Health data privacy is entering a new era—and the warning signs are already here. While the Health Information Privacy Reform Act (HIPRA) proposed by Senator Bill Cassidy may not make its way through Congress, its message to digital health companies and HIPAA-covered entities is unmistakable: the regulatory gap around consumer health data is closing fast.
For years, many digital health tools, wellness apps, wearables, and data-driven health platforms have operated outside the scope of HIPAA, relying instead on broader consumer privacy frameworks. That approach is becoming increasingly risky. A growing wave of state health privacy laws such as Washington and Nevada, combined with proposals like HIPRA and New York’s Health Information Privacy Act, signals a shift toward treating consumer health data with the same rigor long reserved for “HIPAA-covered” information.
In this recent article, we explore why HIPRA should be viewed less as a question of if it will pass and more as a preview of where health-data regulation is headed—and what organizations should be doing now to stay ahead of enforcement risk, partner expectations, and consumer trust in their use of health data in the AI-era.
KMK Law articles and blog posts are intended to bring attention to developments in the law and are not intended as legal advice for any particular client or any particular situation. The laws/regulations and interpretations thereof are evolving and subject to change. Although we will attempt to update articles/blog posts for material changes, the article/post may not reflect changes in laws/regulations or guidance issued after the date the article/post was published. Please consult with counsel of your choice regarding any specific questions you may have.
ADVERTISING MATERIAL.
© 2025 Keating Muething & Klekamp PLL. All Rights Reserved
- Of Counsel
Eric Cook serves as Of Counsel in the firm’s Business Representation & Transactions Group and is a key member of the firm’s Data Privacy & Cybersecurity Team. Eric is a business-minded attorney that provides strategic and ...
Topics/Tags
Select- Cybersecurity and Privacy Law
- Privacy Laws
- Privacy
- California Consumer Privacy Act
- Cybersecurity Regulation
- GDPR
- Data Breach
- Cyber Insurance
- Coronavirus
- CCPA
- Class Action Litigation
- General Data Protection Regulation
- Mergers & Acquisitions
- SEC
- FISMA
- Incident Response Plan
- Information Governance
- Corporate Law
- E-Discovery
- Federal Trade Commission
- Department of Justice
- Litigation
- Seventh Circuit
Recent Posts
- The Future of Health Data Privacy Is Here—With or Without HIPRA
- Indiana & Kentucky Privacy Laws Go Live in the New Year
- New York Bans Sale of Certain Supplements to Minors
- GDPR Compliance: What is Privacy Shield 2.0?
- Connecticut's Data Privacy Law
- The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA)
- The Utah Consumer Privacy Act
- The Colorado Privacy Act
- The Virginia Consumer Data Protection Act
- State Data Privacy Law Series
