A $450 Million Bet on Preventive Care — and the Health Data It Generates
Function Health has secured $450 million in funding from General Catalyst in a landmark investment round that positions the US-based preventive care startup as one of the most heavily backed health technology companies of its era. The company's core proposition is straightforward but ambitious: running comprehensive health testing and data analysis on individuals before they fall sick is ultimately cheaper — and more effective — than treating illness after the fact. But for privacy professionals, IT decision makers, and policy experts tracking the intersection of health technology and digital rights, the more pressing question is not whether preventive care works. It is who owns the data it generates, and how securely it is handled.
More than 100 million Americans currently lack a primary care doctor, according to reporting from Tech Funding News. For those who do have one, the average appointment lasts just a few minutes — barely enough time to review symptoms, let alone run the kind of comprehensive biomarker panels that Function Health offers its members. The company aims to fill that gap at scale, deploying AI-driven analysis across hundreds of lab tests per user. The result is a vast and deeply personal dataset covering everything from hormonal profiles to cardiovascular risk markers. And that dataset, in the age of GDPR and growing global scrutiny over health data, is as valuable as it is sensitive.

Why Preventive Health Care Is Actually a Data Sovereignty Issue
The business model of companies like Function Health rests on longitudinal data collection — repeated measurements over time that build a richly detailed picture of an individual's biology. This is not incidental data collection; it is the product itself. Users pay for insight derived from their own biomarkers, and in turn, the company accumulates one of the most sensitive categories of personal data recognised under privacy law.
Under the European Union's General Data Protection Regulation (GDPR), health data is classified as a "special category" of personal data under Article 9 — meaning it attracts the highest level of regulatory protection. Processing it requires explicit consent, and even then, controllers must demonstrate a lawful basis and implement robust technical safeguards. For European users or EU citizens accessing US-based health platforms, the question of where that data is stored and processed is not academic. Cross-border health data transfers remain one of the most contested areas of international data law, as the European Data Protection Board has made clear in numerous guidance documents.
The Schrems II ruling by the Court of Justice of the European Union already invalidated one major transatlantic data transfer framework, and while the EU-US Data Privacy Framework now provides a successor mechanism, it remains legally contested. Privacy advocates and policy professionals working at the intersection of digital rights and health technology should pay close attention to how companies like Function Health structure their data governance — particularly as they scale internationally.
"Health data is the most intimate data there is. When it is processed at scale by AI systems, the risk surface is not just technical — it is political, ethical, and jurisdictional all at once."
— Digital health privacy analyst, European Data Protection perspectiveGeneral Catalyst and the Race to Build Health AI Infrastructure
General Catalyst is no stranger to large, infrastructure-level bets. The venture firm has built a reputation for identifying category-defining companies early and backing them aggressively through growth stages. Its investment in Function Health is consistent with a broader thesis that preventive and personalised medicine, powered by AI-driven diagnostics, will restructure healthcare economics over the coming decade.
According to research published by McKinsey & Company on the future of healthcare, preventive interventions can reduce hospitalisation costs significantly, particularly for chronic conditions such as cardiovascular disease and type 2 diabetes. The economic logic is compelling: catching a developing condition through a blood biomarker panel costs a fraction of the acute care required once that condition progresses. Function Health's pitch to General Catalyst was, in essence, a data-driven argument — that better information earlier produces better and cheaper outcomes downstream.
But the infrastructure required to deliver on that promise is itself data infrastructure. Function Health's platform is, at its core, a health data aggregation and analysis engine. As it scales — particularly if it moves into international markets — it will need to make consequential decisions about cloud providers, data residency, encryption standards, and audit trails. These are precisely the kinds of decisions that determine whether a health tech company is trustworthy for privacy-conscious users, or a liability waiting to materialise.
What Mass Health Data Collection Means for Digital Privacy at Scale
The privacy implications of large-scale preventive health testing extend well beyond individual consent checkboxes. When a platform holds detailed biomarker data on millions of users, the aggregate dataset becomes extraordinarily valuable — not just for delivering health insights, but for insurance pricing, pharmaceutical research, employer wellness programmes, and law enforcement requests. The history of health data monetisation is not encouraging.
