[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 3097 Reported in Senate (RS)]

<DOC>





                                                       Calendar No. 538
119th CONGRESS
  2d Session
                                S. 3097

 To provide additional protections with respect to health information, 
                        and for other purposes.


_______________________________________________________________________


                   IN THE SENATE OF THE UNITED STATES

                            November 4, 2025

  Mr. Cassidy introduced the following bill; which was read twice and 
  referred to the Committee on Health, Education, Labor, and Pensions

                             August 4, 2026

               Reported by Mr. Cassidy, with an amendment
 [Strike out all after the enacting clause and insert the part printed 
                               in italic]

_______________________________________________________________________

                                 A BILL


 
 To provide additional protections with respect to health information, 
                        and for other purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

<DELETED>SECTION 1. SHORT TITLE.</DELETED>

<DELETED>    This Act may be cited as the ``Health Information Privacy 
Reform Act''.</DELETED>

<DELETED>SEC. 2. PROTECTIONS FOR APPLICABLE HEALTH 
              INFORMATION.</DELETED>

<DELETED>    (a) In General.--The Secretary of Health and Human 
Services, in consultation with the Federal Trade Commission, shall 
promulgate regulations setting privacy, security, and breach 
notifications standards for the processing of applicable health 
information by regulated entities and their service providers. Such 
standards shall provide protections that are at least commensurate 
with, and wherever feasible and appropriate harmonize with, the 
protections provided through the privacy, security, and breach 
notification rules promulgated under section 264(c) of the Health 
Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d-2 
note) and section 13402 of the HITECH Act (42 U.S.C. 17932) that apply 
to covered entities and business associates with respect to protected 
health information under such rules. Such regulations promulgated under 
this section shall include the following:</DELETED>
        <DELETED>    (1) Privacy requirements, including the 
        following:</DELETED>
                <DELETED>    (A) Permitted uses and disclosures of 
                applicable health information without an individual's 
                written authorization that are consistent with the 
                individual's reasonable expectations.</DELETED>
                <DELETED>    (B) Other permitted uses and disclosures 
                of applicable health information without an 
                individual's written authorization for certain public 
                policy purposes, such as public health, health 
                oversight, law enforcement, judicial and administrative 
                proceedings, and any conditions for such uses and 
                disclosures.</DELETED>
                <DELETED>    (C) Uses and disclosures of applicable 
                health information that require the individual's 
                written authorization and the requirements related to 
                such written authorizations.</DELETED>
                <DELETED>    (D) Prohibited uses and disclosures of 
                applicable health information.</DELETED>
                <DELETED>    (E) Minimum necessary requirements for the 
                request, use, and disclosure of applicable health 
                information and any exceptions.</DELETED>
                <DELETED>    (F) Standards and requirements related to 
                legal representatives of the individual.</DELETED>
                <DELETED>    (G) Standards and requirements related to 
                service providers.</DELETED>
                <DELETED>    (H) Individual rights with respect to 
                applicable health information, including the right of 
                the individual to receive a privacy notice from the 
                regulated entity, access to applicable health 
                information, amendment of applicable health 
                information, deletion of applicable health information, 
                and portability of applicable health information, and 
                any exceptions to such rights (such as with respect to 
                applicable health information collected for research 
                purposes), any conditions on such rights, and any other 
                requirements related to such rights, including 
                timeframes for responding to requests.</DELETED>
                <DELETED>    (I) Administrative safeguards, including 
                designation of a privacy officer, policies and 
                procedures, training of workforce members, non-
                retaliation, documentation, and mitigation.</DELETED>
        <DELETED>    (2) Security requirements, including the 
        following:</DELETED>
                <DELETED>    (A) Physical, technical, and 
                administrative safeguards for applicable health 
                information in any form.</DELETED>
                <DELETED>    (B) For electronic applicable health 
                information, such safeguards shall be based on well-
                established national frameworks, such as cybersecurity 
                performance goals of the National Institute of 
                Standards and Technology or the Department of Health 
                and Human Services.</DELETED>
        <DELETED>    (3) Breach notification requirements in the event 
        of a breach of applicable health information that are 
        substantially similar to the breach notification requirements 
        under subpart D of part 164 of title 45, Code of Federal 
        Regulations (or any successor regulations).</DELETED>
<DELETED>    (b) Enforcement Authority.--The Secretary, in consultation 
with the Federal Trade Commission, is authorized to enforce all 
provisions of this Act as described in subsection (c).</DELETED>
<DELETED>    (c) Civil Penalties.--In addition to any other sanctions 
or remedies that may be available under any provision of Federal law, 
in the case of a regulated entity or service provider that violates 
this section, subpart D of part 160 of title 45, Code of Federal 
Regulations (or any successor regulations), shall apply to the 
regulated entity or service provider with respect to such violation of 
this section in the same manner that such subpart applies to a person 
with respect to a violation of part 160 of title 45, Code of Federal 
Regulations (or any successor regulations).</DELETED>
<DELETED>    (d) Extension of HITECH Act Amendment to Regulated 
Entities and Service Providers.--The privacy and security practices 
under section 13412 of the Health Information Technology for Economic 
and Clinical Health Act (42 U.S.C. 17941) shall apply to regulated 
entities and service providers with respect to applicable health 
information in the same manner that such section applies to covered 
entities and business associates.</DELETED>
<DELETED>    (e) Definitions.--In this section:</DELETED>
        <DELETED>    (1) Applicable health information.--The term 
        ``applicable health information''--</DELETED>
                <DELETED>    (A) means information (including 
                demographic information) that--</DELETED>
                        <DELETED>    (i) identifies an individual or 
                        with respect to which there is a reasonable 
                        basis to believe that the information could be 
                        used to identify an individual; and</DELETED>
                        <DELETED>    (ii) relates to the past, present, 
                        or future physical or mental health or 
                        condition of an individual, the provision of 
                        health care to an individual, or the past, 
                        present, or future payment for the provision of 
                        health care to an individual; and</DELETED>
                <DELETED>    (B) may include information described in 
                subparagraph (A) that was not created or received by a 
                health care provider, health plan, employer, or health 
                care clearinghouse.</DELETED>
        <DELETED>    (2) Covered entities; business associates.--The 
        terms ``covered entities'' and ``business associates'' have the 
        meanings given such terms in section 160.103 of title 45, Code 
        of Federal Regulations (or any successor 
        regulations).</DELETED>
        <DELETED>    (3) Regulated entity.--The term ``regulated 
        entity''--</DELETED>
                <DELETED>    (A) means a natural or legal person that, 
                alone or jointly with others, determines the purpose 
                and means of processing applicable health information; 
                and</DELETED>
                <DELETED>    (B) does not include--</DELETED>
                        <DELETED>    (i) a governmental entity such as 
                        a body, authority, board, bureau, commission, 
                        district, agency, or political subdivision of 
                        the Federal, State, or local 
                        government;</DELETED>
                        <DELETED>    (ii) a person or an entity that is 
                        collecting, processing, or transferring covered 
                        data on behalf of or a Federal, State, Tribal, 
                        territorial, or local government entity; 
                        and</DELETED>
                        <DELETED>    (iii) a covered entity or business 
                        associate, as such terms are defined in section 
                        160.103 of title 45, Code of Federal 
                        Regulations (or any successor 
                        regulations).</DELETED>
        <DELETED>    (4) Service provider.--The term ``service 
        provider'' means a natural or legal entity that processes 
        applicable health information on a behalf of a regulated entity 
        and that is not a covered entity or business associate, as such 
        terms are defined in section 160.103 of title 45, Code of 
        Federal Regulations (or any successor regulations).</DELETED>

