Lawmakers want to ban AI companies from selling your health data

72d ago · US · primary source: theverge.com

Senator Elizabeth Warren and Representative Mary Gay Scanlon are preparing to introduce legislation that would prohibit AI companies from selling Americans' health and location data to data brokers, expanding a 2022 bill to cover information shared with chatbots like ChatGPT and Claude. The updated Health and Location Data Protection Act, also sponsored by Senators Ron Wyden and Bernie Sanders, would require the Federal Trade Commission to issue implementing rules within 180 days [1]. The measure earmarks $1 billion to the FTC over the next 10 years for enforcement and authorizes the agency, state attorneys general, and affected individuals to sue [1]. The original version, introduced in June 2022, barred data brokers from collecting and selling health and location data; the new draft extends the prohibition to any company selling such data to brokers and explicitly covers data entered into AI systems [1]. Senator Warren said in a statement, "It's more important than ever that we crack down on data brokers that are raking in giant profits from selling Americans' most sensitive information" [1]. She added that as more people enter private health data into AI, the information must not be "exploited by the highest bidder" [1]. The bill arrives as AI companies accelerate their push into health care. In January, Elon Musk urged users to upload medical records such as MRI scans to Grok, xAI's chatbot [1]. That same month, OpenAI launched ChatGPT Health, a sandboxed tab it described as more secure, and ChatGPT for Healthcare, aimed at medical providers [1]. Anthropic followed days later with Claude for Healthcare, a tool it called "HIPAA-ready" for individuals, providers, and hospitals [1]. Sara Gerke, a law professor at the University of Illinois Urbana-Champaign, told The Verge in January that data protection for such tools "largely depends on what companies promise in their privacy policies and terms of use" [1]. The United States lacks a comprehensive federal data privacy framework despite years of legislative attempts [1]. Generative AI tools, including the chatbots named in the bill, have seen rapid adoption since the AI boom of the 2020s, driven by advances in large language models based on the transformer architecture [2]. Companies across health care, finance, and other sectors have integrated these systems, even as concerns mount over data security and unauthorized access [2]. The proposed legislation represents one of the most direct congressional efforts to constrain how AI firms monetize sensitive user information.

regulationcontroversy

Background sources we checked (10)
  • en.wikipedia.org ↗ Generative artificial intelligence (GenAI) is a subfield of artificial intelligence (AI) that uses generative models to generate text, images, videos, audio, software code (vibe coding) or other forms of data. These models learn the underlying patterns and structures of their tra…
  • en.wikipedia.org ↗ Instagram is an American photo and short-form video sharing social networking service owned by Meta Platforms. It allows users to upload media that can be edited with filters, be organized by hashtags, and be associated with a location via geographical tagging. Posts can be share…
  • en.wikipedia.org ↗ xHamster is a pornographic video sharing and streaming website, based in Limassol, Cyprus. It was founded by Oleg Netepenko and Dmitri Gusev in 2005. xHamster serves user-submitted pornographic videos, webcam models, pornographic photographs, and erotic literature, and incorporat…
  • en.wikipedia.org ↗ Big Tech, also known as the tech giants or tech titans, are the largest and most influential technology companies in the world. It most commonly refers to the five dominant firms in the U.S. technology industry—Microsoft, Apple, Alphabet (Google), Amazon, and Meta (Facebook)—whic…
  • en.wikipedia.org ↗ Under the second presidency of Donald Trump, the federal government of the United States has pursued an economic policy focused on lower taxation, deregulation, and large-scale protective tariffs. Trump nominated Howard Lutnick as the United States Secretary of Commerce, Scott Be…
  • arxiv.org ↗ We present DarkAgents: a multi-agent system that leverages the reasoning and code-generation capabilities of large language models (LLMs), together with deterministic tested human-written code, to build orchestrated pipelines for theoretical astroparticle physics research. While …
  • arxiv.org ↗ Indirect prompt injection in tool-use agents is a concrete production threat: LLM agents read from integrations (third-party services such as Gmail, Salesforce, or Jira accessed through tool calls) whose response content the user neither writes nor controls. Existing benchmarks u…
  • arxiv.org ↗ Selecting the right electricity market region for a hyperscale AI datacenter requires reasoning across live electricity prices, grid carbon intensity, technology cost trajectories, and causal grid dynamics -- a multi-step, multi-source analytical task that static knowledge benchm…
  • arxiv.org ↗ Coding agents often pass per-prompt safety review yet ship exploitable code when their tasks are decomposed into routine engineering tickets. The challenge is structural: existing safety alignment evaluates overt requests in isolation, leaving models blind to malicious end-states…
  • arxiv.org ↗ Existing benchmarks of language-model refusal on malicious-coding tasks routinely conflate requests for executable malicious software with requests for harmful security knowledge. This conflation matters because the two request types plausibly trigger distinct refusal pathways in…

Sources

Spot something wrong? Report an issue