Palo Alto – September 14, 2026 – Digital health has spent years treating privacy diligence as a question of regulatory classification: HIPAA or non-HIPAA, covered entity or not.
That framework is becoming less useful.
The FTC did not repeal the Health Breach Notification Rule. Much of the 2021 guidance was written into the rule in 2024. What changed is the FTC’s approach: less interpretation through policy statements, more reliance on the rule itself. At the same time, health data is moving through more systems, making it harder to see who can access it, where it goes, and where responsibility sits.
The enforcement timeline around unauthorized sharing of health data is instructive. In February 2023, GoodRx agreed to pay a $1.5 million civil penalty after the FTC alleged health information was disclosed to Facebook, Google and others. In May 2023, the FTC brought a similar action against Premom, alleging that SDKs transmitted sensitive health information to AppsFlyer, Google and other third parties.
Then, in April 2024, the FTC finalized amendments to the Health Breach Notification Rule, expressly clarifying its application to health apps and unauthorized disclosures.
And on July 29, 2026 — only six weeks before this week’s rescission — the FTC sued Hims & Hers, alleging that sensitive health information was shared with Meta, Snap and other advertising platforms.
Those cases have a common feature: the risk was not simply in the core clinical application. It was in the connections around it.
AI expands that surface further. Models, agents, APIs and MCP-connected tools can move or expose information across systems without fitting neatly into traditional application boundaries.
For M&A, that changes the diligence question. Buyers need to understand not just where data sits, but where it travels, what can access it, and how much of that movement is actually necessary.
That also puts more value on advisors who understand the underlying technology. At Woodside Capital Partners, technical diligence is part of understanding what a buyer is actually acquiring — and where the risks or advantages may sit before a process begins.
For companies preparing for a transaction, architecture can also strengthen the asset. Synthetic data can reduce the need to repeatedly expose source patient records for development and testing. Edge AI can keep inference closer to the device or point of care. Federated approaches can bring computation to distributed datasets rather than moving everything into a central environment.
None of these approaches eliminates privacy risk. But they can materially change the data perimeter.
That matters in a transaction. Two companies may have access to similarly valuable health data, but the company that can show precisely where sensitive information resides, how it is accessed, and how unnecessary movement is minimized may be a cleaner asset to underwrite.
In digital health, architecture is becoming part of the value proposition — not just part of the engineering stack.
