The US Senate Health Committee has unanimously approved a sweeping bill aiming to overhaul health-data privacy laws, extending protections to consumer health devices, apps, and wearables amidst ongoing industry concerns.
The US Senate Health, Education, Labour and Pensions Committee has moved closer to a federal health-data privacy overhaul, unanimously advancing the Health Information Privacy Reform Act after chair Bill Cassidy rewrote the measure through a manager’s amendment. The bill is designed to fill gaps left by HIPAA, which protects information handled by covered entities and their business associates, but does not reach much of the consumer health data gathered by wearables, wellness platforms and mobile apps, according to Cassidy’s office and legal analyses of the proposal.
The revised text would impose a wider set of obligations on organisations that collect or process what the bill calls applicable health information. According to the committee summary and practitioner reviews, the amendment would require HHS to issue implementing rules within 18 months, limit collection and retention to what is reasonably necessary, tighten rules on sale and marketing, add protections for precise geolocation data linked to health care, and require written authorisation with a revocation right for transfers or commercial uses. It would also create a data-broker category, restrict disclosures to government bodies absent legal process, and direct HHS, the FDA and the Office of the National Coordinator for Health Information Technology to write binding rules on the use of health data in artificial intelligence and machine-learning systems.
The substitute amendment also narrows the bill in some respects. According to the materials from the HELP Committee and later legal commentary, it adds explicit carve-outs for data already covered by laws and regimes including the Gramm-Leach-Bliley Act, 42 CFR Part 2, FERPA and several clinical research and patient-safety frameworks. It also raises the de-identification bar by requiring the expert-determination approach, rather than allowing the HIPAA safe-harbour method on its own, and adds an express prohibition on re-identification. Enforcement would be shared between HHS and the FTC through a memorandum of understanding, with an aim of avoiding duplicate penalties.
Cassidy has framed the bill as part of a broader push to modernise protections for health information captured by consumer technology. His office said in November 2025 that the original measure was meant to address technologies such as smartwatches and health apps, and he told the committee in July 2026 that robust privacy safeguards are needed if patients are to trust modern tools. The committee approved the bill on a 22-0 vote, with Senator Maggie Hassan among the co-sponsors, and sent it to the Senate calendar. It still faces the usual hurdles of floor scheduling, House consideration and final reconciliation before it could reach the President.
For businesses handling consumer health data, the vote is a warning rather than an immediate compliance deadline. Legal advisers say companies in digital health, advertising technology, wearables, health apps and data brokerage should now assess how the draft’s limits on collection, retention, authorisation, geolocation, deletion and de-identification would affect current practices. The measure may yet change further, but its unanimous committee passage signals that Congress is treating consumer health privacy as a live policy priority.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





