AI-Native Service Business Blueprint · Run 2026-07-21-0413

CHDClear — Consumer Health Data Privacy Authorization & Compliance Desk

Done-for-you compliance operations for the fast-growing "consumer health data" (CHD) patchwork — Washington's My Health My Data Act, Nevada SB 370, Connecticut's CTDPA health-data provisions, and California AB 45 — for digital health, femtech, wellness, telehealth-adjacent, and health-marketing companies. We deliver a filed, counsel-reviewed compliance program, not a dashboard the client must operate.

Final decision: Blueprint

Executive Summary

A new category of U.S. state privacy law — "consumer health data" (CHD) statutes — has emerged since 2023 and is expanding fast: Washington's My Health My Data Act (MHMDA, most provisions effective March 31, 2024), Nevada SB 370 (effective March 31, 2024), Connecticut's CTDPA health-data amendments (effective July 1, 2023), and California's AB 45 family-planning-center provisions (effective January 1, 2026) now sit inside a broader landscape of 24 states with comprehensive privacy laws in effect in 2026. CHD statutes are unusually dangerous for a compliance program built on generic "cookie consent" tooling: they define health data far more broadly than HIPAA (location near a clinic, purchase history, biometric or search data can all qualify), they require opt-in authorization — not opt-out — before health data is sold or shared with most third parties, several ban geofencing within 1,750 feet of medical/reproductive/mental-health facilities, and Washington's law carries a private right of action that has already produced litigation (Maxwell v. Amazon.com, Inc., filed February 2025, alleging an advertising SDK embedded in third-party apps captured location and biometric signals capable of revealing clinic and gym visits).

CHDClear sells the finished outcome — a counsel-reviewed CHD compliance program — to companies that collect health-adjacent consumer data but are too small or too distracted to run a $10K–$120K/year enterprise privacy platform (OneTrust, Osano, TrustArc) themselves, let alone read four overlapping statutes. AI performs the SDK/pixel forensic scan, the statutory cross-reference, the data-flow inventory, and the first-draft authorization/consent language and privacy-policy sections; a privacy-credentialed reviewer and outside counsel sign off before anything ships. Priced per scan and per compliance pack — never hourly.

24 states
Comprehensive privacy laws in effect in 2026 (MultiState, Feb 2026)
4 laws
CHD-specific statutes now live: WA MHMDA, NV SB 370, CT CTDPA health provisions, CA AB 45
1,750 ft
Geofencing ban radius around medical/mental-health/reproductive facilities (NV, CT)
$10K–$120K/yr
Existing OneTrust software spend by company size — budget already exists for the problem

Thesis

Consumer health data law is a genuinely new, fast-expanding, high-stakes regulatory category that most digital-health-adjacent companies have not mapped, because it does not track HIPAA's "covered entity" boundary — non-medical companies (fitness apps, period trackers, DTC supplement sellers, ad-tech vendors embedded in health-adjacent apps) are squarely in scope and often unaware of it. The winner is not another privacy-ops platform the client must configure (that market is served, and is contracting toward usage-based pricing that punishes exactly the SMB/mid-market buyer CHDClear targets) — it is a specialist desk that scans a client's actual data flows, tells them precisely which lines of code and vendor contracts create CHD exposure, and ships a signed-off authorization and policy pack before the next audit, RFP security questionnaire, or plaintiff's firm finds the gap first. Frontier models compound the value of this desk: better multimodal/code-reading models make SDK and pixel forensics faster and cheaper every quarter, and the statutory patchwork itself keeps growing (more states each legislative session), which increases — not decreases — the value of an operator who has already built the cross-state rule engine.

Discovery Rationale

This run began by reading the restored 647-run manifest (see Anti-Duplication) and found the catalog dominated by regulatory-filing and back-office "recovery/dispute/annual-accounting desk" patterns across freight, insurance renewals, fiduciary/guardianship accounting, and Medicaid/Medicare trust compliance. Per the standing instruction to steer into underexplored terrain, fourteen search queries were run across HR/benefits compliance (Fair Workweek — already covered twice; SSA representative-payee accounting — semantically adjacent to two existing fiduciary-accounting entries), staffing-agency unemployment insurance cost management (already covered as "Unemployment Cost Management Engine"), multi-state remote-payroll nexus, and privacy/data-protection compliance. Consumer health data (CHD) privacy law surfaced as the strongest candidate: it is unclaimed in the manifest (zero hits for "consumer health data," "MHMDA," "my health my data," or "geofencing"), it has hard evidence of active litigation and a fast-growing statutory footprint, it has a defined buyer with existing but insufficient budget (privacy software spend that doesn't include the actual mapping/drafting/monitoring labor), and it clears the fatal-disqualifier checklist without relying on generic "AI privacy consulting" positioning.

Candidate Comparison

CandidateBuyer / OutcomeScore /30Decision
CHDClearDigital health / femtech / wellness / health-adjacent ad-tech / signed-off CHD compliance pack28Winner
PayeeBooks ClearSSA organizational representative payee & VA fiduciary annual accounting production21Reject — strong evidence (5.7M payees, 7.7M beneficiaries, FY2024 VA OIG data) but workflow and buyer overlap too closely with existing manifest entries Fiduciary & Court Accounting Engine and WardBooks Clear (Guardianship & Conservatorship Annual Accounting Production Desk) — same underlying "recurring annual accounting to avoid removal/misuse findings" shape
Fair Workweek / predictive-scheduling complianceMulti-location retail/restaurant employersReject — duplicate; already covered twice (Fair Workweek Exposure Audit Compliance Engine, Fair Workweek Predictability Pay Audit Engine)
StaffUI ClearStaffing agencies / unemployment insurance (SUTA) claims & tax-rate protest desk19Defer — real pain but incumbents (Equifax/TALX, Thomas & Company) hold deep state-EDI integration moats that are hard for a new entrant to match at launch
NexusPay ClearRemote-first employers / multi-state payroll tax nexus & withholding registration17Defer — real problem but lower urgency/litigation signal than CHD; thinner evidence base gathered this run

Scoring dimensions (six-gate rubric plus buyer urgency, competitive whitespace, novelty vs. manifest, demand evidence, budget proof, MVP clarity, distribution clarity, licensing feasibility, repeatability, speed to revenue) are detailed in the Rubric Scorecard section below for the winning candidate.

