S3097-119

Reported

Health Information Privacy Reform Act

119th Congress Introduced Nov 4, 2025

Summary

What This Bill Does

The reported Health Information Privacy Reform Act directs the Department of Health and Human Services, in consultation with the Federal Trade Commission, to issue rules within 18 months for identifiable health information that is handled outside ordinary HIPAA coverage. The rules must provide privacy, security, and breach-notification protections at least equivalent to the HIPAA and HITECH framework where feasible. The covered information includes identifiable physical or mental health, health-care, and payment information, including precise geolocation that could indicate an attempt to obtain a health service. Regulated entities include health-data businesses and data brokers that determine how such information is processed; service providers processing the data for them are also covered.

The rules must specify permitted, authorized, and prohibited uses; impose minimum-necessary, purpose-limitation, data-minimization, and secondary-use limits; and establish privacy notices plus rights of access, correction, deletion, and portability. Written authorization is required for sale, licensing, transfer, or marketing, and it must be revocable. Deletion ordinarily must occur within 30 days, subject to regulatory exceptions and an opportunity for the business to communicate with the requester. Entities must appoint privacy personnel, train workers, maintain policies and records, avoid retaliation, mitigate violations, and use physical, technical, and administrative safeguards. They may not retain data longer than reasonably needed. Exceptions preserve necessary processing for requested transactions, legal obligations or claims, security and fraud response, public health, and regulated research.

The bill also bars a regulated entity or service provider from selling or transferring covered health information to a federal, state, local, Tribal, or territorial government unless compelled by a warrant, subpoena, court order, or other compulsory process. Permitted-use rules may not authorize health-data use to investigate or impose liability on a person for seeking, obtaining, providing, or facilitating health care. HHS and the FTC must allocate primary enforcement responsibility through a memorandum of understanding, share notice of investigations, and prevent duplicate civil penalties for the same conduct. HIPAA-style civil penalties apply, and collected penalties fund enforcement. Existing FTC Act authority remains intact.

For protected health information already governed by HIPAA, the bill clarifies requests to send electronic health records to a person chosen by the individual. A covered entity or business associate may require the designated recipient to pay a state-law-consistent fee in advance and accept binding use and disclosure conditions. Preferential access and copying rules are limited to the individual or personal representative, the person's health-care provider, or a personal health record controlled by the individual. The provision cannot be used for information blocking, and no fee or recipient condition may be imposed when the individual or personal representative receives the data through a personally controlled health record. HHS must update guidance within 180 days.

Within one year, HHS must coordinate with the Food and Drug Administration and the National Coordinator for Health Information Technology to regulate how the minimum-necessary standard applies when health information is used to train, develop, validate, modify, fine-tune, or operate artificial-intelligence and machine-learning models. The rules must explain when larger datasets are reasonably necessary and how de-identification, minimization, and privacy-enhancing technologies satisfy the standard. They must also protect lawful interoperability: an entity cannot deny or delay an otherwise required or permitted disclosure merely because further technical limitation is infeasible when reasonable limiting efforts were made. HHS must review these rules at least every three years.

HHS must separately establish unified national de-identification standards. Those standards must be at least as protective as HIPAA's expert-determination method and cannot rely solely on the HIPAA safe-harbor method. Transfers of purportedly de-identified information require written downstream promises against re-identification, and recipients are directly prohibited from attempting re-identification. The standards must account for evolving AI-assisted re-identification methods and specify privacy-enhancing technologies. Violations are subject to the bill's civil-penalty framework.

The bill excludes information already governed by specified financial, substance-use-disorder, education, human-subject research, clinical-research, health-quality, and patient-safety regimes, along with public information and purely personal or household processing. HIPAA covered entities and business associates are excluded only with respect to protected health information. Its preemption clause imports the existing HIPAA preemption rule, so conflicting state requirements may be displaced while state protections that fit HIPAA's exceptions, including qualifying more protective rules, can remain.

