TwinEthosRequest access

Control

Mental-health chatbot conversation content or health data sold or shared with third parties

What a user tells a mental health chatbot, and their identifiable health information, is not sold to or shared with third parties outside narrow statutory exceptions.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.chatbot-user-input-or-health-data-shared-with-third-parties

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Utah (US-UT).

The guard to add

Strip chat text and health fields from every analytics, ad-pixel, CRM, and broker payload, and send health data to vendors only under a recorded HIPAA-equivalent contract.

Route all third-party telemetry from the chatbot through one event helper with an allowlist of non-content properties (event name, counts, latency, plan), so message text, transcripts, and health fields (mood logs, diagnoses, PHQ-9 scores, medications) can never be attached, and do not load ad pixels or session-replay scripts on chat pages. Any call that sends identifiable health information to an outside party first checks the destination against a vendor registry that records HIPAA-equivalent contract terms, or against a stored user consent or request, and refuses anything else. Raw conversation content is never sent to a third party.

Where it goes: 1 application source code, 6 API calls and integrations, 9 AI output handling, 10 logs and telemetry.

What reviewers look for: analytics.track, mixpanel.track, amplitude.track, posthog.capture, gtag('event'), and fbq('track') calls whose properties carry no message, transcript, prompt, or health fields (an allowlist or scrub_user_input before telemetry); no ad pixels or session replay on chat pages; health-data transfers gated on vendor_registry baa == True or a stored consent or request record.

Example (TypeScript + PostHog), before:

posthog.capture('message_sent', { message: input, mood: moodScore });

After:

posthog.capture('message_sent', { length: input.length, turn, latency_ms: latencyMs });  // counts only, no text or health fields

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)