Search

Search bills, members, committees and pages...

S. 3097

U.S. SenateSenate Floor Calendar

Summary

S. 3097, the Health Information Privacy Reform Act, was introduced in the Senate on Nov 4, 2025 by Sen. Bill Cassidy (R) with 1 co-sponsor. It last saw action on Aug 4, 2026: Placed on Senate Legislative Calendar under General Orders. Calendar No. 538.


Record

Text

S. 3097 has 1 co-sponsor.

sb3097/introduced-in-senate.txt
119 S3097 IS: Health Information Privacy Reform Act
U.S. Senate
2025-11-04
text/xml
EN
Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.
II
119th CONGRESS
1st Session
S. 3097
IN THE SENATE OF THE UNITED STATES
November 4, 2025
Mr. Cassidy introduced the following
bill; which was read twice and referred to the Committee on Health, Education, Labor, and
Pensions
A BILL
To provide additional protections with respect to health information, and
for other purposes.
1.
Short title
This Act may be cited as the Health Information Privacy Reform Act .
2.
Protections for applicable health information
(a)
In general
The Secretary of Health and Human Services, in consultation with the Federal Trade Commission, shall promulgate regulations setting privacy, security, and breach notifications standards for the processing of applicable health information by regulated entities and their service providers. Such standards shall provide protections that are at least commensurate with, and wherever feasible and appropriate harmonize with, the protections provided through the privacy, security, and breach notification rules promulgated under section 264(c) of the Health Insurance Portability and Accountability Act of 1996 ( 42 U.S.C. 1320d–2 note) and section 13402 of the HITECH Act ( 42 U.S.C. 17932 ) that apply to covered entities and business associates with respect to protected health information under such rules. Such regulations promulgated under this section shall include the following:
(1)
Privacy requirements, including the following:
(A)
Permitted uses and disclosures of applicable health information without an individual’s written authorization that are consistent with the individual’s reasonable expectations.
(B)
Other permitted uses and disclosures of applicable health information without an individual’s written authorization for certain public policy purposes, such as public health, health oversight, law enforcement, judicial and administrative proceedings, and any conditions for such uses and disclosures.
(C)
Uses and disclosures of applicable health information that require the individual’s written authorization and the requirements related to such written authorizations.
(D)
Prohibited uses and disclosures of applicable health information.
(E)
Minimum necessary requirements for the request, use, and disclosure of applicable health information and any exceptions.
(F)
Standards and requirements related to legal representatives of the individual.
(G)
Standards and requirements related to service providers.
(H)
Individual rights with respect to applicable health information, including the right of the individual to receive a privacy notice from the regulated entity, access to applicable health information, amendment of applicable health information, deletion of applicable health information, and portability of applicable health information, and any exceptions to such rights (such as with respect to applicable health information collected for research purposes), any conditions on such rights, and any other requirements related to such rights, including timeframes for responding to requests.
(I)
Administrative safeguards, including designation of a privacy officer, policies and procedures, training of workforce members, non-retaliation, documentation, and mitigation.
(2)
Security requirements, including the following:
(A)
Physical, technical, and administrative safeguards for applicable health information in any form.
(B)
For electronic applicable health information, such safeguards shall be based on well-established national frameworks, such as cybersecurity performance goals of the National Institute of Standards and Technology or the Department of Health and Human Services.
(3)
Breach notification requirements in the event of a breach of applicable health information that are substantially similar to the breach notification requirements under subpart D of part 164 of title 45, Code of Federal Regulations (or any successor regulations).
(b)
Enforcement authority
The Secretary, in consultation with the Federal Trade Commission, is authorized to enforce all provisions of this Act as described in subsection (c).
(c)
Civil penalties
In addition to any other sanctions or remedies that may be available under any provision of Federal law, in the case of a regulated entity or service provider that violates this section, subpart D of part 160 of title 45, Code of Federal Regulations (or any successor regulations), shall apply to the regulated entity or service provider with respect to such violation of this section in the same manner that such subpart applies to a person with respect to a violation of part 160 of title 45, Code of Federal Regulations (or any successor regulations).
(d)
Extension of HITECH Act amendment to regulated entities and service
providers
The privacy and security practices under section 13412 of the Health Information Technology for Economic and Clinical Health Act ( 42 U.S.C. 17941 ) shall apply to regulated entities and service providers with respect to applicable health information in the same manner that such section applies to covered entities and business associates.
(e)
Definitions
In this section:
(1)
Applicable health information
The term applicable health information —
(A)
means information (including demographic information) that—
(i)
identifies an individual or with respect to which there is a reasonable basis to believe that the information could be used to identify an individual; and
(ii)
relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual; and
(B)
may include information described in subparagraph (A) that was not created or received by a health care provider, health plan, employer, or health care clearinghouse.
