KPSGILL policy proposal · model legislation
Health data outside HIPAA
A clinic that takes two years to hand over records pays a penalty. An app holding the same information owes almost nothing. The duty is attached to the holder rather than to the data, and that is the defect.
The problem
The privacy framework applies to covered entities. Health information does not stay inside them. It moves into symptom trackers, cycle apps, wearables, direct-to-consumer testing, AI assistants asked clinical questions, and the analytics embedded in health-system websites — and in most of those places the obligations that attach to a clinic simply do not exist.
The asymmetry is visible in enforcement. A California eye-care group settled after a records request went unfulfilled for two years, on the strength of a right-of-access rule and an agency willing to enforce it ENFORCEMENT. An app that loses the same data, or refuses to return it, faces a general consumer-protection regime and little else.
Documentary baseline: the right-of-access settlement recorded in the enforcement layer; the EU transparency obligations that began applying in August 2026 and reach any system a patient interacts with; and the consumer-app and tracking-technology analyses in the policy library.
The recommendation
§ 1. Coverage. This article applies to a person who collects, receives or infers health-related data about a resident, whether or not that person is a covered entity, and whether the data is provided by the individual, generated by a device, or inferred from behaviour.
§ 2. Inference is data. A health-related inference drawn from non-health data is health-related data for the purposes of this article. Purchase history that yields a pregnancy inference is a pregnancy inference.
§ 3. Access. On request, a person subject to this article shall provide the individual with the health-related data it holds about her, and any health-related inference it has drawn, in a portable format, within thirty days.
§ 4. Deletion and the limits of it. On request the person shall delete the data and any inference derived from it, and shall notify recipients to whom it was disclosed in the preceding twelve months. A model trained on the data need not be destroyed, but the individual’s data shall not be used in further training.
§ 5. Secondary use. Health-related data shall not be sold, nor used for advertising or eligibility determination, without express, separate, revocable consent that is not a condition of using the service.
§ 6. AI services. A person operating a service that responds to health questions shall disclose whether inputs are retained, whether they are used for training, and whether a human may review them.
§ 7. Enforcement. The Attorney General may enforce this article. An individual may bring an action for a violation of §§ 3, 4 or 5.
§ 2 is the provision the rest depends on, and the one most often left out: nearly all consequential health data about a person is now inferred rather than disclosed. § 4 is drafted to be honest about what deletion can and cannot reach once a model has been trained.
Who bears what
Patient
One rule for her health information regardless of who is holding it, and a thirty-day clock that already applies to her physician.
Physician
Less exposure to being the only accountable holder in a data ecosystem she does not control, and a defensible answer when a patient asks where the data went.
App and device makers
Real compliance cost, concentrated in §§ 3 and 5. The cost is highest for models built on secondary use, which is the point.
AI services
§ 6 is disclosure, not prohibition. It settles a question users currently cannot answer.
Equity
Inference-driven harms — insurance, employment, immigration exposure — fall hardest on people with the least ability to detect them.
Burden
On holders, and proportionate to how much they infer and how much they sell.
The strongest arguments against
- A state statute cannot regulate a national data market.
- Treating inferences as data makes ordinary analytics unlawful.
- Deletion duties are unworkable once data has moved.
- This entrenches large firms that can afford compliance.
- Thirty days is unrealistic for a small developer.
Answers
- It can regulate conduct toward its residents, which is how state privacy law has always worked and how the covered-entity framework itself is enforced in practice.
- It makes them subject to access and consent duties, not unlawful. § 5 prohibits sale and advertising use, not analysis.
- § 4 is drafted to be honest about the model boundary rather than promise erasure it cannot deliver.
- A serious objection. The answer is proportionate obligations, not exemptions from the access right, which is the cheapest duty here.
- A clinic of two people meets it today. A developer holding inferred pregnancy data should not owe less than a family physician.
Metrics. Median days to fulfil an access request by holder type; share of services disclosing retention and training under § 6; enforcement actions involving inferred data. Sunset. Five-year review; §§ 1–5 sunset if a federal framework reaches non-covered holders with equivalent or stronger duties. Open questions. Should § 4 notification run to downstream recipients indefinitely or only for twelve months? Does § 6 need a carve-out for clinical decision support already regulated as a device? Related: consumer health apps outside HIPAA · tracking technologies · the record integrity standard.