Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Oscar may de-identify or anonymize personal information to train, optimize, and enhance AI technology, and may disclose this de-identified information to third-party AI development partners. No specific retention limits, re-identification safeguards, or consent mechanisms are described for this use.
This analysis describes what Oscar Health's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes a use of personal information, including de-identification and third-party disclosure for AI development, that is operationally distinct from standard service delivery purposes; the absence of described safeguards against re-identification or limits on third-party AI partner use creates a compliance consideration under FTC guidance on deidentification and emerging state AI governance frameworks.
Interpretive note: The provision does not specify the deidentification methodology, retention limits for AI vendors, or re-identification safeguards, leaving the operational scope of third-party AI partner access uncertain.
Under this provision, Oscar may process personal information to train internal AI systems and may disclose de-identified versions of that information to third-party AI development vendors. The policy does not describe an opt-out mechanism specific to AI training use, and the general terms do not specify what re-identification protections apply once data is disclosed to third-party AI partners.
Cross-platform context
See how other platforms handle AI Training Use of Personal Information and similar clauses.
Compare across platforms →Monitoring
Oscar Health has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may use Artificial Intelligence (AI) Technology when processing your Personal Information as described above. This may also involve de-identifying or anonymizing your Personal Information to train, optimize, ground or otherwise enhance our AI Technology, including disclosure to third parties who help us develop or provide the systems to enable the AI Technology.Excerpt from Oscar Health's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates FTC guidance on deidentification standards and the FTC Act's prohibition on unfair or deceptive practices, particularly where de-identification claims may not meet the standard required to remove regulatory obligations. State AI governance requirements are emerging in Colorado and other jurisdictions and may require evaluation as they develop. HIPAA de-identification standards under the Safe Harbor or Expert Determination methods are relevant if any de-identified data originates from PHI, though the policy states HIPAA data is governed separately. 2) GOVERNANCE EXPOSURE: Medium. The provision's authorization of third-party disclosure for AI development without specifying re-identification safeguards or data retention limits for AI vendors creates a compliance gap that may need to be addressed through vendor contracts and data processing agreements. The FTC has issued guidance indicating that deidentification must be robust and that downstream use restrictions must be contractually enforced. 3) JURISDICTION FLAGS: California's CPRA and Colorado's Privacy Act both address automated processing and profiling; while the policy states Oscar does not engage in impactful profiling of online users, the AI training disclosure may require evaluation under those frameworks depending on the nature of the AI systems being trained. EU/EEA users, if any, would trigger GDPR considerations regarding automated processing and consent for secondary uses. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify that third-party AI development partners operate under data processing agreements that include use limitations, re-identification prohibitions, and data deletion obligations upon project completion. The policy's general statement that service providers are required by contract to protect personal information should be confirmed as applicable to AI development vendors specifically. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the de-identification methodology used prior to AI training meets applicable standards, including FTC guidance and HIPAA Safe Harbor requirements where health-adjacent data is involved. Data mapping should document the specific categories of personal information used for AI training and the identity of third-party AI partners. A review of consent mechanisms should confirm whether the current privacy notice constitutes adequate disclosure of AI training use under applicable state frameworks.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision authorizes a use of personal information, including de-identification and third-party disclosure for AI development, that is operationally distinct from standard service delivery purposes; the absence of described safeguards against re-identification or limits on third-party AI partner use creates a compliance consideration under FTC guidance on deidentification and emerging state AI governance frameworks.
Under this provision, Oscar may process personal information to train internal AI systems and may disclose de-identified versions of that information to third-party AI development vendors. The policy does not describe an opt-out mechanism specific to AI training use, and the general terms do not specify what re-identification protections apply once data is disclosed to third-party AI partners.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Oscar Health.