The proliferation of AI-driven health tools and consumer health apps has ushered in an era where vast quantities of health-related data are generated outside the traditional confines of the Health Insurance Portability and Accountability Act (HIPAA). This explosion of non-HIPAA-covered health data has created a critical regulatory vacuum, now being aggressively filled by a complex, and often conflicting, patchwork of state-level privacy laws. For AI health companies, this evolving landscape, spearheaded by groundbreaking legislation like Washington’s My Health My Data Act, demands a fundamental shift in compliance strategy, moving beyond a singular HIPAA-centric approach to navigate a new minefield of multi-jurisdictional obligations and heightened enforcement risks.
The HIPAA Gap: Why Your Health App Isn’t (Just) a HIPAA Problem
The foundational challenge in health data privacy stems from HIPAA’s specific jurisdictional boundaries. The HIPAA Privacy Rule primarily governs “covered entities,” which are defined as health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain transactions HHS OCR definition of covered entity. It also extends to “business associates” who perform services for covered entities and handle protected health information (PHI). This narrow scope has historically left a significant portion of the digital health ecosystem unregulated by federal privacy standards. Many modern AI health companies, particularly those operating directly in the consumer space, such as Hims & Hers and BetterHelp, and data aggregators like GoodRx, often fall outside this direct HIPAA purview. When a consumer directly shares health information with a mobile application or a telehealth platform that is not acting on behalf of a covered entity, that data generally does not constitute PHI under HIPAA. This critical gap was starkly illustrated by the Federal Trade Commission’s (FTC) enforcement action against GoodRx, where the company was found to have shared sensitive user health data, including prescription information and health conditions, with third parties for advertising purposes. This activity, while problematic, largely occurred outside HIPAA’s jurisdiction because GoodRx was not classified as a covered entity or business associate under the statute FTC GoodRx settlement details. As legal scholars like I. Glenn Cohen and Carmel Shachar have frequently highlighted, the definition of PHI and covered entities has struggled to keep pace with innovations in health data collection and processing.
The State-Level Solution: A New Generation of Aggressive Health Data Laws
In direct response to this perceived HIPAA gap, states have begun enacting a new wave of robust health data privacy laws. These statutes are designed to extend privacy protections to health-related data collected by entities that typically escape HIPAA’s reach, thereby creating a more comprehensive, albeit complex, regulatory environment.
Washington’s My Health My Data Act: The New Gold Standard
Washington’s My Health My Data Act (MHMDA) stands out as the most significant and far-reaching example of this new legislative trend. Enacted to specifically address the collection and sharing of consumer health data by non-HIPAA-covered entities, MHMDA significantly broadens the definition of “consumer health information” beyond what HIPAA covers. The law defines “consumer health information” broadly to include “any personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status” Washington My Health My Data Act text. Crucially, this encompasses biometric data, location data related to healthcare services, and even non-identifiable data that can be linked to a consumer. MHMDA imposes stringent opt-in consent requirements for both the collection and sharing of consumer health information, a standard often more rigorous than general privacy laws. It also introduces a private right of action, allowing individuals to sue companies for violations, thereby significantly increasing enforcement risk beyond state attorneys general and the FTC. Furthermore, the law includes a groundbreaking prohibition on geofencing around healthcare facilities, preventing the use of location data to identify or target individuals seeking healthcare services. This proactive approach by Washington State sets a new benchmark for health data privacy, forcing AI health companies to re-evaluate their data practices comprehensively.
The Broader Patchwork: CCPA/CPRA, Colorado, and Connecticut
Beyond Washington, other states have also enacted or strengthened general privacy laws that, while not exclusively health-focused, significantly impact how AI health companies manage data. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), includes a broad definition of “sensitive personal information” that can encompass health data, even if it’s not PHI. These laws grant consumers rights such as the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale or sharing. Similarly, the Colorado Privacy Act (CPA) and the recently amended Connecticut Data Privacy Act establish comparable consumer rights and impose obligations on data controllers regarding transparency, purpose limitation, and data security. While these laws provide more general privacy protections compared to MHMDA’s specific health focus, they still require AI health companies to implement robust data governance frameworks. The challenge for companies like BetterHelp, GoodRx, and Hims & Hers is that while they may not be HIPAA-covered entities, they are almost certainly subject to these general state privacy laws, particularly given their scale and consumer reach. The fragmented nature of these regulations means that an AI health app operating nationally must now contend with a complex web of varying definitions, consent requirements, and enforcement mechanisms.