(2)
Covered entities; business associates
The terms covered entities and business associates have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (or any successor regulations).
(3)
Regulated entity
The term regulated entity —
(A)
means a natural or legal person that, alone or jointly with others, determines the purpose and means of processing applicable health information; and
(B)
does not include—
(i)
a governmental entity such as a body, authority, board, bureau, commission, district, agency, or political subdivision of the Federal, State, or local government;
(ii)
a person or an entity that is collecting, processing, or transferring covered data on behalf of or a Federal, State, Tribal, territorial, or local government entity; and
(iii)
a covered entity or business associate, as such terms are defined in section 160.103 of title 45, Code of Federal Regulations (or any successor regulations).
(4)
Service provider
The term service provider means a natural or legal entity that processes applicable health information on a behalf of a regulated entity and that is not a covered entity or business associate, as such terms are defined in section 160.103 of title 45, Code of Federal Regulations (or any successor regulations).
3.
Rights and requirements regarding access to certain protected health
information
(a)
Time and manner of access
In applying section 13405(e) of the Health Information Technology for Economic and Clinical Health Act ( 42 U.S.C. 17935(e) ) or section 164.524(c)(3)(ii) of title 45, Code of Federal Regulations (or any successor regulations), in the case that an individual requests that a covered entity or any business associate of a covered entity transmit, produce, or provide access to a copy of the individual’s protected health information to a person, including an entity, designated by the individual, and except where permitted without authorization under section 164.506(c) of title 45, Code of Federal Regulations (or any successor regulations)—
(1)
the individual’s request shall meet all requirements of a valid authorization under section 164.508(b) of title 45, Code of Federal Regulations (or any successor regulations); and
(2)
the covered entity or business associate may condition the transmittal, production, or provision of access upon the person to whom the information is to be transmitted or produced or to whom access is to be provided—
(A)
paying fees, in accordance with applicable State law and consistent with subsection (b), in advance of such transmittal, production, or access; and
(B)
acknowledging and accepting the terms, limitations, and conditions of use and disclosure contained in the request made by the individual as the legally binding obligation of the person receiving the information.
(b)
Fees
(1)
In general
In applying section 13405(e)(3) of the Health Information Technology for Economic and Clinical Health Act ( 42 U.S.C. 17935(e)(3) ) or section 164.524(c)(4) of title 45, Code of Federal Regulations (or any successor regulations), each such section shall apply only—
(A)
to the provision of access to, or the production, copying, or transmittal of, protected health information directly to—
(i)
the individual, or the individual’s personal representative for health care purposes as described in section 164.502(g) of title 45, Code of Federal Regulations (or any successor regulations);
(ii)
subject to paragraph (2) and section 164.510(b) of title 45, Code of Federal Regulations (or any successor regulation), any other person identified in, and subject to the limitations of, such section; or
(iii)
the individual’s health care provider or the business associates of such provider; and
(B)
as directed by the individual, to the electronic transmittal of the individual’s electronic health record to the patient portal or mobile medical application used and maintained by the individual’s health care provider or for the health care provider by its business associate.
(2)
Additional limitations
In the case of the provision of access to, or the production, copying, or transmittal of, protected health information under paragraph (1)(A) directly to a person described in clause (ii) of such paragraph, such protected health information shall, in accordance with section 164.510(b) of title 45, Code of Federal Regulations (or any successor regulations), be limited to only such information that is—
(A)
directly relevant to the person’s involvement with the care of the individual or with the payment relevant to the care of the individual; or
(B)
needed for notification purposes described in such section.
(c)
Definitions
In this section, the terms business associate , covered entity , health care provider , individual , person , and protected health information have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (or any successor regulations).
(d)
Guidance
Not later than 180 days after the date of enactment of this Act, the Secretary of Health and Human Services shall amend existing guidance as necessary to implement subsections (a) and (b).
4.
Confidentiality of records
Section 543 of the Public Health Service Act ( 42 U.S.C. 290dd–2 ) is amended—
(1)
in subsection (a), by striking subsection (b) and inserting the HIPAA regulations ;
(2)
in subsection (b)—
(A)
in paragraph (2), by redesignating subparagraphs (A) through (D) as paragraphs (1) through (4), respectively, and adjusting the margins accordingly; and
(B)
by striking (b)
Permitted disclosure and all that follows through (2)
Method for disclosure— Whether and inserting the following:
(b)
Permitted disclosure
Whether
;
(3)
in subsection (c), in the matter preceding paragraph (1), by striking subsection (b)(2)(C) and inserting subsection (b)(3) ; and
(4)
in subsection (g), by striking subsection (b)(2)(C) and inserting subsection (b)(3) .
5.
NAS study on compensation to patients for sharing identifiable data for research
purposes
(a)
In general