The introduced version also proposed a National Academies study on compensating patients for research data and separate notices for recipients of patient-access data and wellness-technology users. Those standalone sections do not appear in the reported substitute and are not part of the current bill.

Who Benefits and How

Patients and users of health applications gain baseline rights over identifiable health information that may fall outside HIPAA, including access, correction, deletion, portability, authorization, breach notice, and security protections. People seeking sensitive health care gain an express restriction on investigative uses and government transfers without compulsory legal process. Individuals using personally controlled health records receive protection against fees and recipient conditions. Health-care providers and patients may benefit from the interoperability safeguard when technical data minimization is not feasible. Privacy-enhancing-technology vendors and expert de-identification services may gain demand as businesses adapt to the new standards. HHS and the FTC gain clear enforcement authority and dedicated use of collected penalties.

Who Bears the Burden and How

Health applications, wearable-device platforms, digital-health companies, health-data brokers, analytics firms, and their service providers must redesign consent, notices, retention, deletion, portability, security, breach response, vendor contracts, and data governance. Purchasers and recipients of de-identified health data must accept contractual restrictions and face civil penalties for re-identification attempts. Covered entities, business associates, personal-health-record recipients, and health-data intermediaries must distinguish fee-protected individual access from transfers to designated third parties. AI developers and model operators using health information must document why datasets are reasonably necessary and implement updated minimization or privacy technologies. HHS, the FTC, FDA, and the National Coordinator must write, coordinate, enforce, and periodically update several new regulatory regimes.

Key Provisions

  • Requires HHS and the FTC to establish HIPAA-equivalent privacy, security, breach, authorization, deletion, portability, minimization, and retention rules for applicable health information.
  • Prohibits government transfers without compulsory process and prevents permitted-use rules from authorizing health-care investigations or liability.
  • Clarifies electronic-health-record transfers, third-party fees and conditions, personally controlled records, and information-blocking safeguards.
  • Requires recurring minimum-necessary rules for health information used by artificial-intelligence and machine-learning systems.
  • Replaces safe-harbor-only de-identification with expert-level standards, downstream contracts, privacy-enhancing technologies, and a direct ban on re-identification.
  • Applies HIPAA-style civil penalties, coordinates HHS and FTC enforcement, preserves FTC authority, and imports HIPAA's preemption framework.

Evidence Chain:

This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.

At a Glance

What This Bill Does

Creates a federal privacy, security, breach-notification, access, artificial-intelligence, and de-identification framework for identifiable health information outside ordinary HIPAA coverage, enforced by HHS and the FTC through HIPAA-style civil penalties.

Key Policy Areas

Health Privacy, Consumer Data, Artificial Intelligence, Health Information Technology, Federalism

Primary Purpose

Creates a federal privacy, security, breach-notification, access, artificial-intelligence, and de-identification framework for identifiable health information outside ordinary HIPAA coverage, enforced by HHS and the FTC through HIPAA-style civil penalties.

Policy Domains

Health Privacy Consumer Data Artificial Intelligence Health Information Technology Federalism

Electronic health record access and third-party transmission

Identified Gains
  • Individuals using personal health records
  • Personal representatives
  • Health-care providers receiving records
  • Covered entities managing third-party requests
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Personal representatives: ,
Health-care providers receiving records: ,
Individuals using personal health records: ,
Covered entities managing third-party requests: ,
Identified Costs
  • Commercial health-record recipients
  • Record-transfer application vendors
  • Business associates processing access requests
  • HHS health-information guidance staff
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Commercial health-record recipients: ,
Record-transfer application vendors: ,
HHS health-information guidance staff: ,
Business associates processing access requests: ,

HIPAA-style federal preemption

Identified Gains
  • Entities seeking a familiar compliance framework
  • States with qualifying protective health laws
  • Courts applying established preemption doctrine
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
States with qualifying protective health laws:
Courts applying established preemption doctrine:
Entities seeking a familiar compliance framework:
Identified Costs
  • States with conflicting health-data requirements
  • Multistate health-data compliance teams
  • Litigants disputing federal-state conflicts
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Multistate health-data compliance teams:
Litigants disputing federal-state conflicts:
States with conflicting health-data requirements:

