New bill would ban AI companies from selling your health data to brokers
ChatGPT or Claude health chats could become off-limits to data brokers under new proposal.
A bipartisan group of lawmakers led by Senator Elizabeth Warren (D-MA) and Representative Mary Gay Scanlon (D-PA) plans to reintroduce a strengthened version of the Health and Location Data Protection Act in the coming weeks. The original 2022 bill banned data brokers from selling health and location data. The 2026 update goes further: it also prohibits any company — including AI chatbot providers like OpenAI, Anthropic, and xAI — from selling such data to brokers. The bill explicitly covers sensitive information users share with conversational AI systems, such as medical records uploaded to ChatGPT Health, Claude for Healthcare, or Grok.
This legislative push comes as AI labs aggressively move into health. In January 2026, Elon Musk urged users to upload MRI scans to Grok. OpenAI launched ChatGPT Health (a sandboxed tab) and ChatGPT for Healthcare for medical providers. Anthropic quickly followed with a HIPAA-ready Claude for Healthcare. However, the US lacks a comprehensive federal data privacy law, so protection depends on corporate privacy policies. The bill would require the FTC to issue rules within 180 days, allow lawsuits by state AGs and individuals, and allocate $1B to the FTC over ten years for enforcement. "It's more important than ever that we crack down on data brokers," Warren said.
- Expands 2022 data broker ban to cover all companies selling health/location data, including AI chatbots like ChatGPT, Claude, and Grok.
- Bill follows rapid health AI product launches: ChatGPT Health, Claude for Healthcare, and Musk's call to upload MRI scans to Grok.
- Allocates $1B to FTC over 10 years for enforcement; allows lawsuits by FTC, state AGs, and affected individuals.
Why It Matters
Without federal privacy law, your health chats with AI could be sold — this bill finally closes that loophole.