Senator Elizabeth Warren and Representative Mary Gay Scanlon are preparing a new version of the Health and Location Data Protection Act, expanding a 2022 bill to specifically cover data entered into AI systems. The bill would ban AI companies from selling health and location information to data brokers, and give enforcement teeth to the Federal Trade Commission.
The timing is not coincidental. In January 2025, OpenAI launched ChatGPT Health and ChatGPT for Healthcare, encouraging individuals and medical providers to upload sensitive records. Anthropic followed within days with Claude for Healthcare. Elon Musk publicly called for users to upload MRI scans and medical images to Grok. The health AI push is real, and it is moving fast.
Here is the gap nobody tells you about. Most people assume their health information is protected when they discuss it digitally. That assumption is wrong the moment you leave a doctor's office or hospital. HIPAA, the main US health privacy law, applies to doctors, hospitals, and insurers, not to consumer AI platforms. When you type a medical question into ChatGPT, the data is governed by OpenAI's privacy policy, not by federal health law. The protections depend entirely on what the company chooses to promise.
This is not a theoretical risk. A Duke University study found that data brokers are openly selling mental health records on the open market, with minimal vetting of who buys them. One investigation found hundreds of brokers selling nearly 3 billion profiles of people who were pregnant or buying maternity products. Mental health data has been sold for as little as $275 for 5,000 records. The data broker industry is worth over $300 billion globally and health data is its fastest-growing segment.
Free consumer versions of AI tools present the highest exposure. Unlike enterprise accounts, which typically include negotiated data agreements, free ChatGPT and similar products have no HIPAA protections at all. By default, conversations may be used to improve the model. You can opt out, but many users do not know this option exists. Employees who use personal AI accounts for work, including healthcare consultants or administrators who process patient information, can unknowingly create serious legal exposure for their employers.
The bill proposes giving the FTC 180 days to write binding rules and allocates $1 billion over 10 years for enforcement. It would also allow state attorneys general and affected individuals to sue directly. On paper, that is a meaningful enforcement structure. In practice, the odds of passage are low. There were no serious federal privacy law efforts in 2025, and the current administration has shown little appetite for new regulation of AI. What is filling the gap is a patchwork of state laws, with about 20 states now having some form of comprehensive privacy legislation. Maryland's law already bans the sale of health and precise location data. California has expanded its data broker registration rules. But coverage is uneven and there is no national floor.
For businesses, the implication is practical. Any employee or team using a consumer AI account to handle client or patient information is operating without a legal safety net. Enterprise accounts with signed data agreements are a different matter, but they cost more and require deliberate setup. The question to ask right now is whether the AI tools your teams are using have any formal data handling agreement in place, or whether everyone is running on the free version and hoping for the best.