CHDClear — Consumer Health Data Privacy Authorization & Compliance Desk
Done-for-you compliance operations for the fast-growing "consumer health data" (CHD) patchwork — Washington's My Health My Data Act, Nevada SB 370, Connecticut's CTDPA health-data provisions, and California AB 45 — for digital health, femtech, wellness, telehealth-adjacent, and health-marketing companies. We deliver a filed, counsel-reviewed compliance program, not a dashboard the client must operate.
Executive Summary
A new category of U.S. state privacy law — "consumer health data" (CHD) statutes — has emerged since 2023 and is expanding fast: Washington's My Health My Data Act (MHMDA, most provisions effective March 31, 2024), Nevada SB 370 (effective March 31, 2024), Connecticut's CTDPA health-data amendments (effective July 1, 2023), and California's AB 45 family-planning-center provisions (effective January 1, 2026) now sit inside a broader landscape of 24 states with comprehensive privacy laws in effect in 2026. CHD statutes are unusually dangerous for a compliance program built on generic "cookie consent" tooling: they define health data far more broadly than HIPAA (location near a clinic, purchase history, biometric or search data can all qualify), they require opt-in authorization — not opt-out — before health data is sold or shared with most third parties, several ban geofencing within 1,750 feet of medical/reproductive/mental-health facilities, and Washington's law carries a private right of action that has already produced litigation (Maxwell v. Amazon.com, Inc., filed February 2025, alleging an advertising SDK embedded in third-party apps captured location and biometric signals capable of revealing clinic and gym visits).
CHDClear sells the finished outcome — a counsel-reviewed CHD compliance program — to companies that collect health-adjacent consumer data but are too small or too distracted to run a $10K–$120K/year enterprise privacy platform (OneTrust, Osano, TrustArc) themselves, let alone read four overlapping statutes. AI performs the SDK/pixel forensic scan, the statutory cross-reference, the data-flow inventory, and the first-draft authorization/consent language and privacy-policy sections; a privacy-credentialed reviewer and outside counsel sign off before anything ships. Priced per scan and per compliance pack — never hourly.
Thesis
Consumer health data law is a genuinely new, fast-expanding, high-stakes regulatory category that most digital-health-adjacent companies have not mapped, because it does not track HIPAA's "covered entity" boundary — non-medical companies (fitness apps, period trackers, DTC supplement sellers, ad-tech vendors embedded in health-adjacent apps) are squarely in scope and often unaware of it. The winner is not another privacy-ops platform the client must configure (that market is served, and is contracting toward usage-based pricing that punishes exactly the SMB/mid-market buyer CHDClear targets) — it is a specialist desk that scans a client's actual data flows, tells them precisely which lines of code and vendor contracts create CHD exposure, and ships a signed-off authorization and policy pack before the next audit, RFP security questionnaire, or plaintiff's firm finds the gap first. Frontier models compound the value of this desk: better multimodal/code-reading models make SDK and pixel forensics faster and cheaper every quarter, and the statutory patchwork itself keeps growing (more states each legislative session), which increases — not decreases — the value of an operator who has already built the cross-state rule engine.
Discovery Rationale
This run began by reading the restored 647-run manifest (see Anti-Duplication) and found the catalog dominated by regulatory-filing and back-office "recovery/dispute/annual-accounting desk" patterns across freight, insurance renewals, fiduciary/guardianship accounting, and Medicaid/Medicare trust compliance. Per the standing instruction to steer into underexplored terrain, fourteen search queries were run across HR/benefits compliance (Fair Workweek — already covered twice; SSA representative-payee accounting — semantically adjacent to two existing fiduciary-accounting entries), staffing-agency unemployment insurance cost management (already covered as "Unemployment Cost Management Engine"), multi-state remote-payroll nexus, and privacy/data-protection compliance. Consumer health data (CHD) privacy law surfaced as the strongest candidate: it is unclaimed in the manifest (zero hits for "consumer health data," "MHMDA," "my health my data," or "geofencing"), it has hard evidence of active litigation and a fast-growing statutory footprint, it has a defined buyer with existing but insufficient budget (privacy software spend that doesn't include the actual mapping/drafting/monitoring labor), and it clears the fatal-disqualifier checklist without relying on generic "AI privacy consulting" positioning.
Candidate Comparison
| Candidate | Buyer / Outcome | Score /30 | Decision |
|---|---|---|---|
| CHDClear | Digital health / femtech / wellness / health-adjacent ad-tech / signed-off CHD compliance pack | 28 | Winner |
| PayeeBooks Clear | SSA organizational representative payee & VA fiduciary annual accounting production | 21 | Reject — strong evidence (5.7M payees, 7.7M beneficiaries, FY2024 VA OIG data) but workflow and buyer overlap too closely with existing manifest entries Fiduciary & Court Accounting Engine and WardBooks Clear (Guardianship & Conservatorship Annual Accounting Production Desk) — same underlying "recurring annual accounting to avoid removal/misuse findings" shape |
| Fair Workweek / predictive-scheduling compliance | Multi-location retail/restaurant employers | — | Reject — duplicate; already covered twice (Fair Workweek Exposure Audit Compliance Engine, Fair Workweek Predictability Pay Audit Engine) |
| StaffUI Clear | Staffing agencies / unemployment insurance (SUTA) claims & tax-rate protest desk | 19 | Defer — real pain but incumbents (Equifax/TALX, Thomas & Company) hold deep state-EDI integration moats that are hard for a new entrant to match at launch |
| NexusPay Clear | Remote-first employers / multi-state payroll tax nexus & withholding registration | 17 | Defer — real problem but lower urgency/litigation signal than CHD; thinner evidence base gathered this run |
Scoring dimensions (six-gate rubric plus buyer urgency, competitive whitespace, novelty vs. manifest, demand evidence, budget proof, MVP clarity, distribution clarity, licensing feasibility, repeatability, speed to revenue) are detailed in the Rubric Scorecard section below for the winning candidate.
