States Move to Close Gaps in Health Data Privacy

States Move to Close Gaps in Health Data Privacy

Americans overwhelmingly believe their health information should remain private. In a 2022 survey of 1,000 patients, more than 92% said privacy is a right and that their health data should not be available for purchase by corporations or other individuals. Ninety-four percent said companies that collect, store, analyze, or use health data should be held accountable under the law.

While many Americans assume that existing law already protects most health data, it leaves many gaps. In a 2023 Harris Poll conducted on behalf of ClearDATA, 81% of U.S. adults said they believed health data collected by digital health apps was protected under the Health Insurance Portability and Accountability Act (HIPAA). That misconception matters. In a separate national survey conducted for The Pew Charitable Trusts, 35% of respondents initially said they were very or extremely concerned about the privacy of medical information downloaded to health apps. When told that federal privacy laws such as HIPAA might no longer protect that information once it was downloaded, the share rose to 62%.

HIPAA—the law many Americans assume protects the privacy of their health information—was enacted in 1996, in a world of manila folders and hospital mainframes. The privacy framework that developed under the law applies primarily according to who holds or handles health information, including healthcare providers, health plans, and their business associates. It was established before smartphones, consumer health apps, and wearable devices began generating vast quantities of health-related information outside the traditional healthcare system.

Because HIPAA protects health information according to who holds it, not according to what it reveals, a heart rhythm recorded in a cardiologist’s office is shielded by the law, while the same reading captured by a smartwatch or wellness app generally is not. Today such data pours into companies that operate beyond HIPAA’s reach.

A growing number of states have moved to address this gap. These efforts generally fall into one of four categories. Some states have built entirely new protections for the “consumer health data” that falls outside HIPAA; others have moved to govern genetic, biometric, and increasingly neural data. Still others have adopted protections limiting the disclosure or use of information related to reproductive and gender-affirming care or have written health safeguards into comprehensive privacy laws.

Passed in 2023, Washington’s My Health My Data Act (MHMD) became the first law in the country to protect “consumer health data” as a category unto itself. While HIPAA protects health information held within the traditional healthcare system, MHMD applies to the location pings, search histories, and app entries that can reveal a person’s health without ever passing through a clinician’s hands. The law reaches even the inferences a company draws from ordinary purchases: the Washington Attorney General’s guidance points to retailers assigning shoppers a “pregnancy prediction score” based on changes in their buying habits.[1] Under MHMD, a score like that is itself protected health data, even though nothing in the underlying purchases is medical.

Illinois was an early leader in regulating biometric identifiers—including fingerprints, face scans, and voiceprints—with the passage of the Biometric Information Privacy Act (BIPA) in 2008. More recently, states have begun extending privacy protections to neural data: information generated by measuring activity in the brain or nervous system that can be processed with the assistance of a device. Colorado, California, Montana, and Connecticut have each moved to bring neural data within existing privacy protections.

After the Supreme Court’s 2022 Dobbs decision returned abortion regulation to the states, an individual’s digital trail became a potential source of evidence in states investigating or prosecuting violations of abortion laws. A late menstrual period logged in an app, the location signal of a phone carried into a clinic, or a traceable purchase could potentially be used as evidence. The same exposure creates privacy concerns outside law enforcement as well. Washington’s MHMD statute, referenced above, was in significant part a response to these concerns. In proposing the legislation, the state’s attorney general warned that a period-tracking app could sell data about a woman’s late period or miscarriage to data brokers, potentially allowing that information to be used to target her with messages intended to influence her decision about seeking abortion care.

As of August 2026, twenty-three states and the District of Columbia had some form of shield-law protection related to reproductive health or gender-affirming care, although the scope of those protections varies considerably. Twenty-two states and the District of Columbia prohibit at least some assistance with out-of-state investigations. Separately, states including California, Connecticut, and Washington have restricted geofencing around healthcare facilities, limiting the use of location data to identify or target people seeking care. Many states have also extended shield protections to gender-affirming care: seventeen states and the District of Columbia explicitly protect both reproductive health and gender-affirming care.

The fourth category of data privacy protections is the broadest, and the least specific to health. Beginning with California in 2018, twenty-three states have now enacted comprehensive consumer-privacy laws. Although these laws govern personal information generally rather than health information specifically, they typically classify at least some health-related information as “sensitive data,” along with categories such as precise geolocation, biometric information, and genetic data. That designation generally subjects the information to heightened requirements for its collection or processing.

For health data, the relevance of these laws lies partly in their breadth. Information does not necessarily have to originate in a medical record to receive protection; depending on the state and the law, health-related information collected by other businesses may fall within a broader category of sensitive data. The laws vary considerably in their scope, exemptions, and requirements. Maryland’s Online Data Privacy Act, for example, prohibits the sale of sensitive data and limits its collection to what is reasonably necessary and proportionate to provide or maintain a product or service requested by the consumer.

The growing patchwork of state laws has been accompanied by renewed efforts at the federal level to address health information that falls outside HIPAA. In November 2025, Sen. Bill Cassidy (R-La.), who chairs the Senate Health, Education, Labor, and Pensions Committee, introduced the Health Information Privacy Reform Act (S. 3097), joined by Sen. Maggie Hassan (D-N.H.); the bill would establish privacy protections for health information collected by technologies such as smartwatches and health apps that are not already subject to HIPAA. The committee advanced the measure to the full Senate on a unanimous 22-0 vote in early August 2026.

Passage of the act would only be a beginning. The bill does not set standards. Rather, it would give the Department of Health and Human Services, in consultation with the Federal Trade Commission, eighteen months to write the actual rules. Comparable HHS rulemakings have often run longer than their deadlines. Even then, the federal law would set a floor rather than a ceiling. Its preemption clause preserves state protections that are more stringent. For now, and for some time to come, states continue to define the protections that apply to a growing share of health information generated outside the traditional healthcare system.


[1] The widely retold coda to the retailer example—in which the company supposedly revealed a teenager’s pregnancy to her father—has been questioned. See Colin Fraser’s critique of the anecdote’s sourcing and logic. The pregnancy-prediction model itself was documented in Charles Duhigg’s 2012 reporting for The New York Times Magazine.