S-3097-119
Placed on Senate Legislative Calendar under General Orders. Calendar No. 538.
Sponsored by Bill Cassidy (R-LA)
What it does
This bill would direct the Secretary of Health and Human Services (HHS), in consultation with the FTC, to issue new regulations extending HIPAA-equivalent privacy, security, and breach notification protections to health data held by entities not currently covered by HIPAA — such as health apps, wearable device makers, and data brokers. It would give individuals new rights to access, amend, delete, and transfer their health data, and would prohibit regulated entities from selling health data to governments without a warrant, subpoena, or court order. It would also require HHS to set stronger national standards for de-identifying health data and to issue rules governing how the "minimum necessary" standard applies to artificial intelligence and machine learning applications that use health data.
Who benefits
All U.S. residents whose health data is collected by apps, wearables, or data brokers outside the traditional healthcare system — potentially hundreds of millions of people. Patients seeking stronger control over their health information, including the right to delete it. Individuals in states with weaker health privacy laws who would gain a federal floor of protection. Privacy-focused technology companies that already meet high standards and would benefit from a level playing field. Researchers and public health agencies that would receive clearer rules for lawful data use. Individuals concerned about law enforcement or government access to their health data, given the bill's warrant requirement for government transfers.
Who is hurt
Health technology companies, app developers, and wearable device makers that would face new compliance costs, including hiring privacy officers, updating data practices, and implementing security safeguards. Data brokers whose business models depend on buying and reselling health-related data would face significant new restrictions. Advertisers and marketers who rely on health data for targeting would lose access to data currently sold without individual consent. AI and machine learning companies that train models on large health datasets would face new data minimization requirements. States with stronger health privacy laws could see those laws preempted under the bill's HIPAA-aligned preemption framework. Smaller technology startups may face disproportionate compliance burdens relative to large incumbents.
Supporters argue
Supporters argue that HIPAA was written in 1996, long before smartphones, fitness trackers, and health apps existed, leaving a vast and growing category of sensitive health data entirely unprotected. They contend that data brokers and app developers currently collect, sell, and share detailed health information — including precise geolocation data that can reveal visits to clinics or pharmacies — with no meaningful consent requirement, and that this bill closes that gap by extending proven HIPAA-equivalent protections to these entities. They further argue that the bill's prohibition on selling health data to governments without legal process directly addresses documented cases of law enforcement purchasing location data to track individuals seeking medical care.
Opponents argue
Opponents argue that delegating broad rulemaking authority to HHS to define and regulate an entirely new category of "regulated entities" across the consumer technology sector raises serious questions under the major questions doctrine established in West Virginia v. EPA (2022), which requires clear congressional authorization for agency rules of vast economic significance. They contend that the compliance costs imposed on thousands of app developers, wearable makers, and data brokers — many of them small businesses — could stifle innovation and consolidate the market among large incumbents who can absorb regulatory overhead. They further argue that the bill's preemption of stronger state laws, such as Washington's My Health MY Data Act, could weaken protections in states that have moved ahead of federal standards.
Constitutional context
Congress's authority to regulate health data companies rests on the Commerce Clause (Art. I, §8, cl. 3), as these entities engage in interstate commercial activity. However, the bill's broad delegation to HHS to define and regulate an entirely new class of entities across the consumer technology sector may face scrutiny under the major questions doctrine (West Virginia v. EPA, 2022), which requires clear congressional authorization for agency rules of vast economic and political significance. Post-Loper Bright (2024), courts will independently assess whether the bill's statutory language provides sufficient authorization for HHS's implementing regulations, without deferring to the agency's own interpretation.
Checks and balances
The executive branch (HHS and FTC) gains significant new rulemaking and enforcement authority over a broad new class of regulated entities; checks include a mandatory HHS-FTC memorandum of understanding to prevent duplicative penalties, judicial review of agency rules under the post-Chevron independent judgment standard, and the bill's explicit preservation of FTC Section 5 authority.
Historical precedent
HIPAA (1996) and the HITECH Act (2009) established the existing federal health privacy framework for covered entities and business associates; this bill would extend a structurally similar regime to a new, broader category of non-healthcare-sector entities for the first time.