

It needs to be a system and a contractual framework that complies with the medical privacy regulations of the place where it’s being used (in the US, HIPAA). I have some doubts about whether specific companies or people will actually comply, or the enforcement of those laws by certain governmental authorities, but I don’t think it’s conceptually impossible to have this kind of tech be compliant with those types of regulations.
But it’s not the company itself putting those assets up for sale. It’s the court-approved or court-appointed bankruptcy trustee of that company, executing transactions approved by the court. That’s why bankruptcy has to go through court, but it also provides a level of immunity (commonly called “exculpation” in bankruptcy cases) to the individuals actually doing the things ordered by the court.
If it’s illegal to do, a court shouldn’t be ordering it, so the affected people should have to fight the court order before it happens. But it’s not illegal to sell anonymized user data like this, and not illegal to sell employee work-related data, either, in the U.S.