Health App Privacy Bill Passes Senate Panel 22-0, But Protection Could Take Years

U S Secretary Health Human Services Robert
U.S. Secretary of Health and Human Services Robert F. Kennedy Jr. speaks during a news conference at the at the Robert F. Kennedy Department of Justice building on June 23, 2026 in Washington, DC.
Anna Moneymaker/Getty Images

The Senate Health, Education, Labor and Pensions Committee voted 22–0 on Wednesday to advance S. 3097, the Health Information Privacy Reform Act — the first time any federal health data privacy bill covering consumer apps and wearables has cleared a Senate committee in this Congress. But unanimous bipartisan support does not mean your heart rate, menstrual cycle, and therapy session notes are now protected. The bill contains no operative privacy standards — it directs the Department of Health and Human Services to write them, through a rulemaking process that the agency has already demonstrated can take two or more years even when it is trying to move quickly.

For the roughly 40 percent of Americans who own a consumer wearable and the tens of millions more using health apps, the practical change from Wednesday’s vote is zero. What changed is the political signal: a bill that TechTimes reported last week as one that “had not advanced” passed a Senate committee 22–0, with every Republican and every Democrat on the panel voting yes. That outcome is unusual enough to mean something — and carefully limited enough to require an explanation of what it does not mean.

The consequences are documented in active litigation. Whoop is defending a federal class action (Lomeli v. Whoop Inc., Case No. 3:25-cv-06828, N.D. Cal.) alleging that its companion app forwarded biometric data — heart rate, stress levels, reproductive health metrics, and video viewing history — to Segment, a third-party customer data platform connected to Meta and Google advertising systems, without user consent. Oura faces a separate class action alleging indefinite retention of biometric data after account deletion, in violation of Illinois’ Biometric Information Privacy Act. Both lawsuits rely on state law because no federal statute governs what these companies do with their users’ intimate health data.

What HIPAA Never Covered — and Why It Still Doesn’t

The Health Insurance Portability and Accountability Act of 1996 was written for a world in which health data was generated almost exclusively by hospitals, health plans, and their business partners — what federal law calls “covered entities.” Consumer wearable companies are not covered entities. A fitness tracker maker can collect your heart rate, sleep cycles, GPS coordinates, and menstrual data and share or sell it with no federal health privacy obligation whatsoever.

More than 350,000 mobile health apps are available across app stores, according to data cited by the National Center for Complementary and Integrative Health. Virtually none of them operate under HIPAA. Their data practices are constrained primarily by their own privacy policies, the FTC Act’s bar on deceptive practices, and a patchwork of state laws that apply unevenly depending on where a consumer lives.

What the Bill Would Do — and What It Leaves Unwritten

S. 3097, the Health Information Privacy Reform Act, does not contain a list of rules health app companies must follow. It contains a directive. The bill authorizes the Secretary of Health and Human Services, in consultation with the FTC, to promulgate regulations setting privacy, security, and breach notification standards for what the bill calls “applicable health information” held by companies currently outside HIPAA’s scope. The resulting standards would be required to provide protections at least commensurate with existing HIPAA rules and the corresponding HITECH Act provisions.

The bill also includes direct provisions covering the confidentiality of substance use disorder records — an area where existing law already applies inside HIPAA’s perimeter — and requirements related to patient notification and record access. The manager’s amendment approved by the HELP Committee on July 30 represents the operative version of the legislation going forward, not the bill as originally introduced.

What the bill authorizes HHS to require: limits on data collection, use, and sharing; individual rights to access, amend, delete, and transfer their health data; administrative and technical safeguards; breach notification protocols; and a prohibition on the government purchasing consumer health data. What the bill does not contain is any of those requirements written in enforceable language — those details exist only after rulemaking is complete.

The Center for Democracy and Technology called the manager’s amendment a positive step but identified three gaps that require resolution before the bill becomes fully protective. CDT said the bill lacks clarity on the working relationship between HHS and the FTC, particularly given the FTC’s established experience with non-HIPAA health data enforcement. The organization also called for a private right of action — a mechanism allowing consumers who are harmed to sue companies directly — and for explicit language confirming that state-level privacy regulators retain jurisdiction to enforce the federal framework. Without a private right of action, enforcement depends entirely on federal agencies that have limited capacity and no obligation to prioritize any individual complaint.

Why Unanimous Feels Significant

A 22–0 vote in the Senate HELP Committee is unusual enough to deserve acknowledgment on its own terms. Health data privacy has historically fractured along partisan lines, with disputes over state law preemption, industry liability, and the scope of individual rights typically killing bipartisan momentum before committee markups even occur.

Sen. Bill Cassidy (R-LA), the committee’s chairman and a physician, introduced S. 3097 in November 2025 after years of work on the underlying policy. He has described the problem directly: smartwatches and health apps generate privacy questions that did not exist when healthcare happened only between a patient and a physician in an exam room. The 22–0 vote across a committee divided by many other partisan conflicts suggests that framing has held up across both parties.

It also signals that the bill’s framework — delegating standards to HHS rather than writing them in statute — attracted enough support from both sides to avoid the gridlock that killed prior health data bills. That delegation model may be precisely what made unanimous passage possible: it avoids pre-committing either party to specific rules that could be contested, but it also means the bill as passed into law would be a container, not a safeguard.

What “Committee Passage” Does Not Mean: HHS Rulemaking Takes Years

The practical timeline between committee passage and a consumer seeing any change on their phone involves several more gates — and the rulemaking stage is the one with the longest documented lead time.

After a bill is enacted, an agency conducting notice-and-comment rulemaking under the Administrative Procedure Act must publish a proposed rule (NPRM) in the Federal Register, accept public comment for at least 60 to 90 days on a major rule, review and respond to those comments, and publish a final rule before any compliance obligations begin. That process for major health-privacy rules at HHS has taken years, not months.