CODE Validation
| Lens | Finding | Label |
|---|---|---|
| C — Consumer/buyer trend | State legislatures have added CHD-specific statutes every session since 2023 (WA 2023, NV/CT 2024, CA AB 45 effective Jan 2026); the broader comprehensive-privacy-law count reached 24 states in 2026, and multiple additional CHD or geofencing bills were pending as of Q1–Q2 2026 per legislative trackers. | Verified |
| O — Opportunity | The underserved wedge is not generic "privacy compliance" — it is the specific, technically hard task of finding which of a company's own data flows (SDKs, pixels, geofenced ads, purchase/location data) legally qualify as CHD under statutes with broader-than-HIPAA definitions, then converting that into an authorized (not merely opted-out) consent flow and a defensible privacy policy. | Verified |
| D — Demand | The first MHMDA class action (Maxwell v. Amazon.com, Inc., W.D. Wash., filed Feb. 2025) directly targets SDK-embedded location/biometric tracking across ordinary consumer apps (Weather Channel, OfferUp, Speedtest, Truecaller) — proof that generic apps, not just clinical software, are exposed; law-firm client alerts on MHMDA/NV/CT compliance have proliferated since 2024; AI-native SDK-auditing tooling (Privado AI "App Auditor") already exists as a category, evidencing real vendor spend on the detection half of this problem. | Verified |
| E — Economic sizing | Order-of-magnitude buyer pool: Google Play alone listed roughly 54,500 healthcare/medical-category apps as of Q3 2022 (dated, direction-only), and the global mHealth market was sized near $50.8B in 2022 growing toward $150.7B by 2032 (11.8% CAGR) — both signal a large population of health-adjacent digital products, only a fraction of which need CHD compliance work in any given year, but even 1–2% of a low-tens-of-thousands beachhead (femtech, fitness, telehealth-adjacent, DTC wellness commerce, and their ad-tech vendors) at a $6K–$25K first-year pack is a multi-million-dollar reachable segment. | Inferred |
Rubric Scorecard (Six Gates)
| Gate | Score | Explanation |
|---|---|---|
| 1 Low Trust Burden | 4/5 | Companies already outsource privacy compliance to outside counsel and platforms; they want the finished authorization flow and policy language, not to personally parse four statutes. Partial trust burden remains because output touches legal-adjacent text — mitigated by a licensed-counsel sign-off chokepoint on every pack. |
| 2 Low Task-Level Judgment | 4/5 | Decomposable into: crawl/scan → classify data flows against a CHD ontology → flag geofencing/SDK issues → draft authorization and policy language → route ambiguous classifications to a human. Judgment concentrated on ambiguous data-type calls and final legal sign-off. |
| 3 High Intelligence Threshold | 5/5 | Requires synthesizing overlapping, non-identical statutory definitions (WA/NV/CT/CA), applying them to a specific technical data-flow map, and reconciling with the client's existing (often generic) privacy policy and vendor contracts — a genuine cross-document, cross-jurisdiction reasoning task that improves with frontier models. |
| 4 Regulation as Moat | 5/5 | Washington's private right of action plus an active, precedent-setting class action create real monetary tail risk (the Amazon complaint combines wiretap-act statutory damages up to $100/day per violation, trebled up to $25,000 per person, with MHMDA and Washington Consumer Protection Act claims) — this is not hypothetical risk, and the patchwork keeps growing, which raises switching costs away from a specialist who already tracks it. |
| 5 No Physical Labor | 5/5 | Entirely remote: code/SDK scanning, document review, and drafting. |
| 6 Sam Altman Test | 5/5 | Better multimodal/code-reading models directly cut the cost of SDK/pixel forensics and statutory synthesis; the proprietary moat is CHDClear's accumulating library of "is this specific data flow CHD in this specific state" precedent classifications, which a generic chatbot cannot replicate without that case history. |
Total: 28/30. Clears evidence threshold for blueprint.
Target Buyer
- ICP: US-based digital health, femtech, fitness/wellness, telehealth-adjacent, or DTC health-adjacent commerce company, 10–500 employees, that is NOT a fully HIPAA-covered entity (or is only partially covered) and processes data plausibly meeting a state CHD definition — health app usage, biometric signals, location near health facilities, or health-related purchase/search history.
- Secondary ICP: Ad-tech/martech vendors and SDK providers embedded inside health-adjacent apps who need to demonstrate downstream CHD compliance to their own app-publisher customers (the exact fact pattern in Maxwell v. Amazon).
- Economic buyer: Head of Legal/Compliance, General Counsel, or (pre-GC-stage) the founder/COO who currently owns the privacy policy.
- Champion: Product/engineering lead who knows which SDKs and analytics pixels are actually in the codebase.
- Trigger events: Enterprise/health-system security questionnaire or SOC 2-adjacent audit; a new state CHD law taking effect; a competitor or peer company gets sued or named in a law-firm client alert; an investor or acquirer's diligence checklist flags privacy gaps; expansion into Washington, Nevada, or Connecticut user bases.
Jobs-to-be-Done
- When my app or site touches anything health-adjacent, tell me exactly which of my data flows legally count as "consumer health data" in the states that matter to me — without making me read four statutes.
- When a security questionnaire or diligence process asks about MHMDA/CHD compliance, hand me a completed, defensible answer package instead of a blank stare.
- When my ad-tech/analytics SDKs might be quietly geofencing or tracking near health facilities, find it before a plaintiff's firm does.
- When I need consumer authorization language (not just a cookie banner), give me flows that are actually opt-in-compliant, reviewed by counsel, not generic boilerplate.
Painful Problem
CHD statutes define "consumer health data" far more broadly than most product and legal teams assume — location data that could reveal a visit to a reproductive-health or mental-health facility, biometric data, purchase or search history that infers a health condition, and more can all qualify, independent of HIPAA status. Most affected companies run a generic cookie-consent banner (opt-out) when the law requires opt-in authorization before health data is sold or shared with most third parties, and most have no inventory of which embedded SDKs or ad pixels are quietly collecting the data types now in scope. The cost of inaction is not abstract: Washington's law carries a private right of action, and the first class action (Maxwell v. Amazon, Feb. 2025) shows plaintiffs' firms are actively building theories around exactly this SDK/location fact pattern, with statutory and treble damages that can scale with the number of affected consumers. Existing enterprise privacy platforms (OneTrust et al.) are themselves tools the client must configure — they do not read the client's code, do not classify the client's specific data flows against CHD definitions, and do not draft or file anything.
