Skip to main content
October 05, 2026 | less than a minute read

What Healthtech Founders Raising Capital Need to Know About Data Privacy Before Their Next Pitch

Digital health funding is having a real year. U.S. digital health companies raised $7.4 billion across 244 deals in the first half of 2026 alone, up from $6.4 billion in the same period last year. But the money is more concentrated than the headline number suggests. Megadeals of $100 million or more made up 45% of all capital invested, and healthtech rounds already take longer to close than a comparable SaaS raise because of the regulatory and clinical diligence layered on top. Heading into Tech Week, when a lot of founder-investor conversations get started or accelerated, it’s worth being honest about where those diligence cycles actually stall. Increasingly, it’s not the clinical story. It’s privacy.

Privacy diligence used to be a checklist item near the end of a term sheet process, but it’s now showing up earlier, and investors are asking sharper questions than “Do you have a privacy policy?” Founders are increasingly finding that investors check whether a company’s privacy and security statements are consistent with how the product operates, not just whether the statements exist. They’re also asking a more fundamental question: Does the company actually have the rights to its data that the business plan assumes — to use it, to repurpose it, and to transfer or disclose it? That means looking past the privacy policy to the customer contracts, business associate agreements, data licenses, and user consents governing the data, and asking whether they permit secondary uses such as training AI models, building analytics products, or commercializing de-identified datasets (and whether that data meets the applicable de-identification standard, since HIPAA’s and the state laws’ definitions differ), as well as disclosures to partners and vendors and, eventually, a transfer of the data to an acquirer. A dataset the company can’t lawfully reuse or share is worth far less than the pitch deck implies. And investors aren’t waiting for an enforcement action against a portfolio company to ask. Rather, they’re reading the same FTC, HHS, and state attorney general signals everyone else is.

1. “We have a privacy policy” isn’t the answer investors are listening for.

The follow-up question is typically some version of “Does your actual data flow match what the policy says?” If your product collects more than the policy discloses or shares data with a vendor the policy doesn’t mention, a quick diligence call could become a weeks-long delay or even a pass. In practice, the most common gap arises from a tracking pixel or analytics SDK quietly sending health-related signals to an ad platform, the same conduct behind the FTC’s GoodRx and BetterHelp actions. Investors don’t expect a perfect privacy program at the seed stage. They do expect the founder to know, specifically, where the gaps are, rather than getting caught by surprise on a diligence call.

2. Know exactly what data your AI features use.

If your product includes any AI-powered feature, including triage, risk scoring, or documentation, investors are going to ask what data trained it and whether your consent language or, if you sell to health systems, your business associate agreements, actually covers that use. The BAA piece trips up more B2B founders than consent does. A BAA typically limits you to using PHI to provide services to that customer, so training a product-wide model, or even de-identifying the data, generally requires express permission in the contract. This is a timely concern for companies, as healthcare AI regulation is genuinely fragmented right now. The United States, European Union, and China are moving at different speeds and in different directions, a point healthcare and policy leaders made explicitly at an Atlantic Council Cyber Statecraft Initiative panel on September 8, 2026. Investors know that fragmentation means real compliance risk sits with the companies building and deploying these models, and they’ll want to know you’ve thought about it before they have to ask.

3. The state law patchwork applies to you even if you think you’re not a health company.

Wellness apps, fertility trackers, and mental health chatbots may not resemble traditional “health companies” in the HIPAA sense. But Washington’s My Health My Data Act, along with similar laws in Nevada and Connecticut, regulate consumer health data well outside HIPAA’s scope, with real penalties and, in some states, a private right of action. If your product touches anything that reveals a health condition, including indirectly, through location or behavioral data, investors experienced in this space will ask about compliance with relevant laws. Not knowing the answer reads as a bigger red flag than the underlying compliance gap itself.

4. If you sell or share data with third parties, be ready for that question specifically.

California’s privacy regulator has now brought more than a dozen enforcement actions against data brokers, including, in August, its first action under both the CCPA and the Delete Act. This is a reminder that any data-sharing arrangement, even one that doesn’t feel like “selling data” internally, could carry real regulatory exposure. California defines a “sale” as any disclosure for valuable consideration, and “sharing” to include disclosures for cross-context behavioral advertising, so an ad-tech or analytics integration may qualify without any money changing hands. If any part of your business model involves sharing user data with parties your users don’t directly interact with, have a clear, honest answer ready for why that’s structured the way it is.

Before your next pitch

A short list worth going through before your next round of investor conversations:

  • Confirm your privacy policy matches your current data flows, not what was true a year ago.
  • Audit the pixels, SDKs, and analytics tools in your website and app, since they’re the most common source of undisclosed sharing.
  • Document what data trained any AI feature, and whether your consents and customer contracts (including BAAs) cover that use.
  • Identify which state health data privacy laws apply to your product, even if you don’t think of yourself as a “health company.”
  • Have a clear answer ready if any part of your data model involves third-party sharing.
  • Map your rights to use, repurpose, and transfer or disclose your data against the contracts and consents granting them.
  • Bring documentation, not just a verbal explanation. Investors move faster when you can show your work.