Pediatric health data governance: what is different about consent for minors
Children cannot consent for themselves, and their parents cannot consent forever. Pediatric health data governance sits in a legal and ethical gap that most health systems, AI developers, and researchers fail to address. The consequences show up in broken consent chains, unusable training data, and adolescents who avoid care entirely.
A 12-year-old walks into a pediatrician's office. The clinician hands the child a consent form. The parent, sitting three feet away, wonders why their kid is being asked to sign anything. This scene plays out thousands of times a day across the United States, and almost nobody involved fully understands the legal and ethical framework behind it.
Pediatric health data governance is not a smaller version of adult data governance. It is a fundamentally different problem. The data subject cannot legally consent. The person who can consent today may lose that authority tomorrow. And the data itself will outlive the governance framework that authorized its collection.
Why did my pediatrician have my 12-year-old consent to records?
Many parents encounter this for the first time and assume it is a mistake. It is not. Federal and state laws create a patchwork of situations where minors can consent to their own treatment and, by extension, to the records generated by that treatment.
Under HIPAA, a minor who legally consents to care becomes the individual who controls access to those records. Most states allow minors to consent to treatment for reproductive health, substance use, and mental health services. Some states set this threshold at 12, others at 14. A few have no minimum age for specific categories of care.
The pediatrician who asks a 12-year-old to consent to records is often following state law. The complexity is that the same child may be unable to consent to a flu shot record but fully authorized to consent to a behavioral health record. Two records, same patient, same visit, different consent authorities.
The 3 C's of consent
Consent frameworks in pediatric care rest on three requirements, often called the 3 C's: capacity, competence, and voluntariness.
Capacity refers to the cognitive ability to understand what is being agreed to. Competence is the legal standing to make the decision. Voluntariness means the decision is free from coercion. Adults are presumed to have all three. Children are presumed to lack at least one.
This is where pediatric data governance fractures. A 15-year-old may have the capacity to understand a consent form but lack the legal competence to sign it for general medical records. That same teenager may have full legal competence to consent to a mental health visit in one state and none in the state next door. The 3 C's are not fixed attributes. They shift by age, geography, and care type.
What age can a child consent to their data being processed?
There is no single answer. Under COPPA (Children's Online Privacy Protection Act), the threshold is 13 for online data collection. Under GDPR, member states can set the age for data processing consent anywhere between 13 and 16; most choose 16. HIPAA ties data consent to treatment consent, which varies by state and care category.
A recent MedPageToday report found that a third of states mandate caregiver consent for mental health treatment for teens, and those same states show measurably lower use of depression treatments among adolescents. The consent structure does not just govern data. It shapes whether minors receive care at all.
This means any organization building a pediatric health data trust must map consent authority across at least three legal frameworks (federal, state, and care-type-specific) before a single record can be scored as trustworthy.
How assent differs from informed consent in research on children
Research introduces another layer. Informed consent requires a legally authorized individual to agree to participation. For minors, that is typically a parent or guardian. Assent is a parallel process: the child agrees to participate at a level appropriate to their understanding.
Assent is not consent. It does not carry legal weight on its own. But the Common Rule (45 CFR 46 Subpart D) requires institutional review boards to obtain assent from children capable of providing it, unless the research offers direct therapeutic benefit that is only available through participation.
The practical problem is that assent is rarely tracked as a discrete data element. When a child's data enters a research dataset, the record may show parental consent but contain no structured field for assent status. This gap makes downstream use of pediatric research data a governance liability. The Texas case reported by MedPageToday, where a physician was accused of illegally accessing children's health records, illustrates what happens when access controls and consent documentation fail.
The transition problem nobody solves
A child becomes an adult. The consent authority transfers from parent to patient. In theory, this happens on the 18th birthday. In practice, it happens unevenly and often not at all.
EHR systems rarely trigger a consent re-authorization at age 18. Records collected under parental consent continue to be governed by that original authorization unless someone actively updates it. For data used in AI model training, this creates a specific risk: a model trained on pediatric records authorized by parents may continue to use those records after the patient reaches adulthood, without the now-adult patient ever having consented.
SuperTruth's Data Trust Index addresses this directly. The DTI scores every record across 8 dimensions, and the Consent dimension (weighted at 20% of the total score) evaluates whether authorization is current, whether the consenting party had legal standing at the time of collection, and whether a transition event has invalidated the original consent. A record with expired or ambiguous consent authority scores lower, flagging it before it enters any AI training pipeline or research dataset.
Key statistics
Pediatric health data consent involves numbers that most organizations have never tracked.
What a scored approach to pediatric consent looks like
Most organizations treat consent as binary: you have it or you do not. Pediatric data makes that model collapse. Consent authority changes with age, state, care type, and legal context. A binary flag cannot represent this.
ConsentOS, SuperTruth's consent governance product, tracks consent as a scored, time-aware attribute. Each record carries metadata about who consented, under what legal authority, when that authority expires, and whether a transition event (turning 18, moving states, changing guardianship) has occurred. When the DTI Engine scores the record, it factors all of this into the Consent dimension.
The result is not just compliance documentation. It is a machine-readable consent state that downstream systems, AI training pipelines, and research platforms can query before using a record. Pediatric records that score below threshold on Consent are automatically excluded from training datasets, not deleted, but held until governance is resolved.
The cost of getting this wrong
Pediatric data governance failures are not hypothetical. The Texas case involving illegal access to children's health records resulted in federal charges. States with restrictive adolescent consent laws are measurably reducing access to mental health care. And AI models trained on pediatric data with unresolved consent chains face regulatory exposure under both FDA guidance on AI/ML-based devices and emerging state data privacy laws.
The question is not whether your organization handles pediatric data. If you operate in healthcare, you do. The question is whether your governance framework accounts for the consent complexity that makes pediatric data fundamentally different from everything else in your system.
To build a pediatric health data trust that holds up to regulatory scrutiny and earns the trust of families, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140. SuperTruth scores every record before it enters your pipeline, including the ones where consent is the hardest problem in the dataset.
Further reading:

Jason Alan Snyder
Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.
About SuperTruth · LinkedIn · Substack · jasonalansnyder.com
See it in practice
The FICO score for health data.
8 dimensions. 0–100. Travels with every record permanently.