The Outcome We Sell
A counsel-reviewed CHD Compliance Pack: a completed data-flow inventory scoped to consumer health data, an SDK/pixel/geofencing forensic scan report with remediation items, opt-in authorization and consent-flow copy (not generic cookie banners), a CHD-specific privacy-policy section, a vendor/processor data-processing-agreement (DPA) checklist, and a consumer-rights (access/deletion/appeal) fulfillment runbook — delivered as a filed, signed-off package, not a dashboard the client must operate. Optional Managed Monitoring re-scans the client's live app/site quarterly and on every new-state-law trigger.
First One-Feature MVP Wedge
| Element | Definition |
|---|---|
| ICP | Seed-to-Series-B femtech or fitness/wellness app, US-only, 10–150 employees, no dedicated privacy counsel on staff |
| Trigger | Enterprise/health-system security questionnaire, investor diligence checklist, or expansion into WA/NV/CT users |
| Pain | No inventory of which data flows are CHD; consent flow is opt-out, not opt-in authorization; unknown SDK/geofencing exposure |
| One-feature MVP | Single-product CHD Exposure Scan + Authorization Flow Draft for one state (Washington, the strictest) |
| Input | App/site URL or build access, SDK/vendor list, existing privacy policy, current consent-flow screenshots |
| Output | Signed-off Exposure Scan report + drafted WA-compliant authorization flow copy + policy redline, ready for client's counsel to countersign |
| Human chokepoint | Privacy-credentialed reviewer classifies ambiguous data flows; outside counsel signs off before delivery |
| Success metric | Scan + draft delivered in ≤7 business days; ≥90% of flagged data flows accepted by client's counsel without rework |
| Next ask if wedge works | Multi-state pack (NV/CT/CA) + Managed Monitoring + SDK-vendor-side compliance packs |
Evidence Summary
- Washington MHMDA: most provisions effective March 31, 2024; private right of action; first class action filed February 2025 (Maxwell v. Amazon.com, Inc.).
- Nevada SB 370: effective March 31, 2024; requires affirmative consent before collection/sharing, written authorization before sale, bans geofencing within 1,750 feet of medical facilities; AG enforcement, no private right of action.
- Connecticut CTDPA health-data amendments (SB 3): effective July 1, 2023; consent required before selling consumer health data; 1,750-foot geofencing ban around mental-health and reproductive/sexual-health facilities.
- California AB 45: effective January 1, 2026; bans collection/use/sale/retention of personal data from individuals at or near family-planning centers and bans related geofencing.
- MultiState legislative tracker: 24 states now have comprehensive privacy laws in effect as of 2026; Byte Back (June 2026) separately reports the state privacy-law landscape "expands to 24 states."
- OneTrust pricing data (Enzuzo, 2026): small/mid-market privacy-software spend of $10,000–$40,000/year, median $11,835/year across 306 sampled purchases, with implementation adding 20–40% in year one — evidence of existing, but tool-only, budget.
- Privado AI markets an "App Auditor" product for continuous SDK compliance auditing — an AI-native competitor validating the detection half of the problem, but sold as software the client must run, not a done-for-you filed pack.
- Manifest duplicate check: no entry among 647 restored runs matches "consumer health data," "MHMDA," "my health my data," or "geofencing"; nearest neighbors (FCRA/adverse-action, EVV claim-match, workers'-comp mod/audit) are unrelated ontologies.
Claim Table
| Claim | Label | Confidence |
|---|---|---|
| WA MHMDA most provisions effective March 31, 2024; private right of action exists | Verified | High |
| First MHMDA class action (Maxwell v. Amazon) filed Feb. 2025 over SDK location/biometric tracking | Verified | High |
| NV SB 370 effective March 31, 2024; 1,750-ft geofencing ban; no private right of action | Verified | High |
| CT CTDPA health-data amendment effective July 1, 2023; 1,750-ft geofencing ban (mental/reproductive health) | Verified | High |
| CA AB 45 effective Jan 1, 2026; family-planning-center data/geofencing ban | Verified | High |
| 24 states have comprehensive privacy laws in effect in 2026 | Verified | High |
| OneTrust median customer spend ≈$11,835/yr, range $10K–$120K/yr by company size | Verified | Medium-High (single secondary source aggregating procurement data) |
| ≈54,500 healthcare/medical apps on Google Play as of Q3 2022 | Inferred | Medium — dated count, directional only, current figure likely different |
| 1–2% of health-adjacent digital companies are a realistic first-18-months reachable buyer pool | Unverified | Low — pilot assumption, must be validated in first 10 outreach cycles |
| Average first-pack ACV $6K–$25K with 30%+ converting to Managed Monitoring | Unverified | Low — pricing hypothesis pending pilot data |
Source-Claim Matrix
| Claim | Label | Source | Type | Date | Conf. | Section |
|---|---|---|---|---|---|---|
| MHMDA effective date, provisions | Verified | Goodwin — MHMDA Comes Into Force | Law firm alert | 2024 | H | Regulatory |
| Maxwell v. Amazon lawsuit facts, claims, damages theories | Verified | WilmerHale — First Lawsuit Filed Under MHMDA | Law firm alert | Feb 2025 | H | Demand / Pain |
| Maxwell v. Amazon — additional analysis | Verified | Byte Back — First MHMDA Class Action Filed | Law firm alert | Feb 2025 | H | Demand / Pain |
| Location-data-as-health-data litigation theory | Verified | Ogletree — Location Data as Health Data | Law firm alert | 2025 | H | Demand / Pain |
| NV SB 370 requirements: consent, geofencing ban, DPA, consumer rights | Verified | McDermott — Nevada and Connecticut Pass Consumer Health Data Laws | Law firm alert | 2024 | H | Regulatory |
| NV SB 370 effective date, requirements (secondary) | Verified | Benesch — Nevada Joins Washington | Law firm alert | 2024 | H | Regulatory |
| CT CTDPA health-data amendment requirements | Verified | McDermott — Nevada and Connecticut Pass Consumer Health Data Laws | Law firm alert | 2024 | H | Regulatory |
| CA AB 45 effective Jan 1, 2026; family-planning-center provisions | Verified | MultiState — Comprehensive Privacy Laws Taking Effect in 2026 | Legislative tracker | Feb 2026 | H | Regulatory |
| 24 states have comprehensive privacy laws in effect in 2026 | Verified | Byte Back — U.S. Privacy Law Landscape Expands to 24 States | Law firm alert | June 2026 | H | Market |
| Consumer health data regulatory patchwork continues growing | Verified | Healthcare Dive — Consumer Health Data's Regulatory Patchwork Is Growing | Trade press | 2026 | M-H | Market / Why now |
| OneTrust pricing $10K–$120K/yr, median $11,835/yr, implementation +20-40% | Verified | Enzuzo — OneTrust Pricing for Compliance 2026 | Industry analysis | 2026 | M-H | Budget validation |
| Privado AI "App Auditor" continuous SDK compliance product exists | Verified | Privado AI — App Auditor | Vendor product page | 2026 | H | Competitive |
| Google Play ≈54,546 healthcare/medical apps as of Q3 2022 | Inferred (dated) | Market.us — mHealth Apps Statistics 2026 | Market research aggregator | cites Q3 2022 data | M | Sizing |
| Global mHealth market $50.8B (2022) → $150.7B (2032 proj.), 11.8% CAGR | Verified (as reported) | Market.us — mHealth Apps Statistics 2026 | Market research aggregator | 2026 | M | Sizing |
Market and Demand Evidence
The demand signal for CHDClear is not "digital health is growing" — it is the concrete fact that a private-right-of-action statute now exists, a precedent-setting class action has been filed against a company with enormous compliance resources (Amazon) over an ordinary third-party-SDK fact pattern that is common across thousands of consumer apps, and the number of overlapping state statutes a company must reconcile keeps increasing every legislative session (three CHD-specific laws since 2023, a fourth in 2026, and 24 states now with comprehensive privacy laws generally). Law firms are publishing client alerts at high volume specifically because clients are asking; that volume of legal-market content is itself demand evidence, not just risk commentary.
