The USA doesn't have a GDPR. The only state with something similar is California, and this college is not in that state, so the data is legal.
If the interpretation of the data is screwed up, then I think the school should invest in something meant to monitor cheating. Obviously with online classes you'll need some form of anti-cheating involved, otherwise the issued degree will become almost worthless. As an example of a proper system; for Salesforce exams, you need 2 independent cameras on you. If you use your phone, then you automatically fail.
Sorry, but if medical students are going to be operating on limbs and organs some day, or give medical advice, then yeah - need some form of an anti-cheating measure. The whole point of a degree is to prove some standard of knowledge and without this stuff, then there aren't really any standards at all. I think the student should have the choice to agree as well, or drop out.