After two quiet years, digital health M&A is picking back up. Acquisitions now account for roughly 95% of digital health exits, and average deal size has climbed to $41.0 million in 2026 year-to-date — the highest level in the five-year period Galen Growth tracks. Strategic acquirers are once again buying platforms, patient engagement tools, and diagnostics companies to fill product gaps, and private equity is returning to the space with fresh capital to deploy. But the deals closing in 2026 look different from the ones that closed a few years ago, and the biggest difference is what data diligence now requires.
Five years ago, data diligence in a digital health deal largely meant confirming the target had a HIPAA compliance program and reviewing its breach history. That checklist is no longer sufficient, and buyers today are running into three categories of risk that didn’t exist, or didn’t matter as much, the last time deal volume was this high.
1. The state law patchwork now governs data HIPAA never touched.
Most digital health targets collect data that falls outside HIPAA’s scope entirely, including wellness app usage, symptom-tracker inputs, fertility and reproductive health data, and location data that may reveal a health condition indirectly. Laws like Washington’s My Health My Data Act, and similar statutes now active or pending in other states, regulate this data directly, with consent requirements, private rights of action, and statutory damages that HIPAA doesn’t have. A target’s HIPAA compliance program tells you very little about its exposure under these newer laws.
2. AI features complicate the data you’re buying.
A growing share of digital health targets have built AI-powered features like triage chatbots, risk-scoring models, and ambient documentation tools, which are often trained on patient data collected years before anyone thought about AI governance. Two recent deals show exactly why this matters. Roche’s roughly $1.05 billion acquisition of PathAI, a digital pathology AI company, immediately raised data governance and neutrality questions for the pharma partners who relied on PathAI as an independent platform and now have to reassess that relationship under new ownership. Around the same time, OpenAI’s acquisition of Torch, a startup built to unify a person’s medical records across providers, labs, and wearables into a single AI-accessible profile, folded a large, aggregated health-data asset directly into a foundation model company’s infrastructure in a deal reported at $60–100 million. Buyers in deals like these need to know: What data trained the model? Did the consents in place at the time of collection permit that use? Can the model itself be transferred, or does it carry restrictions — including from third-party partners — that survive the deal? These questions didn’t exist in a standard 2019-era diligence checklist, and getting them wrong may mean inheriting a model, or a partner relationship, you can’t legally keep using post-close.
3. Vendor and sub-processor risk has multiplied.
Digital health companies today typically run on a dense stack of third-party vendors, including cloud infrastructure, analytics, customer support tooling, and AI model providers. Each one is a potential gap in the target’s data protection obligations. A diligence process that stops at the target’s own privacy policy and doesn’t pull the underlying vendor agreements is going to miss the actual risk.
What does this mean for your next deal?
Whether you’re the buyer or the target preparing for a sale, the diligence checklist should now include:
- A current data map covering not just HIPAA-regulated data, but all consumer health data as defined under applicable state laws
- Documentation of what data trained any AI/ML features, and confirmation that the applicable consents permit that use going forward
- A full vendor and sub-processor inventory, with copies of the underlying data processing agreements, not just a policy summary
- Breach and incident history, including any notifications made under state (not just HIPAA) breach notification laws
- Confirmation of how consents were worded at the time of collection, since older consent language may not cover current data uses
The deals that move fastest right now are the ones where this work starts before a term sheet, not after. Sellers who get ahead of this diligence checklist tend to close faster and with fewer post-signing surprises; buyers who skip it tend to find out what they missed after the deal is already done.
Sources
- 95% of digital health exits via M&A; $41.0M average 2026 YTD deal size — Galen Growth — https://www.galengrowth.com/digital-health-exits-2026-ma-dominance/
- Roche’s ~$1.05B acquisition of PathAI and its effect on pharma partners — Galen Growth research report — https://www.galengrowth.com/research-download/digital-health-exits-2026-ma-ipo-market-report/
- OpenAI’s acquisition of Torch (reported $60–100M) — TechCrunch — https://techcrunch.com/2026/01/12/openai-buys-tiny-health-records-startup-torch-for-reportedly-100m/
- OpenAI’s acquisition of Torch (reported ~$60M) — CNBC — https://www.cnbc.com/2026/01/12/open-ai-torch-health-care-technology.html