The landscape of healthcare AI privacy is undergoing a rapid, state-driven transformation, presenting both opportunities and significant compliance challenges for technology developers and healthcare providers alike. As we approach 2026, the analytical question facing the industry is clear: how will the divergent, yet increasingly stringent, state-level privacy laws in Washington, Colorado, and California reshape the architecture of AI-powered health solutions, particularly for those operating outside the traditional HIPAA framework?
This week, Healthcare AI Compliance Watch tracks the legislative currents, examining how these pioneering state regulations are establishing new baselines for data governance and privacy, directly impacting the investment case for AI in health. The focus is on understanding the compliance burden and strategic shifts required to navigate this complex regulatory mosaic, ensuring that innovation remains tethered to robust privacy protections.
The Expanding Reach of State Privacy: Beyond HIPAA’s Traditional Bounds
For years, the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule served as the primary federal benchmark for health data protection. However, the proliferation of digital health applications and AI tools, often operating outside the direct purview of covered entities and business associates, created a significant regulatory gap. This vacuum is now being filled by states, with Washington, Colorado, and California leading the charge to extend privacy protections to a broader spectrum of health-related data.
The Washington My Health My Data Act, for instance, specifically targets health apps directly, a critical distinction that broadens the scope of regulated entities far beyond traditional healthcare providers and insurers. This legislation introduces stringent requirements for consumer consent, data deletion, and even geofencing around healthcare facilities, impacting companies like BetterHelp, GoodRx, and Hims & Hers, whose business models often rely on collecting and processing consumer health information that might not be considered Protected Health Information (PHI) under HIPAA. The My Health My Data Act’s provisions for regulated entities (not small businesses) became effective on March 31, 2024, with small businesses following on June 30, 2024, and the geofencing prohibition effective July 23, 2023. The implications are profound for AI developers who must now contend with a patchwork of definitions for “health data” and “consumer health data” that are often more expansive than HIPAA’s definition of PHI. As legal scholars I. Glenn Cohen and Carmel Shachar have frequently highlighted, the fragmentation of health data privacy laws creates a complex compliance environment, particularly for cross-state operations. Analysis of state health data privacy laws by leading legal scholars
Compliance solution providers such as OneTrust, Vanta, and Drata are increasingly critical for companies navigating these new mandates. These platforms offer tools to manage consent, data mapping, and privacy impact assessments, which are becoming indispensable for maintaining regulatory readiness. The challenge is not just technical implementation but also a fundamental re-evaluation of data collection and processing strategies from the ground up to ensure they align with the strictest state requirements.
California’s Enduring Influence: CCPA, CPRA, and AI Healthcare Implications
California’s privacy framework, anchored by the California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), continues to exert significant influence. While not explicitly health-specific in the same manner as Washington’s Act, CCPA/CPRA adds California requirements that indirectly impact AI healthcare operations by granting consumers extensive rights over their personal information, including health-related data not covered by HIPAA. This includes the right to know, delete, and opt-out of the sale or sharing of personal information. New regulations under the CCPA and CPRA, particularly those addressing automated decision-making technology (ADMT), risk assessments, and cybersecurity audits, took effect on January 1, 2026, significantly expanding compliance requirements. Additionally, the Delete Act, which imposes new requirements on data brokers, also became effective on January 1, 2026. For AI systems, this translates to heightened demands for data provenance, explainability, and the ability to fulfill individual rights requests, such as the deletion of data used for model training. The relationship between these broader privacy laws and specific health data regulations is a key area of ongoing interpretation and enforcement.
The operational burden for companies like BetterHelp, GoodRx, and Hims & Hers operating in California is substantial. They must not only comply with the spirit of these laws but also implement robust data governance mechanisms to track data flows, manage consent, and respond to consumer requests effectively. The intersection of AI’s data-intensive nature and these expansive privacy rights presents a unique compliance puzzle. As per data point CW5-DP-17, the cost of non-compliance, particularly in California, can be significant, ranging from substantial fines to reputational damage. This necessitates proactive investment in privacy-by-design principles for any AI healthcare solution.
Navigating the Regulatory Triad: State AGs, HHS OCR, and FTC Enforcement
The enforcement landscape for healthcare AI privacy is a multi-layered affair, involving State Attorneys General (AGs), the Department of Health and Human Services Office for Civil Rights (HHS OCR), and the Federal Trade Commission (FTC). While HHS OCR primarily enforces HIPAA, State AGs are increasingly active in enforcing their respective state privacy laws. The FTC, with its authority over unfair and deceptive trade practices, has also demonstrated a keen interest in data privacy violations, particularly when companies misrepresent their data practices or fail to secure sensitive information. This creates a complex web of oversight, where a single data breach or privacy lapse could trigger investigations from multiple agencies.
