CDT supports stronger privacy protections for consumer health data that falls outside of HIPAA. We’ve consistently called for privacy protections that move away from outdated notice and consent regimes and instead embrace limitations around corporate data practices that limit data collection, retention, sharing, and use of data that is necessary for the products and services that the consumer has requested.
Greater protections are needed because many types of data can reveal sensitive information about a person’s health and healthcare choices. In addition to more traditional health data sets like medical records and charts, search queries, browsing history, the contents of communications, interactions with large language models (LLMs), and a person’s location data can reveal insights into a person’s health despite not typically being thought of as sources of “medical” or health-related data.
The managers amendment to S.3097 – Health Information Privacy Reform Act that passed the Senate HELP Committee markup today is a positive step and begins to address several of the core privacy protections that CDT has advocated for. While the bill as amended is not perfect, we look forward to working with lawmakers to further improve the bill.
The bill as amended takes a number of steps to keep people’s health data private. For example, the data collection, use, and sharing limitations detailed in the bill will result in less consumer health data being collected in the first place. Moreover, if data is collected, there are limits on how that data can be used and shared. The bill also ensures that people will have access to, and the ability to delete, their data and prohibits the government from buying people’s health data.
While these protections would represent substantial progress in addressing the lack of privacy protections for consumer health data, there are still elements of the bill that can be improved. For example, the bill still lacks clarity regarding how HHS and the FTC will enforce the bill. Clarifying the working relationship between HHS and FTC, particularly given FTC’s experience with non-HIPAA health data, regarding the promulgation of regulations setting privacy, security, and breach notification standards would significantly improve the bill.
Finally, the bill should include additional avenues for enforcement beyond just federal agencies. The bill should also include a private right of action to ensure the consumers who are harmed can hold companies accountable for harmful data practices. The bill should also clarify that state-level privacy regulators have jurisdiction to enforce this bill.
We’re encouraged to see meaningful congressional action to address a long-standing gap in health privacy. As amended, this bill extends HIPAA-like privacy protections to vast amounts of health data that currently lacks meaningful protections. And while it’s not perfect, we look forward to continuing to work with members of congress to improve upon this bill and ensure that people’s health data is private and protected.
Facts Only
* CDT supports stronger privacy protections for consumer health data outside HIPAA.
* The goal is to move away from notice/consent regimes toward limiting corporate data practices regarding collection, retention, sharing, and use.
* Data sources include medical records, search queries, browsing history, communications, LLM interactions, and location data.
* Managers amendment to S.3097 passed the Senate HELP Committee markup.
* The bill limits data collection to reduce the amount of health data collected.
* The bill limits how collected data can be used and shared.
* The bill ensures access to and the ability to delete personal health data.
* The bill prohibits the government from buying people’s health data.
* The bill lacks clarity on how HHS and the FTC will enforce it regarding privacy, security, and breach notification standards.
* Proponents suggest including a private right of action for accountability and clarifying state regulator jurisdiction.
Executive Summary
Full Take
The narrative posits that modern data collection methods—extending far beyond traditional medical records—create a significant gap in health privacy, necessitating legislative intervention to enforce data minimization principles on non-HIPAA health information. The core tension lies between the convenience of vast data aggregation utilized by technology and the fundamental right to informational self-determination. The suggested improvements focus on operationalizing existing legal frameworks (HHS/FTC enforcement) and expanding accountability mechanisms (private rights of action, state jurisdiction). This reflects a broader pattern where regulatory gaps in rapidly evolving technological domains are addressed piecemeal rather than through comprehensive structural reform. The implicit assumption is that without explicit limits on data usage across diverse digital vectors, the asymmetry of information control inherently favors corporate entities over individual health autonomy. The necessary evolution involves not just passing legislation, but defining novel jurisdictional relationships and establishing enforceable deterrents for powerful data stewards.
What operational mechanisms exist to effectively harmonize disparate regulatory bodies like HHS and the FTC when dealing with complex, cross-jurisdictional privacy standards in the age of AI-driven data processing? How do existing legal structures account for privacy rights when data flows across state lines and crosses into the realm of non-medical digital behavior? What are the long-term systemic consequences if accountability remains fragmented between federal agencies and private entities?
Sentinel — Human
The text reads like advocacy commentary, blending factual updates on legislation with calls for specific regulatory improvements, indicating a human-driven perspective rather than pure informational reporting.
