The Health Information Privacy Reform Act has cleared a significant legislative hurdle after the Senate HELP Committee advanced the bill by a unanimous 22-0 vote. Originally introduced in November 2025 by Committee Chair Sen. Bill Cassidy, the legislation seeks to close major gaps in health data privacy protections by extending HIPAA-like safeguards to information collected outside traditional healthcare settings. The bill now proceeds to a full Senate vote, though whether it can secure passage in both chambers remains uncertain.
Current HIPAA regulations only protect health information handled by healthcare providers, health plans, clearinghouses, and their business associates. This narrow scope leaves vast amounts of sensitive health data unprotected, including information collected by fitness trackers, health apps, smartwatches, and consumer wellness devices. While existing federal protections like Section 5 of the FTC Act and the FTC's Health Breach Notification Rule apply to some non-HIPAA data, these regulations are considerably less stringent than HIPAA requirements.
The proposed legislation would require HHS, working with the FTC, to establish comprehensive privacy, security, and breach notification standards within 18 months of enactment. These standards must provide protections at least equivalent to existing HIPAA rules and would apply to all entities processing consumer health data outside HIPAA's current scope. The bill mandates implementation of physical, technical, and administrative safeguards based on frameworks like the NIST Cybersecurity Framework, along with data minimization requirements limiting collection to necessary information only. Covered entities would need to establish permitted and prohibited uses, obtain proper authorization for disclosures, and apply minimum necessary standards when accessing health data.
Consumers would gain significant new rights over their health information under the legislation. Individuals could request deletion of their health data within 30 days, receive privacy notices explaining how their information will be used, access their complete health records, and request amendments to inaccurate data. The bill also requires breach notifications following security incidents, mirroring HIPAA's existing breach notification requirements. Additionally, HHS must issue guidance within one year on how the minimum necessary standard applies to artificial intelligence and machine learning applications processing health data.
Organizations collecting consumer health data should begin preparing for potential compliance requirements by reviewing current data collection practices and security controls. Security teams should assess whether existing safeguards meet NIST Cybersecurity Framework standards and evaluate data minimization opportunities. While the bill's passage is not guaranteed, the unanimous committee vote suggests strong bipartisan support. Organizations should monitor the legislation's progress and consider conducting gap analyses against HIPAA standards to identify areas requiring remediation if the bill becomes law.
Source: https://www.hipaajournal.com/health-information-privacy-reform-act/


