Senator Elizabeth Warren and Representative Mary Gay Scanlon have reintroduced the Health and Location Data Protection Act, an update of the original 2022 bill tailored to the risks posed by modern AI services. Unlike the earlier version, which targeted data brokers, the revised proposal would bar companies from selling health and location data to brokers at all and would explicitly include anything users type into AI systems such as ChatGPT or Claude.
The bill gives the Federal Trade Commission (FTC) 180 days to write implementing rules, allocates $1 billion over ten years for enforcement, and permits both states and private individuals to bring lawsuits. The legislation counts among its supporters Ron Wyden and Bernie Sanders.
Why the revision now
The updated proposal responds to recent developments in which technology companies have actively solicited very sensitive medical information. According to the reporting, in January Elon Musk urged people to upload MRI scans to Grok, OpenAI launched ChatGPT Health for handling medical records, and Anthropic released a HIPAA-ready Claude for Healthcare days later.
Because the United States lacks a comprehensive federal data-privacy framework, much protection today depends on each company’s privacy policy. The new bill is an attempt to impose statutory limits after products that accept health data have already been deployed.
Takeaway
If enacted, the law would aim to prevent the sale of the most sensitive personal data — health and location information — to data brokers and would bring AI-chat inputs explicitly under protection. The FTC would have 180 days to issue rules, $1 billion would be set aside over ten years for enforcement, and both states and individuals would be able to sue for violations.



