The Health Information Privacy Reform Act establishes comprehensive privacy, security, and breach notification standards for health data held by entities currently outside the scope of HIPAA.
Bill Cassidy
Senator
LA
The Health Information Privacy Reform Act establishes comprehensive privacy, security, and breach notification standards for health data held by entities not currently covered by HIPAA. The bill mandates clear disclosures when health information leaves protected environments, sets new requirements for data de-identification, and directs the development of guidance for the use of health data in artificial intelligence. Additionally, it commissions a study on the ethics of compensating patients for the use of their identifiable health data in research.
This bill, the Health Information Privacy Reform Act, is a major attempt to plug the holes in our current privacy laws. Right now, HIPAA protects your data at the doctor’s office, but once that info hits a fitness app or a third-party website, those protections often vanish. This legislation requires the Department of Health and Human Services to set new, HIPAA-strength standards for 'regulated entities'—basically any company that handles your health data but isn't already covered by traditional medical privacy laws. It also gives you the right to delete or move your data, much like modern privacy laws in California or Europe.
One of the biggest changes involves what happens when you ask your doctor to send your records to a third party, like a new health app or a life insurance company. Under Section 6, the company receiving your data must give you a 'plain-language' written notice before they take it. This notice has to explicitly tell you that your info is leaving the HIPAA 'safety bubble' and explain exactly who else might see it. If you’re a patient trying to manage a chronic condition through a new digital platform, you’ll finally get a clear warning if that platform plans to sell your data to advertisers—and the bill requires them to get your specific consent before any such sale happens.
If you use a fitness tracker or a wellness app, Section 6 has a specific provision for you. Any tech that generates 'wellness data'—think heart rate, step counts, or even how often you take your meds—must now provide an advance notice that this data isn't protected by HIPAA. More importantly, they have to give you an easy way to opt out of having that data generated in the first place. For the millions of us wearing tech that tracks our every move, this moves the needle from 'hidden in the fine print' to an upfront choice about our digital footprint.
While the bill makes it easier to move your data, it might also make it more expensive in some cases. Section 3 clarifies the rules on fees. If you’re sending your records to yourself or another doctor, federal fee limits still apply (keeping it cheap or free). However, if you direct your records to a third party that isn't a healthcare provider, the bill allows entities to charge fees based on state law and demand payment upfront. For someone trying to share their medical history with a specialized research group or a non-medical service, those costs could add up quickly.
As healthcare goes high-tech, this bill tries to set some ground rules for Artificial Intelligence. Section 7 requires the government to explain how the 'minimum necessary' rule applies to AI. In plain English, this means companies can't just feed your entire medical history into a machine learning model if they only need a small slice of it to get the job done. For office workers in the health tech space or developers building these tools, this adds a new layer of accountability: you have to prove you’re using the smallest amount of data possible to make the algorithm work.