Congress has not fixed the health data gap yet, but the direction is plain: wearable and AI health startups that built around loose consent should stop treating that loophole as permanent.
The newest warning did not come from a theoretical privacy panel. Axios reported on June 25, 2026, that Whoop and health records platform HealthEx had just announced a way for users to share medical records inside Whoop's app ecosystem. The minute a patient pulls protected health data out of a doctor's office and into a consumer app, HIPAA no longer does the heavy lifting. If you're building a health AI company, that is the part to sit with.
HIPAA still governs hospitals, insurers, clearinghouses, and the contractors tied directly to them. It does not automatically cover the fitness tracker on your wrist, the sleep app on your phone, the AI coach asking about your medication history, or the symptom chatbot collecting details a user would never post anywhere else. Outside that covered system, companies face a patchwork of state laws, privacy policies, and Federal Trade Commission oversight. That's a weak structure for data that can reveal fertility patterns, stress, sleep, exercise, heart rate, and mood.
Congress has been circling this gap for years, and Sen. Bill Cassidy is still one of the names to watch. Axios noted that Cassidy's effort to expand privacy protections for smartwatches and health apps has not gained momentum. That stalled progress does not mean the issue is dead. It means founders have a window, and it may be shorter than they think.
The old Smartwatch Data Act, backed by Cassidy and Sen. Jacky Rosen after Google's Fitbit deal drew scrutiny, tried to stop wearable makers from selling identifiable device data that insurers could use against patients. TechRadar reported this year that Cassidy's Health Information Privacy Reform Act would make wearable companies treat certain data more like protected health information under HIPAA. Sens. Josh Hawley and Richard Blumenthal also introduced the AI Accountability and Personal Data Protection Act in July 2025, aimed at giving people a civil claim when companies use personal data or copyrighted works to train AI without consent. These bills are not identical. They do share a target: the casual collection and reuse of personal data because the user clicked through a screen once.
None has passed.
But waiting for passage is a bad plan. Washington is slow, then suddenly expensive. If your revenue model depends on licensing user-generated health data, training models on it, or helping advertisers and partners infer who is anxious, pregnant, sleepless, diabetic, depressed, or likely to need care, you should assume that the consent standard will tighten. Frankly, it should.
The FDA is pulling the industry in a different direction. TechRadar reported that Oura said the FDA issued a revised General Wellness Policy for Low Risk Devices on January 6, 2026, after the smart ring maker pushed for more flexibility around low-risk wearable features. That kind of change can help companies ship faster. It also means more devices may sit in the broad wellness category while collecting intimate physiological signals at scale.
That is the tension founders now have to manage. Regulators may let more hardware avoid medical-device review, while lawmakers ask whether the data from that hardware deserves tougher privacy rules. You cannot solve that by calling a product wellness in the app store and medical-grade in the investor deck.
The consent problem is becoming the business problem
Health AI startups have grown around a convenient assumption: if the data is outside HIPAA, it is easier to use, share, and monetize. That assumption powered a lot of pitch decks. It also created a fragile base for companies that want to sell into insurers, pharma, employers, or health systems later.
The risk is not only that Congress bans one practice. The larger risk is that customers, partners, and acquirers start asking harder questions before the law changes. Who gave consent? What exactly did they consent to? Was the data sold, shared, enriched, or used for model training? Can the company delete it? Can it prove that? Those are not soft policy questions. They decide whether a startup can pass diligence.
Look at the Whoop and HealthEx example. A user may reasonably think they are moving their own records to improve their own health. They may not understand that the legal protections change once the data lands in a consumer app. That gap between user expectation and company permission is where privacy fights begin.
Founders should build for the expectation, not the loophole. Ask for explicit consent before data is sold or shared. Separate product improvement from third-party monetization. Make model-training permissions clear instead of burying them in general terms. Keep a real map of where health data moves, not a comforting slide that says it is secure.
There is a commercial reason to do this now. If Cassidy, Rosen, Hawley, Blumenthal, or another pair of senators eventually gets a bill through, the companies with clean consent records will adapt faster than the ones trying to unwind years of casual data use. If Congress stalls again, users and enterprise buyers will still care. Health data is too personal for vague permission.
Also read: Taiwan Raided Super Micro's Offices Today as the Nvidia Chip Smuggling Case Reaches a New Front • Arena hit $100M in annualized revenue by letting AI companies pay to be evaluated, and that is exactly the problem • Cursor's mobile app signals that coding has become a job you supervise, not a desk you sit at