<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-GOE21075-2HR-H1-VX9"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S81 IS: Public Health Emergency Privacy Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-01-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 81</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210128">January 28, 2021</action-date><action-desc><sponsor name-id="S341">Mr. Blumenthal</sponsor> (for himself, <cosponsor name-id="S327">Mr. Warner</cosponsor>, <cosponsor name-id="S369">Mr. Markey</cosponsor>, <cosponsor name-id="S354">Ms. Baldwin</cosponsor>, <cosponsor name-id="S361">Ms. Hirono</cosponsor>, <cosponsor name-id="S370">Mr. Booker</cosponsor>, <cosponsor name-id="S306">Mr. Menendez</cosponsor>, <cosponsor name-id="S363">Mr. King</cosponsor>, <cosponsor name-id="S330">Mr. Bennet</cosponsor>, <cosponsor name-id="S366">Ms. Warren</cosponsor>, <cosponsor name-id="S311">Ms. Klobuchar</cosponsor>, and <cosponsor name-id="S253">Mr. Durbin</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSHR00">Committee on Health, Education, Labor, and Pensions</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To protect the privacy of health information during a national health emergency.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Public Health Emergency Privacy Act</short-title></quote>.</text></section><section id="id8407f6f9565b4a28b05c77e3202bc33f"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id4b99c9e7a32e407b94f339cd526fab55"><enum>(1)</enum><header>Affirmative express consent</header><text>The term <term>affirmative express consent</term> means an affirmative act by an individual that—</text><subparagraph id="ide7e7733847374490845f24291d3fc255"><enum>(A)</enum><text>clearly and conspicuously communicates the individual’s authorization of an act or practice;</text></subparagraph><subparagraph id="idba9a39bac7d941859de1235290961c2f"><enum>(B)</enum><text>is made in the absence of any mechanism in the user interface that has the purpose or substantial effect of obscuring, subverting, or impairing decision making or choice to obtain consent; and</text></subparagraph><subparagraph id="id3da9a90e72c5481eb7a2826ac4b30ea3"><enum>(C)</enum><text>cannot be inferred from inaction.</text></subparagraph></paragraph><paragraph id="idbd5c855d8aa544559515a93bf498e038"><enum>(2)</enum><header>Collect</header><text>The term <term>collect</term>, with respect to emergency health data, means obtaining in any manner by a covered organization.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id86040364fe2640a39232877244017c1a"><enum>(3)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission. </text></paragraph><paragraph id="id91b3de14c9fb4dfc9f7084324985fac2"><enum>(4)</enum><header>Covered organization</header><subparagraph id="id0d9f7649e9794ab088339c1b1597a1f7"><enum>(A)</enum><header>In general</header><text>The term <term>covered organization</term> means any person (including a government entity)—</text><clause id="idbed50fa968e643b0879ba6e37e3fb08c"><enum>(i)</enum><text>that collects, uses, or discloses emergency health data electronically or through communication by wire or radio; or</text></clause><clause id="idf2e36672d4a8445384e0301719e41d2d"><enum>(ii)</enum><text>that develops or operates a website, web application, mobile application, mobile operating system feature, or smart device application for the purpose of tracking, screening, monitoring, contact tracing, or mitigation, or otherwise responding to the COVID–19 public health emergency.</text></clause></subparagraph><subparagraph id="id3e9f4c80cf0b45829cc77f8bd62b96ee"><enum>(B)</enum><header>Exclusions</header><text>The term <term>covered organization</term> does not include—</text><clause id="idd84e6cccc75344bca4219113987d3994"><enum>(i)</enum><text>a health care provider;</text></clause><clause id="id4f067b98aff343248d5bba75fbcafe01"><enum>(ii)</enum><text>a person engaged in a de minimis collection or processing of emergency health data;</text></clause><clause id="idd213b5a96aa5459482c496f12ffae97b"><enum>(iii)</enum><text>a service provider;</text></clause><clause id="id2fe9338e335e4f6e8055c471f1f711f1"><enum>(iv)</enum><text>a person acting in their individual or household capacity; or</text></clause><clause id="idfcee791927d7495fa68111a752f50786"><enum>(v)</enum><text>a public health authority.</text></clause></subparagraph></paragraph><paragraph id="idfc222c2573734342b45f05094eec39f9"><enum>(5)</enum><header>Demographic data</header><text>The term <term>demographic data</term> means information relating to the actual or perceived race, color, ethnicity, national origin, religion, sex, gender, gender identity, sexual orientation, age, Tribal affiliation, disability, domicile, employment status, familial status, immigration status, or veteran status of an individual or group of individuals.</text></paragraph><paragraph id="id731c42107c7a4162a25ea137001c18f2"><enum>(6)</enum><header>Device</header><text>The term <term>device</term> means any electronic equipment that is primarily designed for or marketed to consumers.</text></paragraph><paragraph id="idc518d6898c3543a896751a39b5d9a804"><enum>(7)</enum><header>Disclosure</header><text>The term <term>disclosure</term>, with respect to emergency health data, means the releasing, transferring, selling, providing access to, licensing, or divulging in any manner by a covered organization to a third party.