CODE Validation

LensFindingLabel
C — Consumer/buyer trendState legislatures have added CHD-specific statutes every session since 2023 (WA 2023, NV/CT 2024, CA AB 45 effective Jan 2026); the broader comprehensive-privacy-law count reached 24 states in 2026, and multiple additional CHD or geofencing bills were pending as of Q1–Q2 2026 per legislative trackers.Verified
O — OpportunityThe underserved wedge is not generic "privacy compliance" — it is the specific, technically hard task of finding which of a company's own data flows (SDKs, pixels, geofenced ads, purchase/location data) legally qualify as CHD under statutes with broader-than-HIPAA definitions, then converting that into an authorized (not merely opted-out) consent flow and a defensible privacy policy.Verified
D — DemandThe first MHMDA class action (Maxwell v. Amazon.com, Inc., W.D. Wash., filed Feb. 2025) directly targets SDK-embedded location/biometric tracking across ordinary consumer apps (Weather Channel, OfferUp, Speedtest, Truecaller) — proof that generic apps, not just clinical software, are exposed; law-firm client alerts on MHMDA/NV/CT compliance have proliferated since 2024; AI-native SDK-auditing tooling (Privado AI "App Auditor") already exists as a category, evidencing real vendor spend on the detection half of this problem.Verified
E — Economic sizingOrder-of-magnitude buyer pool: Google Play alone listed roughly 54,500 healthcare/medical-category apps as of Q3 2022 (dated, direction-only), and the global mHealth market was sized near $50.8B in 2022 growing toward $150.7B by 2032 (11.8% CAGR) — both signal a large population of health-adjacent digital products, only a fraction of which need CHD compliance work in any given year, but even 1–2% of a low-tens-of-thousands beachhead (femtech, fitness, telehealth-adjacent, DTC wellness commerce, and their ad-tech vendors) at a $6K–$25K first-year pack is a multi-million-dollar reachable segment.Inferred

Rubric Scorecard (Six Gates)

GateScoreExplanation
1 Low Trust Burden4/5Companies already outsource privacy compliance to outside counsel and platforms; they want the finished authorization flow and policy language, not to personally parse four statutes. Partial trust burden remains because output touches legal-adjacent text — mitigated by a licensed-counsel sign-off chokepoint on every pack.
2 Low Task-Level Judgment4/5Decomposable into: crawl/scan → classify data flows against a CHD ontology → flag geofencing/SDK issues → draft authorization and policy language → route ambiguous classifications to a human. Judgment concentrated on ambiguous data-type calls and final legal sign-off.
3 High Intelligence Threshold5/5Requires synthesizing overlapping, non-identical statutory definitions (WA/NV/CT/CA), applying them to a specific technical data-flow map, and reconciling with the client's existing (often generic) privacy policy and vendor contracts — a genuine cross-document, cross-jurisdiction reasoning task that improves with frontier models.
4 Regulation as Moat5/5Washington's private right of action plus an active, precedent-setting class action create real monetary tail risk (the Amazon complaint combines wiretap-act statutory damages up to $100/day per violation, trebled up to $25,000 per person, with MHMDA and Washington Consumer Protection Act claims) — this is not hypothetical risk, and the patchwork keeps growing, which raises switching costs away from a specialist who already tracks it.
5 No Physical Labor5/5Entirely remote: code/SDK scanning, document review, and drafting.
6 Sam Altman Test5/5Better multimodal/code-reading models directly cut the cost of SDK/pixel forensics and statutory synthesis; the proprietary moat is CHDClear's accumulating library of "is this specific data flow CHD in this specific state" precedent classifications, which a generic chatbot cannot replicate without that case history.

Total: 28/30. Clears evidence threshold for blueprint.

Target Buyer

  • ICP: US-based digital health, femtech, fitness/wellness, telehealth-adjacent, or DTC health-adjacent commerce company, 10–500 employees, that is NOT a fully HIPAA-covered entity (or is only partially covered) and processes data plausibly meeting a state CHD definition — health app usage, biometric signals, location near health facilities, or health-related purchase/search history.
  • Secondary ICP: Ad-tech/martech vendors and SDK providers embedded inside health-adjacent apps who need to demonstrate downstream CHD compliance to their own app-publisher customers (the exact fact pattern in Maxwell v. Amazon).
  • Economic buyer: Head of Legal/Compliance, General Counsel, or (pre-GC-stage) the founder/COO who currently owns the privacy policy.
  • Champion: Product/engineering lead who knows which SDKs and analytics pixels are actually in the codebase.
  • Trigger events: Enterprise/health-system security questionnaire or SOC 2-adjacent audit; a new state CHD law taking effect; a competitor or peer company gets sued or named in a law-firm client alert; an investor or acquirer's diligence checklist flags privacy gaps; expansion into Washington, Nevada, or Connecticut user bases.

Jobs-to-be-Done

  • When my app or site touches anything health-adjacent, tell me exactly which of my data flows legally count as "consumer health data" in the states that matter to me — without making me read four statutes.
  • When a security questionnaire or diligence process asks about MHMDA/CHD compliance, hand me a completed, defensible answer package instead of a blank stare.
  • When my ad-tech/analytics SDKs might be quietly geofencing or tracking near health facilities, find it before a plaintiff's firm does.
  • When I need consumer authorization language (not just a cookie banner), give me flows that are actually opt-in-compliant, reviewed by counsel, not generic boilerplate.

Painful Problem

CHD statutes define "consumer health data" far more broadly than most product and legal teams assume — location data that could reveal a visit to a reproductive-health or mental-health facility, biometric data, purchase or search history that infers a health condition, and more can all qualify, independent of HIPAA status. Most affected companies run a generic cookie-consent banner (opt-out) when the law requires opt-in authorization before health data is sold or shared with most third parties, and most have no inventory of which embedded SDKs or ad pixels are quietly collecting the data types now in scope. The cost of inaction is not abstract: Washington's law carries a private right of action, and the first class action (Maxwell v. Amazon, Feb. 2025) shows plaintiffs' firms are actively building theories around exactly this SDK/location fact pattern, with statutory and treble damages that can scale with the number of affected consumers. Existing enterprise privacy platforms (OneTrust et al.) are themselves tools the client must configure — they do not read the client's code, do not classify the client's specific data flows against CHD definitions, and do not draft or file anything.

The Outcome We Sell

A counsel-reviewed CHD Compliance Pack: a completed data-flow inventory scoped to consumer health data, an SDK/pixel/geofencing forensic scan report with remediation items, opt-in authorization and consent-flow copy (not generic cookie banners), a CHD-specific privacy-policy section, a vendor/processor data-processing-agreement (DPA) checklist, and a consumer-rights (access/deletion/appeal) fulfillment runbook — delivered as a filed, signed-off package, not a dashboard the client must operate. Optional Managed Monitoring re-scans the client's live app/site quarterly and on every new-state-law trigger.

Licensing boundary (preview): CHDClear is a privacy-operations and documentation desk. It does not provide legal advice and does not represent clients in litigation or regulatory proceedings. Every authorization flow, policy section, and DPA position is reviewed and approved by independent outside counsel (client's own counsel, or a referred/partnered privacy attorney) before it ships or goes live.

First One-Feature MVP Wedge

ElementDefinition
ICPSeed-to-Series-B femtech or fitness/wellness app, US-only, 10–150 employees, no dedicated privacy counsel on staff
TriggerEnterprise/health-system security questionnaire, investor diligence checklist, or expansion into WA/NV/CT users
PainNo inventory of which data flows are CHD; consent flow is opt-out, not opt-in authorization; unknown SDK/geofencing exposure
One-feature MVPSingle-product CHD Exposure Scan + Authorization Flow Draft for one state (Washington, the strictest)
InputApp/site URL or build access, SDK/vendor list, existing privacy policy, current consent-flow screenshots
OutputSigned-off Exposure Scan report + drafted WA-compliant authorization flow copy + policy redline, ready for client's counsel to countersign
Human chokepointPrivacy-credentialed reviewer classifies ambiguous data flows; outside counsel signs off before delivery
Success metricScan + draft delivered in ≤7 business days; ≥90% of flagged data flows accepted by client's counsel without rework
Next ask if wedge worksMulti-state pack (NV/CT/CA) + Managed Monitoring + SDK-vendor-side compliance packs

Evidence Summary

  • Washington MHMDA: most provisions effective March 31, 2024; private right of action; first class action filed February 2025 (Maxwell v. Amazon.com, Inc.).
  • Nevada SB 370: effective March 31, 2024; requires affirmative consent before collection/sharing, written authorization before sale, bans geofencing within 1,750 feet of medical facilities; AG enforcement, no private right of action.
  • Connecticut CTDPA health-data amendments (SB 3): effective July 1, 2023; consent required before selling consumer health data; 1,750-foot geofencing ban around mental-health and reproductive/sexual-health facilities.
  • California AB 45: effective January 1, 2026; bans collection/use/sale/retention of personal data from individuals at or near family-planning centers and bans related geofencing.
  • MultiState legislative tracker: 24 states now have comprehensive privacy laws in effect as of 2026; Byte Back (June 2026) separately reports the state privacy-law landscape "expands to 24 states."
  • OneTrust pricing data (Enzuzo, 2026): small/mid-market privacy-software spend of $10,000–$40,000/year, median $11,835/year across 306 sampled purchases, with implementation adding 20–40% in year one — evidence of existing, but tool-only, budget.
  • Privado AI markets an "App Auditor" product for continuous SDK compliance auditing — an AI-native competitor validating the detection half of the problem, but sold as software the client must run, not a done-for-you filed pack.
  • Manifest duplicate check: no entry among 647 restored runs matches "consumer health data," "MHMDA," "my health my data," or "geofencing"; nearest neighbors (FCRA/adverse-action, EVV claim-match, workers'-comp mod/audit) are unrelated ontologies.

Claim Table

ClaimLabelConfidence
WA MHMDA most provisions effective March 31, 2024; private right of action existsVerifiedHigh
First MHMDA class action (Maxwell v. Amazon) filed Feb. 2025 over SDK location/biometric trackingVerifiedHigh
NV SB 370 effective March 31, 2024; 1,750-ft geofencing ban; no private right of actionVerifiedHigh
CT CTDPA health-data amendment effective July 1, 2023; 1,750-ft geofencing ban (mental/reproductive health)VerifiedHigh
CA AB 45 effective Jan 1, 2026; family-planning-center data/geofencing banVerifiedHigh
24 states have comprehensive privacy laws in effect in 2026VerifiedHigh
OneTrust median customer spend ≈$11,835/yr, range $10K–$120K/yr by company sizeVerifiedMedium-High (single secondary source aggregating procurement data)
≈54,500 healthcare/medical apps on Google Play as of Q3 2022InferredMedium — dated count, directional only, current figure likely different
1–2% of health-adjacent digital companies are a realistic first-18-months reachable buyer poolUnverifiedLow — pilot assumption, must be validated in first 10 outreach cycles
Average first-pack ACV $6K–$25K with 30%+ converting to Managed MonitoringUnverifiedLow — pricing hypothesis pending pilot data

Source-Claim Matrix

ClaimLabelSourceTypeDateConf.Section
MHMDA effective date, provisionsVerifiedGoodwin — MHMDA Comes Into ForceLaw firm alert2024HRegulatory
Maxwell v. Amazon lawsuit facts, claims, damages theoriesVerifiedWilmerHale — First Lawsuit Filed Under MHMDALaw firm alertFeb 2025HDemand / Pain
Maxwell v. Amazon — additional analysisVerifiedByte Back — First MHMDA Class Action FiledLaw firm alertFeb 2025HDemand / Pain
Location-data-as-health-data litigation theoryVerifiedOgletree — Location Data as Health DataLaw firm alert2025HDemand / Pain
NV SB 370 requirements: consent, geofencing ban, DPA, consumer rightsVerifiedMcDermott — Nevada and Connecticut Pass Consumer Health Data LawsLaw firm alert2024HRegulatory
NV SB 370 effective date, requirements (secondary)VerifiedBenesch — Nevada Joins WashingtonLaw firm alert2024HRegulatory
CT CTDPA health-data amendment requirementsVerifiedMcDermott — Nevada and Connecticut Pass Consumer Health Data LawsLaw firm alert2024HRegulatory
CA AB 45 effective Jan 1, 2026; family-planning-center provisionsVerifiedMultiState — Comprehensive Privacy Laws Taking Effect in 2026Legislative trackerFeb 2026HRegulatory
24 states have comprehensive privacy laws in effect in 2026VerifiedByte Back — U.S. Privacy Law Landscape Expands to 24 StatesLaw firm alertJune 2026HMarket
Consumer health data regulatory patchwork continues growingVerifiedHealthcare Dive — Consumer Health Data's Regulatory Patchwork Is GrowingTrade press2026M-HMarket / Why now
OneTrust pricing $10K–$120K/yr, median $11,835/yr, implementation +20-40%VerifiedEnzuzo — OneTrust Pricing for Compliance 2026Industry analysis2026M-HBudget validation
Privado AI "App Auditor" continuous SDK compliance product existsVerifiedPrivado AI — App AuditorVendor product page2026HCompetitive
Google Play ≈54,546 healthcare/medical apps as of Q3 2022Inferred (dated)Market.us — mHealth Apps Statistics 2026Market research aggregatorcites Q3 2022 dataMSizing
Global mHealth market $50.8B (2022) → $150.7B (2032 proj.), 11.8% CAGRVerified (as reported)Market.us — mHealth Apps Statistics 2026Market research aggregator2026MSizing

Market and Demand Evidence

The demand signal for CHDClear is not "digital health is growing" — it is the concrete fact that a private-right-of-action statute now exists, a precedent-setting class action has been filed against a company with enormous compliance resources (Amazon) over an ordinary third-party-SDK fact pattern that is common across thousands of consumer apps, and the number of overlapping state statutes a company must reconcile keeps increasing every legislative session (three CHD-specific laws since 2023, a fourth in 2026, and 24 states now with comprehensive privacy laws generally). Law firms are publishing client alerts at high volume specifically because clients are asking; that volume of legal-market content is itself demand evidence, not just risk commentary.

Active Buyer Conversations

  • Dozens of law-firm client alerts (WilmerHale, Goodwin, McDermott, Benesch, Ogletree, Paul Hastings, Clark Hill, Cooley, Baker Donelson, Troutman) published through 2024–2026 specifically instructing clients how to assess MHMDA/NV/CT exposure — a strong proxy for active client demand for exactly this work.
  • Privado AI, Feroot, and Trackingplan market SDK/pixel-auditing products directly at this compliance gap, evidencing real buyer budget for the detection layer of the problem (though not the done-for-you drafting/filing layer CHDClear adds).
  • OneTrust's own 2026 pricing shift (minimum raised to $10K/year, usage-based metering causing renewal "pricing uplifts of 500%" per Enzuzo) is actively pushing SMB/mid-market buyers to look for lower-cost, more targeted alternatives — a direct wedge-opening signal.

Pilot outreach (first 10 companies) must confirm actual willingness-to-pay at the proposed pack price and the real conversion rate from free scan to paid pack — until then, funnel assumptions remain Unverified.

Competitive Landscape

PlayerTypeGap CHDClear exploits
OneTrust / Osano / TrustArcEnterprise privacy-ops softwareClient must configure and operate the platform; does not read the client's own SDKs/code or draft state-specific CHD authorization language; pricing has moved upmarket away from the SMB buyer.
Privado AI (App Auditor), Feroot, TrackingplanAI-native SDK/pixel scanning toolsDetects tracking technology but is sold as a tool the client's engineering team must run and interpret; does not classify findings against CHD statutory definitions or draft authorization/policy language.
Boutique privacy law firmsOutside counselProvides legal opinions at hourly rates; typically does not perform the technical SDK/pixel forensic scan or maintain an ongoing monitoring cadence — CHDClear feeds counsel a pre-scanned, pre-classified pack that cuts their hours.
Generic AI copilots (ChatGPT/Claude direct use)DIYCan summarize statutes but cannot scan a client's actual codebase/SDK inventory, has no cross-state rule engine, and produces no counsel-reviewed, filed deliverable.

Competitor and Budget Validation

Budget already exists in two forms: (1) direct privacy-software spend ($10K–$120K/year per OneTrust procurement data, now rising and pushing SMB buyers to look elsewhere) and (2) outside-counsel hourly spend on privacy questions, which CHDClear reduces rather than replaces by delivering a pre-scanned, pre-classified pack for counsel to review instead of build from scratch. This is not a clone of OneTrust: OneTrust sells a platform the client's own team must operate indefinitely; CHDClear sells a finished, signed-off compliance pack. It is not a clone of Privado AI: Privado sells a scanning tool; CHDClear uses scanning as one internal step toward a delivered, counsel-approved outcome.

Pricing Evidence and Proposed Pricing

OfferPriceUnit
Free CHD Exposure Scan$0Automated SDK/pixel/data-flow scan of one app or site, top findings summary (no drafted deliverables)
Single-State Compliance Pack (WA)$4,500–$9,000Per product, one state, includes counsel sign-off review coordination
Multi-State Compliance Pack (WA+NV+CT+CA)$9,000–$18,000Per product, up to four states
SDK/Vendor-Side Compliance Pack$6,000–$15,000Per SDK/ad-tech product, for vendors embedded in health-adjacent apps
Managed Monitoring$1,500–$3,500/moQuarterly re-scan + new-law trigger re-review + consumer-rights-request handling

Never hourly. Pricing is per product/per pack and per monitoring period, not per hour of analyst or attorney time; outside-counsel review fees (where CHDClear does not have an in-house/partnered privacy attorney) are disclosed separately and are not marked up as legal fees.

Regulatory and Compliance Considerations

  • Applicable statutes: WA MHMDA (RCW 19.373), NV SB 370 (NRS Chapter 603A amendments), CT CTDPA health-data provisions (SB 3), CA AB 45; monitor additional states as legislative trackers (MultiState, Troutman, DLA Piper) report new CHD bills each session.
  • WA MHMDA's private right of action is the single highest-stakes feature — any client-facing material must be precise about what CHDClear does and does not represent about litigation risk reduction; no outcome guarantees.
  • Handle client SDK/vendor data and any sample consumer data under a mutual NDA and data-processing agreement; minimize retention of any real consumer data encountered during scanning.
  • Do not provide tax advice on any related matters; refer to client's CPA.
  • HIPAA-covered-entity clients (rare in this ICP but possible at the margin) require a boundary check — CHDClear addresses CHD statutes, not HIPAA Privacy/Security Rule compliance, and will refer HIPAA-specific work to qualified HIPAA compliance specialists.

Licensing Boundary

LayerAllowedForbidden
AIScan SDKs/pixels/data flows; classify against CHD ontology; draft authorization language, policy sections, and DPA checklistsIssue legal opinions; guarantee litigation-risk reduction; represent classifications as final without human/counsel review
Trained privacy operatorReview AI classifications; assemble packs; coordinate with client's engineering team on remediation; manage consumer-rights-request workflowPractice law; give case-specific legal advice; sign off on final authorization/policy language without counsel review
Licensed privacy attorney (client's own counsel or CHDClear's referred/partnered counsel)Reviews and approves final authorization flow, policy language, and DPA positions before delivery/go-liveCHDClear itself does not practice law or appear in enforcement/litigation matters
Claims we never make"Guaranteed lawsuit-proof"; "certified compliant"; UPL; representation in any AG or court proceeding

AI-Native Advantage

AI changes the unit economics of this work by collapsing SDK/pixel forensic scanning and cross-statute synthesis from many attorney-hours to a machine-generated first pass reviewed in minutes. Personalization comes from a growing, versioned library of "is this specific data flow CHD in this specific state" precedent classifications built from every prior engagement — a data moat a generic chatbot session cannot replicate. As frontier models improve at code comprehension and long-context statutory reasoning, both the scan quality and the draft quality improve every quarter without adding headcount, and as more states pass CHD laws, the same rule-engine architecture extends rather than needing to be rebuilt.

Internal AI Engine Architecture (10 Layers)

Layer 1 · Intake

Secure scoping intake

App/site access or SDK manifest, vendor list, existing privacy policy, consent-flow screenshots; signed NDA/DPA.

Layer 2 · Normalization

Data-flow extraction

Static/dynamic scan of network calls, SDKs, pixels, cookies; normalize into a canonical data-type taxonomy (location, biometric, purchase, search, health-app-usage, etc.).

Layer 3 · Retrieval / Knowledge

Statutory rule cards

Versioned per-state CHD definitions, consent/authorization requirements, geofencing radii, and consumer-rights timelines (WA/NV/CT/CA, expandable).

Layer 4 · AI Workbench

Classify & draft

Match each data flow against rule cards; draft authorization copy, policy sections, and DPA checklist items.

Layer 5 · Deterministic Rules

Completeness & risk gates

Hard fail if any flow is unclassified; escalate any flow touching reproductive/mental-health signals or geofencing to mandatory human review.

Layer 6 · Human Chokepoint

Privacy operator + counsel sign-off

Operator reviews classifications and draft; outside/partnered counsel approves before delivery.

Layer 7 · QA

Second-pass sample

100% of flows flagged high-risk; 20% sample of standard flows re-checked against source statute text.

Layer 8 · Delivery

Pack + evidence log

PDF/portal pack with scan report, drafted language, DPA checklist, and sign-off record.

Layer 9 · Learning Loop

Classification precedent library

Every counsel-approved (or corrected) classification feeds back into the rule engine and prompt library.

Layer 10 · Model Portability

Provider-agnostic

Swap LLM/code-scanning backends; statutory rule cards and precedent library remain in-house.

AI-vs-Human Operations Pipeline

AI
Scan SDKs/pixels/data flows
AI
Classify against CHD rule cards
Rules
Escalation & completeness gates
AI
Draft authorization/policy/DPA language
Human
Privacy operator review
Human
Outside counsel sign-off

Dynasty Translation Layer

  • Buyer: Head of Legal/Compliance or founder/COO at a health-adjacent digital company; urgency spikes at security-questionnaire, diligence, or new-state-law moments.
  • Service: DFY CHD Compliance Pack + optional Managed Monitoring; client receives filed, counsel-reviewed deliverables, not a platform login.
  • Workflow: Intake → scan/normalize → retrieve rule cards → AI classify/draft → risk gates → operator review → counsel sign-off → QA → deliver → learn.
  • Tooling: Static/dynamic app scanning tools, frontier LLM for classification/drafting, Airtable/Notion ops board, secure client portal, e-signature for sign-off records, Stripe billing.
  • Sales: "Your app likely has at least one data flow that qualifies as consumer health data under Washington law — free scan this week before your next security review."
  • Delivery: Manual scan review and drafting acceptable for first 10 packs; automate the scan pipeline once the data-type taxonomy stabilizes.
  • Expansion: Multi-state packs → SDK-vendor-side packs → Managed Monitoring → benchmark "CHD exposure by app category" reports as a content/lead-gen asset.

Anti-Duplication Analysis

Checked the restored manifest.json (647 runs after self-heal from commit 1565a1d0, confirmed already healed to 647 on origin/main via manifest-guard.yml before this run's append) and root *-blueprint.html filenames for "consumer health data," "MHMDA," "my health my data," "geofencing," "CHD," and "privacy" — zero substantive matches. Nearest adjacent entries are Fcra Adverse Action Compliance Engine (employment background screening, unrelated ontology), Evv Claim Match Denial Prevention Engine (Medicaid home-care visit verification, unrelated), and various fiduciary/trust accounting desks (different regulator, different workflow shape). A closely adjacent candidate this run — SSA representative-payee/VA-fiduciary annual accounting — was deliberately rejected specifically because its workflow shape (recurring annual accounting to avoid removal/misuse findings) was judged too similar to existing Fiduciary & Court Accounting Engine and WardBooks Clear entries; see Candidate Comparison. CHDClear is not a generic "AI privacy consulting" wrapper, not a clone of OneTrust/Privado AI (both sell tools the client operates), and not a customer-operated co-pilot.

Anti-Commoditization Analysis

If future general models let a founder paste their privacy policy into ChatGPT and get generic advice, CHDClear still wins via (1) actual SDK/code-level scanning of the client's live product, which a chatbot session cannot perform without tooling access; (2) a maintained, versioned, cross-state rule-card library that tracks every new CHD statute as it passes; (3) an accumulating precedent-classification library from real counsel-reviewed engagements; (4) the counsel sign-off relationship itself, which a DIY chatbot output cannot substitute for when a security questionnaire or diligence process demands evidence of review; and (5) ongoing monitoring that catches new SDKs/vendors added after the initial pack. Commoditize the first-draft language; productize the scan-classify-monitor desk.

