TL;DR: Healthcare privacy protections now lag far behind the ways PHI is collected, inferred, and shared across apps, wearables, data brokers, and AI systems, according to Ground Labs, leaving many organisations without durable control over sensitive health data. The governance gap is no longer limited to HIPAA coverage; it is a discovery, classification, and minimisation problem.
NHIMG editorial — based on content published by Ground Labs: The privacy crisis in healthcare
By the numbers:
- In 2025, HHS-reported incidents averaged more than 125,000 individuals’ health records breached every single day.
- In 2022, more than a third of the top 100 US hospitals were found using the Meta Pixel tracking pixel.
Questions worth separating out
Q: How should organisations protect health data that sits outside HIPAA scope?
A: They should treat sensitivity as the organising principle, not regulatory coverage.
Q: Why do inferred health attributes create privacy risk?
A: Because they can expose medical, behavioural, or demographic information without looking like clinical records.
Q: What breaks when PHI disclosure tracking is incomplete?
A: When disclosure tracking is incomplete, organisations lose the ability to explain who accessed sensitive information, for what purpose, and under what authority.
Practitioner guidance
- Build a cross-domain PHI inventory Map where health data, inferred health attributes, and identifiers live across EHRs, consumer apps, wearables, brokers, and AI pipelines.
- Classify inferred health data as sensitive Extend classification rules so model outputs, enrichment fields, and profiling attributes are treated as protected when they can reveal health status or personal welfare information.
- Segment access to high-risk PHI Separate sensitive records from general operational data and limit who and what can query them.
What's in the full article
Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:
- Examples of how health data moves through consumer apps, brokers, and wearable ecosystems beyond HIPAA-covered environments.
- Operational guidance on data discovery and classification for PHI, including where inferred health attributes should be captured.
- Practical steps for segmentation, minimisation, and cleanup of obsolete sensitive data in mixed regulated and unregulated estates.
- Discussion of how AI models can leak or reproduce health-related information from training data and prompts.
👉 Read Ground Labs' analysis of the healthcare privacy crisis and PHI governance gaps →
Healthcare privacy gaps and PHI sprawl: what teams need to know?
Explore further
PHI governance now depends on discovery, not just disclosure rules. The article shows that the core failure is structural: organisations cannot protect what they cannot continuously locate. Privacy programmes that rely on a static HIPAA boundary miss consumer apps, brokers, wearables, and analytics pipelines where sensitive health data accumulates. The practical conclusion is that PHI governance must start with inventory and classification across the full data estate.
A question worth separating out:
Q: Who is accountable when sensitive health data is exposed through vendors or AI systems?
A: Accountability should remain with the organisation that collects, processes, or benefits from the data, even if a vendor or model handles it operationally. Privacy laws may differ by state or sector, but governance responsibility does not disappear when data moves into external systems. Ownership must be explicit in contracts, controls, and review processes.
👉 Read our full editorial: Healthcare privacy gaps are exposing PHI beyond HIPAA’s reach