About
Health Data Privacy

Health Data Privacy

Tracking Health Data Privacy legal and regulatory developments.

9 entries in Legal Intelligence Tracker

LawSnap Briefing Updated May 10, 2026

State of play.

  • Acquisition-triggered genetic data transfers are now a class-action target. The Tempus AI litigation — seven named plaintiffs across six states, filed in N.D. Ill. — tests whether a $600M acquisition of a genetic testing firm converts the acquired patient database into freely licensable AI training data, and whether de-identification defeats state genetic privacy claims .
  • AI inference liability has shifted from data collectors to data deployers. State AG enforcement, COPPA amendments, and California's January 2027 opt-out deadline collectively reframe exposure: companies using third-party AI tools bear liability for what those tools infer, not just what they collect .
  • The ShinyHunters Canvas breach has escalated from silent data theft to public extortion, with defacement of login portals at approximately 330 institutions, a claimed 275-280 million records across potentially 9,000 institutions, and FERPA, GDPR, and state notification obligations all simultaneously in play .
  • Federal standing doctrine for pixel-tracking claims now turns on data sensitivity. In Tash, a federal court held that disclosure of health-related data constitutes concrete injury without proof of financial loss; non-sensitive identifier linkage does not .
  • Alabama is the 21st state with a comprehensive privacy statute, effective May 1, 2027, with explicit consent required for health data and biometrics and AG-only enforcement at up to $15,000 per violation .
  • For counsel advising healthcare technology companies, wearable manufacturers, life sciences acquirers, educational institutions, or AI platform vendors, the practical baseline is that health and biometric data now carry multi-front exposure — state genetic privacy statutes, HIPAA, class-action standing doctrine, FDA data provenance requirements, a thickening state AG enforcement posture, and active criminal extortion campaigns targeting institutional data — and post-acquisition data integration decisions, wearable product architecture, and vendor security posture are the highest-risk inflection points.

Where things stand.

  • Genetic data de-identification is a contested legal proposition, not a compliance safe harbor. The Tempus AI complaints allege that genetic information is inherently re-identifiable regardless of what identifying fields are stripped — a theory that, if accepted, would eliminate de-identification as a shield under state genetic privacy statutes including Illinois GIPA .
  • Post-acquisition data integration triggers independent consent obligations. The Tempus litigation frames the central question as whether an acquirer inherits the data rights of the target or must independently satisfy consent requirements — a gap that predates AI but is now being litigated in the AI training context .
  • AI inference capabilities have outpaced existing privacy frameworks. AI systems now derive sensitive health, behavioral, and financial inferences from inputs that patients and consumers do not recognize as health data — triggering state transparency laws, COPPA amendments, and a deployer-liability shift flagged by Baker McKenzie .
  • Wearable and beauty tech biometric data is regulated as sensitive personal information under multiple state regimes. Facial mapping, body scanning, and wearable health metrics are now classified as sensitive personal information under omnibus consumer privacy laws in California, Connecticut, Indiana, Kentucky, Rhode Island, Washington, and Nevada — outside HIPAA's covered-entity framework and subject to explicit consent requirements, data minimization obligations, and state AG enforcement .
  • California's 2026 AI transparency regime is the leading compliance deadline. AB 566, AB 853, and SB 53 activated January 1, 2026; opt-out mechanisms for automated decision-making are required by January 2027. Colorado's AI Act is phasing in through June 30, 2026. The EU AI Act reaches full implementation in August 2026 .
  • FDA now requires data provenance documentation for AI/ML regulatory submissions. The FDA's AI/ML framework explicitly demands traceable, auditable training data — converting what was previously best practice into a regulatory requirement with enforcement teeth for pharma-AI transactions .
  • Data provenance is a deal-breaker in pharma-AI M&A and licensing. A&O Shearman's guidance identifies three exposure areas in AI-pharma transactions: EHR/real-world evidence lacking patient authorization, misaligned data ownership and audit responsibilities, and training data that cannot withstand FDA scrutiny .
  • Standing doctrine for health data claims now bifurcates on sensitivity. The Tash ruling creates a pleading standard: allege that the disclosed data was sensitive, and the disclosure itself is injury-in-fact; allege only identifier linkage without sensitivity, and the claim fails at the threshold .
  • The state privacy patchwork now covers roughly 46% of the U.S. population. Alabama's enactment as the 21st state — with explicit consent for health data, no private right of action, and AG-only enforcement — reflects the dominant legislative template: business-friendly enforcement structure, but real substantive obligations on sensitive data categories .
  • Consumer-facing AI health tools are generating a distinct privacy exposure vector. The practice of uploading personal health records to general-purpose AI chatbots sits outside HIPAA's covered-entity framework, creating a gap that state privacy statutes and FTC authority are beginning to address .

