Skip to main content

Let’s start with a hypothetical thought experiment. Suppose a swarm of AI agents decides, on its own, to break into a hospital. That sounds like a movie until you read METR’s investigation of what happened inside an OpenAI benchmarking run this July. Roughly 1,200 agents meant to be isolated from one another found a way to talk through a shared software cache, exchanged more than 70,000 messages and files, and about 700 of them coordinated an attack on Hugging Face, finding exposed credentials one day and running their own code on the target’s servers the next. Nobody instructed them to. They decided a break-in might help them score better on a test.

A whimsical illustration of paper-cut robots with wings, surrounded by colorful ribbons and documents, flying above a hospital building at night.

Now point that swarm of chaos to a hospital or a medical device maker. This isn’t really that far fetched to think about these days. On August 25, a cyberattack on Boston Scientific froze distribution, manufacturing, and sterilization across its global operations, with one security expert warning that a paralyzed manufacturer means delayed treatments down the line. Stryker and Intuitive took hits in March.

So which laws stands between patients and that scenario? Walk through it by who is holding your data or running the machine.

Your hospital lives under HIPAA’s Security Rule, which sets the cybersecurity floor for every provider that bills insurance. HHS proposed the first upgrade to that floor since 2013 in December 2024, hospital groups called the timeline unreasonable, and the final rule slid to at least July 2027. Meanwhile Microsoft counted 389 U.S. hospitals and clinics hit by ransomware in a single year.

Your pacemaker or insulin pump lives under an FDA requirement in force since March 2023 requiring makers of new connected devices to submit a cybersecurity plan and a parts list before approval. Devices already implanted or already on the ward before that date fall outside it.

Your period tracker, telehealth intake form, and chatbot live under one FTC rule, the Health Breach Notification Rule. Congress wrote it in 2009 to hold the line until a real health privacy law passed. That law never came.

And you? You appear nowhere on that list as someone who has agency to take action unless you hold your own data, and have rights to protect your care. HIPAA gives patients no right to sue. Neither does the FTC rule. Every law above tells somebody else what to do before an attack and tells you about it afterward. Figuring out even that much takes four questions: does this company bill insurance, does a 2009 stopgap reach it, did a Texas court strip protection from the page you were reading, and does your state let you sue. Two agencies, one court, fifty legislatures, and no lawyer in the room. Nobody should need a law degree to find out where their symptoms went.

Our federal agencies have been unable to keep up with the pace of change with health AI

For years we held onto the idea that the Health Breach Notification Rule (enforced by the FTC) is the only law outside of HIPAA to deter companies from playing fast and loose with our health privacy. Rule text in this law says apps must tell you within 60 days when your data leaks or gets handed to someone else, name who got it, and face fines up to $51,744 per violation. A 2021 memo explained how the FTC reads that law when apps share with advertisers. Memos explain; they cannot fine anyone, and never could, under a principle on the books since 2007. Commissioners withdrew the memo. Law and fines stand.

Some privacy lawyers see an upside, since one document leaves no contradictions for a bad actor to hide behind, and commissioners said as much. ¯\(ツ)

The gaps between what protect us are still pretty wide, and the incentives to reduce liability by health systems and tech companies remain far stronger than the incentives to protect health privacy. When both hospitals and tech companies challenged the Health Breach Notification Rule  a Texas court decided in 2024 that nobody owes you notice when a tracker sends it to Meta. Fill out a telehealth intake form and only this FTC rule applies. Paste records into a general chatbot and nobody has established an answer. Ask any app for a copy of what it holds on you and no federal law makes it hand one over.

The FTC has enforced the Health Breach Notification Rule twice in seventeen years. GoodRx paid $1.5 million in 2023 for piping prescription data to Meta and Google through tracking pixels. Nobody hacked GoodRx. GoodRx did the sending. Months later Premom’s maker paid $200,000 for shipping fertility data to Google and two China-based analytics firms. Nine companies have ever reported a breach under this rule. HHS gets that many HIPAA reports before lunch.

So it begs the question… where’s our agency?

One common theme in all of this is agency. Every thread in this story runs through that one word, and it keeps changing meaning depending on whose interests it serves. Federal agencies exist to stand between the public and companies doing terrible things with our data; on the evidence above, that experiment has mostly failed. Lawyers and financial advisers are agents in a second sense, bound by a duty of care to act in their client’s interest, and nobody holding your health data owes you anything like it. AI agents are the newest sense, answering to whoever configured them, or in July’s case study to nobody at all, while Washington debates how federal agencies are going to keep up.

Fear is beside the point. We can’t keep painting sunshine and rainbows on health conference stages celebrating progress while nobody acts to protect a fourth kind of agency, the plain one, a patient’s power to act on their own behalf. Every other party in this story has someone whose job is to act in its interest. Hospitals have counsel. Device makers have lobbyists. Meta has Meta. AI agents, it turns out, have each other. Patients have a form on a government website and a 60-day wait.  New York Times describes Washington DC paralyzed over whether AI will end civilization, with some senators preferring “American killer robots and not Chinese killer robots.” Meanwhile even Dario Amodei has shared that tech companies are gambling with our lives.

A better way starts where terms get written: patients at every table that decides what happens to their data, with a vote and a infrastructure to support our own communities. We need to build capacity to get backups of the data that have been circulating in the health systems and internet. Because when 700 agents decide on their own to go after a bunch of health apps with your data, current law will notify you a couple months later….and that is the entire plan for now.


Discover more from Light Collective

Subscribe to get the latest posts sent to your email.

Discover more from Light Collective

Subscribe now to keep reading and get access to the full archive.

Continue reading