This website uses cookies

Read our Privacy policy and Terms of use for more information.

Last year I wrote about Apple's policy changes and why they matter for the Social Determinants of Health. The argument was simple: the terms we accept on our devices are no longer just software paperwork. They shape how health data is collected, shared, and acted on in daily life.

That was true then. It is more true now.

The bigger story in 2026 is not Apple. It is the rise of consumer AI assistants — Claude, ChatGPT, Gemini, and others — as everyday infrastructure for health, work, caregiving, and life admin. People already use these tools to ask about symptoms, summarize medical bills, draft insurance appeals, manage care notes for aging parents, navigate benefits, compare housing options, and make sense of financial stress. They are using AI in exactly the messy, real-world spaces where the Social Determinants of Health show up every day.

And SDOH was never only about where you live or whether you can see a doctor. It is about the systems that shape access, trust, literacy, and decision-making. In a digital world, the privacy settings, retention rules, training defaults, and connected-app permissions of AI platforms are becoming part of that environment.

SDOH now has a digital policy layer

The SDOH conversation needs to catch up.

We usually describe SDOH through five familiar domains: economic stability, education, healthcare access and quality, neighborhood and built environment, and social and community context. Digital systems now sit inside all five. A parent uses a chatbot before they can get an appointment. A family turns to an AI assistant to understand a denied claim before they reach a case manager. A caregiver uploads medication lists and appointment notes to keep up with a loved one's care. None of that looks like traditional health IT. All of it is health-adjacent. And all of it can touch deeply sensitive information.

The real issue is who carries the burden

Here is the part that makes this an SDOH issue and not just a privacy one: power, asymmetry, and who carries the burden of understanding the system.

People with more time, education, and technical fluency are more likely to understand model-improvement settings, retention windows, and the difference between deleting a chat and preventing future training. They know when not to paste a raw medical record. They can tell a consumer chatbot apart from a governed clinical workflow.

People under the greatest strain often cannot. The person juggling shift work, childcare, housing instability, immigration stress, or chronic illness is the same person most likely to reach for an AI assistant as a low-cost first line of support. That is not a failure of judgment. It is a rational response to broken systems. But it means the people most likely to benefit from these tools are often the least protected from opaque data practices, consent fatigue, or overreliance on systems they do not fully understand.

The defaults are where this becomes concrete. In 2025, Anthropic changed how consumer data is handled so that, for its everyday users, chats could be used to train future models unless the user actively opted out — with a deadline to make the choice. Reasonable people can debate that design. But notice who it falls hardest on. The person with time and fluency reads the notice and flips the setting. The person carrying the most weight never sees the toggle before the clock runs out. A privacy decision became a default, and a default became a divide.

What the policy stack actually says

That same policy stack, read closely, shows how far this has moved. Anthropic's consumer policies tell users that Claude may collect prompts, outputs, files, feedback, technical information, and data from connected tools. Deleted chats are removed from history immediately and from backend systems within thirty days. If a user allows their data to improve the model, de-identified chat or coding data may be retained in training pipelines for up to five years. Feedback can be retained for up to five years. Chats flagged for safety or policy reasons may be kept longer. There is a separate consumer health-data privacy policy for certain jurisdictions, and the usage policy already treats healthcare, insurance, finance, employment, and housing as high-risk domains that require stronger safeguards.

Anthropic is not unusual here — its documentation is simply clear enough to read. Taken together, these policies show general-purpose AI assistants becoming a new layer of health-adjacent infrastructure without being named that way in the public conversation.

We have to stop assuming the only sensitive health data is the data inside a hospital EHR or a covered HIPAA workflow. A person does not need to upload a full medical record for an AI assistant to learn something meaningful about their health. A handful of questions about sleep, medications, mood, caregiving stress, transportation barriers, food costs, eviction risk, or insurance denials reveals a great deal. Add location history, calendar patterns, uploaded documents, or connected apps, and the picture gets sharper. "General AI" and "health data" are no longer separate categories, and we should stop pretending they are.

What consumers should do right now

If you use a consumer AI assistant, treat it as part of your health data footprint — even if you never think of it as a health app. A few habits go a long way:

  • Don't paste medical records, therapy notes, insurance documents, or identifying health details unless you've made a deliberate choice to.

  • Review model-improvement and privacy settings before using the tool for anything sensitive — and check whether your data is shared by default.

  • Use privacy-protective modes like Incognito when available, but don't assume they erase all retention or risk.

  • Be careful with connected apps. The risk isn't only what you type. It's what you let the assistant reach.

  • Redact names, dates of birth, and account numbers wherever you can.

What builders and health leaders should do

For founders, health systems, payers, and public-interest teams, the lesson is direct: privacy UX is now part of care quality and trust.

If you are building AI into care navigation, SDOH screening, case management, benefits support, or caregiver workflows, don't push the burden onto the user through vague consent and buried settings. Build for legibility. Build for data minimization. Build for retention control. Build for clear disclosure of what the system stores, what it learns from, what it shares, and what it can infer.

And if you set policy, stop drawing the boundary at HIPAA alone. The next generation of health-data governance has to account for consumer AI tools, non-clinical health-adjacent data, and the fact that many of the most important health interactions now happen outside formal care settings.

Final thought

We are entering a period where the policies behind consumer AI tools will quietly shape how people navigate health, money, work, caregiving, and crisis. That makes them more than privacy documents. It makes them part of the social infrastructure around health. Because the next time someone asks an AI assistant for help with a denied claim, a panic attack, a rent problem, or a child's symptoms, they are not just talking to a machine. They are stepping into a policy environment that decides what is collected, what is retained, what is inferred, and who carries the risk.

The SDOH conversation needs to catch up.

Keep Reading