Get all your news in one place.
100's of premium titles.
One app.
Start reading
Medical Daily
Medical Daily
Health
Joseph James

A Senate Committee Voted 22 to 0 to Cover the Health Data That HIPAA Was Never Written to Protect

The Senate's health committee voted unanimously this week to advance a bill built on a premise most Americans get wrong: the heart rate on your smartwatch, the cycle you logged in a period app, and the symptoms you typed into a wellness platform are, in most cases, not protected by HIPAA at all.

The Health Information Privacy Reform Act cleared the Senate Health, Education, Labor, and Pensions Committee by a vote of 22 to 0. The bill was introduced by committee chairman Sen. Bill Cassidy, a Louisiana Republican and a physician, who has said that smartwatches and health apps change the way people manage their health while creating privacy questions that did not exist when care happened only in an exam room.

A unanimous vote on a health data bill is unusual enough to be the story. It is also worth being clear about what a committee vote is: an early procedural step, not a law.


What HIPAA Actually Covers, and What It Never Did

The confusion is understandable because the law is named for portability and insurance, not privacy, and because "HIPAA" gets invoked constantly as a catch-all for medical confidentiality.

HIPAA's privacy and security rules apply to covered entities and their business associates. Covered entities are health plans, health care clearinghouses, and health care providers that conduct certain transactions electronically, such as billing insurance. Business associates are the companies that handle protected health information on their behalf.

That structure made sense when it was written. Health information was generated and held by doctors, hospitals, insurers, and their vendors. Today, a substantial share of the most intimate health data a person produces never touches any of them. A fitness tracker recording sleep patterns, a mental health app storing session notes, a fertility app tracking cycles, and a direct-to-consumer wellness platform selling supplements are typically outside HIPAA entirely.

What applies instead is a patchwork. The Federal Trade Commission's Health Breach Notification Rule reaches some of these companies, and Section 5 of the FTC Act prohibits unfair or deceptive practices. Some states, notably Washington and California, have built their own consumer health data protections. The result is that identical data can carry very different legal protection depending on which company holds it.


What the Bill Would Require

S. 3097 does not itself write the rules. It directs the Secretary of Health and Human Services, in consultation with the FTC, to promulgate regulations setting privacy, security, and breach notification standards for what the bill calls applicable health information held by regulated entities and their service providers.

Those standards would have to provide protections at least commensurate with, and where feasible harmonized with, the existing HIPAA privacy, security, and breach notification rules and the corresponding HITECH Act provisions. The introduced text also reaches individual rights such as accessing, amending, and deleting personal health data, administrative and technical safeguards, and standards for de-identifying information.

The bill additionally addresses areas that sit inside HIPAA's existing perimeter, including the confidentiality of substance use disorder records and patient notification requirements, along with the process by which patients direct their medical records to outside apps.

The committee approved the bill with a manager's amendment, according to the HELP Committee's executive session agenda. That means the advanced text is not identical to what was introduced, and the final language is what will matter.


Why the Vote Count Matters More Than the Text Right Now

Comprehensive privacy legislation has failed in Congress repeatedly, usually along partisan lines and usually over preemption of state law and whether individuals can sue.

A 22-to-0 committee vote signals that this particular bill has avoided those fault lines so far, at least at the committee stage. That is meaningful for a topic that has generated white papers and hearings for years without moving. As the McDermott+ health policy summary of the week noted, the measure was the only health-related bill among ten the committee considered.

It is not a prediction. Bills clear committee unanimously and then never receive floor time. The Senate calendar is compressed heading into August recess, and nothing has been scheduled.


What Is Not Settled

Because the bill delegates the substance to a rulemaking, the questions that determine whether it protects anyone remain open.

The definition of applicable health information will decide whether ordinary behavioral data such as location, purchases, and search activity counts when it reveals a health condition. The scope of permitted uses will decide whether companies can continue sharing data for advertising with consent buried in terms of service. The de-identification standard will decide how easily stripped data can be re-linked to a person. Enforcement authority and whether the framework preempts stronger state laws are unresolved in public reporting.

Rulemaking would take considerable time after any enactment, which means the practical effect on a person's phone today is zero.


What You Can Do About Your Own Data Now

The gap the bill targets exists right now, and consumers are not without options while Congress works.

Reviewing app permissions is the highest yield step, particularly location access for health-related apps, which frequently has no clinical purpose. Most phones allow location to be restricted to while using the app or denied outright. Health apps commonly offer a data sharing or personalization toggle in settings that is enabled by default.

Reading what a company says it does with data before entering sensitive information is tedious but useful, and the section to look for is the one about sharing with third parties or affiliates rather than the general privacy language. Deleting an account, where the option exists, is generally more effective than simply deleting the app, which often leaves data on the company's servers.

For anyone worried about a specific category of information, the practical rule is that data given to a clinician, hospital, insurer, or their contractor carries HIPAA protection, and data given to a consumer app generally does not. Suspected misuse of health data by a company can be reported to the FTC, and to a state attorney general in states with consumer health data laws.

The next milestone worth watching is whether Senate leadership schedules floor time in the fall, and whether a companion measure emerges in the House.


Frequently Asked Questions

What happened? The Senate HELP Committee voted 22 to 0 to advance the Health Information Privacy Reform Act, which would extend HIPAA-style protections to health data held by companies HIPAA does not cover.

Is it law now? No. Committee approval is an early step. The bill has not passed the Senate or the House and is not law.

Does HIPAA cover my fitness tracker? Generally no. HIPAA applies to health plans, clearinghouses, most providers, and their business associates. Consumer apps and wearables usually fall outside it.

So my health app data has no protection at all? It has some. The FTC's Health Breach Notification Rule and Section 5 of the FTC Act apply to some companies, and several states have their own consumer health data laws.

What would the bill actually do? Direct HHS, with the FTC, to write privacy, security, and breach notification rules at least commensurate with HIPAA for this category of data.

When would anything change for consumers? Not soon. Even if enacted, the standards would come through a rulemaking process that takes substantial time.

What can I do right now? Review app permissions, especially location. Turn off default data sharing settings. Delete accounts rather than just apps. Report suspected misuse to the FTC or your state attorney general.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.