Technology

Warren, Scanlon plan bill to curb AI health data sales

A revised privacy proposal would bar sales of health and location data to brokers, including information people share with AI chatbots.

Hana Yoshida

By Hana Yoshida · Markets Reporter

2 min read

Warren, Scanlon plan bill to curb AI health data sales
Photo: The Verge

Sen. Elizabeth Warren and Rep. Mary Gay Scanlon plan to introduce a revised privacy bill aimed at stopping the sale of Americans’ health and location data to data brokers, The Verge reported. The update matters for AI users because it would cover sensitive information that people type into chatbot services such as ChatGPT or Claude.

The proposal is a new version of the Health and Location Data Protection Act, according to The Verge. Warren, a Massachusetts Democrat, and Scanlon, a Pennsylvania Democrat, are expected to unveil it in the coming weeks.

The earlier bill, first introduced in June 2022, focused on data brokers themselves, The Verge reported. It would have barred brokers from collecting and selling health and location information.

The new version would go further. According to The Verge, it would also prevent other companies from selling that kind of data to brokers and would specifically apply to information submitted to AI systems.

AI companies move into health tools

The push comes as major AI firms have begun promoting products tied to health and medicine, The Verge reported. In January, Elon Musk publicly asked people to upload medical records, including MRI scans, to Grok, the chatbot from xAI.

OpenAI also introduced ChatGPT Health in January, according to The Verge. The company described it as a more secure, sandboxed area inside ChatGPT and encouraged users to upload medical records and other sensitive information.

OpenAI separately launched ChatGPT for Healthcare, a product aimed at medical providers, The Verge reported. A few days later, Anthropic introduced Claude for Healthcare, describing it as a “HIPAA-ready” tool for individuals, health providers and hospitals.

Those products put more personal health information inside AI services, where protections may depend heavily on company rules. Sara Gerke, a law professor at the University of Illinois Urbana-Champaign, told The Verge in January that safeguards for tools from companies such as OpenAI and Anthropic largely rest on what the companies commit to in privacy policies and terms of use.

The revised bill would target one part of that risk: the transfer of health and location information into the data broker market. The Verge reported that the measure would limit sales to brokers rather than setting out broader rules for every use of health information inside AI products.

The bill has not yet been formally debuted, according to The Verge. Its planned introduction signals that lawmakers are trying to update older data privacy proposals for a period in which people are being asked to share medical records with AI systems.

This story draws on original reporting from The Verge.