Senator Elizabeth Warren and Representative Mary Gay Scanlon are reintroducing the Health and Location Data Protection Act with new language that pulls AI chatbots directly into its scope, banning companies from selling health and location data that users hand over to systems like ChatGPT, Claude, and Grok. The revamped bill would also bar non-broker companies from selling that data to brokers in the first place, and it earmarks $1 billion to the Federal Trade Commission over 10 years for enforcement.
The original bill, introduced in June 2022, prohibited data brokers from collecting and selling health and location information. Four years later, the chatbot interface has become a primary collection point for exactly the data the bill was meant to protect, and the new draft writes that reality into the statute. The FTC would be required to enact implementing rules within 180 days, and the FTC, state attorneys general, and affected individuals would all have standing to sue.
The timing tracks a specific shift in how the frontier AI labs are courting users. In January, Elon Musk publicly urged people to upload medical records, including MRI scans, to xAI's Grok. The same month, OpenAI launched ChatGPT Health, a sandboxed tab inside ChatGPT that the company positioned as more secure for medical record uploads, alongside ChatGPT for Healthcare aimed at providers. Days later, Anthropic released Claude for Healthcare, marketed as a HIPAA-ready tool for individuals, providers, and hospitals.
Key facts
- 01Warren and Scanlon are reintroducing the Health and Location Data Protection Act, expanded to cover data entered into AI chatbots like ChatGPT, Claude, and Grok.
- 02The bill would require the FTC to enact rules within 180 days of passage.
- 03It earmarks $1 billion to the FTC over 10 years for enforcement.
- 04Co-sponsors include Senators Ron Wyden (D-OR) and Bernie Sanders (I-VT).
- 05The original bill was first introduced in June 2022 and targeted only data brokers; the new version reaches the AI companies collecting the data.
What none of those products carry is a federal floor underneath them. The United States still has no comprehensive federal data privacy law, leaving health information entered into chatbots governed primarily by each company's own privacy policy and terms of service — documents the company writes and can revise.
The bill is co-sponsored by Senators Ron Wyden and Bernie Sanders. Warren framed the proposal around the data-broker market that monetizes consumer health information downstream of the original collection point.
That broker market is the structural target. The expansion to cover AI inputs matters because chatbot transcripts are unusually rich: users describe symptoms, paste lab results, upload scans, and ask follow-up questions in a single session, producing a more complete medical profile than most traditional health apps capture. Selling that downstream, or licensing it for training, is currently a contractual question rather than a legal one.
Sara Gerke, a law professor at the University of Illinois Urbana-Champaign, said in January that the existing protections for tools from OpenAI and Anthropic rest almost entirely on what each company promises in its own policies.
Enforcement money is the part of the bill most likely to determine whether any of this changes behavior. The $1 billion FTC allocation over 10 years is meant to fund the kind of sustained investigative work the agency has historically struggled to staff against well-resourced tech defendants. The 180-day rulemaking clock is also aggressive by federal standards, designed to prevent the bill from passing and then stalling in administrative limbo.
The proposal faces the usual hurdles. Comprehensive federal privacy legislation has failed repeatedly in Congress over the past decade, and a narrower bill targeting one data category still has to clear committees and survive industry lobbying. AI companies are likely to argue that existing HIPAA-adjacent product tiers already address the concern, and that broad restrictions on data flows would limit beneficial medical research and product development. No vote has been scheduled.
For the AI labs, the bill is a preview of where US policy is heading even if this specific version doesn't pass. Health and medical use cases are one of the clearest near-term commercial wedges for chatbot products — high willingness to pay, sticky workflows, and a clear gap between what consumer chatbots can do and what their clinical counterparts cost. A federal rule that forces those products onto a tighter data-handling regime would push the labs toward more on-device processing, stricter retention defaults, and contractual cleanup with any downstream partners. The companies that have already invested in HIPAA-ready architectures will absorb that more easily than the ones still treating health data as ordinary chat traffic.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




