• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Bipartisan Legislation Introduced to Ban Selling Health and Location Data

August 9, 2022/in Blog, Data Privacy, DOJ, HIPAA, HIPAA Privacy Rule

Guest Author: Rachel V. Rose, JD, MBA

The new legislation would tighten the use of patients’ health and location information.

The HIPAA Privacy Rule, which had the U.S. Department of Health and Human Services (HHS) modify certain standards on August 14 2002, established parameters for certain types of marketing and the sale of protected health information (PHI). Found at 45 CFR §§ 164.501, 164.508(a)(3), the HIPAA Privacy Rules provides individuals with certain privacy rights and important controls over how their PHI is used and disclosed. As HHS iterates on its website, “[w]ith limited exceptions, the Rule requires an individual’s written authorization before a use or disclosure of his or her protected health information can be made for marketing. So as not to interfere with core health care functions, the Rule distinguishes marketing communications from those communications about goods and services that are essential for quality health care.” There are different applications of “marketing” and the one that constitutes the disclosure of PHI “in exchange for direct or indirect remuneration, for the other entity or its affiliate” requires the express written consent of the individual patient, which must be prominently placed on the HIPAA Authorization Form and give the patient (or the patient’s legal representative) the option of “opting out” of the sale at any time. And, depending on the nature of the relationship between the covered entity, business associate, and/or subcontractor, a business associate agreement (BAA).

In 2018, HHS Office for Civil Rights (OCR) announced a $100,000 settlement with Filefax, Inc. – a company that once provided storage and disposal services for medical records – for allowing an unauthorized person to remove PHI, leave it unsecured outside the facility, and attempting to sell the PHI without the patient’s express written authorization. The take-away – its not legal.

Fast forward to June 2022, in light of Roe v. Wade being overturned, privacy rights which have been protected under the 14th Amendment of the U.S. Constitution under an individual’s “zone of privacy” are at risk. A bipartisan group of Senators introduced the Health and Location Data Protection Act, which, if passed, may mitigate the effects of Roe v. Wade being overturned and would fill a significant gap in U.S. privacy law. The data broker industry is a $200 billion dollar a year industry. Three of the key features of the bill are as follows:

Ban data brokers from selling or transferring location data and health data. The bill forbids data brokers from selling or transferring location data and health data and requires the Federal Trade Commission to promulgate rules to implement the law within 180 days, while making exceptions for HIPAA-compliant activities, protected First Amendment speech, and validly authorized disclosures.

Ensure robust enforcement of the bill’s protections. The bill empowers the Federal Trade Commission, state attorneys general, and injured persons to sue to enforce the provisions of the law, allowing for remedies such as damages and injunctions to stop any illegal practices.

Provide funding to the Federal Trade Commission to act. The bill provides $1 billion to the Federal Trade Commission over the next decade to carry out its work, including the enforcement of this law.

In the meantime, HIPAA’s Privacy Rule coupled with the 14th Amendment’s “zone of privacy” may be a solution. Individual states have also begun to follow California’s lead and pass legislation similar to the California Privacy Protection Act (CCPA). Regardless of an individual’s stance on abortion, all Americans should take issue with companies, whether medical device companies, big tech companies, or data brokers (among others), selling or disclosing information without the express written consent of the person in a manner that does not constitute a contract of adhesion. Rare situations, such as a grand jury subpoena, exist for the government to directly request such information without violating a person’s individual Constitutional rights, which is why both substantive and procedural due process exist. It is critical that patients are aware of their rights and that companies are aware of what’s legal and have adequate compliance programs in place.

Rachel V. Rose, JD, MBA

About the Author

Rachel V. Rose, JD, MBA, advises clients on compliance, transactions, government administrative actions, and litigation involving healthcare, cybersecurity, corporate and securities law, as well as False Claims Act and Dodd-Frank whistleblower cases. She also teaches bioethics at Baylor College of Medicine in Houston. Rachel can be reached through her website, www.rvrose.com.

Originally posted on: physicianspractice.com

Tags: dobbs, GRC, health data, Health law, HHS, HIPAA, Privacy, Rachel V. Rose, Roe
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2022/08/privacy-selling-location-data_FT.jpg 758 1200 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2022-08-09 10:06:542025-04-15 12:42:00Bipartisan Legislation Introduced to Ban Selling Health and Location Data
You might also like
email Implement Reasonable Safeguards Before Hitting Reply to a Patient Email
healthcare compliance online training 2021 Online Healthcare Compliance Training for Employees: 4 Topics to Consider
OCR Notice Did You Receive an OCR Notice for the Phase 2 Audit? What’s Next?
Congratulations to our 2022 Presenter of the Year!
Exclusion Screening Requirements for Healthcare Entities: Ensuring Compliance and Protecting Your Organization Who are your Business Associates?
Exclusion Screening Requirements for Healthcare Entities: Ensuring Compliance and Protecting Your Organization Exclusion Screening Requirements for Healthcare Entities: Ensuring Compliance and Protecting Your Organization

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only