September 11, 2026 · 16 min read · Sugam Budhraja

Three Governments Just Made Wearable Data a Regulated Input: CMS ACCESS, the NHS 10 Year Plan and the EU Health Data Space

Between July 2025 and July 2026 the United States, England and the European Union each wrote wearable and app data into health policy with money or law attached. CMS now pays $180 to $420 a year per Medicare patient for outcomes that must be measured with source-verified device data. England committed to wearables as standard care by 2035 and to buying devices for its poorest areas. The EU's Health Data Space makes wellness-app data a category that must be handed to research bodies from March 2029, behind a mandatory interoperability label. None of the three pays for the device. All three demand provenance.

Not legal advice. This is a reading of three public policy instruments, with article and page references, written to help product teams see what each one asks of the data they already produce. Dates and amounts are quoted from the documents as retrieved on 10 September 2026. Anything commercial that depends on them should rest on counsel reading the instrument.

For a decade the health-data industry described wearable data as a consumer feature: something an app displayed, a score it computed, a nudge it sent. In the fourteen months between July 2025 and July 2026 three governments changed its legal status.

The United States started paying for chronic-care outcomes that have to be measured with source-verified device data. England wrote wearables into the national plan for its health service, with a date, a standard of care and a state buyer for the devices. The European Union made data from wellness applications a defined category in law, with a mandatory label, a public register and a duty to hand it to research bodies on request.

None of the three pays for the device. All three demand to know where the number came from. Here is what each requires, and then what they have in common.


United States: CMS pays for outcomes, and defines what counts as a measurement

ACCESS. The Advancing Chronic Care with Effective, Scalable Solutions model began its first performance period on 1 July 2026 and runs to 30 June 2036 [1]. It pays “Outcome-Aligned Payments” to Medicare-enrolled participants, which include digital health and remote care companies as well as physician groups, for managing beneficiaries with hypertension, prediabetes and diabetes, obesity, kidney disease, heart disease, musculoskeletal pain, and depression or anxiety. The payment document for the first effective period sets the money [2]:

TrackInitial period, per beneficiary per yearFollow-on period
Early cardio-kidney-metabolic (eCKM)$360$180
Cardio-kidney-metabolic (CKM)$420$210
Musculoskeletal (MSK)$180none
Behavioural health (BH)$180$90

Those are allowed amounts including the 20% beneficiary coinsurance. Half of the Medicare portion is paid monthly; the other half is withheld and reconciled after the 12-month care period against two adjustments. An organisation earns full payment if at least 50% of its aligned beneficiaries meet every required outcome target, and loses payment when beneficiaries receive substitute services elsewhere above a 90% threshold [2]. Rural beneficiaries in the cardiometabolic tracks attract an additional fixed $15 “to offset higher operational costs related to connected device distribution and support” [2]. That sentence is the whole of the model’s device funding.

What makes ACCESS a data regulation rather than a payment rule is the definition of a valid measurement. Each outcome measure carries a clinical validity window: blood pressure and weight readings must be no more than 15 days old at submission, patient-reported outcome measures 15 days, HbA1c up to one year for people with diabetes or prediabetes and two years otherwise [2]. Baseline measures must arrive through the model’s data reporting API within 60 days of alignment or the beneficiary is unaligned. And “except for weight and PROMs, patient self-reported values are not permitted for OAP Measures” [2]. The targets themselves are clinical: systolic blood pressure below 130 mmHg or a 15-point reduction, HbA1c below 6.5% for prediabetes or 7.5% for diabetes, BMI below 30 or a 5% weight reduction [2]. Implementation guides interpret the collection requirements as validated upper-arm cuffs with device source, timestamp and patient attribution on every reading, with manual transcription excluded [3].

There is also a sentence about the future: “In future model years CMS may consider adding a measure of physical fitness or activity to the eCKM/CKM tracks” [2]. Activity data is not yet a payment input. It is on the list.

The 2026 remote monitoring codes. Separately, the 2026 physician fee schedule created CPT 99445, paying about $52 for device supply when a patient records between 2 and 15 days of data in a 30-day period, and CPT 99470, paying about $26 for the first 10 minutes of monthly management with a live interaction [4]. Until this year, device supply under 99454 required 16 days of data, and “days with data” was the remote-monitoring industry’s core metric. It no longer gates payment.

