Health Information Privacy Reform Act
Summary
What This Bill Does
The reported Health Information Privacy Reform Act directs the Department of Health and Human Services, in consultation with the Federal Trade Commission, to issue rules within 18 months for identifiable health information that is handled outside ordinary HIPAA coverage. The rules must provide privacy, security, and breach-notification protections at least equivalent to the HIPAA and HITECH framework where feasible. The covered information includes identifiable physical or mental health, health-care, and payment information, including precise geolocation that could indicate an attempt to obtain a health service. Regulated entities include health-data businesses and data brokers that determine how such information is processed; service providers processing the data for them are also covered.
The rules must specify permitted, authorized, and prohibited uses; impose minimum-necessary, purpose-limitation, data-minimization, and secondary-use limits; and establish privacy notices plus rights of access, correction, deletion, and portability. Written authorization is required for sale, licensing, transfer, or marketing, and it must be revocable. Deletion ordinarily must occur within 30 days, subject to regulatory exceptions and an opportunity for the business to communicate with the requester. Entities must appoint privacy personnel, train workers, maintain policies and records, avoid retaliation, mitigate violations, and use physical, technical, and administrative safeguards. They may not retain data longer than reasonably needed. Exceptions preserve necessary processing for requested transactions, legal obligations or claims, security and fraud response, public health, and regulated research.
The bill also bars a regulated entity or service provider from selling or transferring covered health information to a federal, state, local, Tribal, or territorial government unless compelled by a warrant, subpoena, court order, or other compulsory process. Permitted-use rules may not authorize health-data use to investigate or impose liability on a person for seeking, obtaining, providing, or facilitating health care. HHS and the FTC must allocate primary enforcement responsibility through a memorandum of understanding, share notice of investigations, and prevent duplicate civil penalties for the same conduct. HIPAA-style civil penalties apply, and collected penalties fund enforcement. Existing FTC Act authority remains intact.
For protected health information already governed by HIPAA, the bill clarifies requests to send electronic health records to a person chosen by the individual. A covered entity or business associate may require the designated recipient to pay a state-law-consistent fee in advance and accept binding use and disclosure conditions. Preferential access and copying rules are limited to the individual or personal representative, the person's health-care provider, or a personal health record controlled by the individual. The provision cannot be used for information blocking, and no fee or recipient condition may be imposed when the individual or personal representative receives the data through a personally controlled health record. HHS must update guidance within 180 days.
Within one year, HHS must coordinate with the Food and Drug Administration and the National Coordinator for Health Information Technology to regulate how the minimum-necessary standard applies when health information is used to train, develop, validate, modify, fine-tune, or operate artificial-intelligence and machine-learning models. The rules must explain when larger datasets are reasonably necessary and how de-identification, minimization, and privacy-enhancing technologies satisfy the standard. They must also protect lawful interoperability: an entity cannot deny or delay an otherwise required or permitted disclosure merely because further technical limitation is infeasible when reasonable limiting efforts were made. HHS must review these rules at least every three years.
HHS must separately establish unified national de-identification standards. Those standards must be at least as protective as HIPAA's expert-determination method and cannot rely solely on the HIPAA safe-harbor method. Transfers of purportedly de-identified information require written downstream promises against re-identification, and recipients are directly prohibited from attempting re-identification. The standards must account for evolving AI-assisted re-identification methods and specify privacy-enhancing technologies. Violations are subject to the bill's civil-penalty framework.
The bill excludes information already governed by specified financial, substance-use-disorder, education, human-subject research, clinical-research, health-quality, and patient-safety regimes, along with public information and purely personal or household processing. HIPAA covered entities and business associates are excluded only with respect to protected health information. Its preemption clause imports the existing HIPAA preemption rule, so conflicting state requirements may be displaced while state protections that fit HIPAA's exceptions, including qualifying more protective rules, can remain.
The introduced version also proposed a National Academies study on compensating patients for research data and separate notices for recipients of patient-access data and wellness-technology users. Those standalone sections do not appear in the reported substitute and are not part of the current bill.
