The Health Information Privacy Reform Act, advanced by the HELP Committee with a unanimous vote, will require non-HIPAA-regulated entities to implement HIPAA-like protections within 18 months of enactment. If your organization collects health data through apps, wearables, or direct-pay services, you'll need a compliance framework before the Department of Health and Human Services issues final regulations.
This checklist provides a structured approach to assess your current state and build toward readiness.
Purpose of the Checklist
Use this checklist to determine if your organization collects "consumer health data" that falls under the Act's scope, identify gaps in your current privacy and security controls, and document remediation steps. It's designed for compliance officers at companies that operate outside traditional HIPAA-covered entities but collect, store, or process health information.
The checklist covers five domains: scope determination, privacy controls, security safeguards, individual rights mechanisms, and breach response capabilities.
Prerequisites
Before you start, gather:
- Data inventory: A complete list of data elements your systems collect, including health metrics, biometric data, symptom logs, and any information that could reveal health conditions.
- Current privacy notice: Your existing terms of service, privacy policy, or consent forms.
- Technical architecture diagram: Where health data flows, who has access, and which third parties receive it.
- Incident response plan: Your current breach notification and containment procedures, if any.
You'll also need access to decision-makers who can authorize policy changes, budget for technical controls, and commit to timeline-driven remediation.
Compliance Readiness Checklist
Scope and Applicability
☐ Does your organization collect health information?
Document specific data types: fitness metrics, menstrual cycle data, glucose readings, medication adherence, symptom tracking, genetic information, mental health assessments.
☐ Are you currently regulated under HIPAA or the Health Information Technology for Economic and Clinical Health Act?
If yes, you're already subject to comparable requirements. If no, continue.
☐ Do you operate as a healthcare provider accepting only out-of-pocket payments?
The Act explicitly covers providers who don't bill insurance, closing a longstanding gap.
☐ Do you share health data with service providers or third parties?
List every entity that processes health data on your behalf. Under the Act, service providers will face compliance obligations similar to HIPAA business associates.
Privacy Framework Requirements
☐ Have you established permitted uses and disclosures without individual authorization?
The HHS will define these categories, likely mirroring HIPAA's treatment, payment, and healthcare operations carve-outs. Draft your permitted-use policy now, knowing you'll refine it once regulations are final.
☐ Do you have a written authorization process for uses beyond permitted categories?
Your authorization form must explain what data you'll collect, how you'll use it, who will receive it, and how individuals can revoke consent. Store signed authorizations for at least six years.
☐ Have you identified prohibited uses and disclosures?
Start with HIPAA's prohibited uses as a baseline: no sale of health data without explicit authorization, no marketing without consent, no disclosure for underwriting purposes.
☐ Does your data collection meet a minimum necessary standard?
Document why each data element is required for your stated purpose. If you're collecting data "just in case" or for unspecified future uses, you're not meeting minimum necessary requirements.
☐ Do you have Data Minimisation controls in place?
Implement automated purge schedules, limit data fields in collection forms, and configure systems to collect only what your privacy notice permits.
Security Safeguards
☐ Have you implemented physical safeguards for health data?
Secure server rooms, locked file cabinets for any paper records, visitor logs, and device disposal procedures that meet data destruction standards.
☐ Are technical safeguards aligned with the NIST Cybersecurity Framework 2.0 or HHS health sector cybersecurity performance goals?
The Act specifically references these frameworks. At minimum: encryption at rest and in transit, multi-factor authentication for system access, audit logging, and network segmentation.
☐ Do administrative safeguards include workforce training and access controls?
Assign a privacy officer, conduct annual training on health data handling, implement Role-Based Access Control, and maintain documentation of who accessed what data and when.
☐ Have you documented your risk assessment methodology?
You'll need a repeatable process for identifying threats to health data confidentiality, integrity, and availability, plus evidence that you've addressed identified risks.
Individual Rights Mechanisms
☐ Can individuals access their health data within a defined timeframe?
Under HIPAA, covered entities have 30 days. Build a portal or process that lets users download their data in a portable format.
☐ Do you have a process for data deletion requests?
The Act requires deletion within 30 days of a request. Configure your systems to purge data across all environments, including backups and third-party processors.
☐ Does your privacy notice inform individuals that data disclosed to them is no longer protected?
This is a specific requirement in the Act. When someone exercises their right to access, warn them that once they download their data, your security controls no longer apply.
☐ Can individuals request amendments to inaccurate health data?
Document your process for reviewing amendment requests, making corrections, and notifying any parties who received the inaccurate data.
Breach Notification Capabilities
☐ Do you have breach detection mechanisms in place?
Deploy intrusion detection, configure alerts for unusual data access patterns, and establish thresholds for what constitutes a "breach" under the Act's forthcoming definition.
☐ Have you drafted breach notification templates?
Prepare templates for individual notifications, HHS notifications (likely required within 60 days, mirroring HIPAA), and media notifications if a breach affects more than 500 individuals.
☐ Is your incident response plan aligned with HIPAA Breach Notification Rule timelines?
The Act calls for HIPAA-like breach notification. That means you'll need to notify affected individuals "without unreasonable delay" and no later than 60 days after discovery.
☐ Do you maintain a breach log?
Track every suspected breach, your investigation findings, whether notification was required, and what remediation steps you took.
Customizing the Checklist
Tailor the checklist to your organization's risk profile:
- Health app developers: Add items for mobile app security testing, third-party SDK audits, and app store privacy label accuracy.
- Wearable device manufacturers: Include firmware update mechanisms, Bluetooth security protocols, and device decommissioning procedures.
- Direct-pay healthcare providers: Add items for patient portal security, electronic health record access controls, and payment processor data flows.
If you operate in California or other states with existing health data privacy laws, add a section comparing state requirements to the federal baseline. The Act includes similar preemptions as HIPAA, meaning states can impose stricter requirements.
Validation Steps
Once you've completed the checklist:
1. Conduct a gap analysis
For every unchecked item, document the current state, required end state, estimated cost, and timeline to close the gap. Prioritize items that require vendor procurement or significant technical architecture changes.
2. Assign ownership
Every remediation item needs a named owner and a due date. Don't assign everything to your privacy officer; distribute responsibility across legal, IT, product, and operations teams.
3. Build a compliance timeline
The Act requires the HHS to promulgate regulations within 18 months of enactment. Work backward from that deadline. If the bill passes in early 2027, final regulations could arrive by mid-2028. You'll need at least six months to implement technical controls and train your workforce, which means starting remediation before regulations are final.
4. Engage your service providers
Send this checklist to every vendor that processes health data on your behalf. Ask them to complete it and provide evidence of their compliance readiness. If they can't meet the Act's requirements, you'll need to find alternative providers or bring capabilities in-house.
5. Document everything
The HHS and Federal Trade Commission will share enforcement authority. In the event of an investigation, you'll need evidence that you conducted a thorough assessment, identified gaps, and took reasonable steps to remediate them. Save dated versions of this checklist, gap analysis reports, and remediation project plans.
Your compliance readiness isn't binary. Even if you can't check every box before regulations are final, you can demonstrate good faith effort by documenting your assessment, prioritizing high-risk gaps, and making measurable progress toward full compliance.





