Health privacy

California lawmakers advance health app privacy rules

Assemblymember Mia Bonta’s bill would bring more consumer health software and AI tools under the state’s medical confidentiality law. That could limit how apps, chatbots and similar services share, sell or reuse sensitive health information.

2 min read·544 words·View source
California lawmakers advance health app privacy rules
1 / 3
Photo by Ivan S on Pexels

California’s AB 1979 would extend medical privacy protections to more digital health tools. For people using apps or chatbots for health information, that means stronger limits on what companies can do with sensitive data.

  • More health apps could fall under California medical-privacy law.
  • The bill focuses on AI tools that handle information tied to care.
  • Consumers could get stronger limits on sharing and selling health data.
  • Recorded votes show the bill cleared a floor vote.
  • California health apps that store lab results, summarize doctor’s notes or answer symptom questions could face stricter privacy rules under AB 1979

health apps that store lab results, summarize doctor’s notes or answer symptom questions could face stricter privacy rules under . Assemblymember ’s bill would fold certain AI-related health services and consumer tools into the , or , the state law that already limits how covered medical information can be shared, sold or reused.

The bill does not ban artificial intelligence in health care. It changes which products have to live inside ’s medical-privacy rules when they handle information tied to diagnosis, treatment or management of a condition.

Where the privacy line moves

’s CMIA already bars covered health entities from intentionally sharing, selling or using medical information for purposes not necessary to provide care. It also already reaches some consumer software and hardware designed to maintain medical information so a patient or provider can access it at the individual’s request.

AB 1979 would clarify that this can include tools that query a medical history, organize lab results or summarize doctor’s notes. It would also define a healthcare chatbot as a with a natural-language interface that gives adaptive, human-like responses and uses consumer health information to help deliver mental or physical health services.

The practical effect is that some consumer-facing health tech would have to behave more like a records keeper than a general app. That means tighter limits on what can be shared, sold or repurposed once the information is being used to manage care.

Why the AI piece matters

The bill is aimed at a simple gap. Health data now moves through apps, websites and chatbots long before a person sees a clinician, and those tools can collect some of the most personal information in daily life. AB 1979 would bring more of that market under the existing confidentiality structure instead of creating a separate privacy regime from scratch.

Recorded votes show the bill cleared a floor vote. In a field where software changes faster than the law, that matters because the rules would follow the data, not just the device that stores it.

What users would notice

For patients, the change is not about whether an app is useful. It is about whether the app has to follow medical-privacy rules once it starts handling information tied to diagnosis, treatment or condition management.

For providers and health plans, the bill would push more digital tools into the same privacy lane as traditional medical records systems, with the same basic expectation that sensitive information is not there to be used for whatever purpose a company prefers.

Sources

Synthesized from 12 verified citationsSynthesized by AI linked to original documents.

goflashCover everything