Health-data de-identification and re-identification controls

Identified Gains
  • People represented in de-identified datasets
  • Expert de-identification services
  • Privacy-enhancing-technology vendors
  • Responsible health-data researchers
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Expert de-identification services: ,
Responsible health-data researchers: ,
Privacy-enhancing-technology vendors: ,
People represented in de-identified datasets: ,
Identified Costs
  • Health-data safe-harbor users
  • Recipients of de-identified health data
  • Data resale platforms
  • AI-assisted re-identification businesses
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Data resale platforms: ,
Health-data safe-harbor users: ,
Recipients of de-identified health data: ,
AI-assisted re-identification businesses: ,

Minimum-necessary rules for health-data AI systems

Identified Gains
  • Patients represented in AI training data
  • Health-data interoperability users
  • Privacy-enhancing-technology vendors
  • Entities making reasonable minimization efforts
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Health-data interoperability users: ,
Privacy-enhancing-technology vendors: ,
Patients represented in AI training data: ,
Entities making reasonable minimization efforts: ,
Identified Costs
  • Health AI model developers
  • Machine-learning model operators
  • Covered entity data science teams
  • Federal health technology regulators
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Health AI model developers: ,
Machine-learning model operators: ,
Covered entity data science teams: ,
Federal health technology regulators: ,

Privacy and security rules for non-HIPAA health data

Identified Gains
  • Users of consumer health applications
  • Patients seeking sensitive health care
  • People requesting deletion or portability
  • Federal health-privacy enforcement offices
  • Privacy compliance technology vendors
  • Victims of health-data breaches
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Victims of health-data breaches:
Privacy compliance technology vendors:
Users of consumer health applications:
Patients seeking sensitive health care:
People requesting deletion or portability:
Federal health-privacy enforcement offices:
Identified Costs
  • Consumer health application operators
  • Wearable device platforms
  • Health-data brokers
  • Health analytics service providers
  • Health-data marketing firms
  • Government investigators seeking health data
Model: codex-gpt-5 | Version: bill_summary_v2 | Source: rs
Health-data brokers:
Wearable device platforms:
Health-data marketing firms:
Health analytics service providers:
Consumer health application operators:
Government investigators seeking health data:

Legislative Progress

Reported
Introduced Committee Passed
Aug 4, 2026

Placed on Senate Legislative Calendar under General Orders. Calendar No. …

Aug 4, 2026

Committee on Health, Education, Labor, and Pensions. Reported by Senator …

Aug 4, 2026

Reported by Mr. Cassidy, with an amendment

Jul 30, 2026

Committee on Health, Education, Labor, and Pensions. Ordered to be …

Nov 4, 2025

Mr. Cassidy introduced the following bill; which was read twice …

Nov 4, 2025

Read twice and referred to the Committee on Health, Education, …

Nov 4, 2025

Introduced in Senate

Nov 4, 2025

Mr. Cassidy introduced the following bill; which was read twice …

Stakeholder Effects

cui bono?

How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.

Healthcare
20 mentions across 12 clauses
+6 positive -9 negative ~5 mixed

Business associates processing access requests, Commercial electronic-record recipients, Commercial health-record recipients

Positive-direction: Expert de-identification services, HIPAA covered entities, Health information exchange users, Multistate health-data businesses

Negative-direction: Commercial electronic-record recipients, Commercial health-record recipients, Consumer health application operators, Health AI model developers, Health-data safe-harbor users, Patient-access data recipients, Recipients of de-identified health data

Government
14 mentions across 13 clauses
-1 negative ~9 mixed ?4 uncertain

Congressional health-policy counsel, Federal health technology regulators, Federal health-privacy regulators

General Public
13 mentions across 12 clauses
+10 positive -1 negative ~2 mixed

Individuals directing records to third parties, Individuals using personal health records, Patients contributing research data