The plumbing. On 30 July 2025 the White House and CMS launched the Health Technology Ecosystem, with more than 60 technology and healthcare companies, including Apple, Google, Amazon, OpenAI and Anthropic, pledging to a voluntary interoperability framework, and 21 data networks pledging to become CMS Aligned Networks with FHIR APIs and a record locator service by 4 July 2026 [5]. At the one-year mark CMS added eight pledge categories and a Medicare App Library, and described the effort as “a movement, not a mandate” [6]. The September 2025 MAHA strategy separately proposed a Real-World Data Platform linking claims, electronic health records and wearable data for research [7]. And the FDA’s January 2026 General Wellness guidance told device makers where the regulatory line sits: estimate, trend and contextualise freely; diagnose and you are a device [8]. We covered that guidance when it landed.

The American position, read as one thing: the government will not buy the sensor, will pay for what the sensor helps achieve, and will only count readings it can trace.


England: a date, a standard of care and a buyer

The 10 Year Health Plan for England, published 3 July 2025, is a policy document rather than a payment rule, but it contains the most direct commitment any government has made to wearables as care [9].

The plan’s wording: “make wearables standard in preventative, chronic and post-acute NHS treatment by 2035. All NHS patients will have access to these technologies, which will be part of routine care.” And on the population the market does not reach: “We will provide devices for free in areas where health need and deprivation are highest” [9]. The accompanying commitments set remote monitoring of cardiovascular disease with wearables as a standard part of NHS care by 2028 [10].

Three mechanisms sit underneath. The Single Patient Record, a single authoritative account of a patient’s data, becomes viewable through the NHS App from 2028 [11]. The HealthStore is a platform inside the NHS App through which patients access approved digital tools to manage or treat conditions [9]; tools reach it after evaluation by NICE and are then procured centrally on behalf of all NHS organisations [12]. And NICE’s remit expands from medicines to “devices, diagnostics and digital products” [9], which makes a health technology assessment body the gate for consumer-grade tools entering the health service.

The English position, read as one thing: the state names the standard, buys the device where the market will not, evaluates the software centrally, and expects the data to land in one record.


Regulation (EU) 2025/327 establishing the European Health Data Space entered into force on 26 March 2025 and applies from 26 March 2027, with most substantive obligations phased to 2029 and 2031 [13]. Two parts of it reach wellness apps and wearables directly.

The label. The regulation defines a wellness application as software, or hardware and software, “intended by the manufacturer to be used by a natural person, for the processing of electronic health data, specifically for providing information on the health of natural persons, or the delivery of care for purposes other than the provision of healthcare” [14]. Recital 49 states the intent plainly: “A mandatory labelling scheme for wellness applications for which interoperability with EHR systems is claimed should therefore be established” [13]. Under Articles 47 to 49 the manufacturer must test the app in a digital testing environment established by the Commission or a Member State, then issue a label valid for at most three years, and register the application and its test results in a public EU database [14]. Interoperability does not mean automatic sharing: data may only be inserted into a person’s record with their consent and with the technical ability to choose which parts to insert [14]. Articles 47 to 49 apply from 26 March 2029 for the first priority categories of data [15].

The duty to share. Chapter IV, on secondary use, applies from 26 March 2029 [15]. Article 51 lists the minimum categories of electronic health data that health data holders must make available to Health Data Access Bodies for approved research, policy, regulatory and algorithm-training purposes, and the list includes electronic health data from wellness applications alongside data from medical devices, EHRs, registries and genomics [16]. Individuals hold a reversible right to opt out under Article 71. Member States may adopt stricter safeguards for wellness-application data specifically, including opt-in consent, a discretion they do not have for EHR or medical device data [14][16]. Microenterprises are exempt from some holder obligations [13].

The European position, read as one thing: if your app touches health data, the law now has a name for it, a test for its claims, a register for its existence and a claim on its data for research, with the individual holding the veto.


Side by side

United States (CMS ACCESS, 2026 RPM codes)England (10 Year Health Plan)European Union (EHDS)
InstrumentPayment model and fee scheduleNational plan and procurementRegulation with direct effect
In force1 July 2026 (ACCESS); 1 January 2026 (codes)Published 3 July 202526 March 2025; applies 26 March 2027
Key datesEffective period to 31 Dec 2027; model to 2036CVD monitoring standard 2028; SPR via NHS App 2028; wearables standard 2035Label and secondary use from 26 March 2029; extended categories 2031
Who paysMedicare, per beneficiary, outcome-contingentNHS central budget for HealthStore tools; state-funded devices in deprived areasNobody; compliance is the cost
Pays for the device?No. $15 rural supplement for distributionYes, in high-deprivation areas onlyNo
What counts as dataMeasured, attributed, timestamped, within validity window; no self-report except weight and PROMsNICE-evaluated tools; data into the Single Patient RecordTested interoperability; consent-gated insertion; wellness data as a legal category
Who verifiesCMS via reporting API and reconciliationNICE, then central procurementTesting environment, EU database, Health Data Access Bodies
Individual controlCoinsurance may be waived; standard Medicare rightsNHS App consent modelConsent for insertion; opt-out from secondary use; Member State opt-in option