</text></paragraph><paragraph id="id4176b4c9a3da4a938fe951e87b12ae57"><enum>(8)</enum><header>Emergency health data</header><text>The term <term>emergency health data</term> means data linked or reasonably linkable to an individual or device, including data inferred or derived about the individual or device from other collected data provided such data is still linked or reasonably linkable to the individual or device, that concerns the public COVID–19 health emergency. Such data includes—</text><subparagraph id="idd1f6e4c518e74b41a1304ebfaee39261"><enum>(A)</enum><text>information that reveals the past, present, or future physical or behavioral health or condition of, or provision of healthcare to, an individual, including—</text><clause id="ida3f6a491e745485a8c182cc50ae1fdf7"><enum>(i)</enum><text>data derived from the testing or examination of a body part or bodily substance, or a request for such testing;</text></clause><clause id="id02a0f56b8dd14cd39175f52dd076dfea"><enum>(ii)</enum><text>whether or not an individual has contracted or been tested for, or an estimate of the likelihood that a particular individual may contract, such disease or disorder; and</text></clause><clause id="idd7666b4748914499b1a3523bdf818b23"><enum>(iii)</enum><text>genetic data, biological samples, and biometrics; and</text></clause></subparagraph><subparagraph id="id17de355b89c5473eacf5382a5d41c12f"><enum>(B)</enum><text>other data collected in conjunction with other emergency health data or for the purpose of tracking, screening, monitoring, contact tracing, or mitigation, or otherwise responding to the COVID–19 public health emergency, including—</text><clause id="id93b3d71215f740d18ef295d472d359e2"><enum>(i)</enum><text>geolocation data, when such term means data capable of determining the past or present precise physical location of an individual at a specific point in time, taking account of population densities, including cell-site location information, triangulation data derived from nearby wireless or radio frequency networks, and global positioning system data;</text></clause><clause id="ide874aaf8e01f4dcabe892b9f7d6d1646"><enum>(ii)</enum><text>proximity data, when such term means information that identifies or estimates the past or present physical proximity of one individual or device to another, including information derived from Bluetooth, audio signatures, nearby wireless networks, and near-field communications;</text></clause><clause id="id187a6f3da1ac413c94e03c903a5a6813"><enum>(iii)</enum><text>demographic data;</text></clause><clause id="id89fb5a7fabc9479aa5ff547172d1a31a"><enum>(iv)</enum><text>contact information for identifiable individuals or a history of the individual’s contacts over a period of time, such as an address book or call log; and</text></clause><clause commented="no" display-inline="no-display-inline" id="iddfd4142941b54effa30f931e4e07c680"><enum>(v)</enum><text>any other data collected from a personal device. </text></clause></subparagraph></paragraph><paragraph id="id4768508a009645ba89b555d5e0623470"><enum>(9)</enum><header>Government entity</header><text>The term <term>government entity</term> includes a Federal agency, a State, a local government, and other organizations, as such terms are defined in section 3371 of title 5, United States Code. </text></paragraph><paragraph id="id2391f0e4e18a4d93a362a61f3ae062cc"><enum>(10)</enum><header>Health care provider</header><text>The term <term>health care provider</term> has the meaning given the term <term>eligible health care provider</term> in title VIII of division B of the CARES Act (<external-xref legal-doc="public-law" parsable-cite="pl/116/136">Public Law 116–136</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc6e7997fb92444ecb5e0a8cbe32e9c8d"><enum>(11)</enum><header>HIPAA regulations</header><text>The term <term>HIPAA regulations</term> means parts 160 and 164 of title 45, Code of Federal Regulations. </text></paragraph><paragraph id="id1c788979e5c0454d91974d1be06ecefd"><enum>(12)</enum><header>Public health authority</header><text>The term <term>public health authority</term> means an entity that is authorized by law to collect or receive information for the purpose of preventing or controlling disease, injury, or disability including, but not limited to, the reporting of disease, injury, vital events such as birth or death, and the conduct of public health surveillance, public health investigations, and public health interventions, and a person, such as a designated agency or associate, acting under a grant of authority from, or under a contract with, such public entity, including the employees or agents of such entity or its contractors or persons or entities to whom it has granted authority.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida570ec3dfa8b4b8c80e4cc7ceddace44"><enum>(13)</enum><header>COVID–19 Public health emergency</header><text>The term <term>COVID–19 public health emergency</term> means the outbreak and public health response pertaining to Coronavirus Disease 2019 (COVID–19), associated with the emergency declared by the Secretary on January 31, 2020, under section 319 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/247d">42 U.S.C. 247d</external-xref>), and any renewals thereof and any subsequent declarations by the Secretary related to the coronavirus. </text></paragraph><paragraph id="id5c8811ba6e8e46a085d564b1898deeb7"><enum>(14)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Health and Human Services.</text></paragraph><paragraph id="idf6d24be4cac64dceae88639f8e81efb7"><enum>(15)</enum><header>Service provider</header><subparagraph id="id7533E94E610C4D4E8653558199CC648E"><enum>(A)</enum><header>In general</header><text>The term <term>service provider</term> means a person that collects, uses, or discloses emergency health data for the sole purpose of, and only to the extent that such entity is, conducting business activities on behalf of, for the benefit of, under instruction of, and under contractual agreement with a covered organization.</text></subparagraph><subparagraph id="idf4f8d9b3893a4fc990127027b1e3a07c"><enum>(B)</enum><header>Limitation of application</header><text>Such person shall only be considered a service provider in the course of activities described in subparagraph (A).</text></subparagraph><subparagraph id="idd1ebde04b5d2428fb325d2707dbff088"><enum>(C)</enum><header>Exclusions</header><text>The term <term>service provider</term> excludes a person that develops or operates a website, web application, mobile application, or smart device application for the purpose of tracking, screening, monitoring, contact tracing, or mitigation, or otherwise responding to the COVID–19 public health emergency.</text></subparagraph></paragraph><paragraph id="id125d85307e86415aba77832cd8a4dd78"><enum>(16)</enum><header>State</header><text>The term <term>State</term> means each State of the United States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each federally recognized Indian Tribe.</text></paragraph><paragraph id="id695ec45c234349b3b3be3d83074db6ab"><enum>(17)</enum><header>Third party</header><subparagraph id="idd43fb30f146f4c7bbcc8520361d277dd"><enum>(A)</enum><header>In general</header><text>The term <term>third party</term> means, with respect to a covered organization—</text><clause id="idf9370c2331a94d7b981e9c8eb1ab3a48"><enum>(i)</enum><text>another person to whom such covered organization disclosed emergency health data; and</text></clause><clause id="id8c44d6a82be649e29dc964759002ea1e"><enum>(ii)</enum><text>a corporate affiliate or a related party of the covered organization that does not have a direct relationship with an individual with whom the emergency health data is linked or is reasonably linkable.</text></clause></subparagraph><subparagraph id="id8a3a1a559afc4c2db9465818bf1e42a7"><enum>(B)</enum><header>Exclusion</header><text>The term <term>third party</term> excludes, with respect to a covered organization—</text><clause id="idfd54cbcfeef045da9626618b12ecc6ab"><enum>(i)</enum><text>a service provider of such covered organization; or</text></clause><clause id="ida477b664a77c40ab8fcf35da57495fdf"><enum>(ii)</enum><text>a public health authority.</text></clause></subparagraph></paragraph><paragraph id="id8c1afb8090ed4f628b7ed72843893cd5"><enum>(18)</enum><header>Use</header><text>The term <term>use</term>, with respect to emergency health data, means the processing, employment, application, utilization, examination, or analysis of such data by a covered organization that maintains such data. </text></paragraph></section><section id="idd85122f44e044f44bb2c2acaed973e6c"><enum>3.</enum><header>Protecting the privacy and security of emergency health data</header><subsection id="idcc8abbce53044181bd6d9c15c4bc80ec"><enum>(a)</enum><header>Right to privacy</header><text>A covered organization that collects emergency health data shall—</text><paragraph id="id535db0fd1142467ebbe9381bb22cab43"><enum>(1)</enum><text>only collect, use, or disclose such data that is necessary, proportionate, and limited for a good faith public health purpose, including a service or feature to support such a purpose;</text></paragraph><paragraph id="id3d6ba588f37c44aeb3a43a4e03c464eb"><enum>(2)</enum><text>take reasonable measures, where possible, to ensure the accuracy of emergency health data and provide an effective mechanism for an individual to correct inaccurate information;</text></paragraph><paragraph id="id92fd464981254d79abe86c30563f4ce5"><enum>(3)</enum><text>adopt reasonable safeguards to prevent unlawful discrimination on the basis of emergency health data; and</text></paragraph><paragraph id="id50efbaa4eae6489c877ccdb86882374d"><enum>(4)</enum><text>only disclose such data to a government entity when the disclosure—</text><subparagraph id="idade931f6f77843e8981c3e84e207c380"><enum>(A)</enum><text>is to a public health authority; and</text></subparagraph><subparagraph id="id7d641da4fa0b44e1a17ea719f6fe4372"><enum>(B)</enum><text>is made in solely for good faith public health purposes and in direct response to exigent circumstances.</text></subparagraph></paragraph></subsection><subsection id="idf432348e55414563af33a9a9bd950055"><enum>(b)</enum><header>Right to security</header><text>A covered organization or service provider that collects, uses, or discloses emergency health data shall establish and implement reasonable data security policies, practices, and procedures to protect the security and confidentiality of emergency health data. </text></subsection><subsection id="id9337c2e85a764b069db769a5ac271587"><enum>(c)</enum><header>Prohibited uses</header><text>A covered organization shall not collect, use, or disclose emergency health data for any purpose not authorized under this section, including—</text><paragraph id="idd928fc3592ed45c9b31aeb85c36b58a4"><enum>(1)</enum><text>commercial advertising, recommendation for e-commerce, or the training of machine-learning algorithms related to, or subsequently for use in, commercial advertising and e-commerce;</text></paragraph><paragraph id="idecf65f45e36244e5b1f5dd355c98465f"><enum>(2)</enum><text>soliciting, offering, selling, leasing, licensing, renting, advertising, marketing, or otherwise commercially contracting for employment, finance, credit, insurance, housing, or education opportunities in a manner that discriminates or otherwise makes opportunities unavailable on the basis of emergency health data; and</text></paragraph><paragraph id="idd3a015c5b97a4cbba0b667537b6b022e"><enum>(3)</enum><text>segregating, discriminating in, or otherwise making unavailable the goods, services, facilities, privileges, advantages, or accommodations of any place of public accommodation (as such term is defined in section 301 of the Americans With Disabilities Act of 1990 (<external-xref legal-doc="usc" parsable-cite="usc/42/12181">42 U.S.C. 12181</external-xref>)), except as authorized by a State or Federal Government entity for a public health purpose notwithstanding subsection (g). </text></paragraph></subsection><subsection id="idb1c943c1bba549f7b53984b4743246c9"><enum>(d)</enum><header>Consent</header><paragraph id="idee53e2dd135e4c9ebd42487fd613fcc8"><enum>(1)</enum><header>In general</header><text>It shall be unlawful for a covered organization to collect, use, or disclose emergency health data, unless—</text><subparagraph id="idfe32a61fae1f46a7a4978f807c277134"><enum>(A)</enum><text>the individual to whom the data pertains has given affirmative express consent to such collection, use, or disclosure;</text></subparagraph><subparagraph id="id3aeaf729cd574132bf6c5de6414e311a"><enum>(B)</enum><text>such collection, use, or disclosure is necessary and for the sole purpose of—</text><clause id="idbd55776be84c474683d9a17033dab11c"><enum>(i)</enum><text>protecting against malicious, deceptive, fraudulent, or illegal activity; or</text></clause><clause id="idbe016a271397471eb1bc53589e4b9959"><enum>(ii)</enum><text>detecting, responding to, or preventing information security incidents or threats; or</text></clause></subparagraph><subparagraph id="id58485ac93c4a4c8a92f91ec4a25b3e44"><enum>(C)</enum><text>the covered organization is compelled to do so by a legal obligation.