Humotech hired a dedicated HIPAA compliance officer. Here is what that signals about connected prosthetic devices and your health data.

A personnel appointment at a wearable prosthetic and exoskeleton platform company is a quiet indicator of where the regulatory ground is shifting for devices that collect biometric and movement data. Here is what the compliance role is, what data connected P&O devices generate, and the questions worth raising with your clinic.

brown concrete building under white sky during daytime

Humotech, a developer of wearable device platforms for prosthetics, orthotics, and exoskeletons, named Jessica Zeff, JD, CHC, CHPC, as its HIPAA compliance officer this week. The announcement ran in the trade press and generated no particular fanfare, which is roughly what personnel appointments at wearable-device companies normally generate.

The appointment is worth a closer look than it usually gets, because the role it describes — a dedicated, credentialed HIPAA compliance officer at a company that makes sensor-equipped wearable devices — is a signal about where the regulatory environment is heading, and what it means for people who use connected prosthetic and orthotic technology.

What the credentials say

Zeff’s titles are specific. JD means she is an attorney. CHC is the Certified in Healthcare Compliance credential, issued by the Health Care Compliance Association; it indicates demonstrated knowledge of healthcare compliance program structures, regulatory requirements, and audit practices. CHPC is the Certified in Healthcare Privacy Compliance credential, which focuses on the specific legal and operational requirements of health information privacy — which in the U.S. context means HIPAA, its enforcement history, and the practical mechanics of operating under it.

The combined credential set describes someone whose job is not to wave at HIPAA from a distance but to run an active compliance function: policies, training, breach protocols, vendor agreements, and audit-readiness. Hiring for that specific skill set is a choice that reflects what the company believes its regulatory exposure is. Wearable device platforms that touch prosthetics and orthotics are making a statement about where they think the puck is going.

What HIPAA covers and where wearable devices sit

HIPAA’s Privacy and Security Rules apply to covered entities — healthcare providers, health plans, healthcare clearinghouses — and to business associates who handle protected health information on their behalf. A device company is not automatically a covered entity simply because it makes products that clinicians use. The regulatory picture depends on how data flows: who collects it, who stores it, how it is transmitted, and whether it is associated with identifiable patient records.

Wearable prosthetic and orthotic platforms increasingly do generate health-relevant data. A powered prosthetic ankle or knee tracks gait cycles, load distribution, and usage patterns. An exoskeleton used in rehabilitation records range of motion and step counts. That data may sit on the device, move to a cloud platform, be visible to a clinician through a connected portal, or feed into device-tuning algorithms. Whether any of that flow constitutes PHI under HIPAA depends on how the data is associated with an individual and who is touching it.

The regulatory and litigation landscape around health data has been moving. The FTC has taken enforcement action against companies that misrepresented how they handled health-related consumer data. State-level health data privacy laws — Washington’s My Health MY Data Act being the most significant — have created obligations that apply regardless of whether a company meets the technical definition of a covered entity under HIPAA. The effect is that companies operating in or near the health space are increasingly advised to build compliance infrastructure that would hold up under multiple frameworks simultaneously.

Hiring a dedicated officer rather than routing compliance through outside counsel or a generalist is a decision that reflects anticipated scope. It is not a company doing the minimum.

What this does not tell us

A compliance appointment does not tell us what data Humotech’s platforms currently collect, how long it is retained, or whether it has ever been shared in ways a user would not expect. Those are open questions that would require reading the company’s privacy policy, the terms of service associated with any connected platform, and any agreements your clinic signed when deploying the devices.

It also does not mean users have any particular problem to solve right now. The appointment may be driven by growth, by new product lines, by investor requirements, or by the anticipation of regulatory requirements that haven’t arrived yet. Compliance officers get hired before problems happen when the compliance function is working correctly.

What this means and what to ask

If you use a connected prosthetic or orthotic device that syncs data — to an app, to a clinical portal, to a cloud platform — these are the questions worth raising:

  • What data does this device collect, and where does it go? Ask your prosthetist or the device manufacturer directly. Your right to know what health-related data a product generates is not controversial.
  • Who has access to my data? “The clinic” and “the company” are different access levels with different legal frameworks.
  • Can I request a copy or deletion of my data? Some state laws require this; the answer also tells you how mature the company’s data infrastructure is.
  • Does my device share data with third parties for anything other than device function? Marketing, research aggregation, and product improvement are common; they each have different consent implications.

None of these questions require a compliance crisis to be worth asking. They are the ordinary questions that apply to any health-adjacent technology, and the fact that they are not yet standard in O&P clinical conversations reflects how recently connected devices became routine equipment rather than research prototypes.

The Humotech appointment is a small data point in a larger trend: wearable device companies that operate near healthcare are building the legal infrastructure to match what the technology is already doing. The people wearing the devices are the last to hear about it, which is one of the more persistent problems in health technology rollout.


This article reports on a personnel announcement and regulatory context. It is not legal or compliance advice. If you have questions about your rights under HIPAA or state health privacy laws, a healthcare attorney or your state’s attorney general’s office can provide guidance.

Source notebook: This reporting draws on The O&P EDGE: Humotech Names Compliance Officer (August 21, 2026) ↗. We link out so you can follow the receipts.