The bill strengthens individual privacy and standardizes protections (de‑identification, breach rules, limits on sales) and clarifies AI/interoperability obligations, at the cost of substantial compliance burdens, potential limits on research and innovation, and reduced flexibility for states to maintain stronger rules.
Patients (including people with chronic conditions, people with disabilities, and Medicaid beneficiaries) gain stronger, HIPAA‑equivalent privacy and access rights — including the ability to access, delete, amend, port, and direct electronic health information to third parties with limits on downstream sharing.
Patients and beneficiaries get stronger security and breach‑notification protections through application of HIPAA Security Rule standards and mandatory breach notices, raising baseline data safety for electronic health information.
Patients and consumers benefit from limits on secondary uses, sales, and re‑identification (including written‑authorization requirements and bans on re‑identification), reducing commercial exploitation of health data.
Hospitals, providers, business associates, tech developers, and small businesses face substantial new compliance costs (policies, privacy officers, security safeguards, contractual obligations, deletion systems) that will be borne largely by the health sector and vendors.
Researchers, public‑health agencies, and patients may see reduced or delayed access to data (stricter de‑identification, deletion requirements, sale limits, and tighter 'minimum necessary' rules), which could slow clinical research, public‑health analytics, and AI innovation.
Patients, caregivers, app developers, and third‑party tools may face fees, binding contractual obligations, or legal exposure to receive EHR transmissions, creating barriers that could limit practical patient access via intermediaries.
Based on analysis of 9 sections of legislative text.
Establishes national privacy, security, de‑identification, and breach-notification standards for health data, clarifies HIPAA 'minimum necessary' for AI, and bans recipient re‑identification.
Official title: Provide additional protections with respect to health information, and for other purposes.
Introduced November 4, 2025 by Bill Cassidy · Last progress November 4, 2025
Sets national privacy, security, and breach-notification rules for health-related data beyond HIPAA and requires HHS (with FTC/FDA/ONC coordination) to issue regulations and guidance on how HIPAA standards apply to modern data uses, including AI/ML. It creates unified federal standards for de-identification, bans re-identification by recipients, strengthens individual rights (access, amendment, deletion, portability), and harmonizes minimum-necessary rules for data used in AI and interoperability. Requires multiple rulemakings and guidance documents within 12–18 months, applies administrative and breach-notification duties to regulated entities and their service providers, and makes violations subject to civil penalties and contractual limits on re-identification when sharing de-identified information.