</text></subparagraph></paragraph><paragraph id="id6bf5d07631cb403b9ee5e91b83554505"><enum>(2)</enum><header>Revocation</header><subparagraph id="idb4de8df3fb3a424797960877c2e2c97f"><enum>(A)</enum><header>In general</header><text>A covered organization shall provide an effective mechanism for an individual to revoke consent after it is given.</text></subparagraph><subparagraph id="idc572e467cb194d15aaa8f36030bb9e7f"><enum>(B)</enum><header>Effect</header><text>After an individual revokes consent, the covered organization shall cease collecting, using, or disclosing the individual’s emergency health data as soon as practicable, but in no case later than 15 days after the receipt of the individual’s revocation of consent.</text></subparagraph><subparagraph id="id7D3B9735BF22422DA49C90276C32B41F"><enum>(C)</enum><header>Destruction</header><text>Not later than 30 days after the receipt of an individual’s revocation of consent, a covered organization shall destroy or render not linkable that individuals emergency health data under the same procedures in subsection (f).</text></subparagraph></paragraph></subsection><subsection id="idd7cb437d1f9a4b9b80dbca8dcfcbb62c"><enum>(e)</enum><header>Notice</header><text>A covered organization that collects, uses, or discloses emergency health data shall provide to an individual a privacy policy that—</text><paragraph id="id29f22fbf061f4ffda110088caf6d801e"><enum>(1)</enum><text>is disclosed in a clear and conspicuous manner, in the language in which the individual typically interacts with the covered organization, prior to or at the point of the collection of emergency health data;</text></paragraph><paragraph id="idd31096e77dd7480b9aa51f3021fb581b"><enum>(2)</enum><text>describes how and for what purposes the covered organization collects, uses, and discloses emergency health data, including the categories of recipients to whom it discloses data and the purpose of disclosure for each category;</text></paragraph><paragraph id="id3e9a4d17d168475d9284b00012b1dae8"><enum>(3)</enum><text>describes the covered organization’s data retention and data security policies and practices for emergency health data; and</text></paragraph><paragraph id="id8083e3683a10412dbdee4a5c8bc40154"><enum>(4)</enum><text>describes how an individual may exercise the rights under this Act and how to contact the Commission to file a complaint.</text></paragraph></subsection><subsection id="id0bb81f86846a43ab8fd995e270b61c87"><enum>(f)</enum><header>Public reporting</header><paragraph id="id2ad2c4b1837d46ff8001219185868874"><enum>(1)</enum><header>In general</header><text>A covered organization that collects, uses, or discloses emergency health data of at least 100,000 individuals shall, at least once every 90 days, issue a public report—</text><subparagraph id="id74e85b91e38c42baa9ab820d23d71251"><enum>(A)</enum><text>stating in aggregate terms the number of individuals whose emergency health data the covered organization collected, used, or disclosed to the extent practicable; and</text></subparagraph><subparagraph id="id59505fbf62994d8aba9612c3cd3beca3"><enum>(B)</enum><text>describing the categories of emergency health data collected, used, or disclosed, the purposes for which each such category of emergency health data was collected, used, or disclosed, and the categories of third parties to whom it was disclosed.</text></subparagraph></paragraph><paragraph id="ida49087ed6e3f4db68250bca8a86db75d"><enum>(2)</enum><header>Rules of construction</header><text>Nothing in this subsection shall be construed to require a covered organization to—</text><subparagraph id="idf115c9503e4f4768b2b5ec7dd6855525"><enum>(A)</enum><text>take an action that would convert data that is not emergency health data into emergency health data;</text></subparagraph><subparagraph id="id665e153056da48dfb39484c32d2cf853"><enum>(B)</enum><text>collect or maintain emergency health data that the covered organization would otherwise not maintain; or</text></subparagraph><subparagraph id="id7a3c850a1b0d4a2cabcec50bce0ad9c3"><enum>(C)</enum><text>maintain emergency health data longer than the covered organization would otherwise maintain such data.</text></subparagraph></paragraph></subsection><subsection id="idac43e2075ab043f9919038f758a1c9da"><enum>(g)</enum><header>Required data destruction</header><paragraph id="id3e681fe2aaef4b25bb69705181b1542d"><enum>(1)</enum><header>In general</header><text>A covered organization may not use or maintain emergency health data of an individual after the later of—</text><subparagraph id="id93f97304b12d4b7883c69d4a88dc1481"><enum>(A)</enum><text>the date that is 60 days after the termination of the public health emergency declared by the Secretary on January 31, 2020, pertaining to Coronavirus Disease 2019 (COVID–19) under section 319 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/247d">42 U.S.C. 247d</external-xref>) and any renewals thereof;</text></subparagraph><subparagraph id="id8add3c9112594c6a8aec960b72ccc400"><enum>(B)</enum><text>the date that is 60 days after the termination of a public health emergency declared by a governor or chief executive of a State pertaining to Coronavirus Disease 2019 (COVID–19) in which the individual resides; or</text></subparagraph><subparagraph id="id0a98a2a3800049f2bc2676f25abde6ed"><enum>(C)</enum><text>60 days after collection.