As AI companies race into healthcare — with Anthropic launching Claude for Healthcare, OpenAI unveiling ChatGPT Health, and autonomous agents gaining system-level access through frameworks like OpenClaw — the gap between what is legally protected and what is actually at risk has never been wider.
This declaration addresses that gap. It’s now available as an open framework on GitHub for anyone to adopt, customize, or implement.
🔗 GitHub Repository: github.com/starwreckntx/Health_Data_Sovereignty_Declaration
Why This Exists
In January 2026, Anthropic launched Claude for Healthcare — enabling users to sync lab results, medical records, Apple Health data, and Android Health Connect metrics directly into conversations with Claude. OpenAI did the same with ChatGPT Health days earlier.
Both companies say the right things about privacy: opt-in, user control, no training on health data. But there’s a critical problem neither company has addressed:
Consumer AI platforms like Claude and ChatGPT are NOT HIPAA-covered entities. HIPAA protects health data held by insurance companies, clearinghouses, and healthcare providers. The moment your health data lives in an AI assistant’s context window, it exists in a regulatory gray zone — protected by terms of service, not by federal law.
Worse: AI memory systems operate through compaction and synthesis — automated processes that summarize conversations and persist information across sessions. These processes decide what’s “key information” without asking you. There is no pre-synthesis consent gate. There is no audit surface showing what was evaluated and dropped. And there is no firewall preventing health-adjacent data from being accumulated into a de facto health profile you never consented to.
This declaration creates the consent architecture that doesn’t exist yet.
This Is Pro-Innovation, Not Anti-AI
I believe AI-mediated healthcare is one of the most significant opportunities to reduce human suffering. This declaration exists because public trust requires individual control — and individual control requires explicit infrastructure.
The framework supports clinical decision support, prior authorization, care coordination, drug discovery, and patient education. These are among the most important applications of AI. The individual must simply retain meaningful, informed, granular consent — the same standard applied to human healthcare providers.
Key Definitions
The declaration intentionally uses broader definitions than HIPAA to cover the gap between federal law and what consumer AI platforms actually process:
Explicit Health Data: Information directly describing health status, diagnoses, treatments, medications, lab results, vital signs, genetic information, or disability status.
Inferred Health Data: Health-relevant conclusions derived by AI from data that wasn’t itself health data — like occupational exposure risk profiles, fatigue patterns from session behavior, or mental health inferences from sentiment patterns.
Health-Adjacent Data: Information that isn’t health data in isolation but enables health profiling when accumulated across sessions (occupational hazard descriptions, exercise/sleep/diet references, environmental data).
Scope Creep: The gradual expansion of health data collection through accumulation of health-adjacent data — creating a profile you never consented to.
Binding Instructions
The framework establishes four core protection mechanisms:
A. No Health Data Persistence
No explicit, inferred, or health-adjacent data shall be stored across sessions without explicit, session-specific consent. The AI system must actively prevent scope creep.
B. Consent Architecture
Consent must be explicit, granular, and revocable. “Remember everything” does not constitute health data consent. The AI system shall never prompt users to connect health data sources unless the individual initiates it unprompted.
C. Compaction & Synthesis Protections
Health data must be excluded from compaction summaries. Cross-session memory synthesis shall not incorporate health data. Individuals retain audit rights over memory summaries.
D. Agentic & Third-Party Protections
No autonomous agent, tool, connector, or integration shall access health data without per-instance consent. This applies to all agentic frameworks including OpenClaw, MCP servers, and tool-use APIs.
Legal Grounding
This declaration is informed by several frameworks:
• HIPAA Privacy Rule (45 CFR §164.502) — Minimum Necessary Standard
• Texas TRAIGA / HB 149 (effective Jan 1, 2026) — AI disclosure requirements in healthcare
• Consumer Privacy Laws (VCDPA model) — Rights to access, correct, delete, and opt out of profiling
• Colorado AI Act (2024) — Risk management for high-risk AI in healthcare
• FTC Enforcement Precedent (GoodRx, BetterHelp, 1Health.io) — Consent requirements under Section 5
The System Instruction
The repository includes a copy-ready directive designed for embedding in AI system instructions or user preferences:
“Health data is sovereign. NEVER store, memorize, synthesize, or persist any health information across sessions without explicit consent. NEVER generate health inferences from non-health data. NEVER prompt me to connect health data sources unless I initiate that request. During compaction/synthesis, EXCLUDE all health data. No agent or tool may access my health data without per-instance consent.”
How to Use This Framework
The declaration is uncopyrighted and free for adoption:
1. Add the system instruction to your AI assistant’s custom instructions
2. Reference it in conversations where health data might be discussed
3. Customize it for your specific needs
4. Share it with others who need consent infrastructure
All files are available in the GitHub repository including the full declaration (HTML, DOCX), the system instruction (TXT), and documentation on implementation.
The Burden Falls on System Providers
Individuals shouldn’t need declarations like this one. The fact that this is necessary reflects a gap in platform design. AI providers should implement pre-synthesis consent gating, health data firewalls, and transparent audit surfaces as standard features.
Until they do, this framework gives individuals the tools to assert sovereign authority over their health data.
📄 Full Declaration: github.com/starwreckntx/Health_Data_Sovereignty_Declaration
📝 Published: February 10, 2026
🏷️ License: Uncopyrighted — Free for Adoption
