Oura makes the Oura Ring, a smart ring that collects health-related measurements such as heart rate, movement, breathing rate, and temperature changes. Its companion app uses these measurements to estimate sleep duration and stages and provide insights into activity and recovery. Oura also collects information users provide, including contact details, height, weight, and notes entered in the app.
When a patient sends an Oura report containing identifiable health information to a covered entity, the practice must protect the copy it receives as protected health information (PHI). The protection applies while the report is in the practice’s inbox, even before it is added to the patient’s chart.
Sharing a report does not extend HIPAA protection to the patient’s entire consumer Oura account. Oura states that it meets HIPAA requirements when handling PHI for healthcare partners. Its direct-to-consumer services generally fall outside HIPAA and remain subject to applicable privacy laws and Oura’s privacy policy.
What does Oura say about HIPAA compliance?
Oura ties its HIPAA commitments to the work it performs for healthcare partners. Its Trust Center states, “We also meet HIPAA requirements where we handle protected health information for a healthcare partner.” This statement specifically addresses how Oura handles PHI within those healthcare relationships.
Its privacy policy distinguishes those arrangements from personal use: “Oura is generally not a Covered Entity under HIPAA for our direct-to-consumer Services.” The policy also acknowledges situations where Oura acts as a business associate, handling PHI on behalf of a covered healthcare organization. Consumer accounts remain governed by Oura’s privacy policy and applicable privacy laws.
For healthcare organizations using Oura’s business services, its Business Terms and Conditions include a specific requirement: customers subject to HIPAA must enter into a business associate agreement with Oura before uploading PHI. The agreement governs each party’s obligations for the uploaded information. A practice planning to upload patient information should therefore confirm the agreement and the services it covers before proceeding.
Is an Oura report PHI?
In Patient Privacy in the Era of Big Data, author Mehmet Kayaalp explains, “Protected health information (PHI) is the intersection of health information (HI) and personally identifying information (PII).”
When a covered entity receives an Oura report containing identifiable health information, the report is considered PHI, including while it is held in the practice’s email system. The HHS website clarifies that the Privacy Rule encompasses information in various formats, not solely what is entered into a patient's chart.
Paubox looked at 170 healthcare email breaches that were disclosed in 2025. In the 2026 report, it is stated, "Misconfiguration is a bigger problem than platform choice." Covered entities should look into how the practice's email secures patient information before requesting Oura reports from patients, including emails before a telehealth visit.
When exactly does an emailed Oura report become PHI?
The article The Need for a Privacy Standard for Medical Devices That Transmit Protected Health Information Used in the Precision Medicine Initiative for Diabetes and Other Diseases states, “PHI is any individually identifiable health information created or collected by a covered entity or business associate.” For a covered entity receiving an identifiable Oura report for patient care and protection begins when the practice receives it. Staff does not need to open the attachment or add it to the chart first. Say the patient's Oura report is sent to a covered practice's inbox at 9 am. And they view it at 1 pm that day. Providers should treat it as PHI from the time of receipt, not only once accessed. According to the executive summary of the Paubox Healthcare Email Security Maturity Index 2026, "58% of respondents experienced at least one email-related data breach in the past 24 months." It would apply to all organizations that took the survey, not only Oura. So, practices should make sure they are covering their patients' inboxes, as well as attachments and downloads.
Can a practice ask patients to email Oura screenshots or reports?
Yes, a practitioner can request an Oura report by email with appropriate safeguards. According to the HHS guidance for emails, HIPAA allows for treatment to be conducted over email and recommends precautions like confirming the identity of an email correspondent. Oura’s Export & Share Your Oura Data explains that patients can create a report that is downloadable. In the report, What small healthcare practices get wrong about HIPAA and email security, Paubox found that 64% of IT leaders and practice managers believed that portals were necessary to meet HIPAA requirements. Its executive summary notes, “Most compliance gaps have straightforward fixes that don't require major IT overhauls or additional staff.”
Make sure patients know how to send the practice information before their remote appointment. Patients are allowed to send information over email, and they are allowed to receive information through other means of communication if requested. If the patient would like to use an alternative communication method, provide another appropriate route.
What changes when a patient shares their Oura data with their doctor?
The review Consumer Wearables for Patient Monitoring in Otolaryngology: A State of the Art Review states, “Wearable-derived data that are shared with health care organizations or integrated into electronic health records must be protected and stored in a HIPAA-compliant manner.” Apply that principle to a patient who sends an Oura report before a virtual appointment. Covered entities should have protocols in place to assign an authorized staff member to route the attachment to the clinician, confirm receipt, and explain the next step through the practice’s approved email system.
Another one of those safety features can include encryption. Email security in clinical practice: ensuring patient confidentiality explains, “Cryptography refers to processes for converting text from a readable to an unreadable format (‘encryption’) and back again (‘decryption’).” Paubox recently did a study on the Healthcare Email Security Maturity Index 2026 that reviewed 170 healthcare IT professionals in the US. In the Paubox article, the report states, “46% of healthcare organizations rely on manual encryption triggers, partial department coverage, or no encryption at all.”
With the Paubox telehealth email solution, practices can use encrypted appointment links and summary notes after a visit. When a practice is looking at patients' Oura data, they could use these features to send patient instructions prior to the visit and follow up after the visit. By using these protocols, staff will not have to remember to use encryption each time they respond.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Can ordinary measurements, such as sleep scores, activity levels, or heart rate, qualify as PHI without a diagnosis?
They would be PHI if it is being tracked about a person and stored by the medical practice or its business associate; no diagnosis is needed.
Does a screenshot need the patient’s name on it, or can the sender’s email address make it identifiable?
A name is not required; the sender’s email address or other identifying context can connect the screenshot to a patient.
When does Oura operate as a consumer wellness service, and when does it act as a business associate for a healthcare organization?
Under Oura’s policy, personal tracking generally uses its consumer service, while handling PHI on behalf of a covered healthcare organization can make Oura a business associate.
Does sharing data with a personal trainer, wellness coach, or employer have the same implications as sharing it with a doctor?
Not automatically; HIPAA obligations depend on the recipient’s role and arrangement, including whether they act as a covered entity or its business associate.