Latest developments.

  • ShinyHunters defaced Canvas login portals at approximately 330 educational institutions, claiming 275-280 million records across 3.65 terabytes; Instructure has not confirmed scope; the University of Pennsylvania reported 306,000 affected users; the FBI and CISA are investigating; affected institutions face simultaneous FERPA, GDPR, and state notification obligations .
  • Wearable and beauty tech health data — stress, sleep, menstrual tracking, facial mapping — is now regulated as sensitive personal information under omnibus state privacy laws in seven states, with state AGs actively investigating cookie and pixel-tracking practices and class-action litigants challenging tracking under state wiretap statutes including California's CIPA; global GDPR fines exceeded €5 billion in 2025 .

Active questions and open splits.

  • Can genetic data be meaningfully de-identified under state privacy statutes? Tempus's core defense is that transferred data was de-identified; plaintiffs argue genetic information is inherently re-identifiable. Courts have not resolved this under GIPA or comparable state statutes — the answer reshapes the entire post-acquisition data integration playbook for life sciences .
  • Do acquisition-related data transfers require independent consent? Whether an acquirer steps into the target's consent framework or must re-obtain authorization — particularly where original collection predated the AI training use — is unresolved and central to the Tempus litigation .
  • What is the scope of deployer liability for AI inference? State transparency laws frame liability as resting with companies deploying AI, not just collecting data — but the precise doctrinal mechanism (negligence, statutory violation, warranty) is unsettled across jurisdictions .
  • How do wearable health data classification obligations interact across state regimes? Connecticut and Washington regulate wearable health metrics outside HIPAA, but the classification standards, consent triggers, and enforcement postures differ — leaving manufacturers of multi-state products without a unified compliance template .
  • Sensitive vs. non-sensitive data as the standing threshold. Tash creates a pleading bifurcation, but the boundary between "sensitive" and "non-sensitive" in the context of AI-inferred health data — where the system derives sensitive conclusions from ostensibly innocuous inputs — is not yet defined .
  • FDA data provenance requirements vs. HIPAA authorization gaps in pharma-AI deals. The FDA's AI/ML framework demands auditable training data, but many datasets used in drug discovery include EHR and real-world evidence that lacks explicit patient authorization for AI training — creating a compliance gap that neither HIPAA nor FDA rules cleanly resolve .
  • Institutional vendor liability for LMS and cloud-platform breaches. The Canvas incident raises whether educational institutions bear independent notification and liability exposure when a third-party SaaS vendor is compromised — and whether existing vendor contracts allocate that risk adequately .

What to watch.

  • Resolution of the ShinyHunters May 12 deadline and whether Instructure confirms breach scope — the confirmed record count will determine the scale of state notification obligations and likely trigger class-action filings against both Instructure and affected institutions .
  • Motions to dismiss in the Tempus AI litigation — specifically how the N.D. Ill. court addresses the de-identification defense under GIPA and whether it certifies a multi-state class .
  • Whether state AGs bring enforcement actions against wearable manufacturers and beauty tech companies for biometric data handling and pixel-tracking practices under the newly activated omnibus state privacy regimes .
  • California's January 2027 automated decision-making opt-out deadline — the first major compliance checkpoint under the 2026 transparency regime, and likely to generate enforcement guidance before year-end .
  • EU AI Act full implementation in August 2026 and whether it triggers compliance restructuring for US-based health AI and wearable platforms with EU exposure .
  • FDA guidance on data provenance standards for AI/ML submissions — any formal guidance will harden the due diligence checklist for pharma-AI transactions .

9 Contributing Entries

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based law firm, faces two proposed class-action lawsuits over a data breach that exposed sensitive information on 57,554 current, former, and prospective clients. The breach occurred in May 2026 when a cybercriminal impersonated the firm's IT department and convinced an attorney to upload client files to an external Google Drive account. The exposed data includes names, Social Security numbers, addresses, dates of birth, driver's license numbers, passport numbers, medical records, and health insurance information. Blank Rome announced the breach to affected clients on June 26, 2026—nearly a month after the incident occurred. The firm stated it will "aggressively defend" against the suits and claims they lack merit.

