threat_intelligence478 wordsRead on Arc Codex

Health Privacy Legislation Advances in the Senate

Health Privacy Legislation Advances in the Senate CDT supports stronger privacy protections for consumer health data that falls outside of HIPAA. We’ve consistently called for privacy protections that move away from outdated notice and consent regimes and instead embrace limitations around corporate data practices that limit data collection, retention, sharing, and use of data that is necessary for the products and services that the consumer has requested. Greater protections are needed because many types of data can reveal sensitive information about a person’s health and healthcare choices. In addition to more traditional health data sets like medical records and charts, search queries, browsing history, the contents of communications, interactions with large language models (LLMs), and a person’s location data can reveal insights into a person’s health despite not typically being thought of as sources of “medical” or health-related data. The managers amendment to S.3097 – Health Information Privacy Reform Act that passed the Senate HELP Committee markup today is a positive step and begins to address several of the core privacy protections that CDT has advocated for. While the bill as amended is not perfect, we look forward to working with lawmakers to further improve the bill. The bill as amended takes a number of steps to keep people’s health data private. For example, the data collection, use, and sharing limitations detailed in the bill will result in less consumer health data being collected in the first place. Moreover, if data is collected, there are limits on how that data can be used and shared. The bill also ensures that people will have access to, and the ability to delete, their data and prohibits the government from buying people’s health data. While these protections would represent substantial progress in addressing the lack of privacy protections for consumer health data, there are still elements of the bill that can be improved. For example, the bill still lacks clarity regarding how HHS and the FTC will enforce the bill. Clarifying the working relationship between HHS and FTC, particularly given FTC’s experience with non-HIPAA health data, regarding the promulgation of regulations setting privacy, security, and breach notification standards would significantly improve the bill. Finally, the bill should include additional avenues for enforcement beyond just federal agencies. The bill should also include a private right of action to ensure the consumers who are harmed can hold companies accountable for harmful data practices. The bill should also clarify that state-level privacy regulators have jurisdiction to enforce this bill. We’re encouraged to see meaningful congressional action to address a long-standing gap in health privacy. As amended, this bill extends HIPAA-like privacy protections to vast amounts of health data that currently lacks meaningful protections. And while it’s not perfect, we look forward to continuing to work with members of congress to improve upon this bill and ensure that people’s health data is private and protected.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.