Active Buyer Conversations
- Dozens of law-firm client alerts (WilmerHale, Goodwin, McDermott, Benesch, Ogletree, Paul Hastings, Clark Hill, Cooley, Baker Donelson, Troutman) published through 2024–2026 specifically instructing clients how to assess MHMDA/NV/CT exposure — a strong proxy for active client demand for exactly this work.
- Privado AI, Feroot, and Trackingplan market SDK/pixel-auditing products directly at this compliance gap, evidencing real buyer budget for the detection layer of the problem (though not the done-for-you drafting/filing layer CHDClear adds).
- OneTrust's own 2026 pricing shift (minimum raised to $10K/year, usage-based metering causing renewal "pricing uplifts of 500%" per Enzuzo) is actively pushing SMB/mid-market buyers to look for lower-cost, more targeted alternatives — a direct wedge-opening signal.
Pilot outreach (first 10 companies) must confirm actual willingness-to-pay at the proposed pack price and the real conversion rate from free scan to paid pack — until then, funnel assumptions remain Unverified.
Competitive Landscape
| Player | Type | Gap CHDClear exploits |
|---|---|---|
| OneTrust / Osano / TrustArc | Enterprise privacy-ops software | Client must configure and operate the platform; does not read the client's own SDKs/code or draft state-specific CHD authorization language; pricing has moved upmarket away from the SMB buyer. |
| Privado AI (App Auditor), Feroot, Trackingplan | AI-native SDK/pixel scanning tools | Detects tracking technology but is sold as a tool the client's engineering team must run and interpret; does not classify findings against CHD statutory definitions or draft authorization/policy language. |
| Boutique privacy law firms | Outside counsel | Provides legal opinions at hourly rates; typically does not perform the technical SDK/pixel forensic scan or maintain an ongoing monitoring cadence — CHDClear feeds counsel a pre-scanned, pre-classified pack that cuts their hours. |
| Generic AI copilots (ChatGPT/Claude direct use) | DIY | Can summarize statutes but cannot scan a client's actual codebase/SDK inventory, has no cross-state rule engine, and produces no counsel-reviewed, filed deliverable. |
Competitor and Budget Validation
Budget already exists in two forms: (1) direct privacy-software spend ($10K–$120K/year per OneTrust procurement data, now rising and pushing SMB buyers to look elsewhere) and (2) outside-counsel hourly spend on privacy questions, which CHDClear reduces rather than replaces by delivering a pre-scanned, pre-classified pack for counsel to review instead of build from scratch. This is not a clone of OneTrust: OneTrust sells a platform the client's own team must operate indefinitely; CHDClear sells a finished, signed-off compliance pack. It is not a clone of Privado AI: Privado sells a scanning tool; CHDClear uses scanning as one internal step toward a delivered, counsel-approved outcome.
Pricing Evidence and Proposed Pricing
| Offer | Price | Unit |
|---|---|---|
| Free CHD Exposure Scan | $0 | Automated SDK/pixel/data-flow scan of one app or site, top findings summary (no drafted deliverables) |
| Single-State Compliance Pack (WA) | $4,500–$9,000 | Per product, one state, includes counsel sign-off review coordination |
| Multi-State Compliance Pack (WA+NV+CT+CA) | $9,000–$18,000 | Per product, up to four states |
| SDK/Vendor-Side Compliance Pack | $6,000–$15,000 | Per SDK/ad-tech product, for vendors embedded in health-adjacent apps |
| Managed Monitoring | $1,500–$3,500/mo | Quarterly re-scan + new-law trigger re-review + consumer-rights-request handling |
Never hourly. Pricing is per product/per pack and per monitoring period, not per hour of analyst or attorney time; outside-counsel review fees (where CHDClear does not have an in-house/partnered privacy attorney) are disclosed separately and are not marked up as legal fees.
Regulatory and Compliance Considerations
- Applicable statutes: WA MHMDA (RCW 19.373), NV SB 370 (NRS Chapter 603A amendments), CT CTDPA health-data provisions (SB 3), CA AB 45; monitor additional states as legislative trackers (MultiState, Troutman, DLA Piper) report new CHD bills each session.
- WA MHMDA's private right of action is the single highest-stakes feature — any client-facing material must be precise about what CHDClear does and does not represent about litigation risk reduction; no outcome guarantees.
- Handle client SDK/vendor data and any sample consumer data under a mutual NDA and data-processing agreement; minimize retention of any real consumer data encountered during scanning.
