Legislator Brief · one page · drafted to be printed and carried into a meeting
Health data outside HIPAA
If a fact about a patient's body is protected in one hand and unregulated in another, the duty is attached to the wrong thing.
Object type
Legislator Brief
Label
MODEL LEGISLATION
Status
OPEN FOR CRITIQUE
Jurisdiction
California / federal
Domain
Health data & digital medicine
Baseline verified
2026-08-30
Issue
Health-related data and inferences held by entities outside HIPAA — apps, wearables, brokers, advertising platforms — carry no access, deletion or use duties comparable to those attaching to the same facts inside a medical record.
Why now
Inference now does the work formerly done by disclosure: a condition can be derived from behaviour without any protected record being touched.
Current law
HIPAA binds covered entities and business associates. California consumer-privacy law grants access and deletion rights to residents against businesses meeting thresholds, with exemptions; state confidentiality law binds providers and plans. Inferences are treated as personal information in California but not as health data with heightened duties.
Policy gap
Duties follow the holder, not the data. The same fact is protected in one hand and unregulated in another.
KPSGILL recommendation
Attach duties to health-related data and inferences in any holder: thirty-day portable access, deletion with recipient notification and an honest statement of model boundaries, and express separation of clinical from commercial use.
Who can act
Cost
Analysis, not projection. Compliance falls on data holders and is meaningful for those without existing privacy infrastructure. Recipient notification is the costly element. State cost is enforcement capacity.
Trade-offs
| Dimension | Direction | Basis |
|---|---|---|
| Privacy | ↑ increase | The object of the proposal. |
| Innovation | ↓ decrease | Some inference-based products become non-viable. Stated, not hidden. |
| Administrative complexity | ↑ increase | Recipient notification requires downstream mapping. |
| Competition | ± mixed | Compliance cost favours large holders; the threshold must be set with that in view. |
| Litigation risk | ↑ increase | Extraterritorial reach will be challenged. |
| Patient safety | ↑ increase | Clinical decisions stop absorbing unvalidated commercial inference. |
Who is affected
| Group | Expected impact | Why |
|---|---|---|
| Patients | strongly favorable | Access and deletion reach the data that actually describes them. |
| Physicians | favorable | Fewer commercial inferences re-entering clinical decisions unexamined. |
| Technology vendors | strongly unfavorable | Inference-as-data is the provision they will contest. |
| Insurers | unfavorable | Commercial-use separation constrains data acquisition. |
| Government | mixed | Enforcement burden; interstate reach is genuinely contested. |
| Researchers | mixed | Secondary-use pathways must be stated expressly. |
Policy options
Option A — status quo
Protection depends on which hand holds the fact.
Option B — limited reform
Extend existing consumer rights to enumerated health data without touching inference. Administrable, and it misses the mechanism.
Option C — structural reform
Data-following duties including inference, with notification and use separation.
Option D — KPSGILL preferred · preferred
C, with inference defined by clinical sensitivity rather than by technique, and a threshold that does not make compliance a barrier to entry.
How we would know it worked
- Access requests fulfilled within thirty days, by holder class
- Deletion requests with recipient notification completed
- Enforcement actions and their subject matter
- Documented commercial inferences entering clinical or coverage decisions
The five-physician practice
A small practice is not the target; the point of the threshold is that the duty lands on data-holding businesses rather than on clinicians.
Next decision point
California Privacy Protection Agency rulemaking; introduction in the 2027 session; any FTC health-data enforcement that sets the national baseline.
Model language and sources
Model statutory or regulatory language, the documentary baseline it rests on, the strongest arguments against the proposal and the KPSGILL responses to them are on the full page: Health data outside HIPAA: a duty attached to the data, not the holder. Related briefs are indexed at Legislator Briefs.