What the three have in common

None pays for the sensor. CMS pays for blood pressure control, not cuffs. England buys devices only where deprivation is highest, which is a statement that the market will not. The EU pays nothing. The commercial premise that a payer will underwrite hardware for the population does not survive contact with any of the three documents, which is consistent with what the shipment data says about who buys wearables.

All three demand provenance. ACCESS rejects a reading without source, date and attribution. The EHDS label tests whether a claimed data path actually works. NICE evaluates the tool before the HealthStore lists it. The number is no longer enough; the number’s origin is the product.

Self-report is out. CMS says so in a sentence. The EHDS’s label is a test, not a declaration. NICE’s evidence standards are the reason a consumer app cannot simply assert it works. A field that stores a step count without recording whether a device measured it or a person typed it has a data model problem in all three jurisdictions.

The customer is a payer or the state, not the consumer. The buyer’s questions change accordingly: validity windows, attribution, audit, exportability, evaluation evidence. The consumer’s question, is it a good app, does not appear in any of the three instruments.

Everything ends in a record. The Single Patient Record, the EHR systems the EU label targets, the CMS Aligned Networks with their FHIR APIs. Wearable data that cannot leave the app in a standard form is, for policy purposes, not there.


What to build now

For a team shipping a health or wellness product into any of these markets, the requirements converge on a short list.

  1. Per-reading provenance. Source device, model, collection method (measured, derived, self-reported), and collection timestamp with timezone, stored with every value and exposed in every export. This is the ACCESS requirement in its literal form and the EHDS label’s substance.
  2. Local time as the primary key for “when.” Validity windows are counted in days; day boundaries move with timezone. The five platforms already disagree about which day a night’s sleep belongs to. A model that stores only UTC will fail a 15-day window it should have passed.
  3. A consent ledger. What the user agreed to share, with which recipient, from which source, from when. EHDS insertion is consent-gated and granular; secondary use has an opt-out; England’s record is consent-based. The ledger is the audit trail for all three.
  4. A standard export. FHIR for the record systems, with the provenance from point one carried through. If the data cannot reach the Single Patient Record or an EHR system, the label and the HealthStore are not available to you.
  5. A data-holder posture in the EU. Someone to answer a Health Data Access Body, a process for the opt-out, and a decision, country by country, on how to handle Member States that require opt-in for wellness data.
  6. Separation of wellness claims from clinical measurement. The FDA line is generous to trends and context and unforgiving of diagnosis. ACCESS wants clinical-grade measurement from validated devices. A product can live on both sides of that line, but not in the same data field.

Where we sit

Sahha’s product is the layer these instruments are describing: it takes data from phones, wearables and cloud APIs, attaches source and time to every record, normalises it, and delivers it to customers who build on it. So we read all three documents with self-interest and should say so. Our honest reading is that they are good news for anyone whose data carries its provenance and bad news for anyone whose product is a number on a screen. They also confirm something we have argued from the shipment data: the state is stepping in to buy devices for the people the market will not sell to, which means the population that health programs are paid to reach will keep arriving with a phone before it arrives with a ring.


The short version

CMS ACCESS pays $180 to $420 per Medicare patient per year for chronic-care outcomes, withholds half until outcomes are proven, accepts only measured and attributed readings inside 15-day windows for blood pressure and weight, bars self-report, and adds $15 for rural device logistics. The 2026 RPM codes ended the 16-day rule. England’s plan makes wearables standard care by 2035 and cardiovascular remote monitoring standard by 2028, buys devices for its poorest areas, gates apps through NICE into a HealthStore and lands the data in a Single Patient Record from 2028. The EU’s Health Data Space, applying from 2027 with wellness-app provisions from 2029, requires a tested and registered label for any app claiming record interoperability and lists wellness-application data among the categories that must be made available for research, subject to an individual opt-out. None pays for the device. All three pay attention to where the number came from.

Read next. For the FDA guidance that draws the wellness line in the US, see is your health app a medical device. For the EU’s parallel AI obligations, see the EU AI Act for health apps. For the US privacy bill moving alongside all this, see the Senate rewrote HIPRA.