Not later than 60 days after the date of enactment of this Act, the Secretary of Health and Human Services shall seek to enter into a contract with the National Academies of Sciences, Engineering, and Medicine to conduct a study examining potential risks and benefits of paying compensation to patients for sharing their identifiable data for research purposes.
(b)
Inclusions
The study conducted pursuant to the contract under subsection (a) shall include an examination of—
(1)
the risks to patient privacy posed by the integration of identifiable, de-identified, and aggregated health information into datasets used for research;
(2)
privacy enhancing tools and methods for the protection of patient health data;
(3)
the feasibility of tracking patient data and consent for the integration of patient health data into datasets used for research;
(4)
ethical considerations for compensating patients for use of their identifiable and de-identified health data;
(5)
whether the existing exemptions permitting de-identified data to be used for research should consider whether a patient was given an opportunity to opt-in or opt-out of participation; and
(6)
risk of re-identification of de-identified data.
6.
Patient notification requirements under the HIPAA privacy regulations
(a)
Patient notification upon removal
Any regulated entity or service provider who gains access to the protected health information of an individual through the patient right of access under section 164.524 of title 45, Code of Federal Regulations (or any successor regulations) shall—
(1)
provide a written plain language notification to such individual prior to accessing such information—
(A)
that such protected health information will no longer be subject to the protections under the HIPAA privacy regulation; and
(B)
that includes an explanation of how and to which entities such protected health information may be redisclosed; and
(2)
require the consent of the individual before selling such protected health information to third parties.
(b)
Patient notification regarding wellness data
(1)
In general
Any regulated entity or service provider who offers digital technology that generates wellness data about individuals shall, with respect to each individual who uses such technology—
(A)
provide a written plain language notification to the individual in advance of initiating the generation of such data that such data will not be subject to the protections of the HIPAA privacy regulation; and
(B)
offer the individual an opportunity to opt out of such wellness data generation.
(2)
Wellness data
In this subsection, the term wellness data means data generated for the purpose of promoting health or preventing disease, which may include vital statistics, step counts, and medical regimen compliance.
(c)
Definitions
In this section—
(1)
the terms business associate , covered entity , and protected health information have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (or any successor regulations);
(2)
the term HIPAA privacy regulation has the meaning given such term in section 1180(b)(3) of the Social Security Act ( 42 U.S.C. 1320d–9(b)(3) ); and
(3)
the terms regulated entity and service provider have the meanings given such terms in section 2.
(d)
Effective date
This section shall take effect beginning one year after the date of enactment of this Act.
7.
Minimum necessary guidance
Not later than 1 year after the date of enactment of this Act, the Secretary of Health and Human Services shall publish guidance on the application of the minimum necessary standard to data used for artificial intelligence and other machine learning applications and relevant requirements, including health data interoperability requirements under section 3001(c)(9) of the Public Health Service Act ( 42 U.S.C. 300jj–11(c)(9) ) and the use of limited data sets pursuant to section 13405(b) of the HITECH Act ( 42 U.S.C. 17935(b) ).
8.
De-identified information
(a)
Establishment of standards
Not later than 1 year after the date of enactment of this Act, the Secretary of Health and Human Services shall promulgate regulations establishing unified national standards for rendering applicable health information as de-identified information, in a manner similar to the manner in which individually identifiable health information may be rendered de-identified information pursuant to part 164 of title 45, Code of Federal Regulations (or any successor regulations).
(b)
Composition of standards
Such standards shall—
(1)
be at least equivalent to or exceed the de-identification standard specified in section 164.514(b) of title 45, Code of Federal Regulations (or any successor regulations);
(2)
specify standards for the use of privacy-enhancing technologies as a method for creating de-identified information; and
(3)
specify that information shall not qualify as de-identified information when provided by a regulated entity, service provider, covered entity, or business associate to another person or entity unless such person or entity contractually agrees in writing not to re-identify or attempt to re-identify the information, and to require the same of any person or entity to whom such person or entity provides the information.
(c)
Definitions
In this section—
(1)
the term applicable health information has the meaning given such term in section 2;
(2)
the terms business associate , covered entity , and individually identifiable health information have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (or any successor regulations); and
(3)
the term privacy enhancing technologies means any software or hardware solution, technical process, or other technological means of mitigating individuals’ privacy risks arising from data processing by enhancing predictability, manageability, disassociability, and confidentiality.
9.
Preemption
Section 160.203 of title 45, Code of Federal Regulations (or any successor regulations) shall apply to the requirements set forth under this Act in the same manner and to the same extent as such section applies to the standards, requirements, and implementation specifications under subchapter C of chapter I of subtitle A of title 45, Code of Federal Regulations (or any successor regulations).