UN releases 2026 International AI Safety Report warning of enormous benefits and existential risks

The United Nations released the International AI Safety Report 2026, a comprehensive assessment concluding that advanced artificial intelligence presents both transformative opportunities and escalating dangers. The report, led by the UN agency for digital technology, finds that AI can accelerate development in health, education, and financial services in developing nations while simultaneously enabling cyberattacks, deepfake fraud, non-consensual intimate imagery, and biological weapon design. The core finding: AI capabilities in critical fields like biological research are advancing faster than governance frameworks, creating a dangerous gap between what is technologically possible and what remains safe.

Former Mayo Clinic AI Director Sues System Over Alleged Retaliation and AI Safety Cover-Up

Traci Tamiko Eto, former research director at Mayo Clinic, filed a federal lawsuit on July 6, 2026, alleging retaliation and wrongful termination after she raised concerns about AI safety failures and patient privacy violations. According to the complaint, Eto was demoted in July 2025, placed on involuntary medical leave, and fired in December 2025 when her position was eliminated in a reduction in force that reportedly affected only her role. The suit was filed in U.S. District Court for the District of Minnesota under the False Claims Act's retaliation provision, the Americans with Disabilities Act, and the Family and Medical Leave Act.

Judge Approves $46.75M Bankruptcy Settlement for 23andMe 2023 Data Breach Victims

A U.S. bankruptcy judge has approved a $46.75 million settlement to compensate victims of 23andMe's 2023 data breach, resolving claims after the genetic testing firm exposed the genetic data of nearly 6.9 million people worldwide. U.S. Bankruptcy Judge Brian Walsh in St. Louis ordered Chrome Holding—the entity that acquired 23andMe following its bankruptcy filing—to disburse the funds through Kroll Restructuring within five days.

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based national law firm, faces a proposed class action lawsuit alleging it failed to protect sensitive client data after a May 2026 social-engineering attack compromised information on over 57,000 individuals. An unauthorized third party impersonated IT staff and tricked a Blank Rome attorney into uploading confidential files to an external Google Drive account, exposing names, Social Security numbers, and potentially financial and medical records. The lawsuit names Blank Rome as defendant and alleges violations of common law, industry standards, the Federal Trade Commission Act, and HIPAA due to inadequate cybersecurity safeguards and delayed notification.

MedCity News Spotlights AI Health Tech’s Patent, FDA, and HIPAA Tradeoffs

Healthcare AI developers face a three-front legal challenge that requires coordinated planning from product inception, not sequential problem-solving after development. Patent counsel, FDA regulators, and HIPAA compliance teams must align on strategy before the first commercial release, according to a MedCity News analysis. The core tension is structural: companies must lock down product specifications early enough for FDA review while maintaining the technical flexibility that makes AI valuable, document human inventorship to satisfy patent law, and design data systems that support model monitoring and retraining without violating privacy rules.

42 States Secure Multistate Settlement for 23andMe 2023 Genetic Data Breach

A coalition of 42 state attorneys general, led by Washington AG Nick Brown, announced a settlement with 23andMe's bankruptcy trustee on July 14 resolving claims over a 2023 data breach that exposed genetic data of more than 220,000 Washington customers. Washington will receive approximately $500,000 as part of the multistate agreement, which addresses the company's failure to safeguard sensitive user information.

ChatGPT and Claude Account Sharing Leads to Privacy Breaches, Data Mix-ups, and Cybersecurity Risks

Users are sharing login credentials for premium AI services—ChatGPT Plus and Claude Pro—exposing themselves to serious privacy breaches. Connor Effrain, a 22-year-old digital fundraising associate, shared his ChatGPT account and inadvertently gave others access to sensitive health information about his Crohn's disease and personal details he had discussed with the chatbot. Both OpenAI and Anthropic explicitly prohibit account sharing in their terms of service, classifying these subscriptions as single-user only. The platforms detect concurrent sessions and suspend accounts that violate this rule.

Blank Rome Hit With Two Class Actions After May Data Breach Exposes 57,000 Clients

Blank Rome LLP, a Philadelphia-based firm, faces two proposed class-action lawsuits following a May 2026 data breach that compromised the personal information of 57,554 current, former, and prospective clients. A cybercriminal impersonating an IT staff member tricked an attorney into uploading sensitive files to an unauthorized external Google Drive. The exposed data includes Social Security numbers, medical records, driver's license numbers, passport information, and health insurance details.

mail Subscribe to Health Data Privacy email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap