A permitted login can matter as much as a promised output format. Once an outside user can enter a national health system, the safety of the arrangement depends on permissions, audit logs, export controls, and enforcement. That technical question sits at the center of a foreign-policy dispute that reached the Senate in August 2026.
ProPublica reported that eight Democratic senators wrote to Secretary of State Marco Rubio about health-data requirements attached to American aid. Their concern followed reporting on agreements covering HIV, tuberculosis, malaria, and other health programs in Africa.
The clearest documented example is Uganda. Its data-sharing agreement gives the United States direct, real-time access to nine national health data systems for seven years. The agreement requires Uganda to provide U.S. representatives and contractors with logins or other secure access mechanisms.
The systems include a central health-information repository, laboratory data, information collected by community health workers, and a system used to manage electronic medical records. That is broader than a single HIV database, although HIV treatment data forms part of the information at stake.
The same agreement says shared data should be aggregated, stripped of personally identifiable information, and used to deliver or audit healthcare services. The State Department told ProPublica that neither the U.S. government nor private American companies receive or review personally identifiable information under the agreements.
Those assurances must be included in any fair account. At the same time, direct access to systems containing sensitive records creates questions that an anonymized-output promise does not answer on its own. The public reporting does not establish that an American contractor can browse named patient records, but it does show why access permissions and technical controls matter.

The senators’ August 11 letter says some data-sharing agreements require U.S. officials to hold direct login credentials for nationally owned systems. It describes Uganda as receiving up to $1.7 billion for health programs while providing access to nine systems.
The letter also makes an important limitation visible. It says 34 countries had signed broader health memorandums, but only eight memorandums and one data-sharing agreement had been made public. The available evidence therefore does not establish that every African health agreement contains Uganda’s contractor-login terms.
Experts consulted by ProPublica warned that removing names does not always make a dataset permanently anonymous. Location, age, diagnosis, and treatment dates can sometimes be combined with other information to identify an individual. That risk is especially sensitive when a record concerns HIV or another stigmatized condition.
Uganda’s legal environment raises the stakes. Its 2023 Anti-Homosexuality Act can punish same-sex conduct with life imprisonment and allows the death penalty for aggravated homosexuality in some circumstances, according to an Associated Press report on the law.
HIV status alone is not proof that someone has engaged in illegal same-sex conduct. Even so, exposure of a person’s medical history can create risks of stigma, discrimination, or violence. A 2016 study of women using reproductive health services in Kenya documented risks of partner violence following HIV-status disclosure, although it was not a study of Uganda or of these agreements.
The practical public-health concern is trust. If people believe that seeking testing or treatment could expose sensitive information beyond the clinic, some may delay care. The agreements have not been shown to cause that result, but privacy safeguards affect whether patients consider confidentiality credible.
Brad Smith led the effort to establish the new aid arrangements, according to ProPublica. Smith founded three healthcare companies and led a government-efficiency panel during the 2024 presidential transition. After Trump took office, he presided over approximately $67 billion in Department of Health and Human Services cuts before joining the State Department as an adviser.
The agreements form part of the America First Global Health Strategy, which ties foreign health assistance more directly to American interests and asks recipient countries to invest more in their own systems. That marks a change from the longstanding PEPFAR program, launched in 2003 to support HIV prevention, care, and treatment worldwide.
ProPublica reported that PEPFAR previously built separate systems to handle anonymized data rather than giving American representatives direct access to foreign government records. The Uganda agreement moves access inside the government’s own health-data infrastructure.

Privacy and global-health experts told ProPublica that the reviewed agreements were vague and lacked some standard language limiting what information may be collected and how it may be used. That supports concern about possible exposure, misuse, or commercialization. It does not establish that contractors have already copied records or licensed datasets to third parties.
The senators asked whether information could be shared with American third parties for commercial purposes, including training artificial-intelligence models. Their question highlights an unresolved issue rather than a confirmed use of the data.
Uganda accepted the agreement while facing substantial needs for HIV, tuberculosis, malaria, polio, and outbreak response. The funding benefits are measurable, but so is the sensitivity of the infrastructure opened to outside access. Public reporting provides no guarantee that people represented in those systems will have a meaningful say in future uses of their information.
The privacy question is also a sovereignty question. A country retains control only when access rules are specific, enforceable, and visible enough to audit. A login does not prove that patient records have already been taken, but it creates a pathway that deserves stronger scrutiny than an ordinary transfer of aggregated statistics.
That is the precedent the senators are challenging. The humanitarian purpose of the funding remains real, but so does the need to define exactly what American officials and contractors can see, copy, retain, and reuse before direct access becomes standard practice.