<DELETED>SEC. 3. RIGHTS AND REQUIREMENTS REGARDING ACCESS TO CERTAIN 
              PROTECTED HEALTH INFORMATION.</DELETED>

<DELETED>    (a) Time and Manner of Access.--In applying section 
13405(e) of the Health Information Technology for Economic and Clinical 
Health Act (42 U.S.C. 17935(e)) or section 164.524(c)(3)(ii) of title 
45, Code of Federal Regulations (or any successor regulations), in the 
case that an individual requests that a covered entity or any business 
associate of a covered entity transmit, produce, or provide access to a 
copy of the individual's protected health information to a person, 
including an entity, designated by the individual, and except where 
permitted without authorization under section 164.506(c) of title 45, 
Code of Federal Regulations (or any successor regulations)--</DELETED>
        <DELETED>    (1) the individual's request shall meet all 
        requirements of a valid authorization under section 164.508(b) 
        of title 45, Code of Federal Regulations (or any successor 
        regulations); and</DELETED>
        <DELETED>    (2) the covered entity or business associate may 
        condition the transmittal, production, or provision of access 
        upon the person to whom the information is to be transmitted or 
        produced or to whom access is to be provided--</DELETED>
                <DELETED>    (A) paying fees, in accordance with 
                applicable State law and consistent with subsection 
                (b), in advance of such transmittal, production, or 
                access; and</DELETED>
                <DELETED>    (B) acknowledging and accepting the terms, 
                limitations, and conditions of use and disclosure 
                contained in the request made by the individual as the 
                legally binding obligation of the person receiving the 
                information.</DELETED>
<DELETED>    (b) Fees.--</DELETED>
        <DELETED>    (1) In general.--In applying section 13405(e)(3) 
        of the Health Information Technology for Economic and Clinical 
        Health Act (42 U.S.C. 17935(e)(3)) or section 164.524(c)(4) of 
        title 45, Code of Federal Regulations (or any successor 
        regulations), each such section shall apply only--</DELETED>
                <DELETED>    (A) to the provision of access to, or the 
                production, copying, or transmittal of, protected 
                health information directly to--</DELETED>
                        <DELETED>    (i) the individual, or the 
                        individual's personal representative for health 
                        care purposes as described in section 
                        164.502(g) of title 45, Code of Federal 
                        Regulations (or any successor 
                        regulations);</DELETED>
                        <DELETED>    (ii) subject to paragraph (2) and 
                        section 164.510(b) of title 45, Code of Federal 
                        Regulations (or any successor regulation), any 
                        other person identified in, and subject to the 
                        limitations of, such section; or</DELETED>
                        <DELETED>    (iii) the individual's health care 
                        provider or the business associates of such 
                        provider; and</DELETED>
                <DELETED>    (B) as directed by the individual, to the 
                electronic transmittal of the individual's electronic 
                health record to the patient portal or mobile medical 
                application used and maintained by the individual's 
                health care provider or for the health care provider by 
                its business associate.</DELETED>
        <DELETED>    (2) Additional limitations.--In the case of the 
        provision of access to, or the production, copying, or 
        transmittal of, protected health information under paragraph 
        (1)(A) directly to a person described in clause (ii) of such 
        paragraph, such protected health information shall, in 
        accordance with section 164.510(b) of title 45, Code of Federal 
        Regulations (or any successor regulations), be limited to only 
        such information that is--</DELETED>
                <DELETED>    (A) directly relevant to the person's 
                involvement with the care of the individual or with the 
                payment relevant to the care of the individual; 
                or</DELETED>
                <DELETED>    (B) needed for notification purposes 
                described in such section.</DELETED>
<DELETED>    (c) Definitions.--In this section, the terms ``business 
associate'', ``covered entity'', ``health care provider'', 
``individual'', ``person'', and ``protected health information'' have 
the meanings given such terms in section 160.103 of title 45, Code of 
Federal Regulations (or any successor regulations).</DELETED>
<DELETED>    (d) Guidance.--Not later than 180 days after the date of 
enactment of this Act, the Secretary of Health and Human Services shall 
amend existing guidance as necessary to implement subsections (a) and 
(b).</DELETED>

