[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 3097 Reported in Senate (RS)]
<DOC>
Calendar No. 538
119th CONGRESS
2d Session
S. 3097
To provide additional protections with respect to health information,
and for other purposes.
_______________________________________________________________________
IN THE SENATE OF THE UNITED STATES
November 4, 2025
Mr. Cassidy introduced the following bill; which was read twice and
referred to the Committee on Health, Education, Labor, and Pensions
August 4, 2026
Reported by Mr. Cassidy, with an amendment
[Strike out all after the enacting clause and insert the part printed
in italic]
_______________________________________________________________________
A BILL
To provide additional protections with respect to health information,
and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
<DELETED>SECTION 1. SHORT TITLE.</DELETED>
<DELETED> This Act may be cited as the ``Health Information Privacy
Reform Act''.</DELETED>
<DELETED>SEC. 2. PROTECTIONS FOR APPLICABLE HEALTH
INFORMATION.</DELETED>
<DELETED> (a) In General.--The Secretary of Health and Human
Services, in consultation with the Federal Trade Commission, shall
promulgate regulations setting privacy, security, and breach
notifications standards for the processing of applicable health
information by regulated entities and their service providers. Such
standards shall provide protections that are at least commensurate
with, and wherever feasible and appropriate harmonize with, the
protections provided through the privacy, security, and breach
notification rules promulgated under section 264(c) of the Health
Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d-2
note) and section 13402 of the HITECH Act (42 U.S.C. 17932) that apply
to covered entities and business associates with respect to protected
health information under such rules. Such regulations promulgated under
this section shall include the following:</DELETED>
<DELETED> (1) Privacy requirements, including the
following:</DELETED>
<DELETED> (A) Permitted uses and disclosures of
applicable health information without an individual's
written authorization that are consistent with the
individual's reasonable expectations.</DELETED>
<DELETED> (B) Other permitted uses and disclosures
of applicable health information without an
individual's written authorization for certain public
policy purposes, such as public health, health
oversight, law enforcement, judicial and administrative
proceedings, and any conditions for such uses and
disclosures.</DELETED>
<DELETED> (C) Uses and disclosures of applicable
health information that require the individual's
written authorization and the requirements related to
such written authorizations.</DELETED>
<DELETED> (D) Prohibited uses and disclosures of
applicable health information.</DELETED>
<DELETED> (E) Minimum necessary requirements for the
request, use, and disclosure of applicable health
information and any exceptions.</DELETED>
<DELETED> (F) Standards and requirements related to
legal representatives of the individual.</DELETED>
<DELETED> (G) Standards and requirements related to
service providers.</DELETED>
<DELETED> (H) Individual rights with respect to
applicable health information, including the right of
the individual to receive a privacy notice from the
regulated entity, access to applicable health
information, amendment of applicable health
information, deletion of applicable health information,
and portability of applicable health information, and
any exceptions to such rights (such as with respect to
applicable health information collected for research
purposes), any conditions on such rights, and any other
requirements related to such rights, including
timeframes for responding to requests.</DELETED>
<DELETED> (I) Administrative safeguards, including
designation of a privacy officer, policies and
procedures, training of workforce members, non-
retaliation, documentation, and mitigation.</DELETED>
<DELETED> (2) Security requirements, including the
following:</DELETED>
<DELETED> (A) Physical, technical, and
administrative safeguards for applicable health
information in any form.</DELETED>
<DELETED> (B) For electronic applicable health
information, such safeguards shall be based on well-
established national frameworks, such as cybersecurity
performance goals of the National Institute of
Standards and Technology or the Department of Health
and Human Services.</DELETED>
<DELETED> (3) Breach notification requirements in the event
of a breach of applicable health information that are
substantially similar to the breach notification requirements
under subpart D of part 164 of title 45, Code of Federal
Regulations (or any successor regulations).</DELETED>
<DELETED> (b) Enforcement Authority.--The Secretary, in consultation
with the Federal Trade Commission, is authorized to enforce all
provisions of this Act as described in subsection (c).</DELETED>
<DELETED> (c) Civil Penalties.--In addition to any other sanctions
or remedies that may be available under any provision of Federal law,
in the case of a regulated entity or service provider that violates
this section, subpart D of part 160 of title 45, Code of Federal
Regulations (or any successor regulations), shall apply to the
regulated entity or service provider with respect to such violation of
this section in the same manner that such subpart applies to a person
with respect to a violation of part 160 of title 45, Code of Federal
Regulations (or any successor regulations).</DELETED>
<DELETED> (d) Extension of HITECH Act Amendment to Regulated
Entities and Service Providers.--The privacy and security practices
under section 13412 of the Health Information Technology for Economic
and Clinical Health Act (42 U.S.C. 17941) shall apply to regulated
entities and service providers with respect to applicable health
information in the same manner that such section applies to covered
entities and business associates.</DELETED>
<DELETED> (e) Definitions.--In this section:</DELETED>
<DELETED> (1) Applicable health information.--The term
``applicable health information''--</DELETED>
<DELETED> (A) means information (including
demographic information) that--</DELETED>
<DELETED> (i) identifies an individual or
with respect to which there is a reasonable
basis to believe that the information could be
used to identify an individual; and</DELETED>
<DELETED> (ii) relates to the past, present,
or future physical or mental health or
condition of an individual, the provision of
health care to an individual, or the past,
present, or future payment for the provision of
health care to an individual; and</DELETED>
<DELETED> (B) may include information described in
subparagraph (A) that was not created or received by a
health care provider, health plan, employer, or health
care clearinghouse.</DELETED>
<DELETED> (2) Covered entities; business associates.--The
terms ``covered entities'' and ``business associates'' have the
meanings given such terms in section 160.103 of title 45, Code
of Federal Regulations (or any successor
regulations).</DELETED>
<DELETED> (3) Regulated entity.--The term ``regulated
entity''--</DELETED>
<DELETED> (A) means a natural or legal person that,
alone or jointly with others, determines the purpose
and means of processing applicable health information;
and</DELETED>
<DELETED> (B) does not include--</DELETED>
<DELETED> (i) a governmental entity such as
a body, authority, board, bureau, commission,
district, agency, or political subdivision of
the Federal, State, or local
government;</DELETED>
<DELETED> (ii) a person or an entity that is
collecting, processing, or transferring covered
data on behalf of or a Federal, State, Tribal,
territorial, or local government entity;
and</DELETED>
<DELETED> (iii) a covered entity or business
associate, as such terms are defined in section
160.103 of title 45, Code of Federal
Regulations (or any successor
regulations).</DELETED>
<DELETED> (4) Service provider.--The term ``service
provider'' means a natural or legal entity that processes
applicable health information on a behalf of a regulated entity
and that is not a covered entity or business associate, as such
terms are defined in section 160.103 of title 45, Code of
Federal Regulations (or any successor regulations).</DELETED>
<DELETED>SEC. 3. RIGHTS AND REQUIREMENTS REGARDING ACCESS TO CERTAIN
PROTECTED HEALTH INFORMATION.</DELETED>
<DELETED> (a) Time and Manner of Access.--In applying section
13405(e) of the Health Information Technology for Economic and Clinical
Health Act (42 U.S.C. 17935(e)) or section 164.524(c)(3)(ii) of title
45, Code of Federal Regulations (or any successor regulations), in the
case that an individual requests that a covered entity or any business
associate of a covered entity transmit, produce, or provide access to a
copy of the individual's protected health information to a person,
including an entity, designated by the individual, and except where
permitted without authorization under section 164.506(c) of title 45,
Code of Federal Regulations (or any successor regulations)--</DELETED>
<DELETED> (1) the individual's request shall meet all
requirements of a valid authorization under section 164.508(b)
of title 45, Code of Federal Regulations (or any successor
regulations); and</DELETED>
<DELETED> (2) the covered entity or business associate may
condition the transmittal, production, or provision of access
upon the person to whom the information is to be transmitted or
produced or to whom access is to be provided--</DELETED>
<DELETED> (A) paying fees, in accordance with
applicable State law and consistent with subsection
(b), in advance of such transmittal, production, or
access; and</DELETED>
<DELETED> (B) acknowledging and accepting the terms,
limitations, and conditions of use and disclosure
contained in the request made by the individual as the
legally binding obligation of the person receiving the
information.</DELETED>
<DELETED> (b) Fees.--</DELETED>
<DELETED> (1) In general.--In applying section 13405(e)(3)
of the Health Information Technology for Economic and Clinical
Health Act (42 U.S.C. 17935(e)(3)) or section 164.524(c)(4) of
title 45, Code of Federal Regulations (or any successor
regulations), each such section shall apply only--</DELETED>
<DELETED> (A) to the provision of access to, or the
production, copying, or transmittal of, protected
health information directly to--</DELETED>
<DELETED> (i) the individual, or the
individual's personal representative for health
care purposes as described in section
164.502(g) of title 45, Code of Federal
Regulations (or any successor
regulations);</DELETED>
<DELETED> (ii) subject to paragraph (2) and
section 164.510(b) of title 45, Code of Federal
Regulations (or any successor regulation), any
other person identified in, and subject to the
limitations of, such section; or</DELETED>
<DELETED> (iii) the individual's health care
provider or the business associates of such
provider; and</DELETED>
<DELETED> (B) as directed by the individual, to the
electronic transmittal of the individual's electronic
health record to the patient portal or mobile medical
application used and maintained by the individual's
health care provider or for the health care provider by
its business associate.</DELETED>
<DELETED> (2) Additional limitations.--In the case of the
provision of access to, or the production, copying, or
transmittal of, protected health information under paragraph
(1)(A) directly to a person described in clause (ii) of such
paragraph, such protected health information shall, in
accordance with section 164.510(b) of title 45, Code of Federal
Regulations (or any successor regulations), be limited to only
such information that is--</DELETED>
<DELETED> (A) directly relevant to the person's
involvement with the care of the individual or with the
payment relevant to the care of the individual;
or</DELETED>
<DELETED> (B) needed for notification purposes
described in such section.</DELETED>
<DELETED> (c) Definitions.--In this section, the terms ``business
associate'', ``covered entity'', ``health care provider'',
``individual'', ``person'', and ``protected health information'' have
the meanings given such terms in section 160.103 of title 45, Code of
Federal Regulations (or any successor regulations).</DELETED>
<DELETED> (d) Guidance.--Not later than 180 days after the date of
enactment of this Act, the Secretary of Health and Human Services shall
amend existing guidance as necessary to implement subsections (a) and
(b).</DELETED>
<DELETED>SEC. 4. CONFIDENTIALITY OF RECORDS.</DELETED>
<DELETED> Section 543 of the Public Health Service Act (42 U.S.C.
290dd-2) is amended--</DELETED>
<DELETED> (1) in subsection (a), by striking ``subsection
(b)'' and inserting ``the HIPAA regulations'';</DELETED>
<DELETED> (2) in subsection (b)--</DELETED>
<DELETED> (A) in paragraph (2), by redesignating
subparagraphs (A) through (D) as paragraphs (1) through
(4), respectively, and adjusting the margins
accordingly; and</DELETED>
<DELETED> (B) by striking ``(b) Permitted
Disclosure'' and all that follows through ``(2) Method
for disclosure--Whether'' and inserting the
following:</DELETED>
<DELETED> ``(b) Permitted Disclosure.--Whether'';</DELETED>
<DELETED> (3) in subsection (c), in the matter preceding
paragraph (1), by striking ``subsection (b)(2)(C)'' and
inserting ``subsection (b)(3)''; and</DELETED>
<DELETED> (4) in subsection (g), by striking ``subsection
(b)(2)(C)'' and inserting ``subsection (b)(3)''.</DELETED>
<DELETED>SEC. 5. NAS STUDY ON COMPENSATION TO PATIENTS FOR SHARING
IDENTIFIABLE DATA FOR RESEARCH PURPOSES.</DELETED>
<DELETED> (a) In General.--Not later than 60 days after the date of
enactment of this Act, the Secretary of Health and Human Services shall
seek to enter into a contract with the National Academies of Sciences,
Engineering, and Medicine to conduct a study examining potential risks
and benefits of paying compensation to patients for sharing their
identifiable data for research purposes.</DELETED>
<DELETED> (b) Inclusions.--The study conducted pursuant to the
contract under subsection (a) shall include an examination of--
</DELETED>
<DELETED> (1) the risks to patient privacy posed by the
integration of identifiable, de-identified, and aggregated
health information into datasets used for research;</DELETED>
<DELETED> (2) privacy enhancing tools and methods for the
protection of patient health data;</DELETED>
<DELETED> (3) the feasibility of tracking patient data and
consent for the integration of patient health data into
datasets used for research;</DELETED>
<DELETED> (4) ethical considerations for compensating
patients for use of their identifiable and de-identified health
data;</DELETED>
<DELETED> (5) whether the existing exemptions permitting de-
identified data to be used for research should consider whether
a patient was given an opportunity to opt-in or opt-out of
participation; and</DELETED>
<DELETED> (6) risk of re-identification of de-identified
data.</DELETED>
<DELETED>SEC. 6. PATIENT NOTIFICATION REQUIREMENTS UNDER THE HIPAA
PRIVACY REGULATIONS.</DELETED>
<DELETED> (a) Patient Notification Upon Removal.--Any regulated
entity or service provider who gains access to the protected health
information of an individual through the patient right of access under
section 164.524 of title 45, Code of Federal Regulations (or any
successor regulations) shall--</DELETED>
<DELETED> (1) provide a written plain language notification
to such individual prior to accessing such information--
</DELETED>
<DELETED> (A) that such protected health information
will no longer be subject to the protections under the
HIPAA privacy regulation; and</DELETED>
<DELETED> (B) that includes an explanation of how
and to which entities such protected health information
may be redisclosed; and</DELETED>
<DELETED> (2) require the consent of the individual before
selling such protected health information to third
parties.</DELETED>
<DELETED> (b) Patient Notification Regarding Wellness Data.--
</DELETED>
<DELETED> (1) In general.--Any regulated entity or service
provider who offers digital technology that generates wellness
data about individuals shall, with respect to each individual
who uses such technology--</DELETED>
<DELETED> (A) provide a written plain language
notification to the individual in advance of initiating
the generation of such data that such data will not be
subject to the protections of the HIPAA privacy
regulation; and</DELETED>
<DELETED> (B) offer the individual an opportunity to
opt out of such wellness data generation.</DELETED>
<DELETED> (2) Wellness data.--In this subsection, the term
``wellness data'' means data generated for the purpose of
promoting health or preventing disease, which may include vital
statistics, step counts, and medical regimen
compliance.</DELETED>
<DELETED> (c) Definitions.--In this section--</DELETED>
<DELETED> (1) the terms ``business associate'', ``covered
entity'', and ``protected health information'' have the
meanings given such terms in section 160.103 of title 45, Code
of Federal Regulations (or any successor
regulations);</DELETED>
<DELETED> (2) the term ``HIPAA privacy regulation'' has the
meaning given such term in section 1180(b)(3) of the Social
Security Act (42 U.S.C. 1320d-9(b)(3)); and</DELETED>
<DELETED> (3) the terms ``regulated entity'' and ``service
provider'' have the meanings given such terms in section
2.</DELETED>
<DELETED> (d) Effective Date.--This section shall take effect
beginning one year after the date of enactment of this Act.</DELETED>
<DELETED>SEC. 7. MINIMUM NECESSARY GUIDANCE.</DELETED>
<DELETED> Not later than 1 year after the date of enactment of this
Act, the Secretary of Health and Human Services shall publish guidance
on the application of the minimum necessary standard to data used for
artificial intelligence and other machine learning applications and
relevant requirements, including health data interoperability
requirements under section 3001(c)(9) of the Public Health Service Act
(42 U.S.C. 300jj-11(c)(9)) and the use of limited data sets pursuant to
section 13405(b) of the HITECH Act (42 U.S.C. 17935(b)).</DELETED>
<DELETED>SEC. 8. DE-IDENTIFIED INFORMATION.</DELETED>
<DELETED> (a) Establishment of Standards.--Not later than 1 year
after the date of enactment of this Act, the Secretary of Health and
Human Services shall promulgate regulations establishing unified
national standards for rendering applicable health information as de-
identified information, in a manner similar to the manner in which
individually identifiable health information may be rendered de-
identified information pursuant to part 164 of title 45, Code of
Federal Regulations (or any successor regulations).</DELETED>
<DELETED> (b) Composition of Standards.--Such standards shall--
</DELETED>
<DELETED> (1) be at least equivalent to or exceed the de-
identification standard specified in section 164.514(b) of
title 45, Code of Federal Regulations (or any successor
regulations);</DELETED>
<DELETED> (2) specify standards for the use of privacy-
enhancing technologies as a method for creating de-identified
information; and</DELETED>
<DELETED> (3) specify that information shall not qualify as
de-identified information when provided by a regulated entity,
service provider, covered entity, or business associate to
another person or entity unless such person or entity
contractually agrees in writing not to re-identify or attempt
to re-identify the information, and to require the same of any
person or entity to whom such person or entity provides the
information.</DELETED>
<DELETED> (c) Definitions.--In this section--</DELETED>
<DELETED> (1) the term ``applicable health information'' has
the meaning given such term in section 2;</DELETED>
<DELETED> (2) the terms ``business associate'', ``covered
entity'', and ``individually identifiable health information''
have the meanings given such terms in section 160.103 of title
45, Code of Federal Regulations (or any successor regulations);
and</DELETED>
<DELETED> (3) the term ``privacy enhancing technologies''
means any software or hardware solution, technical process, or
other technological means of mitigating individuals' privacy
risks arising from data processing by enhancing predictability,
manageability, disassociability, and confidentiality.</DELETED>
<DELETED>SEC. 9. PREEMPTION.</DELETED>
<DELETED> Section 160.203 of title 45, Code of Federal Regulations
(or any successor regulations) shall apply to the requirements set
forth under this Act in the same manner and to the same extent as such
section applies to the standards, requirements, and implementation
specifications under subchapter C of chapter I of subtitle A of title
45, Code of Federal Regulations (or any successor
regulations).</DELETED>
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Health Information Privacy Reform
Act''.
SEC. 2. PROTECTIONS FOR APPLICABLE HEALTH INFORMATION.
(a) In General.--Not later than 18 months after the date of
enactment of this Act, the Secretary of Health and Human Services
(referred to in this section as the ``Secretary''), in consultation
with the Federal Trade Commission, shall promulgate regulations
establishing and implementing privacy, security, and breach
notification standards for the processing of applicable health
information by regulated entities and their service providers. Such
standards shall provide rights and protections that are at least
equivalent to, and that, wherever feasible and appropriate, harmonize
with, the rights and protections provided through the privacy,
security, and breach notification rules promulgated under section
264(c) of the Health Insurance Portability and Accountability Act of
1996 (42 U.S.C. 1320d-2 note) and section 13402 of the HITECH Act (42
U.S.C. 17932) that apply to covered entities and business associates
with respect to protected health information under such rules. Such
regulations promulgated under this section shall include the following:
(1) Privacy requirements, including the following:
(A) Permitted uses and disclosures of applicable
health information without an individual's written
authorization that are consistent with the individual's
reasonable expectations, taking into consideration the
context in which the applicable health information was
obtained, provided that such regulations shall not
authorize such a use or disclosure to investigate, or
to impose liability on, any individual in connection
with the seeking, obtaining, providing, or facilitating
of health care.
(B) Uses and disclosures of applicable health
information that require the individual's written
authorization and the requirements related to such
written authorizations, including how the individual
may revoke such authorization, which shall include
requiring the individual's written authorization for
any sale, licensing, transfer, or marketing of
applicable health information.
(C) Prohibited uses and disclosures of applicable
health information.
(D) Minimum necessary requirements for the request,
use, and disclosure of applicable health information
and any exceptions that are necessary for purpose
specification, collection limitation, data
minimization, and limitation on secondary use and that
are consistent with subsection (b).
(E) Standards and requirements for an individual to
be authorized to exercise the rights granted in this
section with respect to applicable health information
of another individual.
(F) Standards and requirements related to service
providers.
(G)(i) Individual rights with respect to applicable
health information, including the following:
(I) The right of the individual to receive
a privacy notice from the regulated entity,
which shall describe the purposes for which the
regulated entity uses and discloses applicable
health information, the rights of the
individual under this subparagraph, and the
manner in which such rights may be exercised.
(II) The right of access to applicable
health information, including the ability of
the individual to direct the transmission of
applicable health information held in an
electronic health record to a third party.
(III) The right to amendment of applicable
health information.
(IV) The right to deletion of applicable
health information, not later than 30 days
after the regulated entity or service provider
receives a request for such a deletion, and
allowing for the regulated entity or service
provider to communicate with the individual
making such request prior to fulfilling such
request.
(V) The right to portability of applicable
health information, including the ability of
the individual to transfer such information
between applications, services, or devices.
(ii) Any exception to, or condition or other
requirement on, a right described in any of subclauses
(I) through (V) of clause (i), including an exception
with respect to applicable health information collected
for research purposes and a timeframe for responding to
a request of an individual for applicable health
information.
(H) Administrative safeguards, including
designation of a privacy officer, policies and
procedures, training of workforce members, non-
retaliation, documentation, and mitigation.
(2) Security requirements, including the following:
(A) Physical, technical, and administrative
safeguards for applicable health information in written
or oral form.
(B) The application of the standards under subpart
C of part 164 of title 45, Code of Federal Regulations
(or any successor regulations) to electronic applicable
health information in the same manner as such standards
apply to electronic protected health information.
(3) Breach notification requirements in the event of a
breach of applicable health information that are substantially
similar to the breach notification requirements under subpart D
of part 164 of title 45, Code of Federal Regulations (or any
successor regulations) for applicable health information that
is not subject to the health breach notification rule at part
318 of title 16, Code of Federal Regulations (or any successor
regulations).
(b) Requirements for Regulated Entities and Service Providers.--
(1) Data minimization.--A regulated entity or service
provider may not collect, process, or transfer applicable
health information beyond what a covered entity is permitted to
collect, process, or transfer under sections 164.502(b) and
164.514(d) of title 45, Code of Federal Regulations (or any
successor regulations).
(2) Retention.--A regulated entity or service provider may
not retain applicable health information for longer than is
reasonably necessary to carry out the purpose for which such
information was collected.
(3) Exceptions.--Paragraphs (1) and (2) shall not apply to
the collection, processing, or transfer of applicable health
information to the extent reasonably necessary for any of the
following purposes:
(A) To complete a transaction or provide a product
or service specifically requested by the individual to
whom such information relates.
(B) To comply with a legal obligation, or to
establish, exercise, or defend a legal claim.
(C) To prevent, detect, or respond to a security
incident, fraud, or harm to an individual.
(D) To carry out a public health activity permitted
under the regulations promulgated under subsection (a).
(E) To conduct research subject to part 46 of title
45, Code of Federal Regulations, or part 50 or 56 of
title 21, Code of Federal Regulations (or any successor
regulations).
(c) Enforcement.--
(1) Coordination.--Not later than 180 days after the date
of enactment of this Act, the Secretary and the Federal Trade
Commission shall enter into a memorandum of understanding that
allocates primary enforcement responsibility under this
section, provides for mutual notification of investigations
into violations of this section, and ensures that a regulated
entity or service provider is not subject to duplicative civil
penalties for the same act or omission.
(2) Rule of construction.--Nothing in this Act shall be
construed to limit or supersede the authority of the Federal
Trade Commission under section 5 of the Federal Trade
Commission Act (15 U.S.C. 45).
(3) Civil penalties.--In addition to any other sanctions or
remedies that may be available under any provision of Federal
law, in the case of a regulated entity or service provider that
violates this section, subpart D of part 160 of title 45, Code
of Federal Regulations (or any successor regulations) shall
apply to the regulated entity or service provider with respect
to such violation of this section in the same manner that such
subpart applies to a person with respect to a violation of part
160, 162, or 164 of subchapter C of chapter I of subtitle A of
title 45, Code of Federal Regulations (or any successor
regulations). Any funds collected through civil penalties under
this paragraph shall be used to support enforcement activity
under this section.
(d) Extension of HITECH Act Amendment to Regulated Entities and
Service Providers.--The privacy and security practices under section
13412 of the Health Information Technology for Economic and Clinical
Health Act (42 U.S.C. 17941) shall apply to regulated entities and
service providers with respect to applicable health information in the
same manner that such section applies to covered entities and business
associates. Not later than 18 months after the date of enactment of
this Act, the Secretary shall promulgate regulations to carry out this
subsection.
(e) Government Access.--A regulated entity or service provider may
not sell or otherwise transfer applicable health information to a
Federal, State, local, Tribal, or territorial governmental entity
except as compelled by warrant, subpoena, court order, or other
compulsory process.
(f) Definitions.--In this section:
(1) Applicable health information.--The term ``applicable
health information''--
(A) means information (including demographic
information)--
(i) that identifies an individual or with
respect to which there is a reasonable basis to
believe that the information could be used to
identify an individual; and
(ii) that relates to the past, present, or
future physical or mental health or condition
of such individual, the past, present, or
future provision of health care to such
individual, or past, present, or future payment
for the provision of health care to such
individual;
(B) includes--
(i) information described in subparagraph
(A) that was not created or received by a
health care provider, health plan, employer, or
health care clearinghouse; and
(ii) precise geolocation information that
could reasonably indicate an attempt by an
individual to acquire or receive a health
service or supply; and
(C) does not include--
(i) information subject to--
(I) title V of the Gramm-Leach-
Bliley Act (15 U.S.C. 6801 et seq.);
(II) the requirements regarding the
confidentiality of substance use
disorder information under section 543
of the Public Health Service Act (42
U.S.C. 290dd-2);
(III) section 444 of the General
Education Provisions Act (20 U.S.C.
1232g; commonly known as the ``Family
Educational Rights and Privacy Act of
1974'') and part 99 of title 34, Code
of Federal Regulations (or any
successor regulations) to the extent
such regulated entity or service
provider is an educational agency or
institution as defined in such section
of such Act or section 99.3 of title
34, Code of Federal Regulations (or any
successor regulations);
(IV) provisions for the protection
of identifiable private information
that is collected pursuant to--
(aa) the Federal
requirements for the protection
of human subjects under part 46
of title 45, Code of Federal
Regulations or part 50 or 56 of
title 21, Code of Federal
Regulations (or any successor
regulations); or
(bb) the good clinical
practice guidelines issued by
the International Council for
Harmonisation of Technical
Requirements for
Pharmaceuticals for Human Use;
(V) the Health Care Quality
Improvement Act of 1986 (42 U.S.C.