References

  1. ACCESS (Advancing Chronic Care with Effective, Scalable Solutions) Model. CMS Innovation Center. Retrieved 10 September 2026. https://www.cms.gov/priorities/innovation/innovation-models/access
  2. ACCESS Model: Model Payment Amounts and Performance Targets, Effective Period 5 July 2026 to 31 December 2027. CMS Innovation Center. Tables 1, 3 and 4; payment frequency; clinical validity windows; data reporting; self-reported values. https://www.cms.gov/priorities/innovation/files/access-payments-amts-perf-targets.pdf
  3. Connected Device Requirements for ACCESS (eCKM and CKM Tracks). Healthfully, 2026. An implementer’s interpretation of the model’s data collection requirements. https://www.healthfully.io/post/cms-access-device-requirements
  4. 2026 Remote Patient Monitoring CPT Codes: What’s New and What to Know. Prevounce, 2026. CPT 99445 and 99470 descriptions and national average payment. https://blog.prevounce.com/2026-remote-patient-monitoring-cpt-codes-whats-new-and-what-to-know
  5. CMS taps tech firms for new patient health data ecosystem. Healthcare IT News, July 2025; and White House Says 60 Firms Commit to Build Digital Health Ecosystem. PYMNTS, 30 July 2025. https://www.healthcareitnews.com/news/cms-taps-tech-firms-new-patient-health-data-ecosystem and https://www.pymnts.com/healthcare/2025/white-house-says-60-firms-commit-to-build-digital-health-ecosystem
  6. CMS marks one year of its Health Tech Ecosystem with eight new pledge categories. MarketScale, July 2026; and Interoperability Framework, CMS. https://www.marketscale.com/industries/healthcare/cms-marks-one-year-of-its-health-tech-ecosystem-with-eight-new-pledge-categories-and-a-rip-clipboard-moment and https://www.cms.gov/initiatives/health-technology-ecosystem/overview/interoperability-framework
  7. MAHA Commission Report Details Federal Response to Childhood Chronic Disease. Holland and Knight, September 2025. Real-World Data Platform linking claims, EHR and wearable data. https://www.hklaw.com/en/insights/publications/2025/09/maha-commission-report-details-federal-response
  8. FDA Updates Two Digital Health Final Guidance Documents. Greenberg Traurig, January 2026; General Wellness: Policy for Low Risk Devices, FDA, 6 January 2026. https://www.gtlaw.com/en/insights/2026/1/fda-updates-two-digital-health-final-guidance-documents
  9. Fit for the Future: 10 Year Health Plan for England (accessible version). Department of Health and Social Care, 3 July 2025. https://www.gov.uk/government/publications/10-year-health-plan-for-england-fit-for-the-future/fit-for-the-future-10-year-health-plan-for-england-accessible-version
  10. Digital health suppliers have at-scale opportunities delivering the UK NHS 10-year plan. Osborne Clarke, 2025. Cardiovascular remote monitoring by 2028. https://www.osborneclarke.com/insights/digital-health-suppliers-have-scale-opportunities-delivering-uk-nhs-10-year-plan
  11. Single patient record to become available via NHS App by 2028. Pulse Today, 2025; and Single Patient Record, NHS England. https://www.pulsetoday.co.uk/news/clinical-areas/cardiovascular/single-patient-record-to-become-available-via-nhs-app-by-2028/ and https://www.england.nhs.uk/digitaltechnology/the-single-patient-record/
  12. What does the 10 year health plan mean for digital? Digital Health, July 2025. HealthStore, NICE evaluation and central procurement. https://www.digitalhealth.net/2025/07/what-does-the-10-year-plan-mean-for-digital/
  13. Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng
  14. EHDS Series 4: The European Health Data Space’s Implications for Wellness Applications and Medical Devices. Covington, Inside Privacy, 2025. Articles 2, 40, 47, 48, 49 and 51(4). https://www.insideprivacy.com/digital-health/ehds-series-4-the-european-health-data-spaces-implications-for-wellness-applications-and-medical-devices/
  15. EHDS Article 105, Entry into force and application. StreamLex consolidated text. Retrieved 10 September 2026. https://streamlex.eu/articles/ehds-en-art-105/
  16. EHDS Article 51, Minimum categories of electronic health data for secondary use. StreamLex consolidated text; and European Health Data Space: Revolutionizing health care, scientific research in the EU. IAPP. https://streamlex.eu/articles/ehds-en-art-51/ and https://iapp.org/news/a/european-health-data-space-revolutionizing-health-care-scientific-research-in-the-eu

Related