As a result, regulatory actions, enforcement activity and associated fines remain the consequence of risk that worries leaders most.
Regulatory action a global concern
Across the three regions we survey – North America, Europe and Asia – regulatory complexity is raising compliance risk and with it concerns over likelihood and severity of litigation.
Health data privacy becomes a battleground
In the US, hospitals and digital health companies are navigating a patchwork of unclear, overlapping and sometimes conflicting rules. These include HIPAA (the federal Health Insurance and Portability and Accountability Act)3, CIPA (the California Invasion of Privacy Act)4 and CMIA (California Confidentiality of Medical Information Act)5.
Cases brought under these laws have made clear that digital medical history bots, symptom-checkers, and online doctor–patient chat tools can be seen to constitute unlawful ‘wiretapping’ when they transmit patient inputs to third parties without their consent or knowledge.
-
Marketing missteps cost millions
It is not just the way companies use technology to gather and share information for legitimate care purposes that is the issue. Marketing overreach is also coming under scrutiny.
An increasing number of companies face legal action for sharing medical-related browsing behaviour. Often cases centre on companies using re-targeting pixels or SDK (software development kit)6 trackers on symptom pages and sending sensitive user information to advertising platforms without consent.
-
“More privacy litigation is inevitable as plaintiff firms exploit ambiguity – using new scanning tools to identify SDKs and tracking technologies inside apps. We see lawsuits now being filed for breaches affecting as few as 90 people. Privacy litigation is no longer about scale – it’s about opportunity.”

Katherine Heaton, Claims Focus Group Leader – Cyber Services & InfoSec Claims, Beazley
Consumer expectations encourage organisational over-reach
The surge in demand for weight-loss drugs illustrates how hard it is for organisations to meet consumer demand responsibly. The frenzy of demand led to shortages of core products and pushed 503B pharmacies, manufacturers and telemedicine providers to compound their own versions7. The issue was not the ingredients themselves, but that many of these new formulations were not approved in this form or for this purpose.
“Risks increased for insurers and consumers when global demand for GLP-1 agonists skyrocketed, and some telemedicine start-ups turned to compounding …There are those who play by the rules, those who don't and those who push the boundary until they get sued.”
Evan Smith, Growth Leader Global Healthcare, Beazley
Even after the shortages were resolved, compounded versions remained widely available, leading to increased regulatory scrutiny, with 30 telehealth businesses receiving official FDA warnings8.
-
Complexity in UK, EU and Asia
Managing regulation and consumer expectations is no easier to navigate outside the US.
In the UK and Europe, companies sit at the intersection of medical device rules, AI-specific regimes (like the EU AI Act9), health-data frameworks (including GDPR and the coming European Health Data Space10) and telehealth rules. There is also debate on whether an AI tool is a wellness service or a medical device, and over what constitutes valid secondary use of health data across borders.
In Asia, rapidly evolving or fragmented national rules, patchy guidance on AI in care, and data-localisation or cybersecurity laws make cross-border virtual care and cloud-based AI models hard to scale.
-
“Organisations find themselves in a regulatory grey zone. They’re expected to comply with requirements set by medical boards, state regulators, the FDA, and similar authorities worldwide, yet many of those requirements remain ambiguous and are evolving at a rapid pace. Keeping up isn’t just challenging – it’s becoming increasingly complex.”

Hannah Smith, Product Leader Miscellaneous Medical, Beazley