Pediatric health data governance: what is different about consent for minors
Photo by Ritesh Thakur on Unsplash
insight

Pediatric health data governance: what is different about consent for minors

By Jason Alan Snyder·April 23, 2026

Children cannot consent for themselves, and their parents cannot consent forever. Pediatric health data governance sits in a legal and ethical gap that most health systems, AI developers, and researchers fail to address. The consequences show up in broken consent chains, unusable training data, and adolescents who avoid care entirely.

A 12-year-old walks into a pediatrician's office. The clinician hands the child a consent form. The parent, sitting three feet away, wonders why their kid is being asked to sign anything. This scene plays out thousands of times a day across the United States, and almost nobody involved fully understands the legal and ethical framework behind it.

Pediatric health data governance is not a smaller version of adult data governance. It is a fundamentally different problem. The data subject cannot legally consent. The person who can consent today may lose that authority tomorrow. And the data itself will outlive the governance framework that authorized its collection.

Why did my pediatrician have my 12-year-old consent to records?

Many parents encounter this for the first time and assume it is a mistake. It is not. Federal and state laws create a patchwork of situations where minors can consent to their own treatment and, by extension, to the records generated by that treatment.

Under HIPAA, a minor who legally consents to care becomes the individual who controls access to those records. Most states allow minors to consent to treatment for reproductive health, substance use, and mental health services. Some states set this threshold at 12, others at 14. A few have no minimum age for specific categories of care.

The pediatrician who asks a 12-year-old to consent to records is often following state law. The complexity is that the same child may be unable to consent to a flu shot record but fully authorized to consent to a behavioral health record. Two records, same patient, same visit, different consent authorities.

The 3 C's of consent

Consent frameworks in pediatric care rest on three requirements, often called the 3 C's: capacity, competence, and voluntariness.

Capacity refers to the cognitive ability to understand what is being agreed to. Competence is the legal standing to make the decision. Voluntariness means the decision is free from coercion. Adults are presumed to have all three. Children are presumed to lack at least one.

This is where pediatric data governance fractures. A 15-year-old may have the capacity to understand a consent form but lack the legal competence to sign it for general medical records. That same teenager may have full legal competence to consent to a mental health visit in one state and none in the state next door. The 3 C's are not fixed attributes. They shift by age, geography, and care type.

What age can a child consent to their data being processed?

There is no single answer. Under COPPA (Children's Online Privacy Protection Act), the threshold is 13 for online data collection. Under GDPR, member states can set the age for data processing consent anywhere between 13 and 16; most choose 16. HIPAA ties data consent to treatment consent, which varies by state and care category.

A recent MedPageToday report found that a third of states mandate caregiver consent for mental health treatment for teens, and those same states show measurably lower use of depression treatments among adolescents. The consent structure does not just govern data. It shapes whether minors receive care at all.

This means any organization building a pediatric health data trust must map consent authority across at least three legal frameworks (federal, state, and care-type-specific) before a single record can be scored as trustworthy.

How assent differs from informed consent in research on children

Research introduces another layer. Informed consent requires a legally authorized individual to agree to participation. For minors, that is typically a parent or guardian. Assent is a parallel process: the child agrees to participate at a level appropriate to their understanding.

Assent is not consent. It does not carry legal weight on its own. But the Common Rule (45 CFR 46 Subpart D) requires institutional review boards to obtain assent from children capable of providing it, unless the research offers direct therapeutic benefit that is only available through participation.

The practical problem is that assent is rarely tracked as a discrete data element. When a child's data enters a research dataset, the record may show parental consent but contain no structured field for assent status. This gap makes downstream use of pediatric research data a governance liability. The Texas case reported by MedPageToday, where a physician was accused of illegally accessing children's health records, illustrates what happens when access controls and consent documentation fail.

The transition problem nobody solves

A child becomes an adult. The consent authority transfers from parent to patient. In theory, this happens on the 18th birthday. In practice, it happens unevenly and often not at all.

EHR systems rarely trigger a consent re-authorization at age 18. Records collected under parental consent continue to be governed by that original authorization unless someone actively updates it. For data used in AI model training, this creates a specific risk: a model trained on pediatric records authorized by parents may continue to use those records after the patient reaches adulthood, without the now-adult patient ever having consented.

SuperTruth's Data Trust Index addresses this directly. The DTI scores every record across 8 dimensions, and the Consent dimension (weighted at 20% of the total score) evaluates whether authorization is current, whether the consenting party had legal standing at the time of collection, and whether a transition event has invalidated the original consent. A record with expired or ambiguous consent authority scores lower, flagging it before it enters any AI training pipeline or research dataset.

Key statistics

Legal frameworks governing pediatric data consent by minimum age threshold
Legal frameworks governing pediatric data consent by minimum age threshold

Pediatric health data consent involves numbers that most organizations have never tracked.

  • 33% of U.S. states require parental consent for adolescent mental health treatment, correlating with lower utilization of depression therapies among teens.
  • COPPA sets 13 as the minimum age for children to consent to online data collection; GDPR allows member states to set the threshold between 13 and 16.
  • 20% of the DTI total score comes from the Consent dimension, which evaluates legal standing of the consenting party, recency of authorization, and transition events.
  • In SuperTruth's work with imaware, standardizing 105,000 diagnostic records reduced processing time from 3 weeks to 2 hours, a 95% reduction. Pediatric records with consent ambiguity were among the most time-consuming to resolve manually.
  • At least 3 overlapping legal frameworks (HIPAA, state minor consent laws, and COPPA or GDPR) must be reconciled before any pediatric record can be classified as governance-ready.
  • What a scored approach to pediatric consent looks like

    DTI scoring dimensions and their weights
    DTI scoring dimensions and their weights

    Most organizations treat consent as binary: you have it or you do not. Pediatric data makes that model collapse. Consent authority changes with age, state, care type, and legal context. A binary flag cannot represent this.

    ConsentOS, SuperTruth's consent governance product, tracks consent as a scored, time-aware attribute. Each record carries metadata about who consented, under what legal authority, when that authority expires, and whether a transition event (turning 18, moving states, changing guardianship) has occurred. When the DTI Engine scores the record, it factors all of this into the Consent dimension.

    The result is not just compliance documentation. It is a machine-readable consent state that downstream systems, AI training pipelines, and research platforms can query before using a record. Pediatric records that score below threshold on Consent are automatically excluded from training datasets, not deleted, but held until governance is resolved.

    The cost of getting this wrong

    Pediatric data governance failures are not hypothetical. The Texas case involving illegal access to children's health records resulted in federal charges. States with restrictive adolescent consent laws are measurably reducing access to mental health care. And AI models trained on pediatric data with unresolved consent chains face regulatory exposure under both FDA guidance on AI/ML-based devices and emerging state data privacy laws.

    The question is not whether your organization handles pediatric data. If you operate in healthcare, you do. The question is whether your governance framework accounts for the consent complexity that makes pediatric data fundamentally different from everything else in your system.

    To build a pediatric health data trust that holds up to regulatory scrutiny and earns the trust of families, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140. SuperTruth scores every record before it enters your pipeline, including the ones where consent is the hardest problem in the dataset.

    Further reading:

  • DTI Engine
  • Health systems solution
  • Why consent governance fails in healthcare data and what fixes it
  • The HIPAA problem health AI companies are ignoring: patient consent does not cover model training
  • The eight dimensions of health data trust: a practical guide
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    The FICO score for health data.

    8 dimensions. 0–100. Travels with every record permanently.

    See the DTI Engine
    Share