Explore our Topics:

What’s next for the Senate bill that puts wearable health data under HIPAA-style rules?

The bill would put wearable makers and health app developers under HIPAA-equivalent federal rules for the first time.
By admin
Aug 31, 2026, 8:46 AM

Late last month, the Senate HELP Committee voted 22–0 to advance the Health Information Privacy Reform Act, a federal bill covering wearables and consumer health apps sponsored by committee chair Bill Cassidy, a Louisiana Republican and physician. If enacted, the bill would help close the gap between federal privacy law and the growing volume of health data being generated by smartwatches, rings, and smartphone apps, which physicians already rely on to help treat patients.

What will the Health Information Privacy Reform Act do?

Currently, HIPAA protections apply to covered entities, not to data. A patient’s heart-rate stream collected through a hospital’s remote monitoring program is protected health information. The same data stream, sitting in a consumer smartwatch account, is governed by the manufacturer’s privacy policy and the FTC’s general authority over deceptive practices.

The bill addresses that disparity by creating a new category of “regulated entities” — companies that hold identifiable health information but are not HIPAA-covered entities or business associates. That category includes:

  • Wearable makers
  • Health app developers
  • Data brokers
  • Cash-pay providers that never bill insurance

Under the legislation, HHS, in consultation with the FTC, would have 18 months to write privacy, security, and breach-notification standards at least equivalent to HIPAA’s. Individuals gain the right to a privacy notice, to access and amend their health information, to have it deleted within 30 days of a request, and to move it between apps and devices.

Some obligations are written directly into the statute. Regulated entities cannot collect or keep data beyond what HIPAA’s minimum-necessary rules allow for a covered entity, and they cannot sell health data to a government agency without a warrant, subpoena, or court order. Enforcement runs through HIPAA’s existing civil penalty structure. There is no private right of action, and stricter state laws survive under the same preemption rule HIPAA uses.

For health systems, where does HIPAA stop and the new law start?

Data leaves a hospital when a patient asks a portal to send records to an app. It enters the hospital when a clinician looks at a reading on a patient’s watch and writes it in their chart. HIPAA covers the hospital’s side, the new law would cover the app’s side, and every time data crosses, the rules change.

For outgoing data, the bill makes a small adjustment to rules that already exist. Since 2020, information-blocking regulations have required hospitals to send records to any app a patient names, with almost no say over what the app does next. The bill would let hospitals require the app to accept, in writing, the terms of use the patient specified. It’s a modest lever, and the bill is explicit that it can’t be used as an excuse to refuse the transfer.

The bill doesn’t address incoming data, because HIPAA already does. Once a smartwatch reading lands in a hospital chart, it’s protected health information, the same as any other patient-supplied value, and hospitals have handled those for years. What the bill changes is upstream. For the first time, the device that produced the reading would have carried federal obligations before the data arrived.

What happens to vendors that have never been regulated?

Most of a hospital’s vendors are already business associates under HIPAA, and the bill leaves them alone. The change is for the partners a hospital has no business associate agreement with—the consumer device makers and app developers whose data reaches clinicians without ever passing through a HIPAA contract.

Today, a hospital’s only leverage over those companies is whatever terms it can negotiate. Under the bill, they would carry federal obligations of their own, and a failure to protect data becomes a regulatory violation rather than a breach of terms.

A reality check for the legislation

Committee approval is an early step toward passage, and the path from here is long:

  • The bill sits on the Senate calendar with no floor date, and it has no House companion.
  • Even if enacted, real obligations arrive in 2028 at the earliest, after HHS rulemaking.
  • Bipartisan support is emerging but limited. Sen. Maggie Hassan of New Hampshire signed on as a Democratic cosponsor on August 5, but that doesn’t move the bill closer to a floor vote by the end of this Congress in January 2027, at which point it would need to be reintroduced.

The unanimous committee vote is notable, but the Center for Democracy and Technology has already signaled it wants more. “While the bill as amended is not perfect,” the group said, “we look forward to working with lawmakers to further improve the bill.”

HHS would gain two things if the bill passes: explicit authority from Congress, and an 18-month deadline to use it. That sounds good, until you remember that the agency is currently five years behind on finalizing a Privacy Rule update it proposed in 2021, and this time it has to write rules for an industry it has never regulated.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.