</text></subparagraph></paragraph><paragraph id="id6bc16678c981496a9fc1679ff2519d30"><enum>(2)</enum><header>Requirement</header><text>For the requirements under paragraph (1), data shall be destroyed or rendered not linkable in such a manner that it is impossible or demonstrably impracticable to identify any individual from the data.</text></paragraph><paragraph id="ida69dbf6f214d446481e7c1fd3141e975"><enum>(3)</enum><header>Relation to certain requirements</header><text>The provisions of this subsection shall not supersede any requirements or authorizations under—</text><subparagraph id="idbec85a6cad3840848eb013f8d60a0b76"><enum>(A)</enum><text>the Privacy Act of 1974 (<external-xref legal-doc="public-law" parsable-cite="pl/93/79">Public Law 93–79</external-xref>);</text></subparagraph><subparagraph id="idebde2c479b884985be08935e78aa2c6b"><enum>(B)</enum><text>the HIPPA regulations; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id404eecd5fded4420839ca2529d95edfb"><enum>(C)</enum><text>Federal or State medical records retention and health privacy laws or regulations, or other applicable Federal or State laws. </text></subparagraph></paragraph></subsection><subsection id="idccbd0ee1f30d43dca07564f23deceed6"><enum>(h)</enum><header>Emergency data collected, used, or disclosed before enactment</header><paragraph id="idbea1333169c04dbd9f979bfb28c477d3"><enum>(1)</enum><header>Initiating a rulemaking</header><text>Not later than 7 days after the date of enactment of this Act, the Commission shall initiate a public rulemaking to promulgate regulations to ensure a covered organization that has collected, used, or disclosed emergency health data before the date of enactment of this Act is in compliance with this Act, to the degree practicable.</text></paragraph><paragraph id="ida3c4529b59a34c1a8e8c51f887630f99"><enum>(2)</enum><header>Completing a rulemaking</header><text>The Commission shall complete the rulemaking within 45 days after the date of enactment of this Act.</text></paragraph></subsection><subsection id="idac807384ecaf4436985b73b285c375e3"><enum>(i)</enum><header>Non-Application to manual contact tracing and case investigation</header><text>Nothing in this Act shall be construed to limit or prohibit a public health authority from administering programs or activities to identify individuals who have contracted, or may have been exposed to, COVID–19 through interviews, outreach, case investigation, and other recognized investigatory measures by a public health authority or their designated agent by a public health authority or their designated agent intended to monitor and mitigate the transmission of a disease or disorder. </text></subsection><subsection id="idad614e47368e43d8ac96a23cbed5c664"><enum>(j)</enum><header>Research and development</header><text>This section shall not be construed to prohibit—</text><paragraph id="idcf354b95e407453f8c20ee9eb745b83e"><enum>(1)</enum><text>public health or scientific research associated with the COVID–19 public health emergency by—</text><subparagraph id="id578b07acb8e24989abfabe5ca433d341"><enum>(A)</enum><text>a public health authority;</text></subparagraph><subparagraph id="ida7349492fd4a471d961db6047de0e42b"><enum>(B)</enum><text>a nonprofit organization, as described in <external-xref legal-doc="usc" parsable-cite="usc/26/501">section 501(c)(3)</external-xref> of the Internal Revenue Code of 1986; or</text></subparagraph><subparagraph id="idc22ef09ea49f423283ba7642fafff9a7"><enum>(C)</enum><text>an institution of higher education, as such term is defined in section 101 of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1001">20 U.S.C. 1001</external-xref>); or</text></subparagraph></paragraph><paragraph id="iddbc25a21c8664618ab11d9a868576e91"><enum>(2)</enum><text>research, development, manufacture, or distribution of a drug, biological product, or vaccine that relates to a disease or disorder that is associated or potentially associated with a public health emergency.</text></paragraph></subsection><subsection id="id5f7526f60e2f43278feb58ab86530ccf"><enum>(k)</enum><header>Legal requirements</header><text>Notwithstanding subsection (a)(5), nothing in this Act shall be construed to prohibit a good faith response to, or compliance with, otherwise valid subpoenas, court orders, or other legal processes, or to prohibit storage or providing information as otherwise required by law.</text></subsection><subsection id="id445f87615e2f4d76be573e793d1e4018"><enum>(l)</enum><header>Application to HIPAA covered entities</header><paragraph id="id98dd2874a7324f14a6df94d277f422e4"><enum>(1)</enum><header>In general</header><text>This Act does not apply to a <quote>covered entity</quote> or a person acting as a <quote>business associate</quote> under the HIPAA regulations (to the extent that such entities or associates are acting in such capacity) or any health care provider.</text></paragraph><paragraph id="id9bd3c3e055334e4681d9f69f8811d6ed"><enum>(2)</enum><header>Guidance for consistency</header><text>Not later than 30 days after the date of enactment of this Act, the Secretary shall promulgate guidance on the applicability of requirements, similar to those in this section to <quote>covered entities</quote> and persons acting as <quote>business associates</quote> under the HIPAA regulations. In promulgating such guidance, the Secretary shall reduce duplication of requirements and may exclude a requirement of this section if such requirement is already a requirement of the HIPAA regulations.</text></paragraph></subsection></section><section id="iddcefbe08d6c24eb38edbd5ec476b36d3"><enum>4.</enum><header>Protecting the right to vote</header><subsection id="id8b6a8bd6cdc44c1188f0c01123d63b6f"><enum>(a)</enum><header>In general</header><text>A government entity may not, and a covered organization may not knowingly facilitate, on the basis of an individual’s emergency health data, medical condition, or participation or non-participation in a program to collect emergency health data—</text><paragraph id="id25fd4cd8fdce4471a0580463128a177b"><enum>(1)</enum><text>deny, restrict, or interfere with the right to vote in a Federal, State, or local election;</text></paragraph><paragraph id="id6c9af38c52f34d5d8208da3c691cf8c4"><enum>(2)</enum><text>attempt to deny, restrict, or interfere with the right to vote in a Federal, State, or local election; or</text></paragraph><paragraph id="id2760e076404241f0a826f544f6b5f091"><enum>(3)</enum><text>retaliate against an individual for voting in a Federal, State, or local election.</text></paragraph></subsection><subsection id="id4f48b975d2254faba1b3b6e14cd4e5ee"><enum>(b)</enum><header>Civil action</header><text>In the case of any violation of subsection (a), an individual may bring a civil action to obtain appropriate relief against a government entity in a Federal district court.</text></subsection></section><section id="id417f3ff818b6473eb7acaaf7af2b59d8"><enum>5.</enum><header>Reports on civil rights impacts</header><subsection id="idb42891f8ef654495baad3acedd887303"><enum>(a)</enum><header>Report required</header><text>The Secretary, in consultation with the United States Commission on Civil Rights and the Commission, shall prepare and submit to Congress reports that examines the civil rights impact of the collection, use, and disclosure of health information in response to the COVID–19 public health emergency.</text></subsection><subsection id="id30ba49df10e844f9b8b43fac972457ea"><enum>(b)</enum><header>Scope of report</header><text>Each report required under subsection (a) shall, at a minimum—</text><paragraph id="iddf5d2a9154034f9fb771ebdb9aadb649"><enum>(1)</enum><text>evaluate the impact of such practices on civil rights and protections for individuals based on race, color, ethnicity, national origin, religion, sex, gender, gender identity, sexual orientation, age, Tribal affiliation, disability, domicile, employment status, familial status, immigration status, or veteran status;</text></paragraph><paragraph id="id1b542013749642b0b308a0478a9fd988"><enum>(2)</enum><text>analyze the impact, risks, costs, legal considerations, disparate impacts, and other implications to civil rights of policies to incentivize or require the adoption of digital tools or apps used for contact tracing, exposure notification, or health monitoring; and</text></paragraph><paragraph id="id5192fd492b9643818c8771749b4f37c3"><enum>(3)</enum><text>include recommendations on preventing and addressing undue or disparate impact, segregation, discrimination, or infringements of civil rights in the collection and use of health information, including during a national health emergency.</text></paragraph></subsection><subsection id="idbc6296d157e3486da236b1bfd47c231d"><enum>(c)</enum><header>Timing</header><paragraph id="id0c8162d4818a446faa0e7b6bdabaea43"><enum>(1)</enum><header>Initial report</header><text>The Secretary shall submit an initial report under subsection (a) not sooner than 9 months, and not later than 12 months after the date of enactment of this Act.</text></paragraph><paragraph id="id9a9ae073fec0448b90d4e103766acab1"><enum>(2)</enum><header>Subsequent reports</header><text>The Secretary shall submit reports annually after the initial report required under paragraph (1) until 1 year after the termination of any public health emergency pertaining to Coronavirus Disease 2019 (COVID–19) under section 319 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/247d">42 U.S.C. 247d</external-xref>). </text></paragraph></subsection></section><section id="id6d625e523a3144fbb7eebfe25459f30d"><enum>6.</enum><header>Enforcement</header><subsection id="id6dffd3e158814d369540f3cdb2297031"><enum>(a)</enum><header>Federal Trade Commission</header><paragraph id="idf90ec1e884604cf783dcaba4467abf1a"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of this Act or a regulation promulgated under this Act shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>) regarding unfair or deceptive acts or practices.</text></paragraph><paragraph id="idfaaf9dc96b92472ca9465666fcbdbcf5"><enum>(2)</enum><header>Powers of Commission</header><text>The Commission shall enforce this Act and the regulations promulgated under this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.) were incorporated into and made a part of this Act. Any person who violates this Act or a regulation promulgated under this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act. Provided, however, that, notwithstanding the requirements of section 16(a) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/56">15 U.S.C. 56(a)</external-xref>), the Commission shall have the exclusive authority to commence or defend, and supervise the litigation of, any action for a violation of this Act or a regulation promulgated under this Act and any appeal of such action in its own name by any of its attorneys designated by it for such purpose, without first referring the matter to the Attorney General.</text></paragraph><paragraph id="id66cb1b98b14743b1bf9ed164f3734142"><enum>(3)</enum><header>Rulemaking authority</header><subparagraph id="idCF504973A35440F5B9FEC37703970246"><enum>(A)</enum><header>In general</header><text>The Commission shall have authority under section 553 of title 5, United States Code, to promulgate any regulations necessary to implement this Act.</text></subparagraph><subparagraph id="id9FF95517C97A45FA9CF380C5A0049DA6"><enum>(B)</enum><header>Consultation</header><text>In promulgating any regulations under this Act, the Commission shall consult with the Secretary.