This bill prohibits data brokers from selling or transferring sensitive health and location data, granting enforcement power to the FTC, state attorneys general, and private citizens.
Mary Scanlon
Representative
PA-5
This bill, the Health and Location Data Protection Act of 2026, prohibits data brokers from selling or transferring sensitive health and location data about individuals. It grants enforcement authority to the Federal Trade Commission (FTC), state attorneys general, and private citizens. The FTC is tasked with issuing necessary regulations to implement these protections.
Imagine you’re using a period-tracking app or searching for a physical therapist to help with that nagging back injury. Right now, there’s a whole industry of 'data brokers'—companies you’ve likely never heard of and never interacted with—that can buy that health info and your GPS history, then turn around and sell it to the highest bidder. The Health and Location Data Protection Act of 2026 aims to cut the cord on this secondary market by flat-out prohibiting these brokers from selling, licensing, or trading your sensitive health and location data. Under Section 2, the ban kicks in either 180 days after the bill passes or as soon as the Federal Trade Commission (FTC) finishes its rulebook. This isn't just about your medical records; it includes 'inferred' data, meaning if a broker uses an algorithm to guess you’re pregnant based on your shopping habits and location, they can’t sell that insight either.
The bill defines a data broker as an entity that makes money by sharing data it didn't collect from you directly. Think of it like a middleman who buys your digital crumbs from various apps and sells them as a loaf of bread to advertisers or researchers. To make this stick, the law also forbids anyone—like that weather app or fitness tracker you actually do use—from providing your health or location data to these brokers in the first place (Section 2). There are common-sense exceptions: doctors and insurance companies already following HIPAA rules are exempt, and you can still choose to authorize a data transfer if you really want to. Journalists also get a pass to report on newsworthy info, ensuring that public interest stories aren't accidentally silenced by privacy rules.
We’ve all seen 'privacy' laws that are basically just suggestions, but this one comes with a heavy toolkit for enforcement. Section 3 allows the FTC to sue violators for civil penalties, and the math is eye-watering: fines can reach up to 15% of a company’s total annual revenue. For a massive tech conglomerate, that’s a 'sell the private jet' kind of number. Beyond the feds, your state’s Attorney General can jump in to protect residents, and—most importantly for the average person—you can personally sue. If a broker illegally moves your data, you can take them to court to force them to delete the info and pay for damages and your legal fees.
While the intent is clear, there are some 'wait and see' moments tucked into the text. The bill gives the FTC $1 billion to get this done (Section 5), but it also leaves the agency to define exactly what 'data' means in a way that’s 'reasonably linkable' to you (Section 4). This medium level of vagueness means the real-world impact depends on how aggressive the FTC gets with its definitions. For example, if you’re a construction worker whose GPS shows you spend ten hours a day at a specific job site, is that 'location data' protected, or is it too generic? The bill also creates a bit of a legal bottleneck by requiring almost all lawsuits to be handled in D.C. courts, which might make it harder for a regular person in California or Texas to see their day in court without a high-powered legal team. Still, by cutting off the supply line to data brokers, the bill attempts to ensure your private health journey doesn't become someone else's profit margin.