Positive-direction: Individuals using personal health records, Patients contributing research data, Patients represented in AI datasets, Patients represented in training data, People represented in health datasets, People seeking sensitive health care, Users of non-HIPAA health services, Users of wellness technology

Negative-direction: Individuals directing records to third parties

Technology
11 mentions across 6 clauses
+5 positive -6 negative

AI-assisted re-identification businesses, Health-data brokers, Health-data resale businesses

Positive-direction: Privacy compliance technology vendors, Privacy-enhancing-technology vendors

Negative-direction: AI-assisted re-identification businesses, Health-data brokers, Health-data resale businesses, Health-data service providers, Machine-learning model operators, Wellness technology operators

Professional Services
5 mentions across 5 clauses
~1 mixed ?4 uncertain

Federal preemption litigants, Health privacy compliance counsel, Health-data research counsel

Education
1 mention across 1 clause
+1 positive

National Academies research program

9/15
sections analyzed
Full impact breakdown

Bill Structure & Actor Mappings

Who is "The Secretary" in each section?

Domains
Health Privacy Consumer Data Cybersecurity
Actor Mappings
"ftc"
→ Federal Trade Commission
"hhs"
→ Department of Health and Human Services
"individuals"
→ People whose applicable health information is processed
"data_brokers"
→ Businesses deriving principal revenue from third-party health data
"service_providers"
→ Processors acting for regulated entities
"regulated_entities"
→ Businesses determining health-data processing purposes
"government_requesters"
→ Government entities seeking health information
Domains
Health Information Technology Patient Access
Actor Mappings
"individuals"
→ Individuals requesting electronic health records
"covered_entities"
→ HIPAA covered entities
"business_associates"
→ HIPAA business associates
"designated_recipients"
→ Third parties designated to receive records
"personal_health_records"
→ Individual-managed personal health record services
"personal_representatives"
→ People acting for an individual
Domains
Artificial Intelligence Health Privacy Interoperability
Actor Mappings
"fda"
→ Food and Drug Administration
"hhs"
→ Department of Health and Human Services
"onc"
→ National Coordinator for Health Information Technology
"ai_developers"
→ Developers using health information for AI models
"model_operators"
→ Operators of health-data machine-learning models
"covered_entities"
→ HIPAA covered entities
"regulated_entities"
→ Non-HIPAA health-data businesses
Domains
Health Privacy Artificial Intelligence Data Governance
Actor Mappings
"hhs"
→ Department of Health and Human Services
"experts"
→ Expert de-identification services
"researchers"
→ Researchers using de-identified health data
"data_holders"
→ Entities rendering health information de-identified
"data_recipients"
→ Recipients of de-identified health information
"technology_vendors"
→ Privacy-enhancing-technology vendors
Domains
Federalism Health Privacy
Actor Mappings
"courts"
→ Courts resolving federal-state conflicts
"states"
→ State privacy lawmakers and regulators
"individuals"
→ People protected by state health-privacy requirements
"regulated_entities"
→ Entities subject to federal and state health-data rules

Note: {'scope_ids': ['non_hipaa_health_data', 'ehr_access'], 'description': 'The bill expands privacy rights for non-HIPAA information while allowing fees and binding recipient conditions for some individual-directed HIPAA record transfers; personally controlled access remains protected.'}

Key Definitions

Terms defined in this bill

4 terms
"Privacy-enhancing technologies" §5

Technical means that reduce privacy risks by improving predictability, manageability, disassociability, and confidentiality.

"Applicable health information" §2a

Reasonably identifiable information about health, health care, or payment, including non-provider data and precise geolocation indicating an effort to obtain health care, subject to listed statutory exclusions.

"Regulated entity" §2b

A person, including a data broker, that determines the purposes and means of processing applicable health information, excluding an individual acting personally and HIPAA entities with respect to protected health information.

"Data broker" §2c

A regulated entity whose principal revenue comes from processing or transferring applicable health information it did not collect directly from the individuals concerned.

We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.

Learn more about our methodology