The landscape of health data privacy is undergoing a profound transformation, moving beyond the foundational, yet increasingly insufficient, framework of the HIPAA Privacy Rule. For AI health companies, this evolving regulatory environment presents a complex, multi-layered challenge, particularly as state-level privacy laws begin to stack on top of federal protections. The critical question for health IT professionals and policymakers alike is: how must AI health companies adapt their data practices to navigate this intricate web of overlapping regulations, and what does this mean for their ability to secure large enterprise and health plan contracts?
The Expanding Regulatory Net Beyond HIPAA
For years, the HIPAA Privacy Rule served as the primary benchmark for health data protection in the United States, governing how covered entities and their business associates handle Protected Health Information (PHI). However, as AI health applications proliferate, processing vast amounts of health-related data that often fall outside HIPAA’s strict definitions of PHI or originate from non-covered entities, a significant regulatory gap has emerged. This is precisely where state laws are stepping in, creating a more expansive and often more stringent privacy landscape. As I. Glenn Cohen and Carmel Shachar have articulated, state laws are increasingly filling these gaps HIPAA leaves for non-covered entities, compelling a re-evaluation of data governance strategies for companies like BetterHelp, GoodRx, and Hims & Hers.
Consider the data practices of these prominent AI health apps. GoodRx, for instance, faced an FTC enforcement action in February 2023 and agreed to pay a $1.5 million civil penalty for sharing user health data with third parties for advertising purposes, highlighting how consumer health data, even when not explicitly PHI, can be aggregated and used in ways that raise significant privacy concerns. Similarly, platforms like BetterHelp and Hims & Hers, while offering valuable services, operate in a space where the line between traditional healthcare providers (often HIPAA-covered) and direct-to-consumer digital health services (often not) is increasingly blurred. Their collection and processing of sensitive user information, from mental health consultations to prescription data, demand a robust compliance posture that extends far beyond federal mandates.
The challenge for these companies, and for the compliance platforms that support them like OneTrust, Vanta, and Drata, is to build systems that can dynamically adapt to this patchwork of regulations. Deven McGraw has consistently advocated for a more comprehensive approach to health data privacy, emphasizing that consumers often lack transparency and control over their health data when it resides outside HIPAA’s purview. The implications for enterprise procurement are direct: health plans and large employers, acting as stewards of their members’ and employees’ data, are increasingly scrutinizing potential vendors not just for HIPAA compliance, but for adherence to these emerging state-level standards. A vendor evaluation framework now necessitates a multi-jurisdictional privacy assessment.
Key State Laws Redefining AI Health Compliance
The push for enhanced state-level privacy protections is not a theoretical exercise; it is manifesting in concrete legislation that AI health companies must track diligently. The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), represent foundational shifts, granting consumers greater control over their personal information, including health-related data not covered by HIPAA. These laws introduce concepts like the right to know, delete, and opt-out of the sale of personal information, which directly impact how AI health apps collect, process, and share user data.
However, some states are going even further, enacting laws specifically targeting health data. The Washington My Health My Data Act stands out as a particularly impactful piece of legislation because it explicitly targets health apps directly, regardless of whether they are HIPAA-covered entities. This act broadens the definition of “consumer health data” and imposes strict requirements for consent, data sharing, and even geofencing around healthcare facilities. Its reach extends to virtually any company collecting health-related information from Washington residents, dramatically expanding the scope of regulatory oversight for AI health platforms. Washington My Health My Data Act text
Beyond the West Coast, states like Colorado with the Colorado Privacy Act and Connecticut with its Data Privacy Act (CTDPA) and related legislation are also contributing to this complex regulatory environment. While these acts are broader consumer privacy laws, their provisions often encompass health data, requiring clear disclosures, specific consent mechanisms, and robust data security measures. The collective impact of these laws means that a “HIPAA compliant” label alone is no longer sufficient for AI health apps seeking to partner with discerning enterprise clients. The Office for Civil Rights (HHS OCR) continues to enforce HIPAA, but the Federal Trade Commission (FTC) and State Attorneys General are increasingly active in pursuing enforcement actions against companies that mishandle consumer health data under these broader state statutes. FTC enforcement actions on health data
Navigating the Procurement Filter: A New Compliance Imperative
For policymakers crafting future legislation and health IT professionals evaluating AI solutions, understanding this confluence of regulations is paramount. The procurement filter for AI health tools has fundamentally changed. Enterprise clients, including large employers and health plans, are now demanding comprehensive compliance checklists that cover not only HIPAA but also the nuances of CCPA, CPRA, the Washington My Health My Data Act, Colorado Privacy Act, and Connecticut SB 1103. The absence of a robust, multi-faceted privacy program can be a decisive disqualifier, regardless of an AI solution’s clinical efficacy or technological sophistication.
Companies like OneTrust, Vanta, and Drata are instrumental in helping AI health apps build and demonstrate this expanded compliance. Their platforms offer tools for privacy program management, consent management, and continuous monitoring, which are essential for navigating this intricate regulatory landscape. The risk tracker for major AI health apps must now incorporate a granular assessment of their adherence to each of these state laws, alongside their HIPAA posture. The era of relying solely on HIPAA is over; the future of AI health necessitates a proactive, adaptable, and comprehensive approach to data privacy that anticipates and integrates the ever-growing stack of state-level protections. OneTrust privacy management solutions
Frequently Asked Questions
Why is HIPAA no longer sufficient for health data privacy in AI health?
HIPAA primarily covers traditional healthcare entities and Protected Health Information (PHI). However, AI health applications process vast amounts of health-related data that often fall outside HIPAA’s strict definitions or originate from non-covered entities, creating regulatory gaps. State laws are now filling these gaps, leading to a more expansive and often more stringent privacy landscape for AI health companies.
What is the role of state laws in regulating AI health data privacy?
State laws are stepping in to regulate health data that falls outside HIPAA’s purview, creating a complex and multi-layered regulatory environment. Laws like the California Consumer Privacy Act (CCPA) and the Washington My Health My Data Act grant consumers greater control over their health-related data and impose strict requirements on AI health companies. This means AI health companies must now comply with a patchwork of state-level standards in addition to federal mandates.
How do state laws impact AI health companies’ ability to secure large contracts?
Health plans and large employers are increasingly scrutinizing potential vendors not just for HIPAA compliance, but for adherence to emerging state-level privacy standards. A ‘HIPAA compliant’ label alone is no longer sufficient for AI health apps seeking enterprise clients. Companies must demonstrate a robust compliance posture that extends far beyond federal mandates to secure large contracts.
Which state laws are particularly impactful for AI health companies?
The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), are foundational. The Washington My Health My Data Act is particularly impactful as it explicitly targets health apps, broadening the definition of ‘consumer health data’ and imposing strict requirements for consent and data sharing. Other states like Colorado and Connecticut also have broader consumer privacy laws that encompass health data.
