Every time someone straps on a smartwatch to track their heart rate or opens a mood-tracking app powered by AI, they generate health data that, in most cases, no federal privacy law actually protects. The Senate Health, Education, Labor and Pensions Committee took a unanimous step toward closing that gap on August 7, 2026, voting 22-0 to advance the Health Information Privacy Reform Act, bipartisan legislation from Chairman Bill Cassidy (R-LA) and Senator Maggie Hassan (D-NH).
The Gap the Bill Is Built to Close
HIPAA, the federal law most Americans assume covers all their health information, only applies to a specific set of “covered entities” — doctors, hospitals, insurers, and their business associates. It says nothing about the fitness tracker on someone’s wrist, the AI-powered symptom checker on their phone, or the mental-health chatbot they confide in at 2 a.m. Data from all of those tools currently flows under whatever privacy policy the company itself chooses to write, with essentially no federal floor. Cassidy, who is also a physician, put the problem plainly: “Smartwatches and health apps are helpful tools but open the door to privacy concerns that didn’t exist when it was just a patient and a doctor in an exam room.” Hassan framed it similarly: “Americans are increasingly using smartwatches, health rings, and apps to take charge of their health, but our privacy laws haven’t kept up with these new technologies.”
What the Bill Actually Requires
The legislation would extend HIPAA-like privacy, security, and breach-notification standards to a newly defined category called “consumer health data,” covering technologies that currently fall outside HIPAA entirely. Companies would have to clearly disclose how they collect and share health information, apply data-minimization principles so they aren’t hoarding more information than a product actually needs, and honor consumer deletion requests within 30 days. Notably, the bill also directs the Department of Health and Human Services to issue specific guidance, within one year of enactment, on how existing HIPAA rules should apply to artificial intelligence and machine learning platforms used in healthcare — an explicit acknowledgment that AI tools built on patient data are a distinct regulatory problem, not just a variant of ordinary software.
Who Has to Follow the New Rules, and When
Under the bill, HHS, in consultation with the Federal Trade Commission, would have 18 months after enactment to write and finalize the detailed privacy, security, and breach-notification regulations that give the law its teeth. That two-step structure — a statute now, detailed rules later — is common for privacy legislation but means the practical protections consumers would feel are still years away even if the bill passes quickly.
Why Bipartisan Consensus Came Together Now
The 22-0 committee vote is notable in a Congress where privacy legislation has repeatedly stalled over disagreements about state preemption and private rights of action. Cassidy and Hassan appear to have sidestepped those fights by narrowly targeting health data specifically rather than attempting comprehensive consumer privacy reform, and by building on momentum from recent high-profile health data scandals — including the 2023 breach and subsequent $150 million multistate settlement involving genetic testing company 23andMe — that have made health data privacy a rare area of continued bipartisan concern even amid broader gridlock on tech regulation.
The Skepticism That Remains
Even bill supporters acknowledge its limitations. A statute requiring HHS to “consider” AI guidance within a year is not the same as Congress writing specific AI rules itself, and privacy advocates who have watched similar delegated-rulemaking approaches slow-walk into years of delay are wary of declaring victory at the committee-vote stage. There is also no private right of action in the bill’s current form, meaning enforcement would run through HHS and the FTC rather than allowing individuals to sue companies directly over violations — a limitation privacy litigators have flagged in similar past legislation as weakening real-world deterrence.
What Happens Next
The bill now moves to the full Senate for consideration, with no confirmed floor vote date yet. Its bipartisan committee margin gives it a better-than-average chance of eventually reaching the Senate floor, but comprehensive federal privacy legislation has a long history of dying between committee approval and a floor vote in Congress. If it does pass, the real test will come in the 18 months after enactment, when HHS and the FTC translate the bill’s broad principles — including its directive on AI and machine learning — into the specific rules that will determine what wearable and AI health app makers can actually do with people’s data.
Photo: Patrick / PEXELS via Pexels