
- Physicians Practice 2022 Newsletter
Bipartisan legislation introduced to ban selling health and location data
The new legislation would tighten the use of patients' health and location information.
The HIPAA Privacy Rule, which had the U.S. Department of Health and Human Services (HHS) modify certain standards on 
In 2018, HHS Office for Civil Rights (OCR) announced a 
Fast forward to June 2022, in light of Roe v. Wade being overturned, privacy rights which have been protected under the 14th Amendment of the U.S. Constitution under an individual’s “zone of privacy” are at risk. A bipartisan group of Senators introduced the 
Ban data brokers from selling or transferring location data and health data. The bill forbids data brokers from selling or transferring location data and health data and requires the Federal Trade Commission to promulgate rules to implement the law within 180 days, while making exceptions for HIPAA-compliant activities, protected First Amendment speech, and validly authorized disclosures.
Ensure robust enforcement of the bill’s protections. The bill empowers the Federal Trade Commission, state attorneys general, and injured persons to sue to enforce the provisions of the law, allowing for remedies such as damages and injunctions to stop any illegal practices.
Provide funding to the Federal Trade Commission to act. The bill provides $1 billion to the Federal Trade Commission over the next decade to carry out its work, including the enforcement of this law.
In the meantime, HIPAA’s Privacy Rule coupled with the 14th Amendment’s “zone of privacy” may be a solution. Individual states have also begun to follow California’s lead and pass legislation similar to the California Privacy Protection Act (CCPA). Regardless of an individual’s stance on abortion, all Americans should take issue with companies, whether medical device companies, big tech companies, or data brokers (among others), selling or disclosing information without the express written consent of the person in a manner that does not constitute a contract of adhesion. Rare situations, such as a grand jury subpoena, exist for the government to directly request such information without violating a person’s individual Constitutional rights, which is why both substantive and procedural due process exist. It is critical that patients are aware of their rights and that companies are aware of what’s legal and have adequate compliance programs in place.
Rachel V. Rose, JD, MBA, advises clients on compliance, transactions, government administrative actions, and litigation involving healthcare, cybersecurity, corporate and securities law, as well as False Claims Act and Dodd-Frank whistleblower cases. She also teaches bioethics at Baylor College of Medicine in Houston. Rachel can be reached through her website, 
Articles in this issue
over 3 years ago
Would you go to a doctor like you?over 3 years ago
How to do away with the broken healthcare systemover 3 years ago
Messy moments: That’s not the way we do things hereover 3 years ago
Managing millennial physiciansalmost 4 years ago
Trusts 101 for physiciansNewsletter
Optimize your practice with the Physicians Practice newsletter, offering management pearls, leadership tips, and business strategies tailored for practice administrators and physicians of any specialty.














