Auditen
sector watch

FDA Targets GenAI Medical Device Regulation Amid FTC Health Pivot

Health tech is squeezed from both sides right now, and one hand comes from the FDA, which is asking for public comments on how to handle medical devices built with generative AI. The other belongs to the FTC, which has changed how it enforces privacy rules in health apps.

This isn't just a shuffle of paperwork. It is a collision between traditional clinical safety and the reality of how large language models actually function.

Article 17 of the GDPR gives people the right to erasure. For ten years, companies used "privacy by design" as a shield to claim privacy was built in from the start; when it comes to GenAI medical devices, that's usually a lie. You can't just delete one patient's data once it's part of the trained model weights, and the info isn't sitting in a spreadsheet row. It's spread across billions of parameters.

A company can wipe a raw training file from a server if a patient asks to be forgotten. That's easy. But they can't strip that person's influence out of the model without retraining everything from zero.

Industry types will bring up synthetic data or differential privacy to deflect. They'll claim Article 17 doesn't apply because the model doesn't "store" data in a traditional way; it's a convenient read of the law. It puts utility over agency. If you can trick a medical device into revealing sensitive patterns from one person, the breach isn't theoretical. It is built into the architecture.

Look at the Conduent settlement involving just under 44 million exposed records. That was a standard failure. Data sat where it didn't belong and leaked. It's messy but solvable. The GenAI problem is quieter. More systemic. We've moved from leaky buckets to poisoned wells.

Regulators are finally seeing the gap. The FDA is looking at GenAI devices, which suggests they know a black box diagnostic tool isn't safe if its data provenance is a mystery.

This hits professional indemnity insurers hard, and malpractice insurance used to focus on how a doctor judged a case. Now things change. If a physician uses an AI device that breaks privacy laws or gives biased results from bad training sets, who pays? Insurers will likely demand model audits before renewing clinic policies; a signed Service Level Agreement won't be enough. They want the data lineage.

The New Mexico trial over Facebook's Cambridge Analytica mess shows that privacy liabilities stick around; failures from 2018 are still in court in 2026. Health tech firms ignoring erasure today are just booking their own depositions for 2032.

Some say over-regulating GenAI now kills innovation and costs lives by delaying better tools. That's a fake choice. Innovation needs trust. You can't have trust when a company can't tell a patient what happened to their data after it hit the training pipeline.

Will the FDA mandate strict versioning or "unlearning" capabilities? If they let firms lean on "privacy by design" without a way to excise data, the regulation is just for show.

Watch the FTC and health app privacy. If they start attacking training sets instead of disclosure forms, the medical AI business model has to change.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Facebook trial over Cambridge Analytica privacy scandal begins in New Mexico - KRQE Data Privacy (Google News)
  2. SEC Proposes Rescinding Investment Adviser Pay-to-Play Rule, but Compliance Risks Remain - WilmerHale Compliance Week (Google News)
  3. SEC Proposes Sweeping Modernization of Transfer Agent Rules - JD Supra Compliance Week (Google News)
  4. FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices - The HIPAA Journal InfoSec Compliance (Google News)
  5. GDPR wasn't designed for AI and that's a security problem - Computer Weekly Compliance Week (Google News)
  6. Years after the Cambridge Analytica scandal, New Mexico takes Facebook to trial - The Guardian Data Privacy (Google News)
  7. Massachusetts towns drop Flock cameras as lawmakers push privacy guardrails - New Bedford Guide Data Privacy (Google News)
  8. Toronto Officer Charged for Database Breach: Know Your Privacy Rights - UL Lawyers Data Privacy (Google News)

How stories are selected and assessed