Tracker

The tracker indicates the progress of this legislation as it moves through the legislative process.

  1. Introduced2025-11-04
  2. Passed Senate
  3. Passed House
  4. Conference
  5. To President
  6. Became Law

A bill to provide additional protections with respect to health information, and for other purposes.

Sponsors

Sen. Bill Cassidy (R) sponsors S. 3097, and 1 member has co-sponsored it.

Committees

S. 3097 went before 1 committee: Health, Education, Labor, and Pensions.

Health, Education, Labor, and Pensions
Health, Education, Labor, and Pensions
Reported By · Aug 4, 2026 · 747 Bills

Actions

S. 3097 has taken 5 actions since Nov 4, 2025, the latest on Aug 4, 2026.

ChamberAction
Aug 4, 2026
Senate
Committee on Health, Education, Labor, and Pensions. Reported by Senator Cassidy with an amendment in the nature of a substitute. Without written report.Health, Education, Labor, and Pensions Committee
Aug 4, 2026
Senate
Placed on Senate Legislative Calendar under General Orders. Calendar No. 538.
Jul 30, 2026
Senate
Committee on Health, Education, Labor, and Pensions. Ordered to be reported with an amendment in the nature of a substitute favorably.Health, Education, Labor, and Pensions Committee
Nov 4, 2025
Senate
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.Health, Education, Labor, and Pensions Committee
Nov 4, 2025
Introduced in Senate

Votes

S. 3097 has not gone to a roll call.

Titles

S. 3097 goes by 4 titles, 2 of them short titles.

  • Health Information Privacy Reform Act — Display Title
  • Health Information Privacy Reform Act — Short Title(s) as Reported to Senate
  • Health Information Privacy Reform Act — Short Title(s) as Introduced
  • A bill to provide additional protections with respect to health information, and for other purposes. — Official Title as Introduced

Lobbying

11 clients hired 10 firms and 84 registered lobbyists who named S. 3097 in 23 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.

Filed under Health Issues, Budget/Appropriations, Immigration, Medicare/Medicaid, Taxation/Internal Revenue Code, Veterans, Education, Defense.

Clients

Who paid to be heard, by how many filings named the bill.

ClientBusinessStateFirmsFilingsReported
AMERICAN MEDICAL ASSOCIATIONDistrict of Columbia15
THE SEQUOIA PROJECTIndustry coalition supporting eHealth ExchangeVirginia13$180K
ALLIANCE FOR HEALTH INFORMATION OPERATIONS AND STANDARDSHealthcare trade group promoting secure access to patient protected health information.Pennsylvania13$160K
LEIDOS HOLDINGS, INC.HealthcareVirginia13$120K
MRO CORP.MRO provides release of information solutions to health care providersPennsylvania12$160K
CONSULIHealthcare TechnologyCalifornia12$100K
SURESCRIPTSHealth information networkVirginia11$50K
AMERICAN ACADEMY OF PEDIATRICSIllinois11
AMERICAN HOSPITAL ASSOCIATIONDistrict of Columbia11
HEALTHCARE LEADERSHIP COUNCILDistrict of Columbia11
PLANNED PARENTHOOD FEDERATION OF AMERICA INCDistrict of Columbia11

Firms

Registrants who filed on the bill, by filings.

