Healthcare AI Governance

Practical AI Governance Insights for Hospital Leaders & Clinicians

Evidence-informed frameworks, governance handbooks, and onsite workshops that help hospitals deploy AI safely—and help patients trust it.

Your Chatbot Therapist Is Listening. But Who Else Is?

In the search for accessible mental health support, millions have turned to AI chatbots. These digital tools promise a confidential, stigma-free space to discuss our deepest anxieties.

Your Chatbot Therapist Is Listening. But Who Else Is?

The Algorithmic Couch, Part 1: Your Chatbot Therapist Is Listening. But Who Else Is?

In the search for accessible mental health support, millions have turned to AI chatbots. These digital tools promise a confidential, stigma-free space to discuss our deepest anxieties. But as we pour our hearts out to an algorithm, a critical question emerges: who is actually listening? The answer is far more complicated than you might think. While we assume these conversations are protected by the same ironclad confidentiality as a human therapist, the reality is a legal gray area that leaves consumers dangerously exposed.

The HIPAA Illusion

Most of us associate health data privacy with HIPAA (the Health Insurance Portability and Accountability Act). This landmark law is the bedrock of patient confidentiality in the U.S.. If a hospital or your doctor's office provides you with a mental health app, that app and its developer are bound by HIPAA's strict rules. They must sign a Business Associate Agreement, legally obligating them to encrypt your data, control access, and maintain audit trails.

Here’s the loophole: The vast majority of mental health apps are downloaded directly by consumers from app stores. In this direct-to-consumer model, the developer has no relationship with your doctor or a hospital. Therefore, they are not considered a Covered Entity or Business Associate, and HIPAA does not apply.

Think about that.

The sensitive data you share—about your depression, your relationships, your suicidal thoughts—is not legally considered Protected Health Information (PHI). It can be collected, analyzed, and even shared with third parties like advertisers without violating HIPAA.

The FTC Steps In

Into this regulatory void has stepped the Federal Trade Commission (FTC). Using its authority to police unfair or deceptive acts, the FTC has become a de facto privacy enforcer for the digital health world.

The agency's powerful tool is the Health Breach Notification Rule (HBNR). This rule requires non-HIPAA covered apps to notify users of any breach of security. Crucially, the FTC defines a breach not just as a hack, but as any unauthorized sharing of user data. An app that shares your mental health journey with an advertiser without your explicit consent is committing a reportable breach. Through significant enforcement actions, the FTC is sending a clear message: your privacy policy is a binding promise, and breaking it has consequences.

A Patchwork of Protection.

To complicate matters further, developers must also navigate a maze of state-level laws. A state like Florida, for example, has its own robust data breach law (FIPA) that explicitly includes mental health history as protected personal information and mandates a strict 30-day notification timeline for breaches. This creates a two-tiered system where the privacy of your mental health data depends not on its sensitivity, but on the business model of the app you use and the state you live in.

It’s a confusing and risky landscape for the very people these apps claim to help. In our next edition, we’ll explore another critical legal question: Is your chatbot a wellness tool or a regulated medical device? The answer determines whether it needs to be proven safe and effective before it ever reaches your phone.

States Stopped Waiting on Washington

Since I wrote the first part of this series, the regulatory gray area I described has started closing — fast, and from an unexpected direction. Illinois Governor JB Pritzker signed the Wellness and Oversight for Psychological Resources Act in August 2025, banning the use of AI for mental health or therapeutic decision-making without oversight by a licensed clinician, with civil penalties up to $10,000 per violation Association of Health Care Journalists on state AI mental health laws. It passed unanimously in both chambers of the Illinois General Assembly Association of Health Care Journalists on state AI mental health laws — which tells you something about how little political appetite remains for defending the current free-for-all.

