The bill strengthens privacy, cybersecurity, and federal accountability around identifiable health records—benefiting patients and health systems—but raises legal and access barriers that could increase costs, slow research, and limit emergency workforce flexibility.
Patients (including those with chronic conditions) and health systems will face stronger privacy protections and access controls, reducing the risk of medical data breaches and misuse and improving cybersecurity resilience.
Federal oversight will be increased through mandated OIG investigations and 30-day reporting to Congress after breaches, improving accountability and transparency when incidents occur.
Federal employees, contractors, and vendors face higher legal risk from new criminal penalties and a 10-year statute of limitations, which could deter legitimate support, raise staffing costs, and discourage outsourcing.
Researchers, contractors, and some specialists may lose access to identifiable health data, delaying research and operations that depend on that data.
Restrictive eligibility rules for access (e.g., one year continuous civil service, exclusion of special government employees) could limit surge capacity and complicate interagency collaboration during emergencies.
Based on analysis of 2 sections of legislative text.
Narrows who may access HHS systems containing identifiable health information, adds criminal penalties and requires IG investigations with 30‑day reports to Congress.
Official title: To prohibit the authorization of certain individuals to access certain systems containing individually identifiable health information.
Introduced March 26, 2025 by Diana DeGette · Last progress March 26, 2025
Prohibits any person or entity from being authorized to access HHS computer systems that contain individually identifiable health information except for narrowly defined categories of authorized HHS personnel and certain non-HHS individuals who meet strict security, ethics, training, and service requirements. Establishes criminal liability with a 10-year statute of limitations for unauthorized access and requires the HHS Inspector General to investigate and report to Congress within 30 days for each unauthorized access.