The proactive stance of State AGs, particularly in Washington, Colorado, and California, means that companies cannot afford to view compliance as a static checkbox exercise. Instead, it requires continuous monitoring of legislative developments and a dynamic approach to privacy program management. The Colorado Privacy Act (CPA), which went into effect on July 1, 2023, saw its 60-day right to cure provision expire on December 31, 2025, allowing for immediate enforcement actions as of January 2026. Colorado also began requiring the recognition of universal opt-out mechanisms in January 2026. Furthermore, Colorado’s Artificial Intelligence Act, which regulates high-stakes algorithmic decisions in sectors including healthcare, is set to become effective on June 30, 2026. For AI healthcare solutions, this means ensuring transparency in data collection and usage, particularly regarding the training and deployment of algorithms. Companies must be prepared to articulate how their AI systems protect consumer privacy and how they comply with the specific requirements of each state law, demonstrating accountability to a diverse set of regulatory bodies. The potential for overlapping enforcement actions underscores the need for a comprehensive and harmonized compliance strategy.
The Path Forward: Strategic Compliance for AI Health Innovators
The emergence of robust state AI health privacy laws in Washington, Colorado, and California marks a significant shift in the regulatory environment for healthcare AI. These laws, while distinct, collectively demand a higher standard of data governance and consumer protection than previously existed. For policymakers and health IT professionals, the key takeaway is that a reactive approach to compliance is no longer viable. Instead, organizations developing or deploying AI in health must adopt a proactive, privacy-by-design methodology, integrating compliance considerations from the earliest stages of product development.
The strategic implication for companies like BetterHelp, GoodRx, and Hims & Hers, as well as the broader AI healthcare ecosystem, is clear: invest in comprehensive compliance infrastructure. Leveraging platforms like OneTrust, Vanta, and Drata can streamline the management of consent, data rights, and privacy assessments across diverse regulatory frameworks. Furthermore, continuous engagement with legal experts, such as those who regularly analyze these evolving privacy landscapes like I. Glenn Cohen and Carmel Shachar, will be crucial. The ability to demonstrate robust compliance with Washington’s My Health My Data Act, Colorado Privacy Act, and California’s CCPA/CPRA, while also adhering to HIPAA where applicable, will be a defining characteristic of regulatory-ready healthcare AI solutions in 2026. This commitment to privacy will not only mitigate legal risks but also build consumer trust, which is paramount for the successful adoption of AI in health. Industry report on best practices for AI privacy compliance
Frequently Asked Questions
How do state privacy laws, particularly in Washington, Colorado, and California, impact AI-powered health solutions that operate outside of HIPAA?
These state laws are extending privacy protections to a broader spectrum of health-related data beyond HIPAA’s traditional scope. They introduce more expansive definitions of “health data” and “consumer health data,” requiring AI developers to contend with a patchwork of regulations. This creates a complex compliance environment, particularly for cross-state operations, and necessitates a fundamental re-evaluation of data collection and processing strategies.
What specific requirements do state privacy laws like Washington’s My Health My Data Act impose on health apps and AI developers?
The Washington My Health My Data Act specifically targets health apps and introduces stringent requirements for consumer consent, data deletion, and geofencing around healthcare facilities. This impacts companies whose business models rely on collecting and processing consumer health information that might not be considered Protected Health Information (PHI) under HIPAA. AI developers must now comply with these broader definitions and requirements.
How do California’s CCPA and CPRA affect AI healthcare operations, even though they are not explicitly health-specific?
California’s CCPA and CPRA indirectly impact AI healthcare operations by granting consumers extensive rights over their personal information, including health-related data not covered by HIPAA. This includes rights to know, delete, and opt-out of the sale or sharing of personal information. For AI systems, this translates to heightened demands for data provenance, explainability, and the ability to fulfill individual rights requests, such as the deletion of data used for model training.
What are the key compliance challenges for AI developers due to these divergent state privacy laws?
The key compliance challenges include navigating a patchwork of definitions for “health data” and “consumer health data” that are often more expansive than HIPAA’s PHI. Developers must also contend with stringent requirements for consumer consent, data deletion, and the ability to fulfill individual rights requests, such as data deletion for model training. This necessitates robust data governance mechanisms and a re-evaluation of data collection and processing strategies.