Wired has extensively documented cases where consumer health apps and testing services have shared or sold user data in ways that users did not anticipate, even when terms of service technically permitted such use. Google's acquisition of Fitbit drew sustained regulatory scrutiny from the European Commission precisely because of concerns about health data being used to inform advertising profiles. The lesson for privacy professionals evaluating any health tech platform — including Function Health — is that the data governance model matters as much as the clinical proposition.
Key questions that IT decision makers and privacy officers should ask when evaluating any preventive health platform include: Where is data stored, and in which jurisdiction? Who are the sub-processors with access to user data? Is health data used to train AI models, and if so, can users opt out? What happens to stored health data if the company is acquired? These are not hypothetical concerns — they are due diligence essentials in a sector where GDPR fines for mishandling health data can reach four percent of global annual turnover.
| Health Data Risk Factor | GDPR Relevance | Mitigation Approach |
|---|---|---|
| Cross-border data transfers | Schrems II / EU-US Data Privacy Framework | Data residency in EU, Standard Contractual Clauses |
| AI model training on health data | Article 9 consent requirements | Explicit opt-in, anonymisation, data minimisation |
| Third-party sub-processor access | Controller-processor agreements (Article 28) | Contractual audit rights, vendor vetting |
| Data retention after account closure | Right to erasure (Article 17) | Clear deletion policy, technical deletion capability |
| Company acquisition / change of ownership | Legitimate interest reassessment required | Contractual user notification obligations |
European Digital Sovereignty and the Health Tech Gap
Europe has no equivalent to Function Health at scale. This is partly a consequence of regulatory caution — GDPR and national health data laws make it considerably harder to build and monetise a large health data platform in the EU — and partly a consequence of fragmented healthcare systems across member states. But the absence of a European preventive health tech champion is itself a digital sovereignty concern. If European citizens are drawn to US-based platforms for comprehensive health insights, their most intimate data flows outside EU jurisdiction by default.
The European Health Data Space (EHDS), a regulatory framework proposed by the European Commission, aims to address this gap by creating a governed, interoperable ecosystem for health data sharing across the EU. According to the European Commission's digital health policy documentation, the EHDS would give citizens clearer rights over their health data while enabling researchers and health authorities to access anonymised data for public benefit purposes. But the EHDS remains in the implementation phase, and in the interim, US-based platforms with strong AI capabilities continue to set the standard for what comprehensive preventive health testing looks like.
For entrepreneurs and small business owners building in the European health tech space, Function Health's $450 million raise signals both an opportunity and a warning. The opportunity is that the market has validated preventive health data at massive scale. The warning is that competing on privacy — offering genuine data sovereignty, EU-based infrastructure, open-source components, and GDPR-native architecture — may be the only viable differentiation strategy against a well-capitalised US incumbent.

How AI Regulation Will Shape the Future of Preventive Health Platforms
Function Health's platform is explicitly AI-driven — using machine learning to interpret complex panels of biomarker data and surface clinically relevant patterns that a human physician reviewing results sequentially might miss. This positions it squarely within the scope of the EU AI Act, which classifies AI systems used in health diagnostics as high-risk applications requiring conformity assessments, transparency obligations, and human oversight mechanisms.
For developers and IT architects building or evaluating health AI systems, the EU AI Act's requirements are not merely compliance overhead — they are a design philosophy. High-risk AI systems must maintain detailed logs, support meaningful human review of outputs, and be built on datasets that are demonstrably representative and free of discriminatory bias. These requirements, combined with GDPR's health data protections, mean that any AI-powered health platform targeting EU users faces a substantially more demanding technical and governance environment than its US domestic counterpart.
Research published through the Future of Life Institute and academic health informatics journals has noted that AI diagnostic tools trained primarily on US population data may exhibit systematic biases when applied to demographically different European populations. This is not a theoretical concern — it has implications for clinical validity and regulatory approval. European health tech developers building in this space have both a compliance imperative and a scientific one to ensure their training data reflects the populations they serve.