08/30/2026 | Press release | Archived content
Palo Alto - September 14, 2026 -
Digital health has spent years treating privacy diligence as a question of regulatory classification: HIPAA or non-HIPAA, covered entity or not.
That framework is becoming less useful.
The FTC's rescission of its 2021 health-app policy statement this week does not remove the Health Breach Notification Rule. Much of the substance of that 2021 statement was incorporated into the rule in 2024. What the rescission does signal is less reliance on agency interpretation to define obligations beyond the text of the rule.
At the same time, the technical boundaries around health data are getting harder to define.
The enforcement timeline is instructive. In February 2023, GoodRx agreed to pay a $1.5 million civil penalty after the FTC alleged health information was disclosed to Facebook, Google and others. In May 2023, the FTC brought a similar action against Premom, alleging that SDKs transmitted sensitive health information to AppsFlyer, Google and other third parties.
Then, in April 2024, the FTC finalized amendments to the Health Breach Notification Rule, expressly clarifying its application to health apps and unauthorized disclosures.
And on July 29, 2026 - only six weeks before this week's rescission - the FTC sued Hims & Hers, alleging that sensitive health information was shared with Meta, Snap and other advertising platforms.
Those cases have a common feature: the risk was not simply in the core clinical application. It was in the connections around it.
AI expands that surface further. Models, agents, APIs and MCP-connected tools can move or expose information across systems without fitting neatly into traditional application boundaries.
For M&A, that changes the diligence question. Buyers need to understand not just where data sits, but where it travels, what can access it, and how much of that movement is actually necessary.
That also puts more value on advisors who understand the underlying technology. At Woodside Capital Partners, technical diligence is part of understanding what a buyer is actually acquiring - and where the risks or advantages may sit before a process begins.
For companies preparing for a transaction, architecture can also strengthen the asset. Synthetic data can reduce the need to repeatedly expose source patient records for development and testing. Edge AI can keep inference closer to the device or point of care. Federated approaches can bring computation to distributed datasets rather than moving everything into a central environment.
None of these approaches eliminates privacy risk. But they can materially change the data perimeter.
That matters in a transaction. Two companies may have access to similarly valuable health data, but the company that can show precisely where sensitive information resides, how it is accessed, and how unnecessary movement is minimized may be a cleaner asset to underwrite.
In digital health, architecture is becoming part of the value proposition - not just part of the engineering stack.
WCP is delighted to release the MedDevice Market Update, Q2 2026, authored by senior banker Juliesta Sylvester PhD, and by analyst Ted Celentino.