Utopia Tech
HealthcareAI-assisted4 min read

Health Information Privacy Reform Act Advanced by HELP Committee

The Health Information Privacy Reform Act, which extends HIPAA-like protections to health data collected by non-regulated entities such as fitness trackers and health apps, has been unanimously advanced by the Senate HELP Committee with a 22-0 vote. The legislation addresses significant privacy gaps by requiring HHS to establish privacy, security, and breach notification standards for consumer hea

UT

Utopia Tech

August 10, 2026 · 4 min read

Share

The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by the HIPAA Rules, has been advanced by a Senate committee. The legislation was proposed by Senate Health, Education, Labor, and Pensions (HELP) Committee Chair Sen. Bill Cassidy in November 2025, and an amended version of the bill was advanced by the HELP Committee by a 22-0 vote.

The bill will now proceed to a full Senate vote. The Health Insurance Portability and Accountability Act (HIPAA) regulates personally identifiable health information created, stored, maintained, or transmitted by healthcare providers, health plans, healthcare clearinghouses and their business associates; however, a considerable amount of health data falls outside the protections of HIPAA, even though that information would be covered by HIPAA if it was collected, stored or transmitted by any of those entities.

Detailed health information is now collected by health apps, wearable devices such as fitness trackers, and many other consumer health devices and applications; however, there are few regulations governing how that data is protected nor limits on disclosures of that information. The Health Information Privacy Reform Act seeks to address these privacy gaps by expanding the privacy protections of HIPAA to cover “consumer health data” collected by non-HIPAA-regulated entities, while also making minor updates to the HIPAA Rules.

Essentially, the bill will ensure that health data is protected, no matter who collects the information. If passed, within 18 months of enactment, the Secretary of the Department of Health and Human Services (HHS), in consultation with the Federal Trade Commission (FTC), is required to promulgate regulations establishing and implementing HIPAA-like privacy, security, and breach notification standards for “applicable health information” processed by regulated entities and their service providers.

They include establishing permitted uses and disclosures without written authorization; establishing the requirements for disclosures authorized by an individual, including how authorization can be revoked; and establishing prohibited uses and disclosures. The bill seeks to establish a minimum necessary standard for the request, use, and disclosure of health data, along with data minimization standards to limit the health information that is collected.

Individuals will be given rights over their health data that are, at least, equivalent to the rights over protected health information under the HIPAA Privacy Rule. Those rights will include the right to request deletion of health information within 30 days of submitting a request. The bill also calls for HIPAA Security Rule-like security standards, such as physical, technical, and administrative safeguards for health data in written and oral form, and breach notification requirements, should health data be impermissibly disclosed or exposed/stolen in a security incident.

The bill also calls for the HHS to issue guidance on HIPAA-protected data used with artificial intelligence and machine learning platforms, and how the HIPAA minimum necessary standard applies in such cases. The guidance must be issued by OCR within one year of the date of enactment, and also requires HIPAA-covered entities to inform the individual that the HIPAA Rules no longer apply to health data disclosed in response to a right of access request, including how that information may be redisclosed.

While the bill has strong bipartisan support, it is currently unclear whether that support is strong enough to pass a full Senate and House vote. November 10, 2026: HELP Committee Chair Introduces Health Information Privacy Reform Act to Protect Americans’ Health Data New legislation – the Health Information Privacy Reform Act – has been introduced to improve privacy protections for health information that is not currently covered by the Health Insurance Portability and Accountability Act ( HIPAA ).

Under HIPAA, there are strict limits on uses and disclosures of personally identifiable health information, and safeguards must be implemented to prevent unauthorized access to physical and electronic protected health information. The problem for consumers is that the scope of HIPAA is quite narrow. HIPAA only applies to health information that is created, collected, maintained, stored, or transmitted by a HIPAA-covered entity (healthcare provider, health plan, or healthcare clearinghouse) or a business associate of a HIPAA-covered entity.

Health apps, such as ovulation and fertility tracking apps, can collect large amounts of personally identifiable health information. While the health data would be classed as protected health information (PHI) and be subject to HIPAA protections if it were collected by a healthcare provider, the health information collected by health apps, smartwatches, and other wearable devices is rarely protected by HIPAA or the HITECH Act of 2009 , which applies to certified health information technologies.

When HIPAA was enacted more than two decades ago, health information was generally only collected and stored by healthcare providers, health plans, healthcare clearinghouses, and vendors of those entities; however, today, technologies that collect health data are widely used outside of a hospital or doctor’s office. While there are federal laws that apply to non-HIPAA-protected health data, such as Section 5 of the FTC Act and the FTC’s Health Breach Notification Rule , they are not as stringent as HIPAA.

Some states, such as California, have introduced legislation to improve privacy protections for non-HIPAA health data, but state laws are patchy. Privacy protections can differ considerably from state to state. U.

S. Senator Bill Cassidy, M. D.

(R-LA), chair of the Senate Health, Education, Labor, and Pensions (HELP) Committee, is looking to change that with the Health Information Privacy Reform Act .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content