Health DATA Act of 2026
Sponsored By: Representative Takano, Mark [D-CA-39]
Introduced
Summary
Control and protection of group health plan data. The bill amends ERISA (the Employee Retirement Income Security Act of 1974) to expand transparency, strengthen privacy rules, broaden fiduciary duties over plan data, and ban discrimination based on plan data.
Personalized for You
How does this bill affect your finances?
Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.
Bill Overview
Analyzed Economic Effects
5 provisions identified: 1 benefits, 1 costs, 3 mixed.
Ban on discrimination using plan data
If enacted, the bill would make it unlawful for an employer, plan sponsor, administrator, or fiduciary to punish or treat a participant worse because of plan data. Participants could sue under ERISA without first using the plan's appeal process. A court could order equitable relief to restore the person to the position they would have had. The bill would also allow a $100 per day penalty for each affected participant until the violation is fixed.
Large penalties for data violations
If enacted, the bill would let the Secretary assess $10,000 per day for each day a violation of the plan-data rules continues. It would also allow a $100 per day penalty for each participant for discrimination tied to plan data, accruing until fixed. The Secretary would be able to collect those penalties, which could create big compliance and financial exposure for plans and vendors.
Broader audits of plan claims data
If enacted, the bill would let group health plans audit all de-identified claims and encounter data. The data must be de-identified under HIPAA rules (45 C.F.R. 164.514). Audits could review pricing and payment formulas, quality measures, overpayment and recovery terms, and other payment methods. Contracts could not delay audits more than 60 days or charge more than reasonable direct costs.
Plan fiduciaries must manage data
If enacted, the bill would expand ERISA fiduciary duties to cover the use, management, and safeguarding of plan data. Plan managers would need to consider data governance when choosing vendors and overseeing plans. That could improve data protection for participants but also increase vendor oversight and compliance costs for fiduciaries.
Privacy rules and attestations for plans
If enacted, the bill would say it does not limit HIPAA or other federal and state privacy and civil-rights laws. If enacted, the Secretary would collect required attestations about contract "gag clauses" and check that service providers who submit attestations have no conflict of interest. These rules would strengthen privacy protections but add modest administrative checks for plans and vendors.
Sponsors & CoSponsors
Sponsor
Takano, Mark [D-CA-39]
CA • D
Cosponsors
There are no cosponsors for this bill.
Roll Call Votes
No roll call votes available for this bill.
View on Congress.gov