</text></subparagraph></paragraph><paragraph id="id85532e4b407a45d5b16617ddf4b98f15"><enum>(4)</enum><header>Common carriers and nonprofit organizations</header><text>Notwithstanding section 4, 5(a)(2), or 6 of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/44">15 U.S.C. 44</external-xref>; 45(a)(2); 46) or any jurisdictional limitation of the Commission, the Commission shall also enforce this Act, in the same manner provided in paragraphs (1) and (2) of this paragraph, with respect to—</text><subparagraph id="idfce9049a3906419d980b20cdecf56ba3"><enum>(A)</enum><text>common carriers subject to the Acts to regulate commerce, air carriers, and foreign air carriers subject to part A of subtitle VII of title 49, and persons, partnerships, or corporations insofar as they are subject to the Packers and Stockyards Act, 1921 (<external-xref legal-doc="usc" parsable-cite="usc/7/181">7 U.S.C. 181</external-xref> et seq.), except as provided in section 406(b) of such Act (<external-xref legal-doc="usc" parsable-cite="usc/7/227">7 U.S.C. 227(b)</external-xref>); and</text></subparagraph><subparagraph id="id0adffe847f21489dafde1c42c63265b4"><enum>(B)</enum><text>organizations not organized to carry on business for their own profit or that of their members.</text></subparagraph></paragraph></subsection><subsection id="idce6fdfb5cb9342cfbe81eb1cdc99f63a"><enum>(b)</enum><header>Enforcement by States</header><paragraph id="id1f87569e1c404c2b9e8d4ac695d3ef7f"><enum>(1)</enum><header>In general</header><text>In any case in which the attorney general of a State has reason to believe that an interest of the residents of the State has been or is threatened or adversely affected by the engagement of any person subject to this Act in a practice that violates such subsection, the attorney general of the State may, as parens patriae, bring a civil action on behalf of the residents of the State in an appropriate district court of the United States to obtain appropriate relief.</text></paragraph><paragraph id="id5921d5144aff4034a8263c1ccb268cbc"><enum>(2)</enum><header>Rights of the Federal Trade Commission</header><subparagraph id="idf0b83a9cb3fd46219cadf9f43c78fdf9"><enum>(A)</enum><header>Notice to Federal Trade Commission</header><clause id="idbe21cfbd8d56427a816ee5ec20f1d9cb"><enum>(i)</enum><header>In general</header><text>Except as provided in clause (iii), the attorney general of a State shall notify the Commission in writing that the attorney general intends to bring a civil action under paragraph (1) before initiating the civil action against a person subject to this Act.</text></clause><clause id="idf7e9a62a6dea445eaa9efe1b73fde700"><enum>(ii)</enum><header>Contents</header><text>The notification required by clause (i) with respect to a civil action shall include a copy of the complaint to be filed to initiate the civil action.</text></clause><clause id="idd9b1a4b249f74448a2e29e99853651c2"><enum>(iii)</enum><header>Exception</header><text>If it is not feasible for the attorney general of a State to provide the notification required by clause (i) before initiating a civil action under paragraph (1), the attorney general shall notify the Commission immediately upon instituting the civil action.</text></clause></subparagraph><subparagraph id="idab3e187c44064b4bbecdcec36db93fa0"><enum>(B)</enum><header>Intervention by the Federal Trade Commission</header><text>The Commission may—</text><clause id="id782b4e8e816e4ad3838216ca0c5d25be"><enum>(i)</enum><text>intervene in any civil action brought by the attorney general of a State under paragraph (1); and</text></clause><clause id="id74b5b0fe5f434e28b6be1761290b601c"><enum>(ii)</enum><text>upon intervening—</text><subclause id="idf216ad356cff4812980a603e63a78518"><enum>(I)</enum><text>be heard on all matters arising in the civil action; and</text></subclause><subclause id="id3473e520afa34002a4e7014fae62839f"><enum>(II)</enum><text>file petitions for appeal of a decision in the civil action.</text></subclause></clause></subparagraph><subparagraph id="id96add728eefe41338266ff0c1e41daf5"><enum>(C)</enum><header>Investigatory powers</header><text>Nothing in this subsection may be construed to prevent the attorney general of a State from exercising the powers conferred on the attorney general by the laws of the State to conduct investigations, to administer oaths or affirmations, or to compel the attendance of witnesses or the production of documentary or other evidence.</text></subparagraph></paragraph><paragraph commented="no" id="id4cd12df14122491194baa6d82d544f46"><enum>(3)</enum><header>Action by the Federal Trade Commission</header><text>If the Commission institutes a civil action with respect to a violation of this Act, the attorney general of a State may not, during the pendency of such action, bring a civil action under paragraph (1) of this subsection against any defendant named in the complaint of the Commission for the violation with respect to which the Commission instituted such action.</text></paragraph><paragraph id="idf072a40fc1fa4bdf85852719ecfbc080"><enum>(4)</enum><header>Venue; service of process</header><subparagraph id="iddfabef382c984043abab697aaaedaa5e"><enum>(A)</enum><header>Venue</header><text>Any action brought under paragraph (1) may be brought in—</text><clause id="ideb7e092304b846809b557d7c8db57d98"><enum>(i)</enum><text>the district court of the United States that meets applicable requirements relating to venue under section 1391 of title 28, United States Code; or</text></clause><clause id="id9303aaa1357d4ddfae3b3aa75e639cc6"><enum>(ii)</enum><text>another court of competent jurisdiction.</text></clause></subparagraph><subparagraph id="id492cd634568d498c8713dc29ecf7e2b3"><enum>(B)</enum><header>Service of process</header><text>In an action brought under paragraph (1), process may be served in any district in which the defendant—</text><clause id="ide27a2742fc9f4d10b70f7f4226a52237"><enum>(i)</enum><text>is an inhabitant; or</text></clause><clause id="idbd3d89e698d84ca9bad4b1ab1d289da2"><enum>(ii)</enum><text>may be found.