- Do not provide tax advice on any related matters; refer to client's CPA.
- HIPAA-covered-entity clients (rare in this ICP but possible at the margin) require a boundary check — CHDClear addresses CHD statutes, not HIPAA Privacy/Security Rule compliance, and will refer HIPAA-specific work to qualified HIPAA compliance specialists.
Licensing Boundary
| Layer | Allowed | Forbidden |
|---|---|---|
| AI | Scan SDKs/pixels/data flows; classify against CHD ontology; draft authorization language, policy sections, and DPA checklists | Issue legal opinions; guarantee litigation-risk reduction; represent classifications as final without human/counsel review |
| Trained privacy operator | Review AI classifications; assemble packs; coordinate with client's engineering team on remediation; manage consumer-rights-request workflow | Practice law; give case-specific legal advice; sign off on final authorization/policy language without counsel review |
| Licensed privacy attorney (client's own counsel or CHDClear's referred/partnered counsel) | Reviews and approves final authorization flow, policy language, and DPA positions before delivery/go-live | CHDClear itself does not practice law or appear in enforcement/litigation matters |
| Claims we never make | — | "Guaranteed lawsuit-proof"; "certified compliant"; UPL; representation in any AG or court proceeding |
AI-Native Advantage
AI changes the unit economics of this work by collapsing SDK/pixel forensic scanning and cross-statute synthesis from many attorney-hours to a machine-generated first pass reviewed in minutes. Personalization comes from a growing, versioned library of "is this specific data flow CHD in this specific state" precedent classifications built from every prior engagement — a data moat a generic chatbot session cannot replicate. As frontier models improve at code comprehension and long-context statutory reasoning, both the scan quality and the draft quality improve every quarter without adding headcount, and as more states pass CHD laws, the same rule-engine architecture extends rather than needing to be rebuilt.
Internal AI Engine Architecture (10 Layers)
Secure scoping intake
App/site access or SDK manifest, vendor list, existing privacy policy, consent-flow screenshots; signed NDA/DPA.
Data-flow extraction
Static/dynamic scan of network calls, SDKs, pixels, cookies; normalize into a canonical data-type taxonomy (location, biometric, purchase, search, health-app-usage, etc.).
Statutory rule cards
Versioned per-state CHD definitions, consent/authorization requirements, geofencing radii, and consumer-rights timelines (WA/NV/CT/CA, expandable).
Classify & draft
Match each data flow against rule cards; draft authorization copy, policy sections, and DPA checklist items.
Completeness & risk gates
Hard fail if any flow is unclassified; escalate any flow touching reproductive/mental-health signals or geofencing to mandatory human review.
Privacy operator + counsel sign-off
Operator reviews classifications and draft; outside/partnered counsel approves before delivery.
Second-pass sample
100% of flows flagged high-risk; 20% sample of standard flows re-checked against source statute text.
Pack + evidence log
PDF/portal pack with scan report, drafted language, DPA checklist, and sign-off record.
Classification precedent library
Every counsel-approved (or corrected) classification feeds back into the rule engine and prompt library.
Provider-agnostic
Swap LLM/code-scanning backends; statutory rule cards and precedent library remain in-house.
AI-vs-Human Operations Pipeline
Dynasty Translation Layer
- Buyer: Head of Legal/Compliance or founder/COO at a health-adjacent digital company; urgency spikes at security-questionnaire, diligence, or new-state-law moments.
- Service: DFY CHD Compliance Pack + optional Managed Monitoring; client receives filed, counsel-reviewed deliverables, not a platform login.
- Workflow: Intake → scan/normalize → retrieve rule cards → AI classify/draft → risk gates → operator review → counsel sign-off → QA → deliver → learn.
- Tooling: Static/dynamic app scanning tools, frontier LLM for classification/drafting, Airtable/Notion ops board, secure client portal, e-signature for sign-off records, Stripe billing.
- Sales: "Your app likely has at least one data flow that qualifies as consumer health data under Washington law — free scan this week before your next security review."
- Delivery: Manual scan review and drafting acceptable for first 10 packs; automate the scan pipeline once the data-type taxonomy stabilizes.
- Expansion: Multi-state packs → SDK-vendor-side packs → Managed Monitoring → benchmark "CHD exposure by app category" reports as a content/lead-gen asset.
Anti-Duplication Analysis
Checked the restored manifest.json (647 runs after self-heal from commit 1565a1d0, confirmed already healed to 647 on origin/main via manifest-guard.yml before this run's append) and root *-blueprint.html filenames for "consumer health data," "MHMDA," "my health my data," "geofencing," "CHD," and "privacy" — zero substantive matches. Nearest adjacent entries are Fcra Adverse Action Compliance Engine (employment background screening, unrelated ontology), Evv Claim Match Denial Prevention Engine (Medicaid home-care visit verification, unrelated), and various fiduciary/trust accounting desks (different regulator, different workflow shape). A closely adjacent candidate this run — SSA representative-payee/VA-fiduciary annual accounting — was deliberately rejected specifically because its workflow shape (recurring annual accounting to avoid removal/misuse findings) was judged too similar to existing Fiduciary & Court Accounting Engine and WardBooks Clear entries; see Candidate Comparison. CHDClear is not a generic "AI privacy consulting" wrapper, not a clone of OneTrust/Privado AI (both sell tools the client operates), and not a customer-operated co-pilot.
Anti-Commoditization Analysis
If future general models let a founder paste their privacy policy into ChatGPT and get generic advice, CHDClear still wins via (1) actual SDK/code-level scanning of the client's live product, which a chatbot session cannot perform without tooling access; (2) a maintained, versioned, cross-state rule-card library that tracks every new CHD statute as it passes; (3) an accumulating precedent-classification library from real counsel-reviewed engagements; (4) the counsel sign-off relationship itself, which a DIY chatbot output cannot substitute for when a security questionnaire or diligence process demands evidence of review; and (5) ongoing monitoring that catches new SDKs/vendors added after the initial pack. Commoditize the first-draft language; productize the scan-classify-monitor desk.
Service Delivery Workflow
- NDA/DPA + scoping intake (app/site access, SDK/vendor list, existing policy).
- AI scan: extract data flows, SDKs, pixels, geofencing configurations.
