The Senate HELP Committee voted 22-0 on 30 July 2026 to advance the Health Information Privacy Reform Act, known as HIPRA, and reported it on 4 August as Calendar No. 538 [1] [2] [5].
Comparing the HIPRA that Senator Cassidy introduced in November 2025 against the HIPRA the committee reported nine months later is the most informative thing available about this bill, because a substitute amendment shows you what a room full of senators decided to keep, strengthen and cut.
They strengthened the AI provision, added two protections, and removed the only duty that would have applied to a health app without waiting for a regulator.
The AI provision got teeth at markup
The introduced bill asked HHS to “publish guidance” on applying the minimum necessary standard to “data used for artificial intelligence and other machine learning applications” [4]. Guidance is non-binding.
The reported text replaces that with rulemaking:
(a) Rulemaking. Not later than 1 year after the date of enactment of this Act, the Secretary of Health and Human Services… in coordination with the Commissioner of Food and Drugs and the National Coordinator for Health Information Technology, shall promulgate regulations regarding the application of the minimum necessary standard under section 164.502(b) of title 45, Code of Federal Regulations, to applicable health information and protected health information, including such information used to train, develop, validate, modify, or operate an artificial intelligence or other machine learning model.
Three upgrades in one section. Guidance became regulations. A vague reference to “AI applications” became five specific verbs: train, develop, validate, modify, or operate. And the drafting is now coordinated with the FDA Commissioner and the National Coordinator for Health IT rather than sitting with HHS alone.
It is still rulemaking, so the substance is unknown until HHS writes it, and the clock only starts at enactment. But the committee looked at a non-binding guidance provision and deliberately made it binding.
Two protections the committee added
Government access now requires legal process. Section 2(e) of the reported text:
A regulated entity or service provider may not sell or otherwise transfer applicable health information to a Federal, State, local, Tribal, or territorial governmental entity except as compelled by warrant, subpoena, court order, or other compulsory process.
Nothing equivalent appears in the introduced bill [4]. HIPAA itself has no such bar.
And location data is now in scope. The definition of applicable health information covers information that identifies an individual, or could reasonably be used to, and relates to their physical or mental health, care or payment. The reported text extends it to:
precise geolocation information that could reasonably indicate an attempt by an individual to acquire or receive a health service or supply
That is a post-Dobbs provision in substance, and it means a location trail can be applicable health information even where no health data was collected at all.
The definition also expressly reaches information “that was not created or received by a health care provider, health plan, employer, or health care clearinghouse,” which is the consumer app and wearable case stated directly.
What the committee took out
The introduced bill contained one duty that applied to a health app without waiting for a single regulation:
Any regulated entity or service provider who offers digital technology that generates wellness data about individuals shall… provide a written plain language notification to the individual in advance of initiating the generation of such data that such data will not be subject to the protections of the HIPAA privacy regulation; and offer the individual an opportunity to opt out.
With “wellness data” defined to include step counts by name [4].
The committee struck it. In the reported bill it survives only as deleted matter [1].
Everything else waits on HHS
Section 2 is a regulatory mandate, not a set of obligations. It directs HHS, in consultation with the FTC, to promulgate privacy, security and breach notification standards within 18 months of enactment, providing protections “at least commensurate with” the HIPAA rules. The topics the regulations must cover include permitted uses and disclosures, written authorization, prohibited uses, minimum necessary, individual rights including access, amendment, deletion and portability, standards for service providers, administrative safeguards and security.
All of that is a list of things a future rule must address. None of it binds anyone on enactment day.
Preemption is a floor, not a ceiling
Section 6 is one sentence, and it does a lot of work:
Section 160.203 of title 45, Code of Federal Regulations (or any successor regulations) shall apply to the requirements set forth under this Act in the same manner and to the same extent as such section applies to the standards, requirements, and implementation specifications under subchapter C of chapter I of subtitle A of title 45, Code of Federal Regulations.
That imports the HIPAA preemption rule wholesale. Under 45 CFR 160.203 a contrary state law is preempted unless it is more stringent. More protective state laws survive.
Washington’s My Health My Data Act is more stringent in the way that bites: it is enforceable through the state Consumer Protection Act, carrying a private right of action [3]. Nothing here displaces that, and HIPAA has never had a private right of action of its own.
So this is a federal floor added underneath a patchwork that keeps operating, and the sharpest enforcement risk in the category is untouched. That is the same pattern as the FDA post: federal requirements loosening or deferring while state regimes and private plaintiffs remain the operative constraint.
An honest handicap
A 22-0 committee vote is real and rare. It is also not a law. The bill needs a floor vote and House action in a crowded calendar, and most bills that clear committee do not become law. Even on a good path, the AI regulations arrive a year after enactment and the main privacy rules eighteen months after, so the substance lands some distance out.
What is worth doing now
Nothing urgent, and two things worth doing regardless, because more stringent state laws and the GDPR already require most of it.
Be able to produce a data inventory. What you collect, from which source, for what purpose, held how long. Minimum necessary, deletion rights and the AI rulemaking all reduce to that document.
Know what sits in front of your models, not just what trained them. The word “operate” in HIPRA Section 4 is the one that reaches a running product, and “how much of this user’s data does the model actually need to see” is a question worth being able to answer before someone writes a rule about it.
The short version
HIPRA cleared the Senate HELP Committee 22-0 and was reported on 4 August 2026 as a full substitute. Comparing it to the introduced bill shows the direction of travel.
The AI provision was upgraded from non-binding guidance to regulations, covering information used to “train, develop, validate, modify, or operate” a model, drafted with the FDA and ONC, due within a year of enactment. A government access bar requiring warrant, subpoena, court order or other compulsory process was added. Precise geolocation indicating an attempt to obtain health care was added to the definition.
And the one duty that would have applied directly to health apps, telling users in plain language that their data is not HIPAA-protected and offering an opt-out, was struck.
Section 6 imports the HIPAA preemption rule, so more stringent state laws survive and the patchwork stays.
References
- S.3097, Health Information Privacy Reform Act, 119th Congress, as reported in Senate 4 August 2026, Calendar No. 538. Full text via the U.S. Government Publishing Office. All statutory quotations in this post are taken from this document; deleted matter is shown there as struck text. https://www.govinfo.gov/content/pkg/BILLS-119s3097rs/html/BILLS-119s3097rs.htm
- S.3097, Health Information Privacy Reform Act, 119th Congress. All Actions. Congress.gov. https://www.congress.gov/bill/119th-congress/senate-bill/3097/all-actions
- Washington My Health My Data Act, HB 1155. Washington State Office of the Attorney General. https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy
- S.3097 as introduced, 4 November 2025, for comparison against the reported text. U.S. Government Publishing Office. https://www.govinfo.gov/content/pkg/BILLS-119s3097is/html/BILLS-119s3097is.htm
- HIPRA Advances Out of Senate HELP Committee: What Businesses Should Know. Alston & Bird, August 2026. https://www.alston.com/en/insights/publications/2026/08/hipra-advances-out-senate-help-committee