Three things happened in the last two weeks, and in every one of them somebody sat down and read a file. A federal agency built a lawsuit out of what a company’s website had quietly recorded. An accreditor handed a health system a certificate after reading four years of its records. Europe made a stack of documents a condition of selling clinical AI. Not one of them opened up an AI tool and inspected how it worked. If you are a coach or a solo practitioner, that is better news than it sounds, and this issue is about why.
Signal 1
The FTC Sued a Telehealth Company Over What Its Website Quietly Recorded About People (July 29, 2026)
On July 29, 2026 the Federal Trade Commission, joined by Utah and California through Los Angeles County Counsel, filed a complaint in federal court against Hims & Hers. The complaint alleges the company shared people’s sensitive health information with advertising platforms including Meta and Snap, both by handing over customer lists and through tracking technologies that automatically reported what visitors did on the site, all while promising to keep that information private. It further alleges that most people were charged and enrolled in a recurring prescription subscription shortly after submitting an intake form, without the consultation the advertising promised, and that the cancel button sat behind several steps. The claims run under the FTC Act and the Restore Online Shoppers’ Confidence Act, plus Utah and California consumer protection law. The case will be decided by the court.
What this means for you
Read this complaint by its evidence rather than its accusations. Almost none of it depends on what anyone at the company meant or believed. It rests on things a regulator can pull and a court can read: which tracking events fired on which page, which lists went to which platform, and how many minutes passed between somebody filling in an intake form and their card being charged. Timestamps, not testimony. Issue 019 argued that the new rules point at the person deploying the tool rather than at the software. This is what that pointing looks like when it is done with server logs, and it is worth noticing that AI never has to enter the argument for the case to land. The mechanism here is ordinary tracking code, which sits on far more coaching websites than any clinical AI ever will. You do not need a clinic or a medical record system for this one to reach you. If you have a booking page, an intake form, or a symptom quiz, your website is writing a record about your clients right now, and you almost certainly did not choose most of what it writes. So get the list of every third-party script your booking and intake pages load. Ask whoever built your site, or look in your platform’s settings under tracking, analytics, or integrations. Then check whether any of them load on a page whose name or address includes a condition. A tracking pixel on a page called thyroid consultation reports the condition on its own, before your client types a single word. Picture the client who filled in your intake form last Tuesday. She told you about her thyroid. She did not decide to tell anyone else.
Signal 2
A Health System Passed the First AI Governance Certification in Three Weeks, After Four Years of Keeping Records (July 29, 2026)
On July 29, 2026 Hackensack Meridian Health announced it is the first health system in the country to earn the Joint Commission’s Responsible Use of AI in Healthcare certification, which the Joint Commission built on the governance playbooks it developed with the Coalition for Health AI. The certification examines no AI product. It examines the organization across five domains: governance, risk and bias reduction, effective data management, monitoring and validating safety and effectiveness, and education and training. Healthcare Dive reported on August 4 that the certification process itself took three weeks, while the internal governance framework being certified had been in use for four years, according to Dr. Lauren Koniaris, the system’s chief medical informatics officer.
What this means for you
Read the ratio, because the ratio is the whole story. Three weeks of review against four years of practice. The certification did not create governance at that health system. It found governance that was already sitting there and put a name on it. That tells you what a review of this kind actually measures, which is whether your ordinary record of decisions holds together when a stranger reads it back to you, or when a client does, and nobody can produce four years of that on demand. Issue 012 covered this certification when it launched and argued that the thing being graded is your governance, not the AI. This is the first case that confirms it. Be clear-eyed about the fit, though. The certification is priced and scoped for organizations, it is sold by company type and size, and a health coach or a two-person practice is not its customer and never will be. What is portable is the list of five domains, because that list is quietly becoming the working definition of adequate, and definitions travel a great deal further than the programs that produce them. Write the five domains down the left side of one page. Next to each, write the name of the document you would hand someone who asked to see it today. Some lines will have a real answer. The blank ones are your work list, in priority order, chosen by somebody else’s audit instead of your own guessing. There is a client-facing version of this too. No client is ever going to ask to see your governance page. But sooner or later a client will ask whether you use AI on their notes, and the answer you give is either backed by something you wrote down or it is improvised on the spot.
Signal 3
Europe Made Documentation a Condition of Selling Clinical AI, Which Hands You Something to Ask For (August 2, 2026)
On August 2, 2026 the bulk of the European Union’s AI Act obligations for high-risk AI systems came into application, a category that covers most clinical AI. They include risk management, technical documentation, record keeping, transparency and instructions for use, a documented design for human oversight, and conformity assessment. The obligations reach deployers, meaning the organizations using these systems, and not only the companies building them. AI already regulated as a medical device under the EU’s device and diagnostics rules, where a third-party assessment applies, gets an extended transition running to August 2027.
What this means for you
Read this as a supply-side event rather than a compliance event. No solo practice in the United States is regulated by the AI Act, and nobody is coming to inspect your files from Brussels. What changed is upstream. A vendor selling a high-risk system into Europe now has to produce instructions for use, a written description of how human oversight is supposed to work, and a record of how the system performs. Documents that are required to exist are documents that can be requested. That is the practical consequence for a practitioner who has never had anything solid to point at when asking a vendor a hard question. Issue 016 covered the first patient-facing generative AI device the FDA cleared, and the reason it passed was that its documentation showed the language model was not permitted to decide anything on its own. That was one review of one product. This turns that class of documentation into a routine condition of sale for an entire category, which is a different thing altogether. So pick the one AI tool that touches your clients most, whether that is your scheduler, your note-taker, or the assistant inside your telehealth platform, and email the company two questions. Do you have instructions for use, and do you have a written description of how a human is meant to check this. Their answer tells you something. So does their silence. Whatever comes back is also what you can honestly tell a client who asks where their information goes.
The Pattern
One object, three faces. A regulator read records to build a case against a company. An accreditor read records to hand a health system a credential. A lawmaker made records a condition of being allowed to sell. Not one of those three examined an AI tool, and all three examined a record about an AI tool. That shift is worth naming plainly, because for two years the live question in this field was who is responsible when AI gets something wrong. Issue 019 covered the answer arriving from three directions at once, and it was the person holding the credential. That question is settled enough to stop asking. The question now taking shape is narrower and far more useful to you, which is what counts as proof that you were careful. Notice the direction of travel. Proof of care is becoming documentary, and a document is far easier to accumulate than to manufacture. That audit took three weeks because four years were already behind it. Nobody can go back and create those four years, which means the only thing separating a coach with a defensible record from a coach without one is the date they started keeping it. Your clients are not going to audit you. But the standard being set around you right now is the one they will eventually assume you already meet.
One Thing You Can Do This Week
Open a blank page and put today’s date at the top. Four headings. Tools: what AI you use and what you use it for, including the ones you never chose, like the summarizer inside your scheduler or the transcription running in your video calls. Checks: what you verify before anything reaches a client, and how you would explain that check to the client if she asked you to. Limits: what you have decided this tool does not get to do. Review: when you will look at this page again, and who else sees it. Fill in what you know and leave the gaps visibly blank. A dated page with honest blanks on it is governance. An undated page claiming everything is covered is not. Twenty minutes, and your four years start today rather than the week somebody asks.