Service Delivery Workflow

  1. NDA/DPA + scoping intake (app/site access, SDK/vendor list, existing policy).
  2. AI scan: extract data flows, SDKs, pixels, geofencing configurations.
  3. AI classify each flow against versioned CHD rule cards (WA/NV/CT/CA).
  4. Deterministic completeness/risk gates; escalate high-risk flows.
  5. AI drafts authorization flow copy, policy sections, DPA checklist.
  6. Privacy operator reviews; outside/partnered counsel signs off.
  7. Deliver pack; log sign-off record for client's own audit trail.
  8. Offer Managed Monitoring for subsequent quarters and new-law triggers.

Operations as Product

  • Structured intake checklist (access, SDK/vendor inventory, existing policy/consent artifacts).
  • Required-evidence list per data-flow classification (source code reference, vendor contract clause, or observed network call).
  • Automated completeness checks and exception queues for unclassified or ambiguous flows.
  • Reviewer assignment by state-law specialty; confidence scoring on every AI classification.
  • Audit trail and version control on every rule card; gold-standard example packs; red-team scans against known-CHD test apps; root-cause review on any counsel-rejected classification.

No-Holes Quality Engine

No pack ships with any unclassified data flow. Every high-risk flow (reproductive/mental-health signal, geofencing, biometric) requires 100% human review before drafting proceeds. Counsel sign-off is mandatory before delivery — no auto-release. Client receives the classification rationale for every flagged item, not just a pass/fail. Quarterly QA audit re-checks a 20% sample of delivered packs against current statute text as laws are amended.

What the Human Expert Actually Does

TaskLicenseMin @ launchMin @ day 90Automation pathQuality riskCannot automateAudit trail
Intake completeness checkNone208Checklist botLowJudging incomplete access grantsIntake log
Classification reviewNone (privacy operator)6025Suggest-only AI + confidence scoringHigh if misclassifiedAmbiguous edge-case judgmentReviewer sign-off record
Counsel sign-offLicensed attorney (JD, privacy-focused)4525Cannot automate — legal judgmentHighFinal legal approvalSigned approval record
Client remediation walkthroughNone3020Recorded explainer + live Q&AMedTrust / technical translationCall notes
Rejected-classification postmortemNone2515Template RCAMedRule-card update judgmentRCA doc

Minimum Viable Offer

CHDClear Exposure Scan (free) → Single-State (WA) Compliance Pack ($4,500–$9,000) for one product. Includes data-flow inventory, SDK/pixel findings, drafted authorization flow and policy section, DPA checklist, and counsel sign-off coordination. Founding-cohort pricing at the low end of the range for the first eight clients.

Fulfillment Process (First 3 Customers)

  1. Manual kickoff call; receive SDK/vendor list and site/app access via secure link.
  2. Founder + contracted privacy operator run scanning tools (open-source network/traffic inspection plus manual SDK manifest review) and classify flows with a frontier LLM against a hand-built rule-card spreadsheet.
  3. Draft authorization copy and policy redlines in Google Docs; route to a partnered outside privacy attorney for sign-off.
  4. Deliver pack as a reviewed PDF + short walkthrough call.
  5. Automate the scan pipeline only after the data-type taxonomy proves stable across 8–10 engagements.

Day-one tools: Google Workspace, a browser-based network-traffic inspector, Airtable, Stripe, a partnered outside counsel relationship (fee-split or referral arrangement), e-signature tool for sign-off records.

Tools and Systems

  • Intake: secure client portal + structured scoping questionnaire.
  • Scanning: static/dynamic SDK and network-traffic inspection tooling.
  • AI: frontier LLM for classification and drafting, with a maintained rule-card knowledge base.
  • Ops: Airtable/Notion (engagement queue, escalations, sign-off tracking).
  • Delivery: reviewed PDF pack + client portal record.
  • Billing: Stripe invoices (pack fee + monitoring subscription).
  • Later: custom SDK-scanning pipeline; automated quarterly re-scan triggers tied to legislative-tracker feeds.

Human-in-the-Loop Quality Control

Privacy operator must review every AI classification before drafting proceeds. Outside/partnered counsel must sign off before any pack is delivered or any authorization flow goes live. Client can veto or request revision on any drafted language. No auto-delivery without a recorded sign-off.

Nonlinear Scaling and Unit Economics

MetricLaunchDay 90Year 1 target
Operator + counsel minutes / pack1609060
Automation %30%55%72%
Packs / operator / week247
Gross margin38%52%60%
Rework rate<15%<8%<5%
Revenue / delivery FTE$150k$260k$380k+

COGS breakdown (steady-state single-state pack @ $6,500): model inference $15–$35; scanning tooling $20; privacy-operator 60 min @ loaded $70/hr ≈ $70; outside-counsel review fee (flat-rate negotiated) ≈ $900–$1,400; QA $40; support $30; payment fees $190 → COGS ≈ $1,265–$1,785 (GM ≈ 73–81% on the pack alone). Blended GM lower once sales/marketing and monitoring-tier support costs are included — target ≥50% blended by day 90 and ≥60% by year one as counsel-review fees are negotiated down with volume and automation share increases.

Funnel assumptions (label Unverified until measured): Scan→Pack 8–15%; Pack→Managed Monitoring 30–40%; CAC payback <3 months on Managed Monitoring.

Distribution Proof Table

ChannelWhy ICP reachableFirst angleConv. assumptionProof sourceMeasurementFollow-up
Privacy/legal LinkedIn outboundGC/Head of Compliance identifiable by title + company category"Is your app's SDK stack MHMDA-exposed?" personalized scan offer3% scanLaw-firm alert publishing volume as proxy for buyer attentionReply→scan rateCalendly walkthrough
Femtech/digital-health founder communities (Slack/Discord, newsletters)Direct ICP densityEducational: "the CHD statute nobody read" post + free scan CTA5% scanFemtech market growth + community activityLink CTR → scan signupsAutomated scan-result email
Outside privacy counsel referral partnershipsCounsel already fields these questions at hourly ratesReverse-referral: "we pre-scan, you review and bill less time"15–20% of referredExisting outside-counsel spend evidenceReferral-code trackingCo-branded pack delivery
SEO / AEO"Is my app subject to Washington My Health My Data Act" search/answer-engine queriesHow-to explainer + free scan CTA2% visit→scanHigh law-firm publishing volume signals search demandGSC + form fillsEmail nurture
Security-questionnaire / diligence moment partnerships (fractional GC networks)Trigger-event alignment"Answer the CHD question on your next SOC 2/diligence checklist"10% of referredDiligence-checklist prevalence (qualitative)Referral trackingExpedited scan SLA
Ad-tech/SDK vendor outboundVendors need to prove downstream compliance to app-publisher customersVendor-side compliance pack offer2% scanMaxwell v. Amazon fact pattern (SDK-embedded tracking)Outreach→scanCase-study follow-up

Sales and Outreach Plan

Three layers: founder-led content teaching the CHD statutory landscape and its litigation risk; warm conversion of free-scan users into paid packs; targeted outbound to companies with visible health-adjacent positioning and identifiable SDK stacks. Offer page: one promise ("Find out if your app is exposed to My Health My Data Act — free scan this week"), one scan CTA, transparent pricing table, and the licensing disclaimer up front.

Founder-Led Content Plan

Teach: what makes data "consumer health data" beyond HIPAA; the opt-in-authorization vs. opt-out-consent distinction; the 1,750-foot geofencing rule; what the Amazon lawsuit actually alleges and why it matters for ordinary consumer apps; myths ("we're not a health company, so this doesn't apply to us"). Avoid generic AI/privacy hype — cite statute sections and the actual complaint.

First 30 Days of Content

  1. 10 posts: (1) What counts as "consumer health data" under WA law, (2) opt-in authorization vs. opt-out consent, (3) the 1,750-ft geofencing rule explained, (4) Maxwell v. Amazon teardown, (5) "we're not a health company" myth-busting, (6) NV SB 370 vs. WA MHMDA differences, (7) CT CTDPA health provisions explainer, (8) CA AB 45 family-planning-center rule, (9) SDK/vendor due-diligence checklist, (10) what a security questionnaire actually asks about CHD.
  2. 3 diagnostic teardowns: anonymized SDK/data-flow scan redlines for a femtech app, a fitness app, and an ad-tech vendor.
  3. 2 lead-magnet angles: free CHD Exposure Scan; "Is Your App CHD-Exposed?" self-assessment checklist PDF.
  4. 1 webinar: "Read the Amazon MHMDA complaint with us — what it means for your SDK stack."
  5. 1 outbound template: personalized scan-findings-preview diagnosis memo.

Lead Magnet and Waitlist Plan

Free CHD Exposure Scan: submit app/site URL and SDK list → receive top-flag summary within 3 business days (no drafted deliverables). Waitlist CTA for Managed Monitoring. Scan captures product category, state-user-base footprint, and whether outside counsel is retained — sales-ready if ≥2 high-risk flows are found and no counsel relationship exists.

Warm GTM Plan

Convert scans with a 30-minute findings review call; founding-cohort pack pricing for the first eight clients; request before/after security-questionnaire-response screenshots as testimonials (with permission). Partner with 3–5 outside privacy attorneys or fractional-GC firms for reciprocal referrals.

Targeted Outbound Plan

Build a prospect list from public femtech/digital-health/wellness startup directories and funding announcements; identify SDK stacks via publicly observable app analysis (no ToS-violating scraping of private systems). First message is a diagnosis offer (a preview of likely exposure) not a generic demo ask.

Answer-Engine / Search Visibility Plan

Publish citation-ready pages answering: "Does my app need to comply with Washington's My Health My Data Act?"; "What is consumer health data under state privacy law?"; "What is the geofencing ban around medical facilities?" Structure with locally-inlined FAQ schema (no external CDN). Aim to be the cited specialist desk in AI-generated answers to these queries.

Pilot Design and Early-Demand-Trap Mitigation

  • Pilot cap: 8 companies / 10 packs.
  • Incentive: founding single-state pack at $4,500 flat (vs. $6,500+ standard) plus a discounted first-quarter Managed Monitoring rate.
  • Learning goals: true classification-review time, counsel-review fee negotiation range, rejected-classification rate, actual willingness-to-pay at proposed price points.
  • Custom-work guardrail: no general privacy-policy rewrites unrelated to CHD; no HIPAA compliance work; no litigation defense work.
  • Early-demand trap: if inbound asks for broad GDPR/CCPA-wide privacy program builds, refuse and keep the wedge narrow to CHD.

Early-Access Feedback Flywheel

Every counsel-rejected or revised classification triggers a root-cause review and a rule-card/prompt update. Product feedback = classification ontology misses or drafting-language gaps; custom work = client-specific negotiation quirks with a particular vendor contract. Corrections become versioned SOP updates. Expand state coverage only after classification accuracy and counsel-review time hit target gates.

Build-Before-Scale Checkpoints

  • After 5 pilots: harden the intake checklist and required-evidence list per data-flow type.
  • After 10 packs: harden the rule-card library, exception queues, and reviewer checklist; lock in at least one reliable outside-counsel review partnership at a negotiated flat fee.
  • After 20 packs: pause new-logo intake until COGS, rework rate, counsel-review turnaround, and cycle time are measured and stable; do not scale by adding operators faster than the automation share improves.

7-Day / 30-Day / 90-Day Launch Plans

7 days: Landing page, NDA/DPA template, WA rule card v0, scanning-tool setup, outreach to 20 femtech/wellness founders, 5 privacy-attorney partnership conversations, first 3 free scans delivered.

30 days: 8 single-state packs sold at founding pricing; first webinar delivered; 2 outside-counsel referral partnerships signed; 10 content pieces published; classification-review time measured.

90 days: Multi-state pack live (NV/CT/CA rule cards built); Managed Monitoring tier live; 20+ packs delivered; blended GM ≥50%; decide on hiring the first dedicated privacy operator.

Metrics and KPIs

  • Scan→pack conversion; pack cycle time; classification accuracy (counsel-accepted rate); counsel-review turnaround time; $ recovered/avoided (qualitative, via reduced outside-counsel hours); operator+counsel minutes/pack; rework %; gross margin; Managed Monitoring attach rate and retention.

Risks and Mitigations

See exhaustive register below. Top risks: mistaken for unauthorized practice of law; counsel-review bottleneck slows delivery; statutory landscape shifts faster than rule cards can be updated; clients treat the pack as a legal guarantee rather than an operational compliance aid; scanning tools miss server-side or first-party data flows.

Exhaustive Risk Register

R1 — Mistaken for unauthorized practice of law
Likelihood: MedImpact: High

Mitigation: Hard disclaimers on every deliverable; mandatory outside-counsel sign-off before delivery; never issue opinions framed as legal advice; require client's own counsel review where no partnered attorney is engaged.

R2 — Outside-counsel review becomes a bottleneck
Likelihood: MedImpact: Med

Mitigation: Negotiate flat-fee, defined-SLA review arrangements with 2–3 partnered attorneys; pre-classify and pre-draft to minimize attorney time to a review-and-approve pass, not a build-from-scratch pass.

R3 — Statutory landscape changes faster than rule cards update
Likelihood: MedImpact: High

Mitigation: Subscribe to legislative trackers (MultiState, Troutman, DLA Piper); quarterly rule-card review cycle; Managed Monitoring clients get proactive re-review triggers on any relevant new law.

R4 — Clients treat the pack as a litigation-proof guarantee
Likelihood: MedImpact: High

Mitigation: Explicit no-guarantee language in every contract and delivered pack; education content sets expectations before sale.

R5 — Scanning tools miss server-side/first-party data flows
Likelihood: MedImpact: High

Mitigation: Supplement automated scanning with a structured engineering-team interview and backend data-flow questionnaire; flag scan-only engagements as limited-scope.

R6 — Misclassification of an ambiguous data flow
Likelihood: MedImpact: High

Mitigation: Mandatory human + counsel review on all ambiguous/high-risk flows; confidence scoring surfaces uncertainty rather than hiding it; RCA on every counsel correction feeds the rule-card library.

R7 — OneTrust or a competitor launches a comparable done-for-you tier
Likelihood: Low-MedImpact: Med

Mitigation: Stay narrow and CHD-specific rather than competing as a general privacy platform; lean on counsel-partnership relationships and precedent-classification library as switching-cost moats.

R8 — PII/PHI-adjacent data mishandling during scanning
Likelihood: LowImpact: High

Mitigation: DPA with every client; minimize retention of any real consumer data encountered; encrypted storage; access logging.

R9 — Low willingness-to-pay at proposed price points
Likelihood: MedImpact: High

Mitigation: Validate pricing in first 8 pilots; free scan lowers funnel friction; kill or reprice if median pack price realized is <60% of target after 10 sales conversations.

R10 — New federal privacy law preempts or supersedes state CHD statutes
Likelihood: LowImpact: Med

Mitigation: Monitor federal privacy legislation; rule-card architecture can absorb a federal layer as an additional rule card rather than requiring a rebuild.

R11 — Buyer confusion with generic "AI privacy consulting"
Likelihood: MedImpact: Med

Mitigation: CHD-specific, statute-cited messaging; lead with the Amazon complaint and specific statutory mechanics, not generic "AI compliance" language.

R12 — Counsel-partner capacity constrains growth
Likelihood: MedImpact: Med

Mitigation: Build a bench of 3–5 partnered attorneys/firms rather than a single dependency; pre-negotiate capacity commitments ahead of pilot scaling.

What Could Kill This

  • Median realized pack price falls well below target after pilot sales conversations, making the model uneconomical at 50%+ GM.
  • Outside-counsel review costs cannot be negotiated down, compressing margin below viability.
  • Regulators or bar associations characterize the classification/drafting service as unauthorized practice of law despite disclaimers and counsel sign-off.
  • Buyers cannot distinguish CHDClear from generic "AI privacy consulting" noise in a crowded content market.
  • Scanning technology limitations (server-side/first-party flows) make the core deliverable materially incomplete without disproportionate manual engineering-interview time.

Go/No-Go Reasoning

Go. Clears buyer, pain, and active-litigation evidence (a filed, precedent-setting class action on the exact SDK/data-flow fact pattern this business addresses), demonstrated existing budget (OneTrust/Osano/TrustArc spend plus outside-counsel hourly spend), a defined and growing statutory footprint (four CHD-specific laws plus 24 states with comprehensive privacy laws), a narrow one-state MVP wedge, fully remote fulfillment, a credible 50%+ gross-margin path once counsel-review fees are negotiated down, a plausible distribution path through legal/privacy-adjacent channels, and confirmed non-duplication against the restored 647-run manifest. The closest alternative candidate (SSA representative-payee/VA-fiduciary accounting) was rejected specifically for semantic proximity to two existing manifest entries — a stronger discipline outcome than forcing a marginal blueprint forward.

Final Recommendation

Build CHDClear as a consumer-health-data-specific compliance desk, launching with a free Exposure Scan and a single-state (Washington) Compliance Pack for femtech, fitness/wellness, and telehealth-adjacent digital products. Cap pilots at 8 companies; secure at least two outside-counsel review partnerships before pilot launch; harden the rule-card library on Washington before expanding to Nevada, Connecticut, and California. Do not expand into general GDPR/CCPA-wide privacy program builds or HIPAA compliance work in year one.

Source List

  1. Goodwin — Washington's My Health My Data Act Comes Into Force
  2. WilmerHale — First Lawsuit Filed Under Washington's My Health My Data Act
  3. Byte Back — First Washington My Health My Data Act Class Action Lawsuit Filed
  4. Ogletree — Location Data as Health Data: Precedent-Setting MHMDA Lawsuit
  5. Paul Hastings — First Class Action Complaint Filed Under MHMDA
  6. McDermott — Nevada and Connecticut Pass Consumer Health Data Laws
  7. Benesch — Nevada Joins Washington With a Consumer Health Data Consent Law
  8. MultiState — All of the Comprehensive Privacy Laws That Take Effect in 2026
  9. Byte Back — U.S. State Privacy Law Landscape Expands to 24 States
  10. Healthcare Dive — Consumer Health Data's Regulatory Patchwork Is Growing
  11. Enzuzo — OneTrust Pricing for Compliance 2026
  12. Privado AI — App Auditor Product Page
  13. Privado AI — G2 Creates Category for Website Privacy Auditing Tools
  14. Market.us — mHealth Apps Statistics 2026
  15. Troutman — Proposed State Privacy Law Update, April 20, 2026
  16. DLA Piper — U.S. Privacy Laws Legislative Update
  17. CRS via Congress.gov — Social Security Administration Representative Payees (rejected-candidate research)
  18. SSA OIG — Allegations of Representative Payees' Misuse of Benefits (rejected-candidate research)
  19. CRS via Congress.gov — The VA Fiduciary Program: An Overview (rejected-candidate research)