S3097119th CongressWALLET

Health Information Privacy Reform Act

Sponsored By: Senator Cassidy, Bill [R-LA]

Introduced

Summary

Creates a federal privacy framework for health data that extends HIPAA-style protections to many non-HIPAA companies. It sets privacy, security, breach notification, and access rules for a new class of "regulated entities" and their service providers and seeks to harmonize standards with HIPAA where feasible.

Personalized for You

How does this bill affect your finances?

Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Bill Overview

Analyzed Economic Effects

6 provisions identified: 4 benefits, 0 costs, 2 mixed.

Stricter rules for de-identified health data

This bill would require HHS to set national rules, within one year, for when health data count as de-identified. The rules must meet or exceed current HIPAA standards and require written contracts that bar recipients from re-identifying data and that bind downstream users.

Stronger federal rules for health data

This bill would extend HIPAA-like privacy, security, and breach rules to many more companies that handle health data. HHS, with the FTC, would write and enforce those rules and could use HITECH-style penalties. The bill would define who counts as a "regulated entity" and who is a "service provider."

Notice and opt-out for wellness apps

If enacted, companies that make wellness apps or devices would have to give plain-language notice before collecting wellness data that it is not covered by HIPAA. Users would get a chance to opt out before data generation. Providers that get your PHI via your access right must tell you before accessing it and must get your consent before selling it. These rules would start one year after enactment.

Limits on AI health data use

This bill would require HHS to publish guidance within one year on how the "minimum necessary" rule applies to AI and machine learning uses of health data. The guidance must also cover interoperability rules and the use of limited data sets.

New rules for patient record requests

This bill would require patient requests to send or access health records to meet written authorization rules. Providers could require recipients to pay fees in advance under state law and to accept the request's terms as legally binding. Electronic transfers would be allowed only to the patient portal or mobile app your provider uses. HHS must update guidance within 180 days.

Study on paying patients for data

Within 60 days, HHS would ask the National Academies to study whether and how to pay patients for sharing identifiable health data for research. The study would examine privacy, consent, ethics, tracking, and re-identification risk, and would not itself pay patients.

Sponsors & CoSponsors

Sponsor

Cassidy, Bill [R-LA]

LA • R

Cosponsors

There are no cosponsors for this bill.

Roll Call Votes

No roll call votes available for this bill.

View on Congress.gov
Back to Legislation