Health Information Privacy Reform Act
Sponsored By: Senator Cassidy, Bill [R-LA]
Introduced
Summary
Creates a federal privacy framework for health data that extends HIPAA-style protections to many non-HIPAA companies. It sets privacy, security, breach notification, and access rules for a new class of "regulated entities" and their service providers and seeks to harmonize standards with HIPAA where feasible.
Personalized for You
How does this bill affect your finances?
Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.
Bill Overview
Analyzed Economic Effects
6 provisions identified: 4 benefits, 0 costs, 2 mixed.
Stricter rules for de-identified health data
This bill would require HHS to set national rules, within one year, for when health data count as de-identified. The rules must meet or exceed current HIPAA standards and require written contracts that bar recipients from re-identifying data and that bind downstream users.
Stronger federal rules for health data
This bill would extend HIPAA-like privacy, security, and breach rules to many more companies that handle health data. HHS, with the FTC, would write and enforce those rules and could use HITECH-style penalties. The bill would define who counts as a "regulated entity" and who is a "service provider."
Notice and opt-out for wellness apps
If enacted, companies that make wellness apps or devices would have to give plain-language notice before collecting wellness data that it is not covered by HIPAA. Users would get a chance to opt out before data generation. Providers that get your PHI via your access right must tell you before accessing it and must get your consent before selling it. These rules would start one year after enactment.
Limits on AI health data use
This bill would require HHS to publish guidance within one year on how the "minimum necessary" rule applies to AI and machine learning uses of health data. The guidance must also cover interoperability rules and the use of limited data sets.
New rules for patient record requests
This bill would require patient requests to send or access health records to meet written authorization rules. Providers could require recipients to pay fees in advance under state law and to accept the request's terms as legally binding. Electronic transfers would be allowed only to the patient portal or mobile app your provider uses. HHS must update guidance within 180 days.
Study on paying patients for data
Within 60 days, HHS would ask the National Academies to study whether and how to pay patients for sharing identifiable health data for research. The study would examine privacy, consent, ethics, tracking, and re-identification risk, and would not itself pay patients.
Sponsors & CoSponsors
Sponsor
Cassidy, Bill [R-LA]
LA • R
Cosponsors
There are no cosponsors for this bill.
Roll Call Votes
No roll call votes available for this bill.
View on Congress.gov