The most directly analogous example: HHS published an NPRM in January 2025 updating the HIPAA Security Rule — the most significant proposed revision since 2013. The agency’s current target for a final rule is July 2027, a minimum of 18 months from the NPRM and with no guaranteed end date. That rulemaking involved a framework that had existed and been implemented for more than two decades, with an established regulatory infrastructure and agency expertise.

A rulemaking under S. 3097 would cover entirely new ground — establishing the first comprehensive federal privacy framework for consumer health apps and wearables. It would start from scratch after enactment, requiring HHS to define “applicable health information” (which will determine whether behavioral and inferred data counts), establish permitted use categories, write technical safeguard requirements, set de-identification standards, and create breach notification procedures. Courts reviewing any HHS definitional choices will exercise independent judgment under the Supreme Court’s Loper Bright Enterprises v. Raimondo ruling (2024), which removed the prior deference doctrine that had shielded agency rules from challenges to their statutory interpretation. That litigation risk means HHS will face pressure to draft definitions defensively, potentially slowing the process further.

A realistic estimate: consumers could see operative federal protections for their health app data — assuming enactment and a rulemaking that proceeds without major interruption — no earlier than 2028 or 2029.

What Remains Open on the Road to Floor Vote

Because the bill delegates its substance to future rulemaking, every definitional question that will determine whether the protection is real or symbolic remains unresolved. The definition of “applicable health information” will determine whether behavioral signals — location history patterns that reveal a patient’s oncologist visits, search query sequences that reveal a mental health diagnosis, purchase records that infer a pregnancy — count as health data subject to federal protection. CDT has argued consistently for a definition broad enough to cover information that reveals health conditions regardless of whether it was generated explicitly in a health context.

The scope of permitted uses will determine whether companies can continue sharing data with advertisers through consent buried in terms-of-service that no consumer reads. The preemption question — whether a federal framework would override stronger state laws like Washington’s My Health My Data Act, which covers data “collected, derived, or inferred” about health conditions — remains explicitly unresolved. If S. 3097 preempts those state laws without substituting equivalent federal protection in advance of rulemaking completion, consumers in states with currently strong coverage could end up with weaker protections during the transition period than they have today.

The bill will next need Senate floor scheduling after the chamber returns from its August recess, and a House companion bill has not yet been introduced. No Senate floor time has been announced.

What Readers Can Do Before Federal Protection Arrives

For consumers who use health apps or wearables, the time between Wednesday’s vote and the arrival of enforceable federal standards is not an abstract legislative waiting period — it is the period during which their biometric and behavioral data continues to operate under the current rules, which means primarily their company’s privacy policy, whichever state’s laws apply to them, and whatever litigation deterrence the Whoop and Oura class actions produce.

Readers in Washington state have some of the strongest existing protections under the My Health My Data Act, which covers consumer health data not covered by HIPAA and provides a private right of action. Illinois residents with wearables have BIPA protections for biometric identifiers. California residents have CCPA coverage. Residents of other states should verify what law applies before assuming protection exists.

Apple Watch users who store health data exclusively in Apple Health — without sharing data to third-party apps — benefit from end-to-end encryption as previously reported by TechTimes, making their data technically inaccessible to law enforcement subpoenas directed at Apple. Every other major wearable platform stores data using company-readable encryption. That architecture does not change with Wednesday’s committee vote.


Frequently Asked Questions

Does HIPAA protect the health data my fitness tracker, period app, or mental health app collects?

No. HIPAA applies to “covered entities” — healthcare providers, health plans, and healthcare clearinghouses, along with vendors who handle protected health information on their behalf. Consumer health app companies and wearable makers are not covered entities. That means no federal mandate caps how long they retain your data, no federal rule requires consent before selling it to advertisers, and no special federal protection applies if they hand your data to law enforcement. The Health Information Privacy Reform Act, if enacted and its rulemaking completed, would create federal protections for the first time — but those protections do not exist yet.

What does the 22-0 Senate committee vote actually change right now?

Procedurally, it advances S. 3097 from “bill referred to committee” to “bill reported out of committee with bipartisan support,” which is the prerequisite for Senate floor consideration. Practically, it changes nothing for consumers today. The bill contains no operative privacy standards — those are delegated to a future HHS rulemaking that has not yet begun and, based on comparable HHS health-privacy rulemaking timelines, could take two or more years after enactment to produce enforceable rules. The committee vote is a political signal, not a protection.

Why does the bill delegate rulemaking to HHS instead of writing the rules directly?

Drafting specific technical standards into statute is politically difficult: a rule that is specific enough to actually protect data will also be specific enough for industry groups to identify and object to particular provisions. Delegating to HHS allows a bill to pass with bipartisan support without resolving every contested substantive question. The tradeoff is that the protective standards are contingent on a rulemaking process that Congress cannot fully control — and that HHS, under different administrations, may pursue at different speeds and with different priorities. CDT has called for stronger enforcement mechanisms and a private right of action to ensure companies can be held accountable even between regulatory cycles.

What specific gaps did privacy advocates identify in the bill after the committee vote?

The Center for Democracy and Technology, which supports the bill’s direction, identified three gaps in the manager’s amendment that passed committee. First, the bill lacks clarity on whether HHS or the FTC will lead enforcement, an ambiguity that matters because the FTC has established experience with non-HIPAA health data. Second, the bill does not include a private right of action, meaning consumers who are harmed cannot sue companies directly under the federal framework — enforcement depends entirely on agency action. Third, the bill does not explicitly confirm that state-level privacy regulators retain jurisdiction, raising the risk that a federal framework could preempt stronger state laws without being fully in force yet. CDT’s full statement outlines each of these concerns in detail.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *