Warren and Scanlon Reintroduce Health Data Sale Ban

Senator Elizabeth Warren (D-MA) and Representative Mary Gay Scanlon (D-PA) are preparing to reintroduce the Health and Location Data Protection Act, updated for the AI era to explicitly cover data disclosed to chatbots, according to reporting by The Verge and a Warren Senate press release. The bill would bar data brokers from selling Americans' health and location information. An earlier Senate version, S.5462, was introduced December 10, 2024, but died without passing in the prior Congress, per Congress.gov and GovTrack. For AI practitioners, tighter limits on brokered health and location data would shrink one class of commercial training and enrichment inputs and raise compliance requirements for products that ingest consumer health signals, including chatbot logs.
For teams that train or fine-tune consumer-facing models using third-party data, this bill matters less for what it does today (it has not yet been formally reintroduced as new text) and more for the direction it signals: reduced availability of brokered geolocation and inferred health signals raises provenance and auditability questions for feature pipelines, and increases legal risk for products that surface sensitive inferences to end users.
What happened
Reporting by The Verge attributes to Senator Elizabeth Warren and Representative Mary Gay Scanlon a plan to introduce a revised version of the Health and Location Data Protection Act tailored for the AI era, saying the proposal would bar the sale of Americans' health and location information to data brokers, including information revealed to chatbots. A Warren Senate press release described earlier iterations of the legislation as banning brokers from selling Americans' location and health data. Per Congress.gov, an earlier Senate filing under the title S.5462 was introduced on December 10, 2024. GovTrack records that the 2024/118th-Congress version did not advance and died in that Congress. HIPAA Journal summarizes provisions from earlier filings that would prohibit data brokers from selling, licensing, trading, or otherwise making available specified sensitive categories, and would create a federal registry of data brokers with consumer opt-out rights.
Policy context
Public reporting and prior bill text indicate the core enforcement lever is a prohibition on sale and transfer of covered categories plus a disclosure/registry requirement for brokers. Companies that historically sourced aggregated or inferred health/location signals from broker feeds or resale markets would face narrower lawful supply channels. For practitioners, that raises the importance of documented consent, first-party collection, and provenance metadata in training datasets; teams should assume broker-origin data will become higher-risk or unavailable in some product flows if similar language becomes law.
For practitioners
If comparable language passes, product teams using consumer chat logs, location telemetry, or third-party enrichment will need tighter data classification and purpose-binding controls. As legislation restricts a class of inputs, downstream model-validation work - label auditing, differential privacy, and adversarial testing for sensitive inference - tends to become more central to risk attestation and to supporting data-minimization claims.
What to watch
Track the formal bill text when released and whether sponsors define "health data" and covered "location data" explicitly, since legal scope will hinge on those definitions. Also watch committee referrals, whether enforcement is civil (FTC/agency) or criminal, and any carve-outs for HIPAA-covered entities - HIPAA Journal notes earlier versions exempted HIPAA-compliant disclosures. Finally, monitor whether the legislation includes transition periods or safe-harbor provisions affecting model retraining schedules and vendor contracts.
Editorial analysis
This is the third attempt at similar legislation (prior versions in 2022 and 2024 both stalled), and it has not yet been formally reintroduced with new bill text as of this reporting. Data scientists and ML engineers working with consumer health signals should treat this as an early-warning signal to inventory brokered inputs and tag provenance now, rather than a near-term compliance deadline.
Key Points
- 1Warren and Scanlon plan to reintroduce the Health and Location Data Protection Act with explicit AI-era provisions covering data disclosed to chatbots.
- 2An earlier Senate version, S.5462, was introduced December 10, 2024 but died without passing in the 118th Congress, per Congress.gov and GovTrack.
- 3If enacted, the ban on brokered health and location data sales would shrink a class of AI training inputs and raise provenance and compliance requirements.
Scoring Rationale
This proposed legislation directly targets commercial health and location data sales - including chatbot data - a notable class of training inputs for consumer-facing AI products, and the AI-tailored framing explicitly covering chatbot data is new. However, the bill has not yet been formally reintroduced with new text, and two prior iterations (2022, 2024) both stalled in Congress, so the score reflects notable-but-speculative policy exposure rather than enacted law.
Sources
Primary source and supporting public references used for this report.
View 6 more sources
- Warren, Sanders, Wyden, Whitehouse Renew Push to Protect Americans' Sensitive Data from Greedy Brokerswarren.senate.gov
- Health and Location Data Protection Act of 2024 - Congress.govcongress.gov
- Health and Location Data Protection Act of 2024 (2024; 118th Congress) - GovTrackgovtrack.us
- Democratic Senators Introduce Bill Banning Data Brokers from Selling Health and Location Datahipaajournal.com
- Senator Warren Introduces Bill to Ban the Sale of Location and Health Dataproskauer.com
- Health and Location Data Protection Act: What It Would Mean for Advertiserspixalate.com
Practice with real Health & Insurance data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Health & Insurance problems