Senator · R-LA
The bill strengthens individual privacy and clarifies national rules for handling health data (including access, de-identification, AI use, and consent) at the cost of substantial compliance burdens, potential limits on innovation and data-driven research, and some retained disclosure exceptions.
Patients and other individuals gain clearer, stronger control over their health data — including notice, access, amendment, deletion, portability, warnings when PHI will lose HIPAA protections, and consent before sales — making it easier to share records with third parties while limiting unauthorized commercialization.
Privacy, security, and breach-notification protections are strengthened and harmonized with HIPAA/HITECH and national cybersecurity standards (e.g., NIST/§160.203), increasing transparency and baseline safeguards for health data across covered entities.
The bill creates clearer, unified standards for de-identification, contractual prohibitions on re-identification, and guidance for AI/ML data use — encouraging privacy-enhancing technologies and safer data sharing for research and algorithm development.
Hospitals, providers, service vendors, and many businesses will face substantial compliance, administrative, and technical costs to implement HIPAA-like privacy/security rules, notices, consent tracking, contractual requirements, and new processes.
Stricter use limits, contractual bans on re-identification, tighter designee requirements, and narrower fee protections could slow or restrict data-driven innovation, limit research and AI development, and reduce some product features or dataset access.
Patients and their designees may face new out-of-pocket charges or reduced access when obtaining records because fee protections are narrowed and some third-party requests can be subject to advance fees or business-imposed restrictions.
Based on analysis of 9 sections of legislative text.
Creates HIPAA-like national privacy, security, breach-notice, de-identification, and consent rules for broader health data and requires HHS/FTC rulemaking and guidance.
Official title: Provide additional protections with respect to health information, and for other purposes.
Introduced November 4, 2025 by Bill Cassidy · Last progress November 4, 2025
Creates a unified national framework that extends HIPAA-style privacy, security, breach-notification, de-identification, and notice/consent rules to a broader category of health-related data called “applicable health information.” It directs HHS (with the FTC) to write regulations and guidance on permitted uses/disclosures, individual rights (notice, access, amendment, deletion, portability), minimum-necessary practices for AI/ML and interoperability, de-identification standards, and requirements for notices to individuals when their data leaves HIPAA protections. The bill also requires a National Academies study on compensating patients for sharing identifiable health data for research.