This bill directs the Department of Health and Human Services, working with the Federal Trade Commission, to create new federal privacy, security, and breach-notification rules for health-related information that currently falls outside HIPAA's protections, such as data collected by wellness apps, fitness trackers, and other digital health tools. It would extend HIPAA-like rights to consumers using these technologies, including the ability to access, amend, delete, and transfer their health data, while requiring companies to get written consent before selling such information and to limit how much data they collect and retain. The bill also restricts government entities from purchasing or obtaining this health data without a warrant or court order, sets new national standards for de-identifying health data to prevent re-identification, and updates rules on substance use disorder record confidentiality. Companies that violate these rules would face civil penalties similar to those under existing HIPAA enforcement. Key deadlines include new regulations within 18 months of enactment, guidance on data access fees within 180 days, and de-identification standards within one year, with most protections primarily affecting technology companies, data brokers, and other entities handling health information that are not already regulated under HIPAA.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.