SECURITY CHALLENGES AND DATA INTEGRITY GAPS IN BLUETOOTH-ENABLED WEARABLE HEALTH DEVICES: A FOCUSED REVIEW

Authors

  • Muhammad Ali Bohyo
  • Mariya Qazi
  • Sarmad Shams
  • Fahad Shamim
  • Sehreen Moorat

Keywords:

smartwatches, wearable health monitoring, Bluetooth security, data integrity, pairing vulnerability, passive attacks, MITM, secure connections.

Abstract

The advent of smartwatches with health-tracking features has changed the way people take care of their wellness to a great extent. What were initially basic step-counting devices have now developed into devices with sensor capabilities of advanced biometrics, such as electrocardiography (ECG), blood oxygen saturation (SpO2) and sleep tracking. The present review is based on a critical evaluation of six popular smartwatches introduced between 2015 (e.g., Apple Watch Series 1) and 2024 (e.g., Samsung Galaxy Watch 7) in terms of their technological development, health features, and the security characteristics.Chronologically, the early-generation gadgets (2015-2018), like the Apple Watch Series 3 and Fitbit Versa, focused mostly on the simple fitness tracking, with the heart-rate monitoring and GPS features. These models were mostly based on Bluetooth 4.0/4.2 connectivity, and they had a low battery life of about 18-24 hours. The evolution of devices in the mid-era (2019-2021) with the introduction of the Apple Watch Series 6 and Garmin Venu 2 offered a step in the right direction of a more holistic approach to health monitoring with the inclusion of SpO2 and sleep staging plus fall detection. Nevertheless, the use of Bluetooth communication is a major security issue despite such improvements. As a result of pairing mechanisms, especially the continued use of Just Works mode, devices are susceptible to man-in-the-middle (MITM) attacks prevailing in  several generations of devices. Though mid-generation watches presented elliptic-curve Diffie-Hellman (ECDH) key exchange, forward secrecy constraints still existed. In the modern models, improved privacy characteristics in Bluetooth 5.4 and LE Secure Connections 2 are already used; nevertheless, our passive security study indicates persisting vulnerabilities, such as a low PIN entropy, and the unencrypted metadata. It is noteworthy that none of the proposed devices include end-to-end verification of the data integrity, leaving confidential health information vulnerable to manipulation.To sum up, the development of smartwatch hardware and health-monitoring features has increased significantly, yet the security mechanisms did not keep up. This loophole highlights the necessity of a standard approach to data-integrity checks which are wearable health device specific. Implementing more rigorous Bluetooth pairing criteria like the mandatory numeric comparison and the use of certificates to pin should be regarded as necessary. It is important to tackle these issues to support the safe usage of wearables in telemedicine and individual healthcare uses

Downloads

Published

2026-03-31

How to Cite

Muhammad Ali Bohyo, Mariya Qazi, Sarmad Shams, Fahad Shamim, & Sehreen Moorat. (2026). SECURITY CHALLENGES AND DATA INTEGRITY GAPS IN BLUETOOTH-ENABLED WEARABLE HEALTH DEVICES: A FOCUSED REVIEW. Spectrum of Engineering Sciences, 4(3), 3050–3060. Retrieved from https://www.thesesjournal.com/index.php/1/article/view/3517