This bill would create new federal privacy, security, and breach-notification rules for a broad set of entities that handle health-related information, including many companies not now covered by HIPAA. It directs the Department of Health and Human Services (HHS), working with the Federal Trade Commission (FTC), to write rules that generally mirror HIPAA protections, add duties about notices and consent, set national de-identification standards, and require studies and guidance on specific topics. The broad goal is to extend stronger, more uniform privacy protections for health information across more types of organizations and uses.
Patients / Consumers
Health care providers, health plans, and business associates (already covered by HIPAA)
Technology companies, app developers, data brokers, and other private businesses
Researchers
Government agencies
No publicly available information.