11101 et seq.); or
(VI) part C of title IX of the
Public Health Service Act (42 U.S.C.
299b-21 et seq.);
(ii) publicly available information; or
(iii) information collected, processed, or
transferred by an individual in the course of a
purely personal or household activity.
(2) Covered entities; business associates.--The terms
``covered entities'' and ``business associates'' have the
meanings given such terms in section 160.103 of title 45, Code
of Federal Regulations (or any successor regulations).
(3) Data broker.--The term ``data broker'' means a
regulated entity whose principal source of revenue is derived
from processing or transferring applicable health information
that the entity did not collect directly from the individuals
to whom such information relates.
(4) Regulated entity.--The term ``regulated entity''--
(A) means a natural or legal person, including a
data broker, that, alone or jointly with others,
determines the purpose and means of processing
applicable health information; and
(B) does not include--
(i) a covered entity or business associate,
with respect to protected health information;
or
(ii) an individual who is the subject of
the applicable health information or who
obtains applicable health information in a
personal or household capacity.
(5) Service provider.--The term ``service provider'' means
a natural or legal entity that processes applicable health
information on behalf of a regulated entity and that is not a
covered entity or business associate.
(g) Regulations.--The Secretary may promulgate regulations to carry
out this section.
SEC. 3. RIGHTS AND REQUIREMENTS REGARDING ACCESS TO CERTAIN PROTECTED
HEALTH INFORMATION.
(a) Time and Manner of Access.--In applying section 13405(e) of the
Health Information Technology for Economic and Clinical Health Act (42
U.S.C. 17935(e)) or section 164.524(c)(3)(ii) of title 45, Code of
Federal Regulations (or any successor regulations), in the case that an
individual requests that a covered entity or any business associate of
a covered entity transmit, produce, or provide access to a copy of the
individual's protected health information in an electronic health
record to a person designated by the individual, the covered entity or
business associate may condition the transmittal, production, or
provision of access upon the person to whom the information is to be
transmitted or produced or to whom access is to be provided--
(1) paying fees, in accordance with applicable State law
and consistent with subsection (b), in advance of such
transmittal, production, or access; and
(2) acknowledging and accepting the terms, limitations, and
conditions of use and disclosure contained in the request made
by the individual as the legally binding obligation of the
person receiving the information.
(b) Fees.--In applying section 13405(e)(3) of the Health
Information Technology for Economic and Clinical Health Act (42 U.S.C.
17935(e)(3)) or section 164.524(c)(4) of title 45, Code of Federal
Regulations (or any successor regulations), each such section shall
apply only to the provision of access to, or the production, copying,
or transmittal of, protected health information to--
(1) the individual, or the individual's personal
representative;
(2) the individual's health care provider or the business
associates of such provider; or
(3) a personal health record managed and controlled by the
individual.
(c) Definitions.--In this section--
(1) the terms ``business associate'', ``covered entity'',
``health care provider'', ``individual'', ``person'', and
``protected health information'' have the meanings given such
terms in section 160.103 of title 45, Code of Federal
Regulations (or any successor regulations); and
(2) the term ``personal health record'' has the meaning
given such term in section 13400 of the Health Information
Technology for Economic and Clinical Health Act (42 U.S.C.
17921).
(d) Guidance.--Not later than 180 days after the date of enactment
of this Act, the Secretary of Health and Human Services shall amend
existing guidance as necessary to implement subsections (a) and (b).
(e) Rules of Construction.--Nothing in this section shall be
construed to--
(1) permit a covered entity or business associate to deny,
delay, or condition a transmission directed by an individual in
a manner that constitutes information blocking under section
3022 of the Public Health Service Act (42 U.S.C. 300jj-52) or
part 171 of title 45, Code of Federal Regulations (or any
successor regulations);
(2) treat an individual or the individual's personal
representative who receives or accesses the individual's
protected health information on the individual's behalf and at
the direction of the individual as a person to whom a fee or
condition may be applied under subsection (a), with respect to
a personal health record that is selected, managed, and
controlled by the individual or the individual's personal
representative; or
(3) alter the rights or responsibilities of covered
entities and individuals under section 13405(e) of the HITECH
Act (42 U.S.C. 17935).
SEC. 4. MINIMUM NECESSARY GUIDANCE.
(a) Rulemaking.--Not later than 1 year after the date of enactment
of this Act, the Secretary of Health and Human Services (referred to in
this section as the ``Secretary''), in coordination with the
Commissioner of Food and Drugs and the National Coordinator for Health
Information Technology, shall promulgate regulations regarding the
application of the minimum necessary standard under section 164.502(b)
of title 45, Code of Federal Regulations, to applicable health
information and protected health information, including such
information used to train, develop, validate, modify, or operate an
artificial intelligence or other machine learning model.
(b) Contents.--The regulations promulgated under subsection (a)
shall--
(1) clarify that such minimum necessary standard does not
permit a covered entity, business associate, regulated entity,
or service provider to deny, delay, or condition a use or
disclosure that is otherwise required or permitted, including a
disclosure required under section 3022 of the Public Health
Service Act (42 U.S.C. 300jj-52), on the ground that limiting
the disclosure to the minimum necessary information is not
technically feasible, and, as applicable, the minimum necessary
standard is satisfied by reasonable efforts to limit the
information used or disclosed, even where further technical
limitation is not feasible;
(2) specify how the minimum necessary standard applies to
the use of applicable health information and protected health
information to develop, train, validate, or fine-tune an
artificial intelligence or machine learning model, including
the circumstances under which the use of a larger data set is
reasonably necessary for such development, and the extent to
which de-identification, data minimization, or privacy-
enhancing technologies satisfy the standard; and
(3) address the minimum necessary standard with respect to
the health data interoperability requirements under sections
3001(c)(9) and 3022 of the Public Health Service Act (42 U.S.C.
300jj-11(c)(9), 300jj-52) and part 171 of title 45, Code of
Federal Regulations (or any successor regulations).
(c) Periodic Review.--The Secretary shall review, and update as
appropriate, the regulations promulgated under subsection (a) not less
frequently than once every 3 years.
SEC. 5. DE-IDENTIFIED INFORMATION.
(a) Establishment of Standards.--Not later than 1 year after the
date of enactment of this Act, the Secretary of Health and Human
Services shall promulgate regulations establishing unified national
standards for rendering applicable health information as de-identified
information, in a manner similar to the manner in which individually
identifiable health information may be rendered de-identified
information pursuant to part 164 of title 45, Code of Federal
Regulations (or any successor regulations).
(b) Composition of Standards.--The standards under subsection (a)
shall--
(1) be at least as protective as the de-identification
standard specified in section 164.514(b)(1) of title 45, Code
of Federal Regulations (or any successor regulations) (relating
to expert determination), and may not permit information to be
rendered de-identified information solely through the method
specified in section 164.514(b)(2) of such title (relating to
safe harbor);
(2) specify standards for the use of privacy-enhancing
technologies as a method for creating de-identified
information;
(3) specify that information shall not qualify as de-
identified information when provided by a regulated entity,
service provider, covered entity, or business associate to
another person or entity unless such person or entity
contractually agrees in writing not to re-identify or attempt
to re-identify the information, and to require the same of any
person or entity to whom such person or entity provides the
information; and
(4) account for evolving methods of re-identification,
including methods that use artificial intelligence or machine
learning.
(c) Prohibition on Re-identification.--An entity that is the
recipient of de-identified information may not re-identify, or attempt
to re-identify, such information. A violation of this subsection shall
be enforceable and subject to the civil penalties under section 2(c).
(d) Definitions.--In this section--
(1) the term ``applicable health information'' has the
meaning given such term in section 2;
(2) the terms ``business associate'', ``covered entity'',
and ``individually identifiable health information'' have the
meanings given such terms in section 160.103 of title 45, Code
of Federal Regulations (or any successor regulations); and
(3) the term ``privacy-enhancing technologies'' means any
software or hardware solution, technical process, or other
technological means of mitigating individuals' privacy risks
arising from data processing by enhancing predictability,
manageability, disassociability, and confidentiality.
SEC. 6. PREEMPTION.
Section 160.203 of title 45, Code of Federal Regulations (or any
successor regulations) shall apply to the requirements set forth under
this Act in the same manner and to the same extent as such section
applies to the standards, requirements, and implementation
specifications under subchapter C of chapter I of subtitle A of title
45, Code of Federal Regulations (or any successor regulations).
Calendar No. 538
119th CONGRESS
2d Session
S. 3097
_______________________________________________________________________
A BILL
To provide additional protections with respect to health information,
and for other purposes.
_______________________________________________________________________
August 4, 2026
Reported with an amendment