The Data Inversion: Who Owns the Story of Your Health

Right now, nearly a billion people talk to AI every week [1]. More than 230 million of them are giving away the most valuable asset they own: the story of their health [2].

You say it; they keep it.

Today’s AI traps that context behind proprietary walls. HIPAA stops at the covered entity; once health data reaches a consumer app, the HIPAA Rules no longer protect it [3]. OpenAI’s own CEO concedes the conversations carry no legal confidentiality [4].

EverBetter changes the rules. Through our Life Data Vault, we return total sovereignty to the human who lived it. One encrypted vault. Universal portability. Any AI, anytime. This isn’t just a data platform; it’s the infrastructure for human care.

The industry calls its answer “data sovereignty,” the most laundered phrase in technology. This is the first article in a series on sovereignty. I start with the definition. Then I test the imitations against one question: who owns the story?

§ 1 The inversion.

SaaS brings your story to the application. Solid brings the application to your story.

SaaS moves your story to the application. You sign up; the vendor provisions a database; your history lives inside its schema, its tenancy, and its terms of service. Every new app starts a new copy. Every copy is a fragment. None of them is yours.

Solid inverts that arrow. A person stores data in a Pod that the person controls, and the person decides which people and applications may access it [5]. The Pod can sit with any provider or on the person’s own server [6]. The application becomes a guest. The person becomes the host.

I call this the data inversion. It is the architecture beneath the Life Data Vault. The story stays in one place, owned by the human who lived it. The AI comes to the story, reads what the person grants, and leaves when the grant ends. That is what “any AI, anytime” means in protocol terms.

Real sovereignty is the inversion, enforced by protocol. It must pass three tests:

  1. Authority. The person, not the vendor, decides who reads the story.
  2. Revocability. Every grant is scoped, revocable, and auditable.
  3. Survivability. The story outlives every application that touched it.

§ 2 The imitations.

Each imitation moves the walls. None returns the story.

Residency. The cloud-infrastructure market sells sovereignty as geography: your story sits in a rack inside your jurisdiction. The vendor still holds the keys. The application still mediates every read. Residency moves the wall to a friendlier country. It fails the authority test.

Runtime locality. The local-first AI movement sells sovereignty as compute on your hardware: your agent, your disk, your weights. The story stays home, locked to one agent on one device. It defines no way for your clinician’s AI to read it with your permission, on terms you revoke. Unstructured text on a laptop is private; it is not a portable record. Runtime locality fails the revocability and survivability tests.

The portal. Healthcare sells sovereignty as access: a patient portal, a download button, an export file. The patient views a chapter. The custodian keeps the book, the schema, and the decision about who else reads it. Every clinic hands the patient a different portal and a different fragment. The portal fails the authority test.

Each attempt is real work. Each is incomplete. Sovereignty is not where the bytes sit; it is who decides who reads the story.

§ 3 HIPAA is about portability.

HIPAA governs the custodian. Sovereignty governs the owner.

Healthcare leaders treat HIPAA as a privacy law. Read the statute. The “P” stands for portability. Congress enacted Public Law 104-191 in 1996 to improve the portability and continuity of health insurance coverage and to simplify the administration of health insurance [7].

The Privacy Rule came later, under that administrative-simplification mandate. HHS states its goal plainly: protect health information “while allowing the flow of health information needed to provide and promote high quality health care” [8]. The rule permits covered entities to use and disclose protected health information for treatment, payment, and health care operations without the patient’s authorization [9]. Inside HIPAA, the custodian holds the story, and the law decides who else may read it.

HIPAA does give the patient one lever. The right of access entitles the patient to a copy of the record [10], and a covered entity may not refuse to send that copy to an app the patient chooses over concerns about how the app will use it [11]. That lever brings the story home. Each copy the patient requests can land in the patient’s own vault, where the patient decides who reads it next.

That is the delineation. HIPAA is a compliance regime for custodians; it regulates how the holder moves the story. Sovereignty is an ownership architecture; it determines who the holder is. HIPAA compliance is necessary. It is not sovereignty.

§ 4 The infrastructure for human care.

Own your story. Take it anywhere.

The data inversion is the definition. Residency, runtime locality, and the portal move the walls. HIPAA is the floor, not the ceiling.

A billion people already hand their story to AI. The story belongs in one vault the person owns, readable by the clinicians and agents the person delegates, on terms the person sets. When a better AI arrives, the person grants it access. When a clinic closes, the story stays. When a vendor fails, the story survives.

One encrypted vault. Universal portability. Any AI, anytime. That is the infrastructure for human care, and it is what we are building at EverBetter.

The next articles in this series test each imitation in depth.

Buzz O’Neil is CTO of EverBetter, which builds EHR and PHR products on the Solid protocol.

References
[1] “ChatGPT,” Wikipedia (reporting 900 million weekly active users, Feb. 2026). [Online]. Available: https://en.wikipedia.org/wiki/ChatGPT
[2] OpenAI, “Introducing ChatGPT Health,” Jan. 7, 2026. [Online]. Available: https://openai.com/index/introducing-chatgpt-health/
[3] U.S. Dept. of Health and Human Services, “Does a HIPAA covered entity bear liability for an app’s use or disclosure of ePHI?” FAQ 3009. [Online]. Available: https://www.hhs.gov/hipaa/for-professionals/faq/3009/does-a-hipaa-covered-entity-bear-liability.html
[4] S. Perez, “Sam Altman warns there’s no legal confidentiality when using ChatGPT as a therapist,” TechCrunch, Jul. 25, 2025. [Online]. Available: https://finance.yahoo.com/news/sam-altman-warns-no-legal-173329143.html
[5] Solid Project, “About Solid.” [Online]. Available: https://solidproject.org/about
[6] Solid Project, “Solid for Users.” [Online]. Available: https://solidproject.org/for_users
[7] Health Insurance Portability and Accountability Act of 1996, Pub. L. 104-191, 110 Stat. 1936, Aug. 21, 1996. [Online]. Available: https://www.govinfo.gov/app/details/PLAW-104publ191
[8] U.S. Dept. of Health and Human Services, “Summary of the HIPAA Privacy Rule.” [Online]. Available: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
[9] U.S. Dept. of Health and Human Services, “Uses and Disclosures for Treatment, Payment, and Health Care Operations.” [Online]. Available: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/disclosures-treatment-payment-health-care-operations/index.html
[10] U.S. Dept. of Health and Human Services, “Individuals’ Right under HIPAA to Access their Health Information 45 CFR § 164.524.” [Online]. Available: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html
[11] U.S. Dept. of Health and Human Services, “Can a covered entity refuse to disclose ePHI to an app chosen by an individual because of concerns about how the app will use or disclose the ePHI it receives?” FAQ 3012. [Online]. Available: https://www.hhs.gov/hipaa/for-professionals/faq/3012/can-a-covered-entity-refuse-to-disclose-ephi.html

Leave a Comment