Policy

Congress targets AI companies' use of patient data with updated health privacy bill

Lawmakers seek to ban the sale of health and location information to data brokers, explicitly extending protections to data entered into AI systems like ChatGPT and Claude.

Last verified:

Congress is moving to restrict AI companies’ ability to monetize user health information. According to The Verge, Senator Elizabeth Warren (D-MA) and Representative Mary Gay Scanlon (D-PA) plan to introduce an updated version of the Health and Location Data Protection Act in coming weeks, explicitly extending its scope to cover health data entered into AI systems. The bill, co-sponsored by Senators Ron Wyden (D-OR) and Bernie Sanders (I-VT), would prohibit not just data brokers but also AI platforms from selling Americans’ health and location information to third parties.

AI health tools accelerate data collection

The legislative push responds to a rapid expansion of AI-powered health products. According to The Verge, in January 2026, Elon Musk publicly called for users to upload medical records—including MRI scans—to Grok, xAI’s chatbot. That same month, OpenAI launched ChatGPT Health, a sandboxed feature designed to securely store medical records, and unveiled ChatGPT for Healthcare, targeting medical providers. Anthropic quickly followed with Claude for Healthcare, marketed as “HIPAA-ready” for individuals, providers, and hospitals. These platforms create new pathways for sensitive data entry, raising concerns about downstream commercialization.

Current protections are inadequate

The original Health and Location Data Protection Act, introduced in June 2022, addressed data brokers but not AI companies directly. The updated version closes this gap, explicitly barring AI systems from selling health and location data to brokers or other commercial buyers. This distinction matters because AI companies currently operate in a regulatory vacuum. Sara Gerke, a law professor at the University of Illinois Urbana-Champaign, told The Verge in January that protections under tools like OpenAI’s and Anthropic’s offerings “largely depends on what companies promise in their privacy policies and terms of use.” The U.S. lacks an overarching federal data-privacy framework despite years of attempted legislation.

Enforcement mechanism and timeline

If passed, the bill would require the Federal Trade Commission to draft implementing rules within 180 days. The FTC, state attorneys general, and affected individuals would gain standing to sue for violations. The proposal allocates $1 billion to the FTC over the next 10 years for enforcement activities. Warren stated: “Especially as more people enter their private health data into AI, we need to make sure that information isn’t exploited by the highest bidder.”

Why This Matters

This bill represents the first explicit legislative attempt to address AI-specific health data risks. AI companies have entered the health market rapidly without prior regulatory guardrails, and a ban on secondary sales would force a business-model shift away from monetizing user health data through brokerage channels. For healthcare startups and established AI labs, the 180-day FTC rulemaking window creates regulatory clarity on what “sale” means in practice—a critical gap that could determine whether feature flags, data-licensing agreements, or analytics partnerships fall under the ban. However, the bill’s passage is uncertain in a divided Congress, and even if enacted, enforcement depends on the FTC’s capacity to investigate AI companies’ data flows, a technical challenge the agency has not yet demonstrated capability to handle at scale.

Frequently Asked Questions

Does this bill apply to all AI companies or just data brokers?

The updated bill targets both AI companies and data brokers. It prohibits AI systems from selling health and location data to third parties, closing a gap in the original 2022 version.

What happens if an AI company violates this law?

According to the bill, the FTC, state attorneys general, and affected individuals can file enforcement suits. The FTC would have $1 billion allocated over 10 years to investigate and prosecute violations.

When would this law take effect?

If passed, the FTC would have 180 days to draft implementing rules. The timeline for congressional passage and presidential signature remains uncertain.

Would this affect existing health AI tools like ChatGPT Health?

Yes—the bill would require OpenAI, Anthropic, and other AI providers to cease selling user health data to data brokers or other third parties. Compliant tools would likely need to contractually restrict such sales.

#data-privacy #regulation #health-data #ftc #ai-safety