</text></clause></subparagraph><subparagraph id="idd8f4f4875cd14d6dacde7dac05d1910e"><enum>(C)</enum><header>Actions by other State officials</header><clause id="id90c690442fea4c2a85ab99026f9188a7"><enum>(i)</enum><header>In general</header><text>In addition to civil actions brought by attorneys general under paragraph (1), any other officer of a State who is authorized by the State to do so may bring a civil action under paragraph (1), subject to the same requirements and limitations that apply under this subsection to civil actions brought by attorneys general.</text></clause><clause id="id6a16d4e11f2a4b7789db077d283c696f"><enum>(ii)</enum><header>Savings provision</header><text>Nothing in this subsection may be construed to prohibit an authorized official of a State from initiating or continuing any proceeding in a court of the State for a violation of any civil or criminal law of the State.</text></clause></subparagraph></paragraph></subsection><subsection id="idecabba13435848408880df08e075663c"><enum>(c)</enum><header>Private right of action</header><paragraph id="id4cd908d875d74bd6a87dbf30d0a5fed9"><enum>(1)</enum><header>Enforcement by individuals</header><subparagraph id="id344cb35379364f0d8fa61089ba788c07"><enum>(A)</enum><header>In general</header><text>Any individual alleging a violation of this Act may bring a civil action in any court of competent jurisdiction, State or Federal.</text></subparagraph><subparagraph id="id649abf9c80a540b29f37b0d1b4fea0a7"><enum>(B)</enum><header>Relief</header><text>In a civil action brought under paragraph (1) in which the plaintiff prevails, the court may award—</text><clause id="id0694fb03115848109fb1b58fad1ccea4"><enum>(i)</enum><text>an amount not less than $100 and not greater than $1,000 per violation against any person who negligently violates a provision of this Act;</text></clause><clause id="id365c13e6ed69432ea707d9de2edd0dff"><enum>(ii)</enum><text>an amount not less than $500 and not greater than $5,000 per violation against any person who recklessly, willfully, or intentionally violates a provision of this Act;</text></clause><clause id="id19717a5200194f7f94282d352158c05d"><enum>(iii)</enum><text>reasonable attorney’s fees and litigation costs; and</text></clause><clause id="id963b1205e09b40b0b31bdd44cc0c6c74"><enum>(iv)</enum><text>any other relief, including equitable or declaratory relief, that the court determines appropriate.</text></clause></subparagraph><subparagraph id="id4b5d05da1b8f4465861d10d861563549"><enum>(C)</enum><header>Injury in fact</header><text>A violation of this Act with respect to the emergency health data of an individual constitutes a concrete and particularized injury in fact to that individual.</text></subparagraph></paragraph><paragraph id="id4f4ed0f5b92d49109591544e13f39bb6"><enum>(2)</enum><header>Invalidity of pre-dispute arbitration agreements and pre-dispute joint action waivers</header><subparagraph id="idd2607d30e50242788ad2676b9745f440"><enum>(A)</enum><header>In general</header><text>Notwithstanding any other provision of law, no pre-dispute arbitration agreement or pre-dispute joint action waiver shall be valid or enforceable with respect to a dispute arising under this Act.</text></subparagraph><subparagraph id="id13aaba10757f4172beb49d87c65822ce"><enum>(B)</enum><header>Applicability</header><text>Any determination as to whether or how this subsection applies to any dispute shall be made by a court, rather than an arbitrator, without regard to whether such agreement purports to delegate such determination to an arbitrator.</text></subparagraph><subparagraph id="idf2d3648b87b14e37bf108c69b9e7e354"><enum>(C)</enum><header>Definitions</header><text>In this subsection:</text><clause id="id3cb68625aedc45618f5f914835def90b"><enum>(i)</enum><text>The term <term>pre-dispute arbitration agreement</term> means any agreement to arbitrate a dispute that has not arisen at the time of making the agreement.</text></clause><clause id="id30858192c7c94d37852578e5423beceb"><enum>(ii)</enum><text>The term <term>pre-dispute joint-action waiver</term> means an agreement, whether or not part of a pre-dispute arbitration agreement, that would prohibit, or waive the right of, one of the parties to the agreement to participate in a joint, class, or collective action in a judicial, arbitral, administration, or other forum, concerning a dispute that has not yet arisen at the time of making the agreement.</text></clause><clause id="id9b216675fcfc46f6a4810865c0a97ab9"><enum>(iii)</enum><text>The term <term>dispute</term> means any claim related to an alleged violation of this Act and between an individual and a covered organization.</text></clause></subparagraph></paragraph></subsection></section><section id="id0138cea0b7c842c5923931d9366250a0"><enum>7.</enum><header>Nonpreemption</header><text display-inline="no-display-inline">Nothing in this Act shall preempt or supersede, or be interpreted to preempt or supersede, any Federal or State law or regulation, or limit the authority of the Commission or the Secretary under any other provision of law.</text></section><section id="id355ce24c97a24025a7fc9c31fe64b96d"><enum>8.</enum><header>Effective date</header><subsection id="id6d4d2379f53a401493d0443c8b9106b8"><enum>(a)</enum><header>In general</header><text>This Act shall apply beginning on the date that is 30 days after the date of enactment of this Act.</text></subsection><subsection id="id643b8e5feb5140cd85a66a25ae5925e3"><enum>(b)</enum><header>Authority To promulgate regulations and take certain other actions</header><text>Nothing in subsection (a) affects—</text><paragraph id="idc665d9e6cb3c4152a41beee8f773bf27"><enum>(1)</enum><text>the authority of any person to take an action expressly required by a provision of this Act before the effective date described in such subsection; or</text></paragraph><paragraph id="id4a168bb98105411b8e0001aa0b1c3396"><enum>(2)</enum><text>the authority of the Commission to promulgate regulations to implement this Act or begin a rulemaking to promulgate such regulations. </text></paragraph></subsection></section></legis-body></bill> 

