The Health Information Privacy Reform Act, introduced by Senator Bill Cassidy in November 2025 and voted out of the Senate HELP Committee 22 to 0 on July 30, finally addresses the health data HIPAA never covered: readings from smartwatches, sleep trackers, and consumer health apps. That gap has been open for more than a decade, so closing it matters.
Here is the part that got my attention. The bill puts rulemaking with the Secretary of Health and Human Services, with the Federal Trade Commission as a consultant, rather than handing the FTC the lead. The Center for Democracy and Technology asked the committee to clarify how the two agencies will divide enforcement, given the FTC’s history with non-HIPAA health data. Behind that polite request sits an obvious objection: why not the FTC? The agency debate is the wrong argument. Security teams spent the last ten years learning the hard way.
The case for the FTC, stated fairly.
That objection deserves a real hearing. The FTC has spent years policing exactly the kind of company this bill newly covers: consumer tech firms that collect personal data and monetize it. HHS grew up around HIPAA, which governs hospitals, insurers, and providers. Most of the businesses in scope here are not core healthcare organizations. They are app developers and hardware makers.
So the worry is a mismatch of expertise. Put a HIPAA-shaped agency in charge of Silicon Valley data practices, and you may get rules that fit neither side well. I am not going to pretend that concern away.
Both records are real, and both arrive late
Here is where the agency debate starts to collapse under its own terms.
The FTC’s health privacy enforcement is genuine. GoodRx in 2023, the first-ever use of the Health Breach Notification Rule. BetterHelp, for handing mental health intake data to advertisers. Premom, the fertility app. Cerebral, for exposing mental health conditions across the internet. These are real actions with real penalties.
Look at the timing, though. Every one of those actions landed after the data had already leaked. Section 5 and the Health Breach Notification Rule, the Commission’s core tools, both trigger on an unfair or deceptive act that has already happened. EPIC has made this point directly: without a data minimization rule, the Commission is mostly stuck notifying people that their health data got out. Enforcement that fires after the breach is a cleanup crew.
Before anyone concludes that HHS is the proactive alternative, its record is worse on this exact axis. In 2024, the HHS Inspector General found that OCR’s audit program reviewed 8 of HIPAA’s 180 standards, that 3 of the 70 entities flagged with serious compliance deficiencies received any follow-up, and that the audits leaned on technical assistance rather than enforcement. HHS went 15 years without meeting the HITECH Act’s audit mandate. Adam Greene, a privacy attorney at Davis Wright Tremaine who previously served in OCR, attributes much of this to the office being significantly understaffed.
So the honest scorecard reads: one agency that punishes after the harm, and one that rarely punishes at all. If that is the choice, arguing about which one should hold the pen is arguing about which perimeter guard gets the night shift. Both enforcement models fixate on the actor: who holds the data, what industry they sit in, which regulator understands their business. That axis is the problem.
What security already figured out
Ask a security architect where they put their controls in 2015, and they would have pointed at firewalls and network segments: the castle wall. Then the wall stopped meaning anything. Data moved to SaaS, phones, partner clouds, and a contractor’s laptop in another country. The environment fractured, and defending the environment stopped working.
The answer was data-centric security. Bind the protection to the data itself, so encryption and access policy travel with the record no matter where it lives or executes. Zero trust is the same idea taken to its conclusion: stop trusting the environment, and verify at the data layer instead. Practitioners adopted it because location-based defense kept failing in exactly the ways attackers kept exploiting.
One precision matters here, because the analogy has limits. Encryption literally travels with a file. A regulation never does; enforcement always lands on some company, somewhere. In policy, the data-centric move is about scoping: deciding what triggers the obligation. Scope by the sensitivity of the information, then enforce against whoever holds it. Heart-rate data off a hospital monitor and heart-rate data off a Garmin are the same sensitive fact about the same human heart. Governing them differently because one company files as a provider and the other as a consumer brand is perimeter thinking wearing a policy suit.
Bill 3097 takes a half-step down this path, perhaps unintentionally. Its trigger is data-defined: “applicable health information,” wherever it sits, with protections at least commensurate with HIPAA. That is the right instinct. But be clear-eyed about what the bill is not. It contains no substantive rules at all, only a directive to HHS, with rulemaking that could run two years or more past enactment. It still constructs a category of regulated entities, and it imports HIPAA’s existing federal preemption framework wholesale. The result is a data-based trigger bolted onto actor-based machinery, on a multi-year fuse. Half-steps still set direction, and this one points the right way.
There is a proactive dimension too. Waiting for a regulator to act after a leak is the policy version of bolting security onto a product after it ships. Anyone who has done product security knows how that ends. You build the protection in from the start, or you pay for it later in incident response. A regime that sets the standard up front, at the data layer, is shifting left. Enforcement-after-harm is the pattern we spent a career learning to abandon, and right now it describes both agencies.
Five questions for the privacy community
I am less interested in being right than in getting security and privacy leaders to argue about the right thing. Here are five questions worth sitting with.
Two apps collect identical heart-rate data. One is a hospital portal; one is a consumer watch. Why should the legal protection differ at all? What are we actually protecting, the company or the heartbeat?
Your own organization already classifies data by sensitivity for its security controls. So why does your compliance program still map obligations to which regulation applies, instead of to how sensitive the data is? Where is the gap between how you secure data and how you govern it?
If controls should travel with the data regardless of environment, does that quietly require a national data classification standard, and a coordination mechanism no current agency provides? Are we prepared to accept that, given how long a comprehensive federal privacy law has stalled? A data-first regime assumes institutions we have repeatedly failed to build. That is the cost of this argument, and I would rather name it than hide it.
When health data is inferred rather than collected, say a model deducing a pregnancy from purchase history, which framework even applies? Candidly, that case breaks the FTC model, the HHS model, and probably Bill 3097’s definition of applicable health information all at once. Only a data-classification lens survives it, and no agency currently wields one.
If you rebuilt your data governance from scratch tomorrow, starting from the sensitivity of the data rather than from a compliance checklist, what would you actually do differently on Monday morning?
Where this leaves us
I am not carrying water for HHS here. The argument is for the principle, and against the enforcement model both agencies currently run. Bill 3097 matters because its scoping choice, deliberate or not, points at the principle.
At Greenbelt Advisors, this is the exact problem I work through with clients in regulated industries: rebuilding data controls around the sensitivity of the information itself rather than the systems it happens to sit in. Zero trust, security built into the product rather than bolted on after, and controls bound to the data wherever it travels. All three run on one worldview, and Bill 3097 just handed that worldview a policy test case.
If your organization is wrestling with where your data standards end and your regulatory obligations begin, let’s talk.
And if you think I have this wrong, I especially want to hear from you. This is a conversation the privacy community needs to have out loud.