Illinois wasn't first and won't be last. Nevada's legislature passed a law in June 2025 prohibiting AI providers from claiming their systems can deliver professional mental or behavioral health care, or from marketing AI as a substitute for it, backed by civil penalties of $15,000 Association of Health Care Journalists on state AI mental health laws. Utah tightened its rules in May 2025: mental health chatbot suppliers can no longer sell or share users' health information with third parties, cannot run undisclosed advertising through the chatbot, and must clearly tell users they're talking to AI, not a human Association of Health Care Journalists on state AI mental health laws. More than 250 AI-in-healthcare bills were pending across state legislatures as of mid-2025 Association of Health Care Journalists on state AI mental health laws, which means the "patchwork" I warned about in part one is now a genuinely different compliance landscape depending on where your patients live — not just where your hospital is licensed.

For hospital systems that operate across state lines or refer patients to direct-to-consumer mental health apps as a stopgap for access gaps, this matters immediately. A referral or informal recommendation to a chatbot that's now flatly illegal in Illinois, restricted in Nevada, or subject to disclosure rules in Utah is not a neutral act anymore. It's a compliance exposure with a per-violation dollar figure attached.

The Breach I Warned About Already Happened

Part one described the HIPAA loophole and the FTC's Health Breach Notification Rule as the backstop. That backstop just got tested at scale. In February 2026, a security researcher discovered an exposed database behind Chat & Ask AI, an app with more than 50 million users built by Codeway, that exposed roughly 300 million messages tied to more than 25 million users Malwarebytes report on AI chat app data leak. The exposed messages reportedly included discussions of illegal activity and requests for suicide assistance Malwarebytes report on AI chat app data leak — precisely the category of disclosure people believe they're making in confidence when they turn to a chatbot instead of a person.

The cause wasn't sophisticated. It was a well-documented Firebase misconfiguration — security rules left open to the public, so anyone with the project URL could read, modify, or delete data without authentication Malwarebytes report on AI chat app data leak. The same researcher scanned 200 iOS apps for the identical flaw and found it in 103 of them, exposing tens of millions of additional files Malwarebytes report on AI chat app data leak. That is not a one-off vendor failure. That is a pattern across roughly half of a random sample of consumer AI chat apps.

Here's the part hospital compliance officers need to sit with: this wasn't a HIPAA-covered entity, so no OCR breach report, no HHS wall of shame listing, no mandatory patient notification under HIPAA applies. Whether it triggers the FTC's Health Breach Notification Rule turns on whether the exposed data counts as PHR identifiable health information and whether the disclosure was "unauthorized" under the rule's definition — a definition broad enough that the FTC has already used it to settle with GoodRx and Easy Healthcare over sharing health data with advertisers without proper disclosure FTC blog on updated Health Breach Notification Rule. If your patient education materials, discharge instructions, or care navigators are pointing patients toward consumer chatbot apps by name, you are recommending tools operating in a security environment where roughly half of a sampled cohort had the same critical, publicly known flaw.

What This Means for Your Organization Right Now

None of this requires you to become a privacy lawyer. It requires a short list of concrete actions before your next patient-facing AI initiative goes live.

  • Stop informally recommending consumer mental health chatbot apps by brand name in discharge materials or care navigation scripts until legal has confirmed the app's status under your state's current law — Illinois, Nevada, and Utah now impose real penalties and disclosure duties.
  • Ask any AI mental health vendor you're evaluating for evidence of a third-party security audit of their backend configuration, not just a HIPAA compliance attestation — the Chat & Ask AI breach happened because of a basic, previously documented cloud misconfiguration, the kind a vendor questionnaire should catch.
  • Build a one-page internal reference tracking which states where you have patients or facilities have passed AI mental health restrictions, since the rules differ meaningfully between Illinois (licensed-clinician oversight required), Nevada (marketing restrictions), and Utah (disclosure and data-sharing limits).
  • Treat any chatbot-adjacent tool your organization builds or licenses as being one misconfiguration away from a reportable incident, and require the same breach-response runbook you'd use for an EHR vendor — because your patients cannot tell the difference between your tool and a consumer app once their data is exposed.

Continue the Conversation

If this resonated, here is where to go next: Join the AI-in-Healthcare Workshop · Get the Books · Contact Dan