Lobbyists

Named on the filings that cite the bill. The 20 named most often, of 84.

Filings

The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.

ClientRegistrantPeriodReportedDocument
AMERICAN MEDICAL ASSOCIATIONAMERICAN MEDICAL ASSOCIATION2026 first_quarter$8M1st Quarter - Amendme…
AMERICAN MEDICAL ASSOCIATIONAMERICAN MEDICAL ASSOCIATION2026 first_quarter$8M1st Quarter - Report
AMERICAN HOSPITAL ASSOCIATIONAMERICAN HOSPITAL ASSOCIATION2025 fourth_quarter$6.6M4th Quarter - Report
AMERICAN MEDICAL ASSOCIATIONAMERICAN MEDICAL ASSOCIATION2025 fourth_quarter$5.5M4th Quarter - Report
AMERICAN MEDICAL ASSOCIATIONAMERICAN MEDICAL ASSOCIATION2026 second_quarter$5.1M2nd Quarter - Amendme…
AMERICAN MEDICAL ASSOCIATIONAMERICAN MEDICAL ASSOCIATION2026 second_quarter$513K2nd Quarter - Report
HEALTHCARE LEADERSHIP COUNCILHEALTHCARE LEADERSHIP COUNCIL2026 second_quarter$200K2nd Quarter - Report
MRO CORP.MCDERMOTT WILL & SCHULTE LLP2026 first_quarter$100K1st Quarter - Report
AMERICAN ACADEMY OF PEDIATRICSAMERICAN ACADEMY OF PEDIATRICS2025 fourth_quarter$100K4th Quarter - Report
PLANNED PARENTHOOD FEDERATION OF AMERICA INCPLANNED PARENTHOOD FEDERATION OF AMERICA, INC.2025 fourth_quarter$94K4th Quarter - Report
ALLIANCE FOR HEALTH INFORMATION OPERATIONS AND STANDARDSTIBER CREEK GROUP2026 second_quarter$60K2nd Quarter - Report
THE SEQUOIA PROJECTTROUTMAN STRATEGIES2026 second_quarter$60K2nd Quarter - Report
ALLIANCE FOR HEALTH INFORMATION OPERATIONS AND STANDARDSTIBER CREEK GROUP2026 first_quarter$60K1st Quarter - Report
THE SEQUOIA PROJECTTROUTMAN STRATEGIES2026 first_quarter$60K1st Quarter - Report
THE SEQUOIA PROJECTTROUTMAN STRATEGIES2025 fourth_quarter$60K4th Quarter - Report
MRO CORP.MCDERMOTT WILL & SCHULTE LLP2025 fourth_quarter$60K4th Quarter - Report
CONSULIFRANKLIN SQUARE GROUP, LLC2026 second_quarter$50K2nd Quarter - Report
SURESCRIPTSVAN SCOYOC ASSOCIATES2026 second_quarter$50K2nd Quarter - Report
CONSULIFRANKLIN SQUARE GROUP, LLC2026 first_quarter$50K1st Quarter - Report
LEIDOS HOLDINGS, INC.TROUTMAN STRATEGIES2026 second_quarter$40K2nd Quarter - Report

Classification

The Congressional Research Service files S. 3097 under Commerce, one of its 31 policy areas, and gives it 5 legislative subjects.

CRS Subjects

CRS assigns every bill one policy area from its 31; S. 3097’s is Commerce.

s3097/policy-areas.txt
CommerceAgriculture and FoodAnimalsArmed Forces and National SecurityArts, Culture, ReligionCivil Rights and Liberties, Minority IssuesCongressCrime and Law EnforcementEconomics and Public FinanceEducationEmergency ManagementEnergyEnvironmental ProtectionFamiliesFinance and Financial SectorForeign Trade and International FinanceGovernment Operations and PoliticsHealthHousing and Community DevelopmentImmigrationInternational AffairsLabor and EmploymentLawNative AmericansPublic Lands and Natural ResourcesScience, Technology, CommunicationsSocial WelfareSports and RecreationTaxationTransportation and Public WorksWater Resources Development

Legislative Subjects

S. 3097 carries 5 of CRS’s legislative subjects, from Civil actions and liability to User charges and fees.

s3097/subjects.txt
Civil actions and liabilityData collection, sharing, protectionHealth information and medical recordsRight of privacyUser charges and fees

Source: congress.gov · legiscan.com