Health Data Privacy Rules

Full Title:
Health Information Privacy Reform Act

Summary#

This bill would create new federal privacy, security, and breach-notification rules for a broad set of entities that handle health-related information, including many companies not now covered by HIPAA. It directs the Department of Health and Human Services (HHS), working with the Federal Trade Commission (FTC), to write rules that generally mirror HIPAA protections, add duties about notices and consent, set national de-identification standards, and require studies and guidance on specific topics. The broad goal is to extend stronger, more uniform privacy protections for health information across more types of organizations and uses.

  • Main change: HHS must write privacy, security, and breach-notice rules for “applicable health information” processed by regulated entities and their service providers (entities that decide how and why health data is used, excluding government bodies and HIPAA-covered entities/business associates).
  • Individual rights: The rules must include access, amendment, deletion, portability, privacy notices, and time limits for responses.
  • Security and breaches: Security safeguards must follow national frameworks (for example NIST). Breach-notification rules will look like existing HIPAA breach rules.
  • De-identification: HHS must set a single national standard for when health information is “de-identified,” require tech-based privacy tools, and require written contracts forbidding re-identification for recipients.
  • Patient notifications: Entities that get a patient’s protected health information via the patient’s right of access must warn the patient that the information will no longer be protected by HIPAA and must get consent before selling it. Digital wellness tools must notify users in advance and offer an opt-out.
  • Other actions: HHS must publish guidance on minimum-necessary rules for AI/ML use of health data and must contract with the National Academies to study paying patients for use of identifiable data in research.

What it means for you#

  • Patients / Consumers

    • You may get stronger privacy protections for health-related data held by many companies that are not now covered by HIPAA.
    • If you use a wellness app or digital health device, the company must give a plain-language notice that the data is not covered by HIPAA and let you opt out of data generation.
    • If you ask a provider to send your protected health information to a third party you designate, you should get clearer rules about what you must sign, possible fees, and what the recipient may do with the data.
    • If a company obtains your protected health information through your access request, it must tell you before it accesses the data that HIPAA protections no longer apply and explain who may re-disclose the data; it must get your consent before selling it.
  • Health care providers, health plans, and business associates (already covered by HIPAA)

    • The bill largely keeps existing HIPAA duties for covered entities and business associates, but it clarifies when and how they may transmit records to third parties designated by patients and limits the fee rules in some situations.
    • HHS must update guidance within 180 days to reflect these rules.
  • Technology companies, app developers, data brokers, and other private businesses

    • Many of these organizations could become “regulated entities” or “service providers” under the bill if they decide how or why health data is used. They would face new privacy, security, breach-notice, and individual-rights obligations similar to HIPAA.
    • If you receive de-identified health data, you would generally need a written agreement not to re-identify the data and to impose the same rule downstream.
    • Companies offering wellness technology must give advance notices and opt-outs and must get consent before selling certain protected information obtained through a patient’s right of access.
  • Researchers

    • De-identification rules and contractual limits on re-identification may affect access to datasets. The bill also requires a National Academies study on compensation to patients for sharing identifiable data for research, which could inform future policy.
  • Government agencies

    • HHS (with input from the FTC) must issue multiple rulemakings, guidance documents, and a contract with the National Academies. HHS is given enforcement authority and civil-penalty powers similar to current HIPAA enforcement rules.

Expenses#

No publicly available information.

  • The bill requires HHS rulemaking, guidance, enforcement activity, and a contract with the National Academies. Those activities typically have administrative costs, but the bill does not include a fiscal note or cost estimates.
  • Regulated entities and service providers would likely face compliance costs for policies, privacy officers, staff training, technical safeguards, contracts, and breach response.
  • De-identification standards and contractual restrictions could change data-sharing arrangements, which may affect business revenues or research access — the bill does not estimate those effects.

Proponents' View#

  • The bill appears intended to extend HIPAA-like protections beyond traditional health care organizations to many companies that now collect and use health-related data. This could be seen as reducing gaps where sensitive health data currently has fewer legal protections.
  • It could be seen as improving clarity by setting national standards for what counts as de-identified data and by requiring written promises not to re-identify data.
  • The security rules tied to established frameworks (for example NIST) could be seen as strengthening technical protection of electronic health information.
  • Requiring plain-language notices and opt-outs for wellness tools and requiring consent before sales could be seen as enhancing consumer control and transparency.
  • The National Academies study could be seen as a cautious step to examine ethical and privacy issues around paying patients for identifiable research data.

Opponents' View#

  • One concern is that the bill may impose substantial compliance costs on many companies (privacy programs, privacy officers, training, technical safeguards, contracts), especially smaller firms, without a clear cost estimate.
  • The definition of “regulated entity” and scope of “applicable health information” may be broad and leave uncertainty about which companies must follow the new rules.
  • Requiring written contracts that bar re-identification could reduce data sharing for legitimate research and public-health work unless the bill’s exceptions or processes are clarified.
  • The rule that information provided by a patient-access request loses HIPAA protection when a non-covered party receives it could create confusing legal boundaries about who must protect data and when.
  • The bill relies on future HHS rulemaking for many key details (for example, what counts as “reasonable expectations,” exact permitted uses, and enforcement procedures), so its practical effects depend heavily on how those rules are written.
  • It is unclear how HHS enforcement will interact with FTC enforcement or state privacy laws; the preemption rule in the bill references existing HIPAA preemption rules but may not resolve all conflicts with state laws.