<DELETED>SEC. 4. CONFIDENTIALITY OF RECORDS.</DELETED>

<DELETED>    Section 543 of the Public Health Service Act (42 U.S.C. 
290dd-2) is amended--</DELETED>
        <DELETED>    (1) in subsection (a), by striking ``subsection 
        (b)'' and inserting ``the HIPAA regulations'';</DELETED>
        <DELETED>    (2) in subsection (b)--</DELETED>
                <DELETED>    (A) in paragraph (2), by redesignating 
                subparagraphs (A) through (D) as paragraphs (1) through 
                (4), respectively, and adjusting the margins 
                accordingly; and</DELETED>
                <DELETED>    (B) by striking ``(b) Permitted 
                Disclosure'' and all that follows through ``(2) Method 
                for disclosure--Whether'' and inserting the 
                following:</DELETED>
<DELETED>    ``(b) Permitted Disclosure.--Whether'';</DELETED>
        <DELETED>    (3) in subsection (c), in the matter preceding 
        paragraph (1), by striking ``subsection (b)(2)(C)'' and 
        inserting ``subsection (b)(3)''; and</DELETED>
        <DELETED>    (4) in subsection (g), by striking ``subsection 
        (b)(2)(C)'' and inserting ``subsection (b)(3)''.</DELETED>

<DELETED>SEC. 5. NAS STUDY ON COMPENSATION TO PATIENTS FOR SHARING 
              IDENTIFIABLE DATA FOR RESEARCH PURPOSES.</DELETED>

<DELETED>    (a) In General.--Not later than 60 days after the date of 
enactment of this Act, the Secretary of Health and Human Services shall 
seek to enter into a contract with the National Academies of Sciences, 
Engineering, and Medicine to conduct a study examining potential risks 
and benefits of paying compensation to patients for sharing their 
identifiable data for research purposes.</DELETED>
<DELETED>    (b) Inclusions.--The study conducted pursuant to the 
contract under subsection (a) shall include an examination of--
</DELETED>
        <DELETED>    (1) the risks to patient privacy posed by the 
        integration of identifiable, de-identified, and aggregated 
        health information into datasets used for research;</DELETED>
        <DELETED>    (2) privacy enhancing tools and methods for the 
        protection of patient health data;</DELETED>
        <DELETED>    (3) the feasibility of tracking patient data and 
        consent for the integration of patient health data into 
        datasets used for research;</DELETED>
        <DELETED>    (4) ethical considerations for compensating 
        patients for use of their identifiable and de-identified health 
        data;</DELETED>
        <DELETED>    (5) whether the existing exemptions permitting de-
        identified data to be used for research should consider whether 
        a patient was given an opportunity to opt-in or opt-out of 
        participation; and</DELETED>
        <DELETED>    (6) risk of re-identification of de-identified 
        data.</DELETED>

<DELETED>SEC. 6. PATIENT NOTIFICATION REQUIREMENTS UNDER THE HIPAA 
              PRIVACY REGULATIONS.</DELETED>

<DELETED>    (a) Patient Notification Upon Removal.--Any regulated 
entity or service provider who gains access to the protected health 
information of an individual through the patient right of access under 
section 164.524 of title 45, Code of Federal Regulations (or any 
successor regulations) shall--</DELETED>
        <DELETED>    (1) provide a written plain language notification 
        to such individual prior to accessing such information--
        </DELETED>
                <DELETED>    (A) that such protected health information 
                will no longer be subject to the protections under the 
                HIPAA privacy regulation; and</DELETED>
                <DELETED>    (B) that includes an explanation of how 
                and to which entities such protected health information 
                may be redisclosed; and</DELETED>
        <DELETED>    (2) require the consent of the individual before 
        selling such protected health information to third 
        parties.</DELETED>
<DELETED>    (b) Patient Notification Regarding Wellness Data.--
</DELETED>
        <DELETED>    (1) In general.--Any regulated entity or service 
        provider who offers digital technology that generates wellness 
        data about individuals shall, with respect to each individual 
        who uses such technology--</DELETED>
                <DELETED>    (A) provide a written plain language 
                notification to the individual in advance of initiating 
                the generation of such data that such data will not be 
                subject to the protections of the HIPAA privacy 
                regulation; and</DELETED>
                <DELETED>    (B) offer the individual an opportunity to 
                opt out of such wellness data generation.</DELETED>
        <DELETED>    (2) Wellness data.--In this subsection, the term 
        ``wellness data'' means data generated for the purpose of 
        promoting health or preventing disease, which may include vital 
        statistics, step counts, and medical regimen 
        compliance.</DELETED>
<DELETED>    (c) Definitions.--In this section--</DELETED>
        <DELETED>    (1) the terms ``business associate'', ``covered 
        entity'', and ``protected health information'' have the 
        meanings given such terms in section 160.103 of title 45, Code 
        of Federal Regulations (or any successor 
        regulations);</DELETED>
        <DELETED>    (2) the term ``HIPAA privacy regulation'' has the 
        meaning given such term in section 1180(b)(3) of the Social 
        Security Act (42 U.S.C. 1320d-9(b)(3)); and</DELETED>
        <DELETED>    (3) the terms ``regulated entity'' and ``service 
        provider'' have the meanings given such terms in section 
        2.</DELETED>
<DELETED>    (d) Effective Date.--This section shall take effect 
beginning one year after the date of enactment of this Act.</DELETED>

<DELETED>SEC. 7. MINIMUM NECESSARY GUIDANCE.</DELETED>

<DELETED>    Not later than 1 year after the date of enactment of this 
Act, the Secretary of Health and Human Services shall publish guidance 
on the application of the minimum necessary standard to data used for 
artificial intelligence and other machine learning applications and 
relevant requirements, including health data interoperability 
requirements under section 3001(c)(9) of the Public Health Service Act 
(42 U.S.C. 300jj-11(c)(9)) and the use of limited data sets pursuant to 
section 13405(b) of the HITECH Act (42 U.S.C. 17935(b)).</DELETED>

<DELETED>SEC. 8. DE-IDENTIFIED INFORMATION.</DELETED>

<DELETED>    (a) Establishment of Standards.--Not later than 1 year 
after the date of enactment of this Act, the Secretary of Health and 
Human Services shall promulgate regulations establishing unified 
national standards for rendering applicable health information as de-
identified information, in a manner similar to the manner in which 
individually identifiable health information may be rendered de-
identified information pursuant to part 164 of title 45, Code of 
Federal Regulations (or any successor regulations).</DELETED>
<DELETED>    (b) Composition of Standards.--Such standards shall--
</DELETED>
        <DELETED>    (1) be at least equivalent to or exceed the de-
        identification standard specified in section 164.514(b) of 
        title 45, Code of Federal Regulations (or any successor 
        regulations);</DELETED>
        <DELETED>    (2) specify standards for the use of privacy-
        enhancing technologies as a method for creating de-identified 
        information; and</DELETED>
        <DELETED>    (3) specify that information shall not qualify as 
        de-identified information when provided by a regulated entity, 
        service provider, covered entity, or business associate to 
        another person or entity unless such person or entity 
        contractually agrees in writing not to re-identify or attempt 
        to re-identify the information, and to require the same of any 
        person or entity to whom such person or entity provides the 
        information.</DELETED>
<DELETED>    (c) Definitions.--In this section--</DELETED>
        <DELETED>    (1) the term ``applicable health information'' has 
        the meaning given such term in section 2;</DELETED>
        <DELETED>    (2) the terms ``business associate'', ``covered 
        entity'', and ``individually identifiable health information'' 
        have the meanings given such terms in section 160.103 of title 
        45, Code of Federal Regulations (or any successor regulations); 
        and</DELETED>
        <DELETED>    (3) the term ``privacy enhancing technologies'' 
        means any software or hardware solution, technical process, or 
        other technological means of mitigating individuals' privacy 
        risks arising from data processing by enhancing predictability, 
        manageability, disassociability, and confidentiality.</DELETED>

<DELETED>SEC. 9. PREEMPTION.</DELETED>

<DELETED>    Section 160.203 of title 45, Code of Federal Regulations 
(or any successor regulations) shall apply to the requirements set 
forth under this Act in the same manner and to the same extent as such 
section applies to the standards, requirements, and implementation 
specifications under subchapter C of chapter I of subtitle A of title 
45, Code of Federal Regulations (or any successor 
regulations).</DELETED>

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Health Information Privacy Reform 
Act''.

SEC. 2. PROTECTIONS FOR APPLICABLE HEALTH INFORMATION.

    (a) In General.--Not later than 18 months after the date of 
enactment of this Act, the Secretary of Health and Human Services 
(referred to in this section as the ``Secretary''), in consultation 
with the Federal Trade Commission, shall promulgate regulations 
establishing and implementing privacy, security, and breach 
notification standards for the processing of applicable health 
information by regulated entities and their service providers. Such 
standards shall provide rights and protections that are at least 
equivalent to, and that, wherever feasible and appropriate, harmonize 
with, the rights and protections provided through the privacy, 
security, and breach notification rules promulgated under section 
264(c) of the Health Insurance Portability and Accountability Act of 
1996 (42 U.S.C. 1320d-2 note) and section 13402 of the HITECH Act (42 
U.S.C. 17932) that apply to covered entities and business associates 
with respect to protected health information under such rules. Such 
regulations promulgated under this section shall include the following:
            (1) Privacy requirements, including the following:
                    (A) Permitted uses and disclosures of applicable 
                health information without an individual's written 
                authorization that are consistent with the individual's 
                reasonable expectations, taking into consideration the 
                context in which the applicable health information was 
                obtained, provided that such regulations shall not 
                authorize such a use or disclosure to investigate, or 
                to impose liability on, any individual in connection 
                with the seeking, obtaining, providing, or facilitating 
                of health care.
                    (B) Uses and disclosures of applicable health 
                information that require the individual's written 
                authorization and the requirements related to such 
                written authorizations, including how the individual 
                may revoke such authorization, which shall include 
                requiring the individual's written authorization for 
                any sale, licensing, transfer, or marketing of 
                applicable health information.
                    (C) Prohibited uses and disclosures of applicable 
                health information.
                    (D) Minimum necessary requirements for the request, 
                use, and disclosure of applicable health information 
                and any exceptions that are necessary for purpose 
                specification, collection limitation, data 
                minimization, and limitation on secondary use and that 
                are consistent with subsection (b).
                    (E) Standards and requirements for an individual to 
                be authorized to exercise the rights granted in this 
                section with respect to applicable health information 
                of another individual.
                    (F) Standards and requirements related to service 
                providers.
                    (G)(i) Individual rights with respect to applicable 
                health information, including the following:
                            (I) The right of the individual to receive 
                        a privacy notice from the regulated entity, 
                        which shall describe the purposes for which the 
                        regulated entity uses and discloses applicable 
                        health information, the rights of the 
                        individual under this subparagraph, and the 
                        manner in which such rights may be exercised.
                            (II) The right of access to applicable 
                        health information, including the ability of 
                        the individual to direct the transmission of 
                        applicable health information held in an 
                        electronic health record to a third party.
                            (III) The right to amendment of applicable 
                        health information.
                            (IV) The right to deletion of applicable 
                        health information, not later than 30 days 
                        after the regulated entity or service provider 
                        receives a request for such a deletion, and 
                        allowing for the regulated entity or service 
                        provider to communicate with the individual 
                        making such request prior to fulfilling such 
                        request.
                            (V) The right to portability of applicable 
                        health information, including the ability of 
                        the individual to transfer such information 
                        between applications, services, or devices.
                    (ii) Any exception to, or condition or other 
                requirement on, a right described in any of subclauses 
                (I) through (V) of clause (i), including an exception 
                with respect to applicable health information collected 
                for research purposes and a timeframe for responding to 
                a request of an individual for applicable health 
                information.
                    (H) Administrative safeguards, including 
                designation of a privacy officer, policies and 
                procedures, training of workforce members, non-
                retaliation, documentation, and mitigation.
            (2) Security requirements, including the following:
                    (A) Physical, technical, and administrative 
                safeguards for applicable health information in written 
                or oral form.
                    (B) The application of the standards under subpart 
                C of part 164 of title 45, Code of Federal Regulations 
                (or any successor regulations) to electronic applicable 
                health information in the same manner as such standards 
                apply to electronic protected health information.
            (3) Breach notification requirements in the event of a 
        breach of applicable health information that are substantially 
        similar to the breach notification requirements under subpart D 
        of part 164 of title 45, Code of Federal Regulations (or any 
        successor regulations) for applicable health information that 
        is not subject to the health breach notification rule at part 
        318 of title 16, Code of Federal Regulations (or any successor 
        regulations).
    (b) Requirements for Regulated Entities and Service Providers.--
            (1) Data minimization.--A regulated entity or service 
        provider may not collect, process, or transfer applicable 
        health information beyond what a covered entity is permitted to 
        collect, process, or transfer under sections 164.502(b) and 
        164.514(d) of title 45, Code of Federal Regulations (or any 
        successor regulations).
            (2) Retention.--A regulated entity or service provider may 
        not retain applicable health information for longer than is 
        reasonably necessary to carry out the purpose for which such 
        information was collected.
            (3) Exceptions.--Paragraphs (1) and (2) shall not apply to 
        the collection, processing, or transfer of applicable health 
        information to the extent reasonably necessary for any of the 
        following purposes:
                    (A) To complete a transaction or provide a product 
                or service specifically requested by the individual to 
                whom such information relates.
                    (B) To comply with a legal obligation, or to 
                establish, exercise, or defend a legal claim.
                    (C) To prevent, detect, or respond to a security 
                incident, fraud, or harm to an individual.
                    (D) To carry out a public health activity permitted 
                under the regulations promulgated under subsection (a).
                    (E) To conduct research subject to part 46 of title 
                45, Code of Federal Regulations, or part 50 or 56 of 
                title 21, Code of Federal Regulations (or any successor 
                regulations).
    (c) Enforcement.--
            (1) Coordination.--Not later than 180 days after the date 
        of enactment of this Act, the Secretary and the Federal Trade 
        Commission shall enter into a memorandum of understanding that 
        allocates primary enforcement responsibility under this 
        section, provides for mutual notification of investigations 
        into violations of this section, and ensures that a regulated 
        entity or service provider is not subject to duplicative civil 
        penalties for the same act or omission.
            (2) Rule of construction.--Nothing in this Act shall be 
        construed to limit or supersede the authority of the Federal 
        Trade Commission under section 5 of the Federal Trade 
        Commission Act (15 U.S.C. 45).
            (3) Civil penalties.--In addition to any other sanctions or 
        remedies that may be available under any provision of Federal 
        law, in the case of a regulated entity or service provider that 
        violates this section, subpart D of part 160 of title 45, Code 
        of Federal Regulations (or any successor regulations) shall 
        apply to the regulated entity or service provider with respect 
        to such violation of this section in the same manner that such 
        subpart applies to a person with respect to a violation of part 
        160, 162, or 164 of subchapter C of chapter I of subtitle A of 
        title 45, Code of Federal Regulations (or any successor 
        regulations). Any funds collected through civil penalties under 
        this paragraph shall be used to support enforcement activity 
        under this section.
    (d) Extension of HITECH Act Amendment to Regulated Entities and 
Service Providers.--The privacy and security practices under section 
13412 of the Health Information Technology for Economic and Clinical 
Health Act (42 U.S.C. 17941) shall apply to regulated entities and 
service providers with respect to applicable health information in the 
same manner that such section applies to covered entities and business 
associates. Not later than 18 months after the date of enactment of 
this Act, the Secretary shall promulgate regulations to carry out this 
subsection.
    (e) Government Access.--A regulated entity or service provider may 
not sell or otherwise transfer applicable health information to a 
Federal, State, local, Tribal, or territorial governmental entity 
except as compelled by warrant, subpoena, court order, or other 
compulsory process.
    (f) Definitions.--In this section:
            (1) Applicable health information.--The term ``applicable 
        health information''--
                    (A) means information (including demographic 
                information)--
                            (i) that identifies an individual or with 
                        respect to which there is a reasonable basis to 
                        believe that the information could be used to 
                        identify an individual; and
                            (ii) that relates to the past, present, or 
                        future physical or mental health or condition 
                        of such individual, the past, present, or 
                        future provision of health care to such 
                        individual, or past, present, or future payment 
                        for the provision of health care to such 
                        individual;
                    (B) includes--
                            (i) information described in subparagraph 
                        (A) that was not created or received by a 
                        health care provider, health plan, employer, or 
                        health care clearinghouse; and
                            (ii) precise geolocation information that 
                        could reasonably indicate an attempt by an 
                        individual to acquire or receive a health 
                        service or supply; and
                    (C) does not include--
                            (i) information subject to--
                                    (I) title V of the Gramm-Leach-
                                Bliley Act (15 U.S.C. 6801 et seq.);
                                    (II) the requirements regarding the 
                                confidentiality of substance use 
                                disorder information under section 543 
                                of the Public Health Service Act (42 
                                U.S.C. 290dd-2);
                                    (III) section 444 of the General 
                                Education Provisions Act (20 U.S.C. 
                                1232g; commonly known as the ``Family 
                                Educational Rights and Privacy Act of 
                                1974'') and part 99 of title 34, Code 
                                of Federal Regulations (or any 
                                successor regulations) to the extent 
                                such regulated entity or service 
                                provider is an educational agency or 
                                institution as defined in such section 
                                of such Act or section 99.3 of title 
                                34, Code of Federal Regulations (or any 
                                successor regulations);
                                    (IV) provisions for the protection 
                                of identifiable private information 
                                that is collected pursuant to--
                                            (aa) the Federal 
                                        requirements for the protection 
                                        of human subjects under part 46 
                                        of title 45, Code of Federal 
                                        Regulations or part 50 or 56 of 
                                        title 21, Code of Federal 
                                        Regulations (or any successor 
                                        regulations); or
                                            (bb) the good clinical 
                                        practice guidelines issued by 
                                        the International Council for 
                                        Harmonisation of Technical 
                                        Requirements for 
                                        Pharmaceuticals for Human Use;
                                    (V) the Health Care Quality 
                                Improvement Act of 1986 (42 U.S.C. 
                                11101 et seq.); or
                                    (VI) part C of title IX of the 
                                Public Health Service Act (42 U.S.C. 
                                299b-21 et seq.);
                            (ii) publicly available information; or
                            (iii) information collected, processed, or 
                        transferred by an individual in the course of a 
                        purely personal or household activity.
            (2) Covered entities; business associates.--The terms 
        ``covered entities'' and ``business associates'' have the 
        meanings given such terms in section 160.103 of title 45, Code 
        of Federal Regulations (or any successor regulations).
            (3) Data broker.--The term ``data broker'' means a 
        regulated entity whose principal source of revenue is derived 
        from processing or transferring applicable health information 
        that the entity did not collect directly from the individuals 
        to whom such information relates.
            (4) Regulated entity.--The term ``regulated entity''--
                    (A) means a natural or legal person, including a 
                data broker, that, alone or jointly with others, 
                determines the purpose and means of processing 
                applicable health information; and
                    (B) does not include--
                            (i) a covered entity or business associate, 
                        with respect to protected health information; 
                        or
                            (ii) an individual who is the subject of 
                        the applicable health information or who 
                        obtains applicable health information in a 
                        personal or household capacity.
            (5) Service provider.--The term ``service provider'' means 
        a natural or legal entity that processes applicable health 
        information on behalf of a regulated entity and that is not a 
        covered entity or business associate.
    (g) Regulations.--The Secretary may promulgate regulations to carry 
out this section.

SEC. 3. RIGHTS AND REQUIREMENTS REGARDING ACCESS TO CERTAIN PROTECTED 
              HEALTH INFORMATION.

    (a) Time and Manner of Access.--In applying section 13405(e) of the 
Health Information Technology for Economic and Clinical Health Act (42 
U.S.C. 17935(e)) or section 164.524(c)(3)(ii) of title 45, Code of 
Federal Regulations (or any successor regulations), in the case that an 
individual requests that a covered entity or any business associate of 
a covered entity transmit, produce, or provide access to a copy of the 
individual's protected health information in an electronic health 
record to a person designated by the individual, the covered entity or 
business associate may condition the transmittal, production, or 
provision of access upon the person to whom the information is to be 
transmitted or produced or to whom access is to be provided--
            (1) paying fees, in accordance with applicable State law 
        and consistent with subsection (b), in advance of such 
        transmittal, production, or access; and
            (2) acknowledging and accepting the terms, limitations, and 
        conditions of use and disclosure contained in the request made 
        by the individual as the legally binding obligation of the 
        person receiving the information.
    (b) Fees.--In applying section 13405(e)(3) of the Health 
Information Technology for Economic and Clinical Health Act (42 U.S.C. 
17935(e)(3)) or section 164.524(c)(4) of title 45, Code of Federal 
Regulations (or any successor regulations), each such section shall 
apply only to the provision of access to, or the production, copying, 
or transmittal of, protected health information to--
            (1) the individual, or the individual's personal 
        representative;
            (2) the individual's health care provider or the business 
        associates of such provider; or
            (3) a personal health record managed and controlled by the 
        individual.
    (c) Definitions.--In this section--
            (1) the terms ``business associate'', ``covered entity'', 
        ``health care provider'', ``individual'', ``person'', and 
        ``protected health information'' have the meanings given such 
        terms in section 160.103 of title 45, Code of Federal 
        Regulations (or any successor regulations); and
            (2) the term ``personal health record'' has the meaning 
        given such term in section 13400 of the Health Information 
        Technology for Economic and Clinical Health Act (42 U.S.C. 
        17921).
    (d) Guidance.--Not later than 180 days after the date of enactment 
of this Act, the Secretary of Health and Human Services shall amend 
existing guidance as necessary to implement subsections (a) and (b).
    (e) Rules of Construction.--Nothing in this section shall be 
construed to--
            (1) permit a covered entity or business associate to deny, 
        delay, or condition a transmission directed by an individual in 
        a manner that constitutes information blocking under section 
        3022 of the Public Health Service Act (42 U.S.C. 300jj-52) or 
        part 171 of title 45, Code of Federal Regulations (or any 
        successor regulations);
            (2) treat an individual or the individual's personal 
        representative who receives or accesses the individual's 
        protected health information on the individual's behalf and at 
        the direction of the individual as a person to whom a fee or 
        condition may be applied under subsection (a), with respect to 
        a personal health record that is selected, managed, and 
        controlled by the individual or the individual's personal 
        representative; or
            (3) alter the rights or responsibilities of covered 
        entities and individuals under section 13405(e) of the HITECH 
        Act (42 U.S.C. 17935).

SEC. 4. MINIMUM NECESSARY GUIDANCE.

    (a) Rulemaking.--Not later than 1 year after the date of enactment 
of this Act, the Secretary of Health and Human Services (referred to in 
this section as the ``Secretary''), in coordination with the 
Commissioner of Food and Drugs and the National Coordinator for Health 
Information Technology, shall promulgate regulations regarding the 
application of the minimum necessary standard under section 164.502(b) 
of title 45, Code of Federal Regulations, to applicable health 
information and protected health information, including such 
information used to train, develop, validate, modify, or operate an 
artificial intelligence or other machine learning model.
    (b) Contents.--The regulations promulgated under subsection (a) 
shall--
            (1) clarify that such minimum necessary standard does not 
        permit a covered entity, business associate, regulated entity, 
        or service provider to deny, delay, or condition a use or 
        disclosure that is otherwise required or permitted, including a 
        disclosure required under section 3022 of the Public Health 
        Service Act (42 U.S.C. 300jj-52), on the ground that limiting 
        the disclosure to the minimum necessary information is not 
        technically feasible, and, as applicable, the minimum necessary 
        standard is satisfied by reasonable efforts to limit the 
        information used or disclosed, even where further technical 
        limitation is not feasible;
            (2) specify how the minimum necessary standard applies to 
        the use of applicable health information and protected health 
        information to develop, train, validate, or fine-tune an 
        artificial intelligence or machine learning model, including 
        the circumstances under which the use of a larger data set is 
        reasonably necessary for such development, and the extent to 
        which de-identification, data minimization, or privacy-
        enhancing technologies satisfy the standard; and
            (3) address the minimum necessary standard with respect to 
        the health data interoperability requirements under sections 
        3001(c)(9) and 3022 of the Public Health Service Act (42 U.S.C. 
        300jj-11(c)(9), 300jj-52) and part 171 of title 45, Code of 
        Federal Regulations (or any successor regulations).
    (c) Periodic Review.--The Secretary shall review, and update as 
appropriate, the regulations promulgated under subsection (a) not less 
frequently than once every 3 years.

SEC. 5. DE-IDENTIFIED INFORMATION.

    (a) Establishment of Standards.--Not later than 1 year after the 
date of enactment of this Act, the Secretary of Health and Human 
Services shall promulgate regulations establishing unified national 
standards for rendering applicable health information as de-identified 
information, in a manner similar to the manner in which individually 
identifiable health information may be rendered de-identified 
information pursuant to part 164 of title 45, Code of Federal 
Regulations (or any successor regulations).
    (b) Composition of Standards.--The standards under subsection (a) 
shall--
            (1) be at least as protective as the de-identification 
        standard specified in section 164.514(b)(1) of title 45, Code 
        of Federal Regulations (or any successor regulations) (relating 
        to expert determination), and may not permit information to be 
        rendered de-identified information solely through the method 
        specified in section 164.514(b)(2) of such title (relating to 
        safe harbor);
            (2) specify standards for the use of privacy-enhancing 
        technologies as a method for creating de-identified 
        information;
            (3) specify that information shall not qualify as de-
        identified information when provided by a regulated entity, 
        service provider, covered entity, or business associate to 
        another person or entity unless such person or entity 
        contractually agrees in writing not to re-identify or attempt 
        to re-identify the information, and to require the same of any 
        person or entity to whom such person or entity provides the 
        information; and
            (4) account for evolving methods of re-identification, 
        including methods that use artificial intelligence or machine 
        learning.
    (c) Prohibition on Re-identification.--An entity that is the 
recipient of de-identified information may not re-identify, or attempt 
to re-identify, such information. A violation of this subsection shall 
be enforceable and subject to the civil penalties under section 2(c).
    (d) Definitions.--In this section--
            (1) the term ``applicable health information'' has the 
        meaning given such term in section 2;
            (2) the terms ``business associate'', ``covered entity'', 
        and ``individually identifiable health information'' have the 
        meanings given such terms in section 160.103 of title 45, Code 
        of Federal Regulations (or any successor regulations); and
            (3) the term ``privacy-enhancing technologies'' means any 
        software or hardware solution, technical process, or other 
        technological means of mitigating individuals' privacy risks 
        arising from data processing by enhancing predictability, 
        manageability, disassociability, and confidentiality.

SEC. 6. PREEMPTION.

    Section 160.203 of title 45, Code of Federal Regulations (or any 
successor regulations) shall apply to the requirements set forth under 
this Act in the same manner and to the same extent as such section 
applies to the standards, requirements, and implementation 
specifications under subchapter C of chapter I of subtitle A of title 
45, Code of Federal Regulations (or any successor regulations).
                                                       Calendar No. 538

119th CONGRESS

  2d Session

                                S. 3097

_______________________________________________________________________

                                 A BILL

 To provide additional protections with respect to health information, 
                        and for other purposes.

_______________________________________________________________________

                             August 4, 2026

                       Reported with an amendment