Bill Seeking HIPAA-like Protections for Consumer Health Data Advanced by Senate Committee

Personally identifiable health information that is created, stored, maintained, or transmitted by a HIPAA-regulated entity is subject to the HIPAA Rules. Limits are placed on uses and disclosures of that information, and safeguards must be implemented to ensure the privacy and security of that information. The same rules do not apply to health information collected by a wearable device or health and wellness app.

Take pulse and blood pressure readings, for example. When that information is collected and entered into your medical record by your physician, the information must be protected, and uses are restricted. The health information cannot be sold or used to serve you adverts, such as ads for medications for reducing your blood pressure. Enter that information into a wellness app, or record it using a wearable device, and your data may be sold or used for those and other purposes.

The privacy and security of personally identifiable health information is dictated not by the type of information, but rather by who collects it. It is worth stating that if health information is collected by a HIPAA-regulated entity, a hospital, for example, and you request they provide your records to you, as is your right under HIPAA, the information they send is no longer subject to HIPAA.

Wearable devices, smartwatches, fitness trackers, wellness apps, and ovulation/fertility trackers are massively popular. Around 40% of Americans have a wearable device, and tens of millions of Americans use health and wellness apps, yet these devices and apps are largely unregulated. Through these devices and apps, a huge volume of health information is collected and stored. That data is not covered by HIPAA, and the companies that collect that information can do what they like with that data. They will only fall foul of the law if they use or disclose data in ways that are not stated in their privacy policies.

There have been several attempts to introduce federal privacy legislation in the United States, but all have failed. One bill, however, has recently made progress. The Health Information Privacy Reform Act, introduced last year by Senate Health, Education, Labor and Pensions (HELP) Committee chairman Sen. Bill Cassidy (R-LA), has been advanced by the HELP Committee in a unanimous 22-0 vote, and will now go to the Senate for a full vote.

The bill seeks to address the privacy gap for healthcare data collected, stored, and transmitted by consumer wearable devices and health apps. The bill calls for the HHS, in consultation with the FTC, to promulgate regulations to establish HIPAA-like privacy, security, and breach notification standards for health data collected by non-HIPAA-regulated entities. Those regulations must provide at least the same level of protections as HIPAA, including limits on uses and disclosures, data security standards, and consumer rights, including the right to request data be deleted. In the event of violations, civil monetary penalties would be imposed, using a similar, tiered penalty structure to HIPAA.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

The bill, if enacted, would also modify HIPAA, inasmuch as it would require HIPAA-regulated entities to clearly inform individuals exercising a HIPAA Right of Access request that any disclosed data pursuant to that request is no longer protected by HIPAA, and that the information may be redisclosed.

While the unanimous Senate vote is significant and the bill has strong bipartisan support, it is unclear if sufficient support could be found in the Senate and the House to get the bill signed into law. If that does happen, it could take years before the regulations are enacted and compliance is enforced. Healthcare rulemaking is a very slow process.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/