access (for example, raw accelerometry and beat-to-beat intervals with per-beat confidence flags via a hardware SDK such as the Garmin Health Companion SDK, or the equivalent through the Apple SDK), you gain reproducibility and analytic control, and you take on a correspondingly heavier duty to disclose and protect. API-only platforms that return processed outputs alone, of which Oura is a common structural example, remove that duty but also remove the option. Neither is right or wrong in the abstract. The point is that the choice should be made on purpose, documented in the protocol, and reflected honestly in what you tell participants and your IRB. Centralive’s platform is built around raw-signal access precisely so that this choice stays in the researcher’s hands rather than being dictated by an API boundary.

The bottom line

Default to expedited or full-board review and a data-minimization design. Write passive-sensing-specific consent that covers continuity, re-identification, bystanders, incidental findings, and third-party platforms, and test it until it actually reads at an eighth-grade level. Pre-specify your incidental-findings policy, and given the overdiagnosis evidence, the defensible default for consumer-grade signals is not to return unvalidated alerts as diagnoses. Use tiered or dynamic e-consent for anything longer than a single measurement burst. Review the manufacturer’s governance terms, and for EU participants settle the explicit-consent-versus-research-derogation question early. None of this is legal advice; HIPAA, GDPR, FTC, and state-law applicability are fact-specific, so involve your privacy counsel and your IRB early.

References

  1. US Department of Health and Human Services. Protection of Human Subjects, 45 CFR 46.116 (General requirements for informed consent), 2018 revised Common Rule. Electronic Code of Federal Regulations.
  2. US Food and Drug Administration. Digital Health Technologies for Remote Data Acquisition in Clinical Investigations: Guidance for Industry, Investigators, and Other Stakeholders. December 2023. Docket FDA-2021-D-1128. FDA guidance document.
  3. US Department of Health and Human Services, Office for Civil Rights. HIPAA Privacy Rule and the applicability to health information collected by consumer devices and apps. HHS.gov.
  4. US Federal Trade Commission. Health Breach Notification Rule, final amendments. 89 Fed. Reg. (published May 30, 2024; effective July 29, 2024). Federal Register.
  5. European Parliament and Council. Regulation (EU) 2016/679 (GDPR), Articles 6, 9, 17, and 89. See also European Data Protection Board, Opinion 3/2019 concerning the interplay of the Clinical Trials Regulation and the GDPR. EUR-Lex.
  6. Torous J, Nebeker C. Navigating ethics in the digital age: introducing Connected and Open Research Ethics (CORE), a tool for researchers and institutional review boards. J Med Internet Res. 2017;19(2):e38. doi:10.2196/jmir.6793.
  7. Saleheen N, et al. WristPrint: characterizing user re-identification risks from wrist-worn accelerometry data. Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS ’21). doi:10.1145/3460120.3484799.
  8. Perez MV, Mahaffey KW, Hedlin H, et al. Large-scale assessment of a smartwatch to identify atrial fibrillation (Apple Heart Study). N Engl J Med. 2019;381(20):1909-1917. doi:10.1056/NEJMoa1901183.
  9. Mannhart D, Lischer M, Knecht S, et al. Clinical validation of 5 direct-to-consumer wearable smart devices to detect atrial fibrillation (BASEL Wearable Study). JACC Clin Electrophysiol. 2023;9(2):232-242. doi:10.1016/j.jacep.2022.09.011.
  10. de Zambotti M, Goldstein C, Cook J, et al. State of the science and recommendations for using wearable technology in sleep and circadian research. Sleep. 2024;47(4):zsad325. doi:10.1093/sleep/zsad325. PMID: 38149978.
  11. Wallace SE, Miola J. Comparing dynamic consent with broad consent: a case study of the EXCEED cohort. BMC Med Ethics. 2021;22:88. doi:10.1186/s12910-021-00636-0.
  12. Martinez-Martin N, Insel TR, Dagum P, Greely HT, Cho MK. Data mining for health: staking out the ethical territory of digital phenotyping. npj Digit Med. 2018;1:68. doi:10.1038/s41746-018-0075-8.
  13. Paasche-Orlow MK, Taylor HA, Brancati FL. Readability standards for informed-consent forms as compared with actual readability. N Engl J Med. 2003;348(8):721-726. doi:10.1056/NEJMsa021212. See also the 2024 analysis of 5,239 ClinicalTrials.gov consent forms in J Clin Transl Sci reporting a mean Flesch-Kincaid grade level of 10.99.
  14. US Food and Drug Administration and Office for Human Research Protections. Use of Electronic Informed Consent: Questions and Answers. December 2016. FDA guidance document.

Sign up for the Centralive Newsletter: https://newsletter.centralive.health/signup