What's Happening?
The Senate HELP Committee has unanimously voted 22-0 to advance the Health Information Privacy Reform Act, a federal bill sponsored by Louisiana Republican Senator Bill Cassidy. This legislation seeks to bridge the gap in federal privacy law concerning
the increasing volume of health data generated by consumer wearables and smartphone applications. Currently, HIPAA protections primarily apply to healthcare providers and their business associates, leaving data collected by smartwatches, rings, and health apps largely governed by manufacturers' privacy policies. The proposed bill introduces a new category of 'regulated entities,' including wearable makers, health app developers, data brokers, and cash-pay providers not covered by HIPAA. These entities would be subject to privacy, security, and breach-notification standards equivalent to HIPAA, to be developed by HHS in consultation with the FTC within 18 months of enactment. Individuals would gain rights to privacy notices, access, amendment, and deletion of their health information, as well as the ability to transfer it between apps and devices. The bill also stipulates that regulated entities cannot collect or retain data beyond HIPAA's minimum-necessary rules and cannot sell health data to government agencies without proper legal orders.
Why It's Important?
This legislation is crucial for enhancing consumer data privacy in the rapidly evolving digital health landscape. As more individuals use wearables and health apps, a significant amount of sensitive health information is being collected outside the traditional healthcare system, creating a privacy gap. The bill aims to standardize data protection across various platforms, ensuring that personal health data from consumer devices receives similar safeguards as data held by hospitals. This could build greater trust in digital health tools, encouraging wider adoption while mitigating risks of data misuse or breaches. For consumers, it means more control over their health data and clearer rights regarding its use and sharing. For the digital health industry, it introduces new regulatory obligations, potentially increasing compliance costs but also fostering a more secure and trustworthy environment for innovation. Hospitals would also gain a modest lever, allowing them to require apps to accept specified terms of use when patients request data transfers from portals, addressing a current limitation where hospitals have little say over what happens to data once it leaves their system.
What's Next?
Despite the unanimous committee vote, the Health Information Privacy Reform Act faces a long path to becoming law. The bill currently sits on the Senate calendar without a scheduled floor vote and lacks a companion bill in the House of Representatives. Even if it were to pass both chambers and be enacted, real obligations for regulated entities would not take effect until 2028 at the earliest, following an 18-month period for HHS to develop and finalize new privacy, security, and breach-notification standards. The bipartisan support, while present with Senator Maggie Hassan joining as a Democratic cosponsor, needs to broaden to ensure passage before the end of the current Congress in January 2027, after which the bill would need to be reintroduced. Stakeholders like the Center for Democracy and Technology have indicated a desire for further improvements to the bill, suggesting ongoing legislative discussions and potential amendments. The ability of HHS to meet the 18-month rulemaking deadline is also a consideration, given its current backlog in finalizing other privacy rule updates.
Beyond the Headlines
The Health Information Privacy Reform Act highlights a broader societal challenge: adapting existing regulatory frameworks to keep pace with technological advancements. HIPAA, enacted in 1996, predates the widespread adoption of smartphones and wearable technology, creating a regulatory void for a significant portion of personal health data. This bill represents an attempt to modernize privacy protections for health information in the digital age, acknowledging that health data is no longer confined to traditional medical records. Its passage could set a precedent for how other sectors might need to update privacy laws to address data collected by consumer-facing technologies. The legislation also touches upon the evolving relationship between individuals, technology companies, and healthcare providers, emphasizing individual control over personal data. The debate around this bill may also spur further discussions on data ownership, the commercialization of health data, and the balance between innovation and privacy in the digital health ecosystem.