Enforcement and Compliance Implications: A New Era of Scrutiny
The regulatory landscape for AI health apps is no longer solely defined by HHS OCR’s HIPAA enforcement. The FTC, with its broad authority to protect consumers from unfair or deceptive practices, has become a prominent enforcer in the digital health space, as evidenced by the GoodRx settlement. This action signaled a clear intent to target companies that misrepresent their data practices or fail to secure sensitive health-related information, regardless of their HIPAA status. State Attorneys General are also increasingly active, leveraging their consumer protection authority and the specific provisions of new state privacy laws to pursue non-compliant entities. For AI health companies, this multi-front enforcement environment necessitates a proactive and comprehensive approach to compliance. Relying solely on self-attestation or minimal privacy policies is no longer viable. Platforms such as OneTrust, Vanta, and Drata are becoming essential tools for managing compliance across diverse regulatory frameworks, offering capabilities for consent management, data mapping, and privacy impact assessments. The benchmark for compliance, once largely defined by HIPAA’s technical and administrative safeguards, is now evolving to include the more granular consent requirements and data minimization principles embedded in state laws. Companies must now conduct thorough vendor evaluations, akin to the rigorous HIPAA business associate agreements, but tailored to the broader definitions of health data and expanded consumer rights found in state statutes. Deven McGraw, a leading voice in health data privacy, has consistently emphasized the need for organizations to move beyond a compliance-as-a-checklist mentality towards a culture of privacy by design, anticipating and addressing these evolving regulatory demands. The compliance burden for AI health apps, therefore, has dramatically increased. What was once a relatively straightforward HIPAA analysis for covered entities and their business associates has transformed into a complex, multi-jurisdictional challenge. Companies must now meticulously track and adhere to a growing body of state laws that define health data more broadly, impose stricter consent requirements, and carry significant enforcement risks from federal and state authorities. The rapid proliferation of non-HIPAA-covered health data, particularly through AI-driven consumer health apps, has exposed a critical regulatory void that states are now aggressively addressing. The emergence of stringent laws like Washington’s My Health My Data Act, alongside the evolving applications of general privacy statutes such as CCPA/CPRA, Colorado Privacy Act, and the recently amended Connecticut Data Privacy Act, has fundamentally reshaped the compliance landscape. The FTC’s actions, exemplified by the GoodRx case, clearly demonstrate the tangible enforcement risks for companies that fail to adapt to this new reality, regardless of their HIPAA status. For AI health companies and their IT/compliance teams, proactive, multi-jurisdictional data governance is no longer merely a best practice; it is an existential imperative. The era of relying solely on HIPAA as the primary framework for health data privacy is over. Instead, a dynamic, layered approach is required, one that incorporates the aggressive scope and granular requirements of state-level privacy legislation. This trend is unlikely to abate, with more states anticipated to adopt similar, stringent health-specific privacy laws in the coming years, further solidifying the need for a robust and adaptable compliance posture.
Frequently Asked Questions
Why is HIPAA insufficient for regulating AI-driven health tools and consumer health apps?
HIPAA’s Privacy Rule primarily governs ‘covered entities’ like health plans and healthcare providers, and their ‘business associates’. Many modern AI health companies and consumer apps operate outside this narrow scope, meaning the health data they collect often does not fall under HIPAA’s definition of Protected Health Information (PHI). This creates a regulatory gap where vast quantities of health-related data are generated without federal privacy standards.
What is the primary regulatory challenge for AI health companies regarding data privacy?
The primary challenge is navigating a complex and often conflicting patchwork of state-level privacy laws that are aggressively filling the HIPAA gap. This requires AI health companies to shift their compliance strategy beyond a singular HIPAA-centric approach to manage multi-jurisdictional obligations and heightened enforcement risks. Laws like Washington’s My Health My Data Act exemplify this new, more stringent regulatory environment.
How do new state laws like Washington’s My Health My Data Act differ from HIPAA in their approach to health data privacy?
State laws like MHMDA significantly broaden the definition of ‘consumer health information’ beyond HIPAA’s PHI, encompassing a wider range of data including biometric and location data. They often impose more rigorous opt-in consent requirements for data collection and sharing. Furthermore, these laws introduce mechanisms like a private right of action, increasing enforcement risks beyond federal agencies.
Beyond health-specific laws, how do general state privacy laws impact AI health companies?
General state privacy laws, such as the CCPA/CPRA, Colorado Privacy Act, and Connecticut Data Privacy Act, include broad definitions of ‘sensitive personal information’ that can encompass health data not covered by HIPAA. These laws grant consumers rights like the right to know, delete, and opt out of the sale or sharing of their personal information. This necessitates that AI health companies adhere to transparency, purpose limitation, and data security obligations even for non-PHI data.