- AI classify each flow against versioned CHD rule cards (WA/NV/CT/CA).
- Deterministic completeness/risk gates; escalate high-risk flows.
- AI drafts authorization flow copy, policy sections, DPA checklist.
- Privacy operator reviews; outside/partnered counsel signs off.
- Deliver pack; log sign-off record for client's own audit trail.
- Offer Managed Monitoring for subsequent quarters and new-law triggers.
Operations as Product
- Structured intake checklist (access, SDK/vendor inventory, existing policy/consent artifacts).
- Required-evidence list per data-flow classification (source code reference, vendor contract clause, or observed network call).
- Automated completeness checks and exception queues for unclassified or ambiguous flows.
- Reviewer assignment by state-law specialty; confidence scoring on every AI classification.
- Audit trail and version control on every rule card; gold-standard example packs; red-team scans against known-CHD test apps; root-cause review on any counsel-rejected classification.
No-Holes Quality Engine
No pack ships with any unclassified data flow. Every high-risk flow (reproductive/mental-health signal, geofencing, biometric) requires 100% human review before drafting proceeds. Counsel sign-off is mandatory before delivery — no auto-release. Client receives the classification rationale for every flagged item, not just a pass/fail. Quarterly QA audit re-checks a 20% sample of delivered packs against current statute text as laws are amended.
What the Human Expert Actually Does
| Task | License | Min @ launch | Min @ day 90 | Automation path | Quality risk | Cannot automate | Audit trail |
|---|---|---|---|---|---|---|---|
| Intake completeness check | None | 20 | 8 | Checklist bot | Low | Judging incomplete access grants | Intake log |
| Classification review | None (privacy operator) | 60 | 25 | Suggest-only AI + confidence scoring | High if misclassified | Ambiguous edge-case judgment | Reviewer sign-off record |
| Counsel sign-off | Licensed attorney (JD, privacy-focused) | 45 | 25 | Cannot automate — legal judgment | High | Final legal approval | Signed approval record |
| Client remediation walkthrough | None | 30 | 20 | Recorded explainer + live Q&A | Med | Trust / technical translation | Call notes |
| Rejected-classification postmortem | None | 25 | 15 | Template RCA | Med | Rule-card update judgment | RCA doc |
Minimum Viable Offer
CHDClear Exposure Scan (free) → Single-State (WA) Compliance Pack ($4,500–$9,000) for one product. Includes data-flow inventory, SDK/pixel findings, drafted authorization flow and policy section, DPA checklist, and counsel sign-off coordination. Founding-cohort pricing at the low end of the range for the first eight clients.
Fulfillment Process (First 3 Customers)
- Manual kickoff call; receive SDK/vendor list and site/app access via secure link.
- Founder + contracted privacy operator run scanning tools (open-source network/traffic inspection plus manual SDK manifest review) and classify flows with a frontier LLM against a hand-built rule-card spreadsheet.
- Draft authorization copy and policy redlines in Google Docs; route to a partnered outside privacy attorney for sign-off.
- Deliver pack as a reviewed PDF + short walkthrough call.
- Automate the scan pipeline only after the data-type taxonomy proves stable across 8–10 engagements.
Day-one tools: Google Workspace, a browser-based network-traffic inspector, Airtable, Stripe, a partnered outside counsel relationship (fee-split or referral arrangement), e-signature tool for sign-off records.
Tools and Systems
- Intake: secure client portal + structured scoping questionnaire.
- Scanning: static/dynamic SDK and network-traffic inspection tooling.
- AI: frontier LLM for classification and drafting, with a maintained rule-card knowledge base.
- Ops: Airtable/Notion (engagement queue, escalations, sign-off tracking).
- Delivery: reviewed PDF pack + client portal record.
- Billing: Stripe invoices (pack fee + monitoring subscription).
- Later: custom SDK-scanning pipeline; automated quarterly re-scan triggers tied to legislative-tracker feeds.
Human-in-the-Loop Quality Control
Privacy operator must review every AI classification before drafting proceeds. Outside/partnered counsel must sign off before any pack is delivered or any authorization flow goes live. Client can veto or request revision on any drafted language. No auto-delivery without a recorded sign-off.
Nonlinear Scaling and Unit Economics
| Metric | Launch | Day 90 | Year 1 target |
|---|---|---|---|
| Operator + counsel minutes / pack | 160 | 90 | 60 |
| Automation % | 30% | 55% | 72% |
| Packs / operator / week | 2 | 4 | 7 |
| Gross margin | 38% | 52% | 60% |
| Rework rate | <15% | <8% | <5% |
| Revenue / delivery FTE | $150k | $260k | $380k+ |
COGS breakdown (steady-state single-state pack @ $6,500): model inference $15–$35; scanning tooling $20; privacy-operator 60 min @ loaded $70/hr ≈ $70; outside-counsel review fee (flat-rate negotiated) ≈ $900–$1,400; QA $40; support $30; payment fees $190 → COGS ≈ $1,265–$1,785 (GM ≈ 73–81% on the pack alone). Blended GM lower once sales/marketing and monitoring-tier support costs are included — target ≥50% blended by day 90 and ≥60% by year one as counsel-review fees are negotiated down with volume and automation share increases.
Funnel assumptions (label Unverified until measured): Scan→Pack 8–15%; Pack→Managed Monitoring 30–40%; CAC payback <3 months on Managed Monitoring.
