Chinese Hospitals Are Selling Patient Data to AI Companies and Regulators Are Struggling to Keep Up

Chinese hospitals are selling patient data to AI companies, and the practice has grown significantly as the country’s AI healthcare boom has created intense demand for large, high-quality medical datasets. A report published by Caixin and distributed through Nikkei Asia documents how hospitals across China are entering into commercial arrangements with AI developers that involve the transfer of patient records, imaging data, and clinical notes, often without meaningful patient consent and in ways that may violate China’s own data protection laws.

The practice is driven by a combination of financial pressure and regulatory ambiguity. Chinese hospitals, particularly at the county and district level, face chronic underfunding and are under pressure from local governments to contribute to the national AI strategy. Selling data to AI companies offers a revenue stream that is difficult to obtain through conventional means. At the same time, China’s data protection framework, which includes the Personal Information Protection Law enacted in 2021 and the Data Security Law enacted the same year, contains provisions that should, in principle, restrict the commercial transfer of sensitive personal data without explicit consent.

How the Transactions Work

The Caixin investigation found that the arrangements take several forms. Some hospitals sell de-identified datasets directly to AI companies, arguing that removing names and identification numbers satisfies the legal requirement for anonymization. Others enter into research partnerships with AI developers that involve data sharing under the guise of academic collaboration, which may qualify for different regulatory treatment than commercial transactions. In some cases, hospital administrators have established separate data companies that act as intermediaries, creating a layer of corporate distance between the hospital and the AI buyer.

The data being sold includes radiology images, pathology reports, electronic health records, and genomic data. These are among the most sensitive categories of personal information, and their commercial value to AI developers is high: training a medical AI model requires large volumes of labeled clinical data, and the quality of the labels, provided by clinicians who understand the medical context, is a significant determinant of model performance.

The Caixin report found that prices for medical datasets vary widely depending on the type of data, the quality of the labeling, and the exclusivity of the arrangement. Radiology datasets with expert annotations can command significant premiums, while raw electronic health records with minimal labeling are cheaper but require more processing before they can be used for model training.

The Regulatory Gap

China’s data protection framework is, on paper, among the most comprehensive in the world. The Personal Information Protection Law requires explicit consent for the collection and processing of sensitive personal information, including health data. The Data Security Law establishes a tiered system of data classification and requires special handling for data that could affect national security or public interests. The Cybersecurity Law, enacted in 2017, requires that personal information collected within China be stored domestically.

In practice, enforcement of these rules in the healthcare sector has been inconsistent. The National Health Commission, which oversees China’s hospital system, has issued guidelines on health data governance but lacks the investigative capacity to audit the data practices of the country’s tens of thousands of hospitals. The Cyberspace Administration of China, which is the primary enforcement body for data protection, has focused its enforcement actions primarily on internet platforms rather than healthcare institutions.

(Related: China Opens Its First AI Hospital in Hainan and Redefines What a Hospital Is)

The result is a regulatory gap that AI companies and hospital administrators have been able to exploit. The Caixin report notes that some hospitals have sought legal opinions confirming that their data-sharing arrangements comply with existing law, but that the opinions are often based on interpretations of the law that have not been tested in court or endorsed by regulators.

The AI Healthcare Opportunity and Its Costs

The demand for Chinese medical data is driven by the scale of China’s healthcare system and the quality of its clinical records. China has the world’s largest population of patients with certain conditions, including diabetes, cardiovascular disease, and certain cancers, and its hospitals generate enormous volumes of clinical data every year. For AI developers building diagnostic tools, treatment recommendation systems, and drug discovery platforms, access to this data is a significant competitive advantage.

China has made AI in healthcare a national priority. The National Health Commission’s 2023 action plan for AI in medicine called for the development of AI diagnostic tools across 15 clinical specialties by 2025, and the government has provided funding and regulatory support for AI healthcare companies. ByteDance, Alibaba Health, and Tencent’s medical AI division are all active in the space, as are dozens of specialized startups.

(Related: ByteDance Is Behind China’s First AI-Native Hospital — 6 Billion RMB, 800 Beds, and No Human Bottlenecks)

The tension between the national AI strategy and the data protection framework is not unique to China, similar debates are playing out in the European Union and the United States, but the scale of the Chinese healthcare system and the pace of AI adoption make the stakes particularly high. If the current practice of informal data monetization continues without regulatory intervention, China’s AI healthcare companies will have access to training datasets that are unmatched anywhere in the world. The cost will be borne by patients who have no meaningful ability to consent to or opt out of the commercial use of their most sensitive personal information.