Skip to main content
Senate Bill Targets Wearables and AI Health DataData Privacy
5 min readFor Compliance Officers

Senate Bill Targets Wearables and AI Health Data

The Senate Health Education Labor and Pension committee voted unanimously last week to advance legislation extending HIPAA-like protections to health data currently outside regulatory reach. This marks a significant attempt to address the privacy gap created by consumer wearables, health apps, and AI-driven health technologies.

The timing is critical. As this bill moves through Congress, the U.S. Department of Health and Human Services (HHS) plans to finalize modifications to the HIPAA Privacy Rule this month, focusing on patient data access and care coordination. You're facing a regulatory landscape that's about to shift on two fronts simultaneously.

What the Bill Actually Does

The Health Information Privacy Reform Act directs HHS, working with the Federal Trade Commission, to establish privacy, security, and breach notification requirements for health data not covered by HIPAA. This includes wearable devices, health applications, and consumer health technology platforms.

The requirements would mirror HIPAA's structure: limits on uses and disclosures, individual rights, data security standards, and civil penalties modeled on existing HIPAA enforcement mechanisms.

Three provisions stand out:

AI guidance requirement: HHS must issue guidance on applying HIPAA's minimum necessary standard to artificial intelligence and machine learning applications within one year of enactment. This addresses a gap that's frustrated compliance teams for years. You've been making judgment calls about AI data use without clear regulatory guardrails.

Access notification: Organizations receiving protected health information through a patient's HIPAA Right of Access must notify the patient that the information will no longer be HIPAA-protected and explain how it may be redisclosed. This shifts the compliance burden to the receiving organization, not just the originating covered entity.

Sale authorization: Before information obtained through Right of Access can be sold to a third party, the individual must provide explicit authorization. This creates a new consent checkpoint in data monetization workflows.

The Regulatory Collision You Need to Plan For

HHS Office for Civil Rights has two major HIPAA Privacy Rule changes in its regulatory pipeline:

The final rule expected this month will strengthen patient access rights, improve information sharing for care coordination, and facilitate family and caregiver involvement during health crises. It also proposes to prohibit unreasonable identity verification measures when patients exercise their Right of Access.

A notice of proposed rulemaking scheduled for November would cut the response time for Right of Access requests from 30 days to 15 days. If finalized, this doubles the operational pressure on your PHI request workflows.

Here's what makes this complicated: the Senate bill extends HIPAA-like protections to new entities while HHS simultaneously tightens requirements for existing covered entities. You're managing compliance convergence, not just incremental change.

What This Means for Your Compliance Program

If you're a covered entity: You'll need to track where PHI goes after patients exercise their Right of Access. The notification requirement means you can't simply fulfill the request and move on. You'll need mechanisms to inform patients about downstream privacy implications and obtain authorization before any sale to third parties.

If you handle consumer health data outside HIPAA: You've operated in a regulatory gray zone. That's ending. Start mapping your data flows now against HIPAA's privacy and security requirements. The bill models its standards on HIPAA, so your gap analysis should use the HIPAA Security Rule's administrative, physical, and technical safeguards as a baseline.

If you use AI with health data: The one-year timeline for AI guidance is aggressive. Don't wait for final guidance to assess your AI applications against the minimum necessary standard. Document your current approach to Data Minimisation in AI training and inference. When guidance arrives, you'll need to demonstrate that you've been applying reasonable limits, not just using whatever data you had access to.

Action Items by Priority

Immediate (next 30 days):

  • Review your current Right of Access fulfillment process. Identify where PHI goes after you fulfill requests and whether you have visibility into downstream uses.
  • Inventory health data sources that fall outside HIPAA: wearables integrations, consumer health apps, wellness platforms. Map data flows and current privacy controls.
  • Document your AI and machine learning applications that use health data. For each, record what data you use, why you need it, and how you apply Data Minimisation principles.

Near-term (60-90 days):

  • Draft notification language for patients exercising Right of Access that explains loss of HIPAA protection and potential redisclosure. Run it through legal review.
  • Build authorization workflows for any third-party sales of information obtained through Right of Access. This includes data brokers, research partners, and analytics vendors.
  • Assess your identity verification process for Right of Access requests. If you're requiring notarization, in-person visits, or excessive documentation, you're likely creating "unreasonable measures" that the upcoming Privacy Rule changes will prohibit.

Strategic (6-12 months):

  • Develop a unified health data privacy framework that addresses both HIPAA-covered and non-HIPAA health data. Applying different standards to different data sources creates operational complexity and increases risk.
  • Prepare for 15-day Right of Access timelines. This isn't just a deadline change; it requires workflow redesign, potentially including automation of request intake, data retrieval, and fulfillment.
  • Establish an AI governance process specifically for health data applications. When HHS issues minimum necessary guidance, you'll need to demonstrate not just current compliance but a systematic approach to evaluating new AI uses.

The Bipartisan Signal

The 22-0 committee vote tells you something important about legislative momentum. Strong bipartisan support doesn't guarantee passage, but it changes the risk calculus for your planning. Treat this as a probable future state, not a speculative possibility.

Congressional liaisons note that the bill's sponsor is pushing key legislation before his term ends in January. That creates urgency but also uncertainty about final provisions.

What to Watch

Federal agencies routinely miss their regulatory timelines. HHS OCR postponed the planned HIPAA Security Rule overhaul from May to at least July 2027. The Privacy Rule modifications scheduled for this month could face similar delays.

But delay doesn't mean abandonment. The policy direction is clear: tighter patient access requirements, expanded regulatory coverage for consumer health technologies, and specific attention to AI applications.

Your compliance program needs to move faster than the regulators. By the time final rules publish, you should already be operating under the new requirements.

Federal Trade Commission

You Might Also Like