Distribution Proof Table
| Channel | Why ICP reachable | First angle | Conv. assumption | Proof source | Measurement | Follow-up |
|---|---|---|---|---|---|---|
| Privacy/legal LinkedIn outbound | GC/Head of Compliance identifiable by title + company category | "Is your app's SDK stack MHMDA-exposed?" personalized scan offer | 3% scan | Law-firm alert publishing volume as proxy for buyer attention | Reply→scan rate | Calendly walkthrough |
| Femtech/digital-health founder communities (Slack/Discord, newsletters) | Direct ICP density | Educational: "the CHD statute nobody read" post + free scan CTA | 5% scan | Femtech market growth + community activity | Link CTR → scan signups | Automated scan-result email |
| Outside privacy counsel referral partnerships | Counsel already fields these questions at hourly rates | Reverse-referral: "we pre-scan, you review and bill less time" | 15–20% of referred | Existing outside-counsel spend evidence | Referral-code tracking | Co-branded pack delivery |
| SEO / AEO | "Is my app subject to Washington My Health My Data Act" search/answer-engine queries | How-to explainer + free scan CTA | 2% visit→scan | High law-firm publishing volume signals search demand | GSC + form fills | Email nurture |
| Security-questionnaire / diligence moment partnerships (fractional GC networks) | Trigger-event alignment | "Answer the CHD question on your next SOC 2/diligence checklist" | 10% of referred | Diligence-checklist prevalence (qualitative) | Referral tracking | Expedited scan SLA |
| Ad-tech/SDK vendor outbound | Vendors need to prove downstream compliance to app-publisher customers | Vendor-side compliance pack offer | 2% scan | Maxwell v. Amazon fact pattern (SDK-embedded tracking) | Outreach→scan | Case-study follow-up |
Sales and Outreach Plan
Three layers: founder-led content teaching the CHD statutory landscape and its litigation risk; warm conversion of free-scan users into paid packs; targeted outbound to companies with visible health-adjacent positioning and identifiable SDK stacks. Offer page: one promise ("Find out if your app is exposed to My Health My Data Act — free scan this week"), one scan CTA, transparent pricing table, and the licensing disclaimer up front.
Founder-Led Content Plan
Teach: what makes data "consumer health data" beyond HIPAA; the opt-in-authorization vs. opt-out-consent distinction; the 1,750-foot geofencing rule; what the Amazon lawsuit actually alleges and why it matters for ordinary consumer apps; myths ("we're not a health company, so this doesn't apply to us"). Avoid generic AI/privacy hype — cite statute sections and the actual complaint.
First 30 Days of Content
- 10 posts: (1) What counts as "consumer health data" under WA law, (2) opt-in authorization vs. opt-out consent, (3) the 1,750-ft geofencing rule explained, (4) Maxwell v. Amazon teardown, (5) "we're not a health company" myth-busting, (6) NV SB 370 vs. WA MHMDA differences, (7) CT CTDPA health provisions explainer, (8) CA AB 45 family-planning-center rule, (9) SDK/vendor due-diligence checklist, (10) what a security questionnaire actually asks about CHD.
- 3 diagnostic teardowns: anonymized SDK/data-flow scan redlines for a femtech app, a fitness app, and an ad-tech vendor.
- 2 lead-magnet angles: free CHD Exposure Scan; "Is Your App CHD-Exposed?" self-assessment checklist PDF.
- 1 webinar: "Read the Amazon MHMDA complaint with us — what it means for your SDK stack."
- 1 outbound template: personalized scan-findings-preview diagnosis memo.
Lead Magnet and Waitlist Plan
Free CHD Exposure Scan: submit app/site URL and SDK list → receive top-flag summary within 3 business days (no drafted deliverables). Waitlist CTA for Managed Monitoring. Scan captures product category, state-user-base footprint, and whether outside counsel is retained — sales-ready if ≥2 high-risk flows are found and no counsel relationship exists.
Warm GTM Plan
Convert scans with a 30-minute findings review call; founding-cohort pack pricing for the first eight clients; request before/after security-questionnaire-response screenshots as testimonials (with permission). Partner with 3–5 outside privacy attorneys or fractional-GC firms for reciprocal referrals.
Targeted Outbound Plan
Build a prospect list from public femtech/digital-health/wellness startup directories and funding announcements; identify SDK stacks via publicly observable app analysis (no ToS-violating scraping of private systems). First message is a diagnosis offer (a preview of likely exposure) not a generic demo ask.
Answer-Engine / Search Visibility Plan
Publish citation-ready pages answering: "Does my app need to comply with Washington's My Health My Data Act?"; "What is consumer health data under state privacy law?"; "What is the geofencing ban around medical facilities?" Structure with locally-inlined FAQ schema (no external CDN). Aim to be the cited specialist desk in AI-generated answers to these queries.
Pilot Design and Early-Demand-Trap Mitigation
- Pilot cap: 8 companies / 10 packs.
- Incentive: founding single-state pack at $4,500 flat (vs. $6,500+ standard) plus a discounted first-quarter Managed Monitoring rate.
- Learning goals: true classification-review time, counsel-review fee negotiation range, rejected-classification rate, actual willingness-to-pay at proposed price points.
- Custom-work guardrail: no general privacy-policy rewrites unrelated to CHD; no HIPAA compliance work; no litigation defense work.
- Early-demand trap: if inbound asks for broad GDPR/CCPA-wide privacy program builds, refuse and keep the wedge narrow to CHD.
Early-Access Feedback Flywheel
Every counsel-rejected or revised classification triggers a root-cause review and a rule-card/prompt update. Product feedback = classification ontology misses or drafting-language gaps; custom work = client-specific negotiation quirks with a particular vendor contract. Corrections become versioned SOP updates. Expand state coverage only after classification accuracy and counsel-review time hit target gates.
Build-Before-Scale Checkpoints
- After 5 pilots: harden the intake checklist and required-evidence list per data-flow type.
- After 10 packs: harden the rule-card library, exception queues, and reviewer checklist; lock in at least one reliable outside-counsel review partnership at a negotiated flat fee.
- After 20 packs: pause new-logo intake until COGS, rework rate, counsel-review turnaround, and cycle time are measured and stable; do not scale by adding operators faster than the automation share improves.
7-Day / 30-Day / 90-Day Launch Plans
7 days: Landing page, NDA/DPA template, WA rule card v0, scanning-tool setup, outreach to 20 femtech/wellness founders, 5 privacy-attorney partnership conversations, first 3 free scans delivered.
30 days: 8 single-state packs sold at founding pricing; first webinar delivered; 2 outside-counsel referral partnerships signed; 10 content pieces published; classification-review time measured.
90 days: Multi-state pack live (NV/CT/CA rule cards built); Managed Monitoring tier live; 20+ packs delivered; blended GM ≥50%; decide on hiring the first dedicated privacy operator.
Metrics and KPIs
- Scan→pack conversion; pack cycle time; classification accuracy (counsel-accepted rate); counsel-review turnaround time; $ recovered/avoided (qualitative, via reduced outside-counsel hours); operator+counsel minutes/pack; rework %; gross margin; Managed Monitoring attach rate and retention.
