Data Privacy

A New Bill Would Extend Health Privacy Law to Your Phone. The Hard Part Comes Next.

Most people might assume that the health information on their phone is protected the way their medical records are. It is not.

Most people might assume that the health information on their phone is protected the way their medical records are. It is not.

The federal medical privacy law Americans know by name, Health Insurance Portability and Accountability Act of 1996 (HIPAA), does not follow health data around. It binds a specific list of institutions: healthcare providers, health plans, claims clearinghouses, and the contractors they hire. So the prescription list your pharmacy keeps is protected from being shared. The same list, sitting in the discount app you used to find a coupon for it, is not.

For example, in 2023 the Federal Trade Commission (FTC) fined GoodRx $1.5 million for sharing users’ prescription and health condition information with Facebook and Google after promising it would not. The FTC acted under consumer protection law. HIPAA was never in play, because it never applied to the company.

That is the gap S. 3097, the Health Information Privacy Reform Act, was written to close. Senator Bill Cassidy of Louisiana, a physician who chairs the Senate health committee, introduced it last November, and on July 30 the committee advanced it by a vote of 22 to 0.

What the Bill Would Do

The bill would change the question the law asks. Instead of asking who holds the information, it would ask what the information is.

The bill’s definition of health information is deliberately broad. It reaches any data that identifies a person, or could be used to identify one, and that relates to their health, their care, or how that care is paid for, including information no doctor, hospital, or health plan ever touched. It would also reach data that is not medical on its face, such as location history showing that a phone spent an hour inside an addiction treatment clinic.

From there, the bill would create rights people do not have now: to see the health data a company holds on them, to correct it, to move it to another service, and to have it deleted within 30 days. Selling health data, or using it for marketing, would require written permission.

It also draws some lines directly. A company could not hand health data to a government agency without a warrant, a subpoena, or similar legal process, and it could not keep that data longer than the purpose it was collected for reasonably requires. Anyone who receives health data stripped of names would be barred from trying to put them back.

What the Bill Would Not Do

It would not change anything on the hospital side. HIPAA keeps governing doctors, health plans, and their business associates, and the bill would build a second set of rules around everything HIPAA never reached. It would not let people sue over a violation, either, since enforcement would sit with the FTC and HHS.

It would not override state law. The bill follows HIPAA’s model, which leaves stronger state protections standing, so the consumer health privacy statutes in Washington and Nevada would survive it.

Most of all, S. 3097 would not do any of this soon. The bill contains almost no actual rules, only instructions, and it would give the U.S. Department of Health and Human Services (HHS) and the FTC 18 months after enactment to write the privacy, security, and breach standards that would carry the real weight. What those standards would say is a question Congress would hand to the agencies.

A few years ago, that would have been routine. Now it is the part of the plan most likely to fail.

A Recent History of Health Privacy Protections

In April 2024, HHS issued a rule giving extra protection to reproductive health information held in medical records. In June 2025, one federal district judge in Texas held that the agency had exceeded its authority and struck the rule down for the whole country, and the appeal was dismissed that September. The last time HHS tried to extend health privacy protection, the effort lasted about a year.

That case turned on the limits of HIPAA itself rather than on the Supreme Court’s decision in Loper Bright Enterprises v. Raimondo. But Loper Bright is why the ground has shifted. Courts used to accept an agency’s reasonable reading of an unclear statute, and now judges decide what a statute means for themselves.

On that score, S. 3097 would put HHS on firmer footing than it had in 2024, because it would hand HHS the pen in so many words instead of leaving it to find authority inside an older law. It would also direct HHS to permit uses that match a person’s “reasonable expectations” in context. The lawsuits would be about whose expectations count and how the agency would measure them.

What the Agencies Would Likely Do

The honest answer to whether S. 3097 would fill the gap is: partly, slowly, and only as far as the rules survive. Agencies that expect to be sued write narrow rules. They stay close to what the statute lists by name, and they borrow from regulations that have already held up in court, which here would mean borrowing from HIPAA.

That borrowing has a cost worth seeing in advance. HIPAA treats protected health information as essentially one category, and the most defensible rules under this bill would do the same, giving a fertility log and a step count the same default protection. I have argued that the law should scale what it demands to how much the data actually reveals, and that is precisely the sort of line a cautious agency declines to draw.

None of this is law yet. The bill still has to clear the Senate, the House, and the President’s desk, and a unanimous committee vote predicts none of that. If it does pass, the headlines will say that Congress protected the health data on your phone. What Congress will have done is assign that job to HHS and the FTC.

About the author

  • Gary Hsuanyu Liu

    Gary Hsuanyu Liu holds a J.S.D. from Washington University School of Law, where he held fellowships at the Cordell Institute for Policy in Medicine & Law and the Bioethics Research Center at the School of Medicine. His scholarship examines health data governance, the regulation of medical artificial intelligence, and fiduciary approaches to data law.