Who Benefits and How
Patients and users of health applications gain baseline rights over identifiable health information that may fall outside HIPAA, including access, correction, deletion, portability, authorization, breach notice, and security protections. People seeking sensitive health care gain an express restriction on investigative uses and government transfers without compulsory legal process. Individuals using personally controlled health records receive protection against fees and recipient conditions. Health-care providers and patients may benefit from the interoperability safeguard when technical data minimization is not feasible. Privacy-enhancing-technology vendors and expert de-identification services may gain demand as businesses adapt to the new standards. HHS and the FTC gain clear enforcement authority and dedicated use of collected penalties.
Who Bears the Burden and How
Health applications, wearable-device platforms, digital-health companies, health-data brokers, analytics firms, and their service providers must redesign consent, notices, retention, deletion, portability, security, breach response, vendor contracts, and data governance. Purchasers and recipients of de-identified health data must accept contractual restrictions and face civil penalties for re-identification attempts. Covered entities, business associates, personal-health-record recipients, and health-data intermediaries must distinguish fee-protected individual access from transfers to designated third parties. AI developers and model operators using health information must document why datasets are reasonably necessary and implement updated minimization or privacy technologies. HHS, the FTC, FDA, and the National Coordinator must write, coordinate, enforce, and periodically update several new regulatory regimes.
Key Provisions
- Requires HHS and the FTC to establish HIPAA-equivalent privacy, security, breach, authorization, deletion, portability, minimization, and retention rules for applicable health information.
- Prohibits government transfers without compulsory process and prevents permitted-use rules from authorizing health-care investigations or liability.
- Clarifies electronic-health-record transfers, third-party fees and conditions, personally controlled records, and information-blocking safeguards.
- Requires recurring minimum-necessary rules for health information used by artificial-intelligence and machine-learning systems.
- Replaces safe-harbor-only de-identification with expert-level standards, downstream contracts, privacy-enhancing technologies, and a direct ban on re-identification.
- Applies HIPAA-style civil penalties, coordinates HHS and FTC enforcement, preserves FTC authority, and imports HIPAA's preemption framework.
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
Creates a federal privacy, security, breach-notification, access, artificial-intelligence, and de-identification framework for identifiable health information outside ordinary HIPAA coverage, enforced by HHS and the FTC through HIPAA-style civil penalties.
Key Policy Areas
Health Privacy, Consumer Data, Artificial Intelligence, Health Information Technology, Federalism
Primary Purpose
Creates a federal privacy, security, breach-notification, access, artificial-intelligence, and de-identification framework for identifiable health information outside ordinary HIPAA coverage, enforced by HHS and the FTC through HIPAA-style civil penalties.
Policy Domains
Electronic health record access and third-party transmission
Identified Gains
- Individuals using personal health records
- Personal representatives
- Health-care providers receiving records
- Covered entities managing third-party requests
Identified Costs
- Commercial health-record recipients
- Record-transfer application vendors
- Business associates processing access requests
- HHS health-information guidance staff
HIPAA-style federal preemption
Identified Gains
- Entities seeking a familiar compliance framework
- States with qualifying protective health laws
- Courts applying established preemption doctrine
Identified Costs
- States with conflicting health-data requirements
- Multistate health-data compliance teams
- Litigants disputing federal-state conflicts
Health-data de-identification and re-identification controls
Identified Gains
- People represented in de-identified datasets
- Expert de-identification services
- Privacy-enhancing-technology vendors
- Responsible health-data researchers
Identified Costs
- Health-data safe-harbor users
- Recipients of de-identified health data
- Data resale platforms
- AI-assisted re-identification businesses
Minimum-necessary rules for health-data AI systems
Identified Gains
- Patients represented in AI training data
- Health-data interoperability users
- Privacy-enhancing-technology vendors
- Entities making reasonable minimization efforts
Identified Costs
- Health AI model developers
- Machine-learning model operators
- Covered entity data science teams
- Federal health technology regulators
Privacy and security rules for non-HIPAA health data
Identified Gains
- Users of consumer health applications
- Patients seeking sensitive health care
- People requesting deletion or portability
- Federal health-privacy enforcement offices
- Privacy compliance technology vendors
- Victims of health-data breaches
Identified Costs
- Consumer health application operators
- Wearable device platforms