Risks and Mitigations
See exhaustive register below. Top risks: mistaken for unauthorized practice of law; counsel-review bottleneck slows delivery; statutory landscape shifts faster than rule cards can be updated; clients treat the pack as a legal guarantee rather than an operational compliance aid; scanning tools miss server-side or first-party data flows.
Exhaustive Risk Register
R1 — Mistaken for unauthorized practice of law
Mitigation: Hard disclaimers on every deliverable; mandatory outside-counsel sign-off before delivery; never issue opinions framed as legal advice; require client's own counsel review where no partnered attorney is engaged.
R2 — Outside-counsel review becomes a bottleneck
Mitigation: Negotiate flat-fee, defined-SLA review arrangements with 2–3 partnered attorneys; pre-classify and pre-draft to minimize attorney time to a review-and-approve pass, not a build-from-scratch pass.
R3 — Statutory landscape changes faster than rule cards update
Mitigation: Subscribe to legislative trackers (MultiState, Troutman, DLA Piper); quarterly rule-card review cycle; Managed Monitoring clients get proactive re-review triggers on any relevant new law.
R4 — Clients treat the pack as a litigation-proof guarantee
Mitigation: Explicit no-guarantee language in every contract and delivered pack; education content sets expectations before sale.
R5 — Scanning tools miss server-side/first-party data flows
Mitigation: Supplement automated scanning with a structured engineering-team interview and backend data-flow questionnaire; flag scan-only engagements as limited-scope.
R6 — Misclassification of an ambiguous data flow
Mitigation: Mandatory human + counsel review on all ambiguous/high-risk flows; confidence scoring surfaces uncertainty rather than hiding it; RCA on every counsel correction feeds the rule-card library.
R7 — OneTrust or a competitor launches a comparable done-for-you tier
Mitigation: Stay narrow and CHD-specific rather than competing as a general privacy platform; lean on counsel-partnership relationships and precedent-classification library as switching-cost moats.
R8 — PII/PHI-adjacent data mishandling during scanning
Mitigation: DPA with every client; minimize retention of any real consumer data encountered; encrypted storage; access logging.
R9 — Low willingness-to-pay at proposed price points
Mitigation: Validate pricing in first 8 pilots; free scan lowers funnel friction; kill or reprice if median pack price realized is <60% of target after 10 sales conversations.
R10 — New federal privacy law preempts or supersedes state CHD statutes
Mitigation: Monitor federal privacy legislation; rule-card architecture can absorb a federal layer as an additional rule card rather than requiring a rebuild.
R11 — Buyer confusion with generic "AI privacy consulting"
Mitigation: CHD-specific, statute-cited messaging; lead with the Amazon complaint and specific statutory mechanics, not generic "AI compliance" language.
R12 — Counsel-partner capacity constrains growth
Mitigation: Build a bench of 3–5 partnered attorneys/firms rather than a single dependency; pre-negotiate capacity commitments ahead of pilot scaling.
What Could Kill This
- Median realized pack price falls well below target after pilot sales conversations, making the model uneconomical at 50%+ GM.
- Outside-counsel review costs cannot be negotiated down, compressing margin below viability.
- Regulators or bar associations characterize the classification/drafting service as unauthorized practice of law despite disclaimers and counsel sign-off.
- Buyers cannot distinguish CHDClear from generic "AI privacy consulting" noise in a crowded content market.
- Scanning technology limitations (server-side/first-party flows) make the core deliverable materially incomplete without disproportionate manual engineering-interview time.
Go/No-Go Reasoning
Go. Clears buyer, pain, and active-litigation evidence (a filed, precedent-setting class action on the exact SDK/data-flow fact pattern this business addresses), demonstrated existing budget (OneTrust/Osano/TrustArc spend plus outside-counsel hourly spend), a defined and growing statutory footprint (four CHD-specific laws plus 24 states with comprehensive privacy laws), a narrow one-state MVP wedge, fully remote fulfillment, a credible 50%+ gross-margin path once counsel-review fees are negotiated down, a plausible distribution path through legal/privacy-adjacent channels, and confirmed non-duplication against the restored 647-run manifest. The closest alternative candidate (SSA representative-payee/VA-fiduciary accounting) was rejected specifically for semantic proximity to two existing manifest entries — a stronger discipline outcome than forcing a marginal blueprint forward.
Final Recommendation
Build CHDClear as a consumer-health-data-specific compliance desk, launching with a free Exposure Scan and a single-state (Washington) Compliance Pack for femtech, fitness/wellness, and telehealth-adjacent digital products. Cap pilots at 8 companies; secure at least two outside-counsel review partnerships before pilot launch; harden the rule-card library on Washington before expanding to Nevada, Connecticut, and California. Do not expand into general GDPR/CCPA-wide privacy program builds or HIPAA compliance work in year one.
Source List
- Goodwin — Washington's My Health My Data Act Comes Into Force
- WilmerHale — First Lawsuit Filed Under Washington's My Health My Data Act
- Byte Back — First Washington My Health My Data Act Class Action Lawsuit Filed
- Ogletree — Location Data as Health Data: Precedent-Setting MHMDA Lawsuit
- Paul Hastings — First Class Action Complaint Filed Under MHMDA
- McDermott — Nevada and Connecticut Pass Consumer Health Data Laws
- Benesch — Nevada Joins Washington With a Consumer Health Data Consent Law
- MultiState — All of the Comprehensive Privacy Laws That Take Effect in 2026
- Byte Back — U.S. State Privacy Law Landscape Expands to 24 States
- Healthcare Dive — Consumer Health Data's Regulatory Patchwork Is Growing
- Enzuzo — OneTrust Pricing for Compliance 2026
- Privado AI — App Auditor Product Page
- Privado AI — G2 Creates Category for Website Privacy Auditing Tools
- Market.us — mHealth Apps Statistics 2026
- Troutman — Proposed State Privacy Law Update, April 20, 2026
- DLA Piper — U.S. Privacy Laws Legislative Update
- CRS via Congress.gov — Social Security Administration Representative Payees (rejected-candidate research)
- SSA OIG — Allegations of Representative Payees' Misuse of Benefits (rejected-candidate research)
- CRS via Congress.gov — The VA Fiduciary Program: An Overview (rejected-candidate research)