<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MUR22493-WT3-N7-VYL"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>104 S4738 IS: Stop Commercial Use of Health Data Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-08-02</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 4738</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220802">August 2, 2022</action-date><action-desc><sponsor name-id="S311">Ms. Klobuchar</sponsor> (for herself and <cosponsor name-id="S316">Mr. Whitehouse</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To protect the privacy of personally-identifiable health data, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Stop Commercial Use of Health Data Act</short-title></quote>.</text></section><section id="id1AF527A232764DFAA70B56109435F1FA"><enum>2.</enum><header>Privacy of personally-identifiable health data</header><subsection id="idD4E8DEBD794943488301901E9C88A50F"><enum>(a)</enum><header>Prohibition on the use of personally-Identifiable health data in commercial advertising</header><paragraph id="id920E67BFD8F94ACEAD7DA9F258F29DC9"><enum>(1)</enum><header>In general</header><text>It shall be unlawful for any covered entity to use the personally-identifiable health data of an individual that is collected from any source (including data volunteered by an individual, medical center-derived data, data from a wearable fitness tracker, data from web browsing history, or any other source determined appropriate by the Commission) for commercial advertising.</text></paragraph><paragraph id="idE3713039C1814FE6BE8AE57F48DC071D"><enum>(2)</enum><header>Exception for public health campaigns</header><text>The prohibition under paragraph (1) shall not apply to any public health campaign directed toward individuals or subpopulations of individuals. </text></paragraph></subsection><subsection id="id587E76988EB94DF985D0A3E5DA21A723"><enum>(b)</enum><header>Right of access and deletion</header><paragraph id="id36F3D424D859494E91A9F605CE670280"><enum>(1)</enum><header>Right of access</header><subparagraph id="id109FDF65C08E487EAA6DFF6271341F1F"><enum>(A)</enum><header>In general</header><text>A covered entity shall make available an easy-to-use mechanism by which an individual, upon verified request, may access any personally-identifiable health data relating to such individual that is retained by such covered entity.</text></subparagraph><subparagraph id="id823AE7589E7342699A75500AD2E0DF05"><enum>(B)</enum><header>Format</header><text>A covered entity shall make the information described in subparagraph (A) available in both a human-readable and a machine-readable format.</text></subparagraph></paragraph><paragraph id="id7724EE44479745ECB7F082898AF46BCD"><enum>(2)</enum><header>Right of deletion</header><text>A covered entity shall make available an easy-to-use mechanism by which an individual, upon verified request, may request the deletion of any personally-identifiable health data relating to such individual that is retained by such covered entity.</text></paragraph><paragraph id="id9F1792AE420547DA96C4FCAAC3F0A823" commented="no"><enum>(3)</enum><header>Requirements for access and deletion</header><subparagraph id="id672741320981469F90562137C14863A1" commented="no"><enum>(A)</enum><header>Timeline for complying with requests</header><text>A covered entity shall comply with a verified request received under this subsection without undue delay, but not later than 45 days after the date on which such covered entity receives such verified request.</text></subparagraph><subparagraph id="idA64B3BBBC05C4A3DA7CE00227D5ACDBB" commented="no"><enum>(B)</enum><header>Fees prohibited</header><text>A covered entity may not charge a fee to an individual for a request made under this subsection.</text></subparagraph><subparagraph id="id2D905D99CD7A4A4F83F1024376D90534" commented="no"><enum>(C)</enum><header>Rules of construction</header><text>Nothing in this section shall be construed—</text><clause commented="no" id="id6C091516960C4B1180F1F0FA7C0BB85E"><enum>(i)</enum><text>as supplanting or abrogating any provision of the Health Insurance Portability and Accountability Act of 1996 (<external-xref legal-doc="public-law" parsable-cite="pl/104/191">Public Law 104–191</external-xref>); or</text></clause><clause commented="no" id="idF585EDB948FE414BB0A24FC7A9F1DCCB"><enum>(ii)</enum><text>to require a covered entity to—</text><subclause id="id337722BA5CFC4F838CD668D2DCBC9ED1" commented="no"><enum>(I)</enum><text>take an action that would convert information that is not personally-identifiable health data into personally-identifiable health data;</text></subclause><subclause id="id67CDE27552254B2699E6F6E37EE030FF" commented="no"><enum>(II)</enum><text>collect or retain personally-identifiable health data that such covered entity would not otherwise collect or retain; or</text></subclause><subclause id="idB75DB9A5A7C149319213F1A317CECD4A" commented="no"><enum>(III)</enum><text>retain personally-identifiable health data longer than such covered entity would otherwise retain such data.</text></subclause></clause></subparagraph></paragraph></subsection></section><section id="idCC523DF1BF6F4DA6897F3CFA165CD9CC"><enum>3.</enum><header>Enforcement</header><subsection id="id074116C2643F4BBC9C788D76972B1874"><enum>(a)</enum><header>Enforcement by the Commission</header><paragraph id="idf046593f69114c7e9115a785510cc4f5"><enum>(1)</enum><header>Unfair and deceptive acts or practices</header><text>A violation of section 2 or a regulation promulgated thereunder shall be treated as an unfair and deceptive act or practice proscribed under section 5(a) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)</external-xref>).</text></paragraph><paragraph id="idc41ba26d78ce4cf1849b7fbd2e074823"><enum>(2)</enum><header>Powers of the Commission</header><subparagraph id="id108fb464aced4fa2af3df5a0ef18cf82"><enum>(A)</enum><header>In general</header><text>The Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this Act.</text></subparagraph><subparagraph id="id27fc2abb00f74d2dad172d9375cf502d"><enum>(B)</enum><header>Privileges and immunities</header><text>Any person who violates this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>).</text></subparagraph><subparagraph id="idf0a21137a0da44e2984266e87a1d5d34"><enum>(C)</enum><header>Authority preserved</header><text>Nothing in this Act shall be construed to limit the authority of the Commission under any other provision of law.</text></subparagraph></paragraph><paragraph id="idd92f7a22e21849889b822797bc9dcad1" commented="no"><enum>(3)</enum><header>Rulemaking</header><text>The Commission shall promulgate in accordance with section 553 of title 5, United States Code, such rules as may be necessary to carry out this Act.</text></paragraph></subsection><subsection commented="no" id="idF101BB1A25AD4092A84C518E0F330515"><enum>(b)</enum><header>Enforcement by individuals</header><paragraph id="id2228d5b243a74ce5b6a8b75a2d33638f"><enum>(1)</enum><header>In general</header><text>Any individual who suffers an injury (including the denial of a right established under this Act) as a result of a violation of this Act or a regulation promulgated thereunder by a covered entity may bring a civil action against such covered entity in Federal district court.</text></paragraph><paragraph id="id1acd639e581346ceaee19673759e5b7c"><enum>(2)</enum><header>Relief</header><text>In a civil action brought under paragraph (1) in which the plaintiff prevails, the court may award the plaintiff—</text><subparagraph id="idaa82129a2a294f5eb62d87ee8a1085c4"><enum>(A)</enum><text>for a—</text><clause id="id08DD7FE715FD401E9587CFD2835430CF"><enum>(i)</enum><text>violation of section 2(a), an amount equal to the greater of—</text><subclause id="id1522D8AF272741CB88FDAB75B71BA7B0"><enum>(I)</enum><text>$1,000 in statutory damages per commercial advertisement generated in violation of such subsection; or</text></subclause><subclause id="id3DF227D30AA3480A9172382D328203E8"><enum>(II)</enum><text>the sum of any actual damages sustained; or</text></subclause></clause><clause id="id95F1382522664A4E8B67032F6D4D4A20"><enum>(ii)</enum><text>violation of section 2(b), an amount equal to the sum of any actual damages sustained; and</text></clause></subparagraph><subparagraph id="idb722e0e2eb994bcdbe7f3ba61ee16f1e"><enum>(B)</enum><text>reasonable attorney’s fees and litigation costs. </text></subparagraph></paragraph></subsection></section><section id="id1A21A870A6564B0E99ACD36E3A3DACBB"><enum>4.</enum><header>Definitions</header><subsection id="idC5C30EC89A124913B7F2AFA8600A0262"><enum>(a)</enum><header>In general</header><text>In this Act:</text><paragraph id="id48B6E894E4B24954925D926151C1BC31"><enum>(1)</enum><header>Collect</header><text>The term <term>collect</term> means, with respect to personally-identifiable health data, to obtain such information in any manner.</text></paragraph><paragraph id="idF39133B421414C598B46602DC205EEB8"><enum>(2)</enum><header>Commercial advertising</header><text>The term <term>commercial advertising</term> means communications that promote the sale of or interest in goods or services, including goods or services that are published digitally, via video or audio, or in print.</text></paragraph><paragraph id="id7ABD835D99404C94B293B7BADF328F4E"><enum>(3)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="id084464FBF3154C858E0AA8CDED90D69B"><enum>(4)</enum><header>Covered entity</header><text>The term <term>covered entity</term> means a person that—</text><subparagraph id="idDA00159F8C2F4CA38FBD2FC6B412BD4E"><enum>(A)</enum><text>is subject to the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>); and</text></subparagraph><subparagraph id="idBADD926C2850414FBC2DBB67D9B7BF8A"><enum>(B)</enum><text>collects, on an annual basis, the personally-identifiable health data of not less than 1,000 individuals in the United States.</text></subparagraph></paragraph></subsection><subsection id="id52B50F23CD9A4412B0767F4BE4A21816"><enum>(b)</enum><header>Rulemaking</header><text>Not later than 180 days after the date of enactment of this Act, the Commission shall conduct a rulemaking pursuant to section 553 of title 5, United States Code, to define the terms <term>public health campaign</term> and <term>personally-identifiable health data</term> for purposes of this Act.</text></subsection></section></legis-body></bill> 

