The Senate Health, Education, Labor and Pensions (HELP) Committee advanced S.3097, the Health Information Privacy Reform Act, on July 30, 2026 by a 22-0 vote — a unanimous bipartisan outcome that is nearly unheard of in the current legislative climate and signals significant momentum for a long-sought update to federal health privacy law.

The bill targets a well-documented gap in the Health Insurance Portability and Accountability Act of 1996. HIPAA applies only to "covered entities" — hospitals, health plans, and their business associates. The explosion of consumer-facing health technology since 1996 has created a sprawling ecosystem of fitness trackers, mental health apps, telehealth platforms, and AI-driven wellness tools that collect extraordinarily sensitive health data while remaining entirely outside HIPAA's reach. S.3097 would change that, establishing a new federal privacy floor for these non-HIPAA entities.

Committee Vote
22–0
Bipartisan unanimous vote in Senate HELP Committee on July 30, 2026
Gap Addressed
350M+
Estimated U.S. health app and wearable users whose data has no HIPAA protection
Dual Oversight
HHS+FTC
Both agencies would jointly develop implementation standards under the bill

What S.3097 Would Require

The core of the legislation establishes four individual rights that apply to any entity collecting personal health information outside HIPAA: the right to access that data in a portable format, to correct inaccurate records, to delete the data, and to port it to another service or directly to a healthcare provider. These rights mirror the framework established by the European Union's General Data Protection Regulation, which health privacy advocates have long argued should have a U.S. analog.

Crucially, the bill prohibits the sale of personal health information without explicit consumer consent. Under current law, a weight-loss app can sell a user's data to insurers, employers, or data brokers with no affirmative consent requirement. S.3097 would make that practice unlawful and require affirmative opt-in consent for any monetization of health data. Violators would face enforcement from both HHS and the Federal Trade Commission, which already has jurisdiction over deceptive data practices but lacks health-specific authority to regulate the sector.

The bill's implementation timeline leaves the rulemaking to the two agencies jointly, which means the practical effect on covered entities would not arrive for at least 18 to 24 months after enactment. Industry groups representing health tech companies have signaled support for a federal standard, in large part because it would preempt the patchwork of state-level health data privacy laws — including California's MY Health MY Data Act and Washington's Health Data Privacy Act — that have created compliance headaches across the sector.

What the HIPAA Gap Looks Like in Practice

To understand the gap S.3097 targets, consider a typical patient interaction in 2026. A patient shares Fitbit sleep data during a telehealth intake visit. The telehealth platform, if it is not a HIPAA business associate, can retain that data and monetize it independently. The patient's fertility tracker app shares cycle data with a third-party data broker who resells it to pharmaceutical companies. A workplace wellness program collects biometric data from employees and shares aggregate — or in some cases identified — data with the employer's insurance carrier. None of these transactions currently require patient consent under federal law.

The FTC took action in 2023 against several health apps for unauthorized data sharing, using Section 5 of the FTC Act to police deceptive practices. But the FTC's authority is limited to fraud and deception — it cannot impose affirmative rights or data minimization standards. S.3097 would give HHS the authority to establish those baseline standards, bringing health data collected outside the clinical setting closer to the protections that govern clinical records.

🏥 Nurse Take

Nurses sit at the intersection of this issue in two distinct ways. First, as workers: nurses who use mental health apps, wearable trackers, or employee wellness programs have their own health data in the unprotected category. Second, as clinicians: increasingly, patient-generated data from non-HIPAA devices — Apple Watch ECG readings, continuous glucose monitors used outside a formal prescription, home blood pressure apps — is being surfaced in clinical conversations and sometimes entered into the EHR. Once that data touches the EHR, it becomes a HIPAA record, but the source system that generated it remains unregulated. S.3097 would begin to close that loop, establishing accountability for the upstream sources of data that nurses are increasingly expected to interpret and act on.

Path to the Full Senate

A unanimous committee vote does not guarantee floor time. Senate leaders will need to schedule a full chamber vote, and the bill could face amendments — particularly from industry-aligned members seeking to limit the preemption of state laws or to narrow the definition of "personal health information" to exclude aggregate or de-identified data. The full text of S.3097 is available on congress.gov.

The American Nurses Association and the American Association of Nurse Practitioners have both supported stronger non-HIPAA health data protections in principle. If the bill reaches the floor and passes the Senate, it would still need to be reconciled with any companion House legislation — no House companion bill has been introduced as of this writing.

For nurses in telehealth, ambulatory, and home health settings — where the boundary between HIPAA-covered and non-HIPAA consumer tools is most porous — the bill's progress bears watching. The committee's 22-0 vote is the strongest legislative signal in years that Congress intends to act.

Sources

  1. U.S. Senate HELP Committee. Committee Markup: S.3097, Health Information Privacy Reform Act. July 30, 2026. help.senate.gov
  2. U.S. Congress. S.3097 — Health Information Privacy Reform Act, 119th Congress. congress.gov
  3. Federal Trade Commission. Health Breach Notification Rule and Health App Enforcement Actions. ftc.gov