S. 3097 would extend HIPAA-style rules to fitness trackers, health apps, and other companies HIPAA does not currently reach. HHS would write the actual regulations.
What happened
The Senate Health, Education, Labor, and Pensions Committee voted 22-0 on July 30, 2026, to advance S. 3097, the Health Information Privacy Reform Act, which would extend HIPAA-style protections to health information held by companies HIPAA has never covered. Senator Bill Cassidy, a Louisiana Republican and the committee's chairman, introduced the bill in November 2025 and reported it out on August 4 with an amendment in the nature of a substitute, according to the congressional record of actions. The measure was placed on the Senate Legislative Calendar under General Orders as Calendar No. 538 the same day.
Going deeper
Section 2 directs the Secretary of Health and Human Services, in consultation with the Federal Trade Commission, to write the regulations setting privacy, security, and breach notification standards for what the introduced text calls "applicable health information." The definition covers identifiable data about a person's physical or mental health, their care, or payment for that care, including data never created or received by a provider, health plan, employer, or clearinghouse. Those standards would have to be at least commensurate with the existing HIPAA privacy, security, and breach notification rules. Security requirements would draw on national frameworks such as the cybersecurity performance goals published by the National Institute of Standards and Technology or HHS. Enforcement runs through the same civil penalty structure at 45 CFR part 160 subpart D that already applies to covered entities. The committee approved a manager's amendment, so the substitute text is what moves forward.
What was said
The manager's amendment "is a positive step," the Center for Democracy and Technology said in a statement on the markup, describing the amended bill as beginning to address core privacy protections the organization has pushed for while stopping short of what it wants. The group named limits on collection, use, and sharing, rights of access and deletion, and a prohibition on government purchases of health data.
In the know
A congressional liaison who asked not to be named told BankInfoSecurity that Cassidy is looking to push several pieces of legislation through before his term ends in January, against a 2026 legislative calendar already close to full. HHS has not begun the rulemaking the bill depends on. Committee approval is an early procedural step, and the bill still needs floor time in both chambers.
The big picture
Under Section 3, a patient's request to send records to an outside app would have to meet the full authorization requirements at 45 CFR 164.508(b), and the covered entity could require fees in advance and make the recipient accept stated limits on use and disclosure. Section 6 puts a duty on the receiving end. Before accessing anything, an app taking records through the patient right of access would have to tell the individual in plain language that HIPAA protection ends there, and get consent before selling the data. Then there is de-identification. Section 8 would set national standards under which nothing counts as de-identified unless the recipient contractually agrees not to re-identify it and binds anyone downstream to the same terms. Patient portals, research data-sharing arrangements, and third-party app integrations would each need revisiting.
FAQs
Why does health data from an app fall outside HIPAA?
HIPAA applies to covered entities, meaning providers, health plans, and clearinghouses, along with their business associates. A company selling a fitness tracker or a symptom-logging app usually has none of those relationships, so the data it collects sits outside the rules regardless of how medical the information looks.
What protections apply to that data today?
Mainly the FTC Act's prohibition on unfair or deceptive practices, the FTC's Health Breach Notification Rule for health apps not covered by HIPAA, and state laws such as Washington's My Health My Data Act. Enforcement generally turns on whether a company did what its own privacy policy promised rather than on a fixed standard of care.
How long would the rulemaking take after enactment?
The bill sets deadlines for some items, including de-identification standards and minimum necessary guidance for artificial intelligence within a year, though the central privacy and security regulations carry no statutory deadline in the introduced text. Comparable HHS rulemakings have run two years or longer from proposal to final rule.
Would the bill preempt state health privacy laws?
Section 9 of the introduced text applies HIPAA's existing preemption framework at 45 CFR 160.203, which leaves state laws standing where they are more stringent than the federal standard. Organizations operating across states would continue tracking both.
Does a committee vote mean the bill is close to becoming law?
No. Reporting a bill out of committee places it on the calendar for possible floor consideration, which requires leadership to schedule time. A companion measure would then need to move through the House, and most bills reported from committee never receive a floor vote.
