Senate HELP Committee Advances Bill Extending HIPAA-Style Protections to Consumer Health Data and Wearables

Table of Contents

The Senate Committee on Health, Education, Labor and Pensions voted 22-0 to advance an amended version of the Health Information Privacy Reform Act. The bipartisan measure, originally introduced in November 2025 by Committee Chair Sen. Bill Cassidy (R-La.), aims to close long-standing gaps in federal health privacy law by extending HIPAA-like privacy, security, and breach-notification requirements to categories of health information that currently fall outside the Health Insurance Portability and Accountability Act.

If enacted, the legislation would direct the Department of Health and Human Services, working with the Federal Trade Commission, to create a regulatory framework covering health data collected by consumer applications, wearable-device platforms, and other non-traditional sources. The requirements would include limits on uses and disclosures, individual rights, data-security standards, and civil penalties modeled on the existing HIPAA structure. The bill also calls for HHS guidance on applying the minimum-necessary standard to health data used in artificial intelligence and machine-learning systems, to be issued within one year of enactment.

Andrew Crawford, privacy attorney at the Center for Democracy & Technology, summarized the practical effect: the bill would “ensure a person’s health data is protected, whether it’s collected by a doctor, the manufacturer of a wearable device or an AI assistant.” While imperfect, he noted, it would deliver meaningful benefits to consumers and reduce the volume of unprotected health data circulating in the commercial marketplace.

The Current Regulatory Gap

HIPAA’s Privacy, Security, and Breach Notification Rules apply primarily to covered entities—health plans, most healthcare providers, and healthcare clearinghouses—and their business associates. Consumer-facing health technologies that sit outside those categories have operated under a thinner and more fragmented set of rules. Wearable devices that track heart rate, sleep, blood oxygen, or activity levels; wellness and fertility applications; mental-health chatbots; and AI-powered symptom checkers often collect highly sensitive information without being bound by HIPAA’s use-and-disclosure restrictions, individual access rights, or mandatory breach-notification timelines.

State laws have partially filled the vacuum. Washington’s My Health My Data Act, Nevada’s consumer health data statute, and similar measures in other jurisdictions impose consent, transparency, and sale-restriction requirements on entities that collect consumer health data. Yet the patchwork creates compliance complexity for national platforms and leaves residents of non-adopting states with weaker baseline protections. A federal floor would reduce that inconsistency while still allowing stronger state rules to remain in place.

The Health Information Privacy Reform Act seeks to establish that floor. Covered organizations would face limits on how they use and share the newly protected data, obligations to provide individuals with rights comparable to those under HIPAA (access, amendment, accounting of disclosures), security standards, and civil penalty exposure for non-compliance. Service providers that receive protected health information through an individual’s HIPAA right of access would be required to notify the patient that the information is leaving the HIPAA-protected environment and to explain potential redisclosures. Sale of that information to third parties would require the individual’s prior authorization.

Timing and Parallel Regulatory Activity

The committee’s action arrives as HHS’s Office for Civil Rights is preparing to finalize long-pending modifications to the HIPAA Privacy Rule. Those modifications, first proposed in January 2021, are intended to strengthen patients’ right of access, improve information sharing for care coordination and case management, and facilitate greater involvement of family members and caregivers in emergency situations. The regulatory agenda indicates a final rule is expected this month, though agencies frequently miss or extend such deadlines.

OCR is also scheduled to issue a notice of proposed rulemaking in November that would shorten the response time for right-of-access requests from 30 days to 15 days. Separate work on a comprehensive overhaul of the 23-year-old HIPAA Security Rule has been postponed until at least July 2027.

Taken together, the legislative and regulatory tracks suggest a period of heightened activity around health data governance. Organizations that already operate under HIPAA will need to track both the new consumer-health framework and the forthcoming Privacy Rule changes. Companies that have previously treated their wellness or wearable data as outside HIPAA’s reach will face a more fundamental shift in obligations if the Health Information Privacy Reform Act becomes law.

Practical Implications for Organizations Collecting Consumer Health Data

For product, compliance, and legal teams, the bill raises several immediate planning questions even though final enactment remains uncertain.

First, data mapping and classification will become more critical. Teams will need to distinguish clearly between data that is already HIPAA-protected, data that would fall under the new consumer-health regime, and data that remains outside both frameworks. Wearable platforms that aggregate sensor data with user-provided health information, or that share data with research partners or advertisers, will need granular inventories to determine which flows trigger the new requirements.

Second, consent and authorization mechanisms will require review. The bill’s restriction on sale of data obtained through a HIPAA right-of-access request, and its broader limits on uses and disclosures, will likely necessitate more granular consent interfaces and clearer downstream contractual controls with service providers and analytics partners.

Third, individual rights processes will expand. Access, correction, and deletion requests that today apply only to HIPAA-covered data may need to be extended to the newly protected consumer-health categories. Organizations that currently operate dual systems—one for clinical data and another for consumer wellness data—will face pressure to harmonize those processes or to maintain carefully segregated workflows with clear user-facing explanations.

Fourth, security and breach-notification programs will need alignment. The bill contemplates security standards and civil penalties modeled on HIPAA. Companies that have relied on general FTC expectations or state-law security requirements may need to elevate technical and administrative safeguards, incident-response playbooks, and vendor-management practices to a HIPAA-comparable level for the newly covered data sets.

Fifth, AI and machine-learning uses of health data will receive specific attention. The requirement that HHS issue guidance on the minimum-necessary standard in AI contexts signals that regulators intend to scrutinize how large volumes of consumer health data are used to train or operate models. Organizations developing or deploying health-related AI features should begin documenting purpose limitation, data minimization, and access controls with that future guidance in mind.

Impact on Wearables, Apps, and AI Health Assistants

Consumer wearables and health applications sit at the center of the bill’s intended coverage. Devices and platforms that collect physiological or behavioral data for wellness, fitness, or self-tracking purposes have grown rapidly, yet many operate with limited transparency about secondary uses, third-party sharing, or retention. Extending structured privacy and security obligations to these services would reduce the current asymmetry between clinical and consumer health data.

AI assistants that ingest health-related prompts or continuous sensor streams raise additional questions. When a user discusses symptoms, medications, or mental-health concerns with a generative AI tool, the resulting conversation data can be highly sensitive. Under the current framework that data often receives only the general protections applicable to ordinary consumer information. The proposed legislation would bring such interactions closer to the standards applied to traditional healthcare interactions, at least with respect to use limitations, individual rights, and breach response.

For manufacturers and platform operators, the practical compliance burden will vary with business model. Companies that already treat consumer health data with elevated care—through strong encryption, limited retention, and clear purpose binding—will face a smaller transition. Those that have monetized health data through advertising, data brokerage, or unrestricted secondary research will need more substantial redesign of product features, contracts, and internal governance.

Legislative Outlook and Political Context

The 22-0 committee vote demonstrates broad bipartisan support within the HELP Committee. Full Senate consideration and House action remain open questions. The 2026 legislative calendar is crowded, and success will depend on prioritization by leadership and the ability to maintain the bipartisan coalition that carried the measure through committee. Sen. Cassidy has indicated interest in advancing key health-related legislation before the end of his current term in January 2027, which may create a window for further movement.

Even if the bill does not become law in its current form, the committee action contributes to a growing consensus that the HIPAA boundary no longer matches the reality of how Americans generate and share health-related information. Parallel state activity and FTC enforcement under Section 5 of the FTC Act against unfair or deceptive health-data practices already signal that the status quo is under pressure. Federal legislation would simply accelerate and standardize the shift.

Time to Update Data Inventories

Organizations that collect or process consumer health data can take several concrete steps while the legislative process continues.

Update data inventories to flag datasets that would likely fall under a new federal consumer-health regime. Pay particular attention to wearable sensor streams, user-entered health information in wellness apps, and conversational data from health-oriented AI features.

Review existing privacy notices and in-product disclosures for clarity about secondary uses, sharing, and retention of health-related information. Gaps that would be problematic under a HIPAA-style regime are already potential sources of regulatory or litigation risk under state laws and FTC authority.

Assess vendor and partner contracts for flow-down of privacy and security obligations. If the bill becomes law, service providers handling the newly protected data will need contractual terms that support compliance with use limitations, individual rights, and breach notification.

Examine internal access controls and audit logging for consumer health data. Demonstrating that access is limited to personnel with a legitimate need, and that access is logged and reviewable, will be central to any future security-standard compliance.

Begin scenario planning for individual rights requests that span both HIPAA-covered and non-covered health data. Users increasingly expect consistent experiences; maintaining entirely separate processes may become operationally and reputationally costly.

Monitor the forthcoming HIPAA Privacy Rule finalization and the November right-of-access proposal. Changes to clinical data rights will interact with any new consumer-health framework and may influence user expectations across both domains.

HIPRA – Health Information Privacy Reform Act

The Health Information Privacy Reform Act reflects a larger trend: regulators and legislators are less willing to accept bright-line distinctions between “clinical” and “consumer” health data when the sensitivity of the information is comparable and the potential for harm is real. Similar dynamics appear in other domains—location data, biometric identifiers, and children’s information—where sector-specific regimes are being supplemented or replaced by broader baseline protections.

For companies whose products sit at the intersection of health, wellness, and technology, the practical response is to treat elevated sensitivity as the default rather than the exception. Building governance, technical controls, and user rights processes that can scale to HIPAA-comparable expectations positions an organization to adapt whether the current bill becomes law, is revised, or is eventually superseded by different federal legislation.

The unanimous committee vote does not guarantee enactment. It does, however, signal that the policy conversation has moved beyond whether consumer health data deserves stronger federal protection to the narrower questions of scope, implementation timeline, and enforcement design. Organizations that begin closing internal gaps now will be better prepared for whatever final framework emerges.

Captain Compliance will continue to track the bill’s progress, the parallel HIPAA Privacy Rule updates, and related state and federal developments that affect how health and wellness data must be governed. Companies evaluating their current posture should treat the committee action as a prompt to test the resilience of their existing privacy and security programs against a more demanding set of expectations—not as a distant legislative possibility that can be safely ignored until final passage.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.