If someone were to ask, 'What is health data?' most people today would still answer with medical records, insurance data, health check-up reports, or clinical notes from hospitals. However, in today’s rapidly advancing artificial intelligence (AI) era, information that truly reflects an individual’s health status is no longer confined to medical records kept by healthcare institutions. Your smartphone’s location, internet search history, consumption preferences, wearable devices, sleep patterns, exercise routes, and even frequently visited places could, through algorithmic analysis, piece together a 'health portrait' far more comprehensive than any medical record.

This marks the biggest shift in global health data governance in recent years. The 2025 lawsuit Maxwell v. Amazon in Washington State, USA, has precisely opened the curtain on this transformation. The plaintiff argues that Amazon, through third-party software development kits (SDKs) and digital tracking technologies, collects users’ operational logs, location data, and other digital footprints within health-related applications (Apps), potentially using them to build analytical datasets capable of reflecting personal health conditions. Although the case has yet to receive a substantive court ruling, it has already raised a critical question for global consideration: when daily life data, analyzed by AI, can infer personal health status, can we still rely on the outdated notion that 'only medical records are health data' as the foundation for health data governance?

The answer is likely no.

What is truly noteworthy is that this case is not the starting point of reform, but rather reflects how Washington State had already anticipated the new challenges facing digital health data governance. As early as 2023, Washington enacted the 'My Health My Data Act' (MHMDA), becoming one of the world’s most representative consumer health data protection laws. Its core principle is clear: even if data is not generated by healthcare institutions, as long as it can identify, infer, or reasonably link to an individual’s health status, it may qualify as legally protected health data.

This system’s greatest breakthrough lies in decoupling the legal definition of health data from its source, instead focusing on the data’s function and purpose. In other words, the law no longer solely asks, 'Is this a medical record?' but rather, 'Can this data depict a person’s health condition?'

This is exactly the significant change brought by the AI era.

Previously, health data was primarily held by hospitals, clinics, and insurance companies, so related regulations centered on healthcare institutions—for example, the U.S. Health Insurance Portability and Accountability Act (HIPAA), or Taiwan’s Medical Act and Human Research Act, all built upon this logic.

Now, with rapid advancements in digital technology and artificial intelligence, those who actually hold vast amounts of health information are no longer limited to medical institutions. Instead, they include mobile operating systems, social media platforms, e-commerce platforms, navigation services, smartwatches, health apps, and various AI service providers. These companies may not possess personal medical records, yet they can analyze hundreds of seemingly fragmented and harmless lifestyle data points to determine whether a user is pregnant, suffers from mental illness, has chronic diseases, or even predict future health risks.

In other words, AI shifts the value of data from individual pieces of information to the ability to connect, integrate, and synthesize disparate data sources. Therefore, what truly needs governance is not just the data itself, but the behaviors involved in how data is analyzed, inferred, and reused.

This reflects a major paradigm shift occurring in global data governance.

The European Union’s recent push for the European Health Data Space (EHDS) emphasizes balancing individual autonomy, healthcare delivery, and scientific innovation—a harmonized space for diverse data uses. To some extent, it creates exceptions to the stricter oversight required under the General Data Protection Regulation (GDPR) for high-risk data through legal adaptation. Conversely, in the U.S., where there is no national health data-specific law, multiple states—including Washington—have taken proactive steps to bring consumer health data into the protected scope.

By contrast, Taiwan is not lacking in health data protection systems. For instance, Article 6 of Taiwan’s Personal Data Protection Act classifies medical records, healthcare, health examinations, and genetic information as special categories of personal data. Laws such as the Medical Act, Human Research Act, and Biobank Management Regulations have established a relatively complete governance framework for medical research. In terms of protecting traditional medical data, Taiwan’s system is not behind.

However, what truly requires rethinking is whether the new types of health data emerging in the AI era—such as the aforementioned consumer health data—have already exceeded the imagination of existing legal frameworks. For example, can a person’s location history infer repeated visits to a cancer center? Can purchase records of specific health supplements indicate chronic illness? Can internet search history reveal mental health conditions? Can sleep, heart rate, and activity data collected by wearables, when analyzed by AI models, constitute legally recognized health data? Current laws still lack consistent and clear criteria to address these questions.

On the other hand, data governance is no longer merely concerned with whether data collection is legal. Data often flows across different platforms, algorithms, and service providers. The same dataset may undergo multiple rounds of analysis, integration, and reuse, ultimately forming new health inferences. Thus, what truly needs management is the entire data lifecycle—including collection, analysis, inference, sharing, cross-border transfer, and AI model training—not just the moment data is acquired.

This also means corporate governance responsibilities are gradually changing. In the future, businesses cannot simply ask, 'Did I legally collect data?' They must also answer: 'Could my AI system infer personal health information?' 'Are related data being repurposed by third parties?' 'Do SDKs, advertising platforms, and data analytics services in the supply chain meet established data governance requirements?' Health data governance will increasingly become a critical issue for ESG governance, board oversight, and enterprise risk management—not just isolated tasks for legal or IT departments.

For governments, Taiwan is at a crucial stage of reforming its personal data protection system. The newly established Personal Data Protection Committee will shoulder the important mission of establishing consistent enforcement standards. Facing new forms of health data arising in the AI era, Taiwan may not need to rush to enact a new dedicated health data law. Instead, it could gradually improve systems within the existing framework of the Personal Data Protection Act—covering health inference data, high-risk AI processing, data protection impact assessments, and platform and supply chain responsibilities—so that current laws can respond to the new challenges of the AI era. From a broader perspective, this is not merely a legal issue, but also concerns how digital societies build public trust in data use—and that is precisely where the crux lies.

If people believe their data will be properly protected and used reasonably under transparent and robust safeguards, health data can become a vital foundation for advancing precision medicine, smart care, and public health. Conversely, without transparent governance and effective oversight, even the most advanced AI technologies may lose social support due to lack of trust and fail to gain widespread acceptance.

The real revelation of the Amazon case is not whether the company is ultimately ruled unlawful, but that it reminds us: the most important health data in the AI era may no longer be medical records in hospitals, but rather scattered digital footprints embedded in our daily digital lives. How to ensure these data promote innovation while still earning public trust and legal protection will be the most critical issue in global health data governance over the next decade—and a new challenge Taiwan cannot avoid.

What Has the Amazon Case Truly Changed?

Over the past year, Maxwell v. Amazon has become one of the most watched cases in global health data governance. Yet its true importance lies not in whether Amazon ultimately loses the case, but in how it has, for the first time, fully presented in judicial proceedings the emerging legal issues arising at the intersection of artificial intelligence, digital platforms, and health data governance—thereby greatly expanding the scope of discussions on personal data protection.

The plaintiff argues that Amazon did not obtain medical records through healthcare institutions, but instead collected device identifiers, advertising identifiers, and precise location data via SDKs embedded in third-party apps, using them for cross-platform identification, behavioral analysis, and commercial analytics. The core controversy is therefore no longer about medical records, but whether these seemingly ordinary digital data are sufficient to identify or infer an individual’s health status—and whether companies thus bear legal obligations for health data protection.

Notably, this case has not yet produced a binding substantive judgment. Therefore, what the world is truly discussing is not whether Amazon has already violated the law, but a more fundamental legal

FACT BOX

  • Source: PR Times
  • Category: News
  • Organizations: Amazon
  • Products / services: Software Development Kit (SDK)