- Health-data brokers
- Health analytics service providers
- Health-data marketing firms
- Government investigators seeking health data
Sponsors
Legislative Progress
ReportedPlaced on Senate Legislative Calendar under General Orders. Calendar No. …
Committee on Health, Education, Labor, and Pensions. Reported by Senator …
Reported by Mr. Cassidy, with an amendment
Committee on Health, Education, Labor, and Pensions. Ordered to be …
Mr. Cassidy introduced the following bill; which was read twice …
Read twice and referred to the Committee on Health, Education, …
Introduced in Senate
Mr. Cassidy introduced the following bill; which was read twice …
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Business associates processing access requests, Commercial electronic-record recipients, Commercial health-record recipients
Positive-direction: Expert de-identification services, HIPAA covered entities, Health information exchange users, Multistate health-data businesses
Negative-direction: Commercial electronic-record recipients, Commercial health-record recipients, Consumer health application operators, Health AI model developers, Health-data safe-harbor users, Patient-access data recipients, Recipients of de-identified health data
Congressional health-policy counsel, Federal health technology regulators, Federal health-privacy regulators
Individuals directing records to third parties, Individuals using personal health records, Patients contributing research data
Positive-direction: Individuals using personal health records, Patients contributing research data, Patients represented in AI datasets, Patients represented in training data, People represented in health datasets, People seeking sensitive health care, Users of non-HIPAA health services, Users of wellness technology
Negative-direction: Individuals directing records to third parties
AI-assisted re-identification businesses, Health-data brokers, Health-data resale businesses
Positive-direction: Privacy compliance technology vendors, Privacy-enhancing-technology vendors
Negative-direction: AI-assisted re-identification businesses, Health-data brokers, Health-data resale businesses, Health-data service providers, Machine-learning model operators, Wellness technology operators
Federal preemption litigants, Health privacy compliance counsel, Health-data research counsel
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "ftc"
- → Federal Trade Commission
- "hhs"
- → Department of Health and Human Services
- "individuals"
- → People whose applicable health information is processed
- "data_brokers"
- → Businesses deriving principal revenue from third-party health data
- "service_providers"
- → Processors acting for regulated entities
- "regulated_entities"
- → Businesses determining health-data processing purposes
- "government_requesters"
- → Government entities seeking health information
- "individuals"
- → Individuals requesting electronic health records
- "covered_entities"
- → HIPAA covered entities
- "business_associates"
- → HIPAA business associates
- "designated_recipients"
- → Third parties designated to receive records
- "personal_health_records"
- → Individual-managed personal health record services
- "personal_representatives"
- → People acting for an individual
- "fda"
- → Food and Drug Administration
- "hhs"
- → Department of Health and Human Services
- "onc"
- → National Coordinator for Health Information Technology
- "ai_developers"
- → Developers using health information for AI models
- "model_operators"
- → Operators of health-data machine-learning models
- "covered_entities"
- → HIPAA covered entities
- "regulated_entities"
- → Non-HIPAA health-data businesses
- "hhs"
- → Department of Health and Human Services
- "experts"
- → Expert de-identification services
- "researchers"
- → Researchers using de-identified health data
- "data_holders"
- → Entities rendering health information de-identified
- "data_recipients"
- → Recipients of de-identified health information
- "technology_vendors"
- → Privacy-enhancing-technology vendors
- "courts"
- → Courts resolving federal-state conflicts
- "states"
- → State privacy lawmakers and regulators
- "individuals"
- → People protected by state health-privacy requirements
- "regulated_entities"
- → Entities subject to federal and state health-data rules
Note: {'scope_ids': ['non_hipaa_health_data', 'ehr_access'], 'description': 'The bill expands privacy rights for non-HIPAA information while allowing fees and binding recipient conditions for some individual-directed HIPAA record transfers; personally controlled access remains protected.'}
Key Definitions
Terms defined in this bill
Technical means that reduce privacy risks by improving predictability, manageability, disassociability, and confidentiality.
Reasonably identifiable information about health, health care, or payment, including non-provider data and precise geolocation indicating an effort to obtain health care, subject to listed statutory exclusions.
A person, including a data broker, that determines the purposes and means of processing applicable health information, excluding an individual acting personally and HIPAA entities with respect to protected health information.
A regulated entity whose principal revenue comes from processing or transferring applicable health information it did not collect directly from the individuals concerned.
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology