The slow expansion of health privacy
The Senate Committee recently voted 22 to 0 in favour of expanding protections for health data that HIPAA was never written to protect. On paper, it is a clean sweep—a rare moment of unanimity in Washington. For the uninitiated or those who prefer their regulations delivered via glossy brochures, this looks like progress. It suggests a tightening of the net around our most sensitive information.
But if you follow the paperwork rather than the press releases, the reality is more cumbersome.
HIPAA was designed for an era when health records lived in manila folders and were transmitted by fax machines that groaned under their own weight. The gap between what constitutes a 'covered entity' and where our actual health data resides has become a canyon. For years, wellness apps and wearable trackers have operated in this grey space, collecting heart rates and sleep cycles without the burden of HIPAA compliance because they didn’t fit the narrow 1996 definition of a healthcare provider or insurance plan.
The proposed expansion aims to close that gap. The implication is straightforward: if you collect health data for profit, regardless of whether you are a licensed doctor in an office or a software engineer in a hoodie, you may soon find yourself answering to the Department of Health and Human Services (HHS).
This creates a liability cliff. For firms currently operating under the assumption that they only need to worry about general privacy laws like CCPA—which provide some protections but lack HIPAA's prescriptive rigidity—the shift is jarring. They’ll have to implement administrative safeguards, designate specific compliance officers and maintain audit logs that actually mean something when an auditor arrives.
The strongest objection here is the usual one: these regulations stifle innovation in health tech. The argument suggests that by imposing legacy bureaucracy on agile startups, we slow down the development of life-saving diagnostics.
This ignores where the data actually goes once it leaves those 'innovative' apps. Look at Hims & Hers. They’ve found themselves sued by the FTC and several state attorneys general over deceptive health data sharing practices. When a company treats sensitive patient information as an asset to be traded or leveraged for subscription billing, they aren’t innovating; they are just ignoring the spirit of privacy law because the letter of HIPAA didn't explicitly catch them yet.
The irony is that while we debate definitions in committee rooms, threat actors don't bother with regulatory frameworks. ShinyHunters has been increasingly active in targeting healthcare data theft. They do not care if a dataset falls under the strict definition of Protected Health Information (PHI) or if it’s just 'wellness metrics'. To a hacker, any health record is valuable currency on the dark web.
We are seeing a pattern where enforcement arrives via consumer protection lawsuits rather than regulatory fines from HHS OCR. The FTC moves faster because they don't have to wait for a rule change; they simply use their existing mandate against deceptive trade practices.
There is an uncomfortable second-order effect here for the insurance market. Professional liability and cyber insurers generally price risk based on known frameworks. If thousands of small health tech firms suddenly shift from 'General Privacy' to 'HIPAA Compliant', there will be a massive spike in demand for audits that these firms cannot actually pass. I suspect we’ll see premiums climb just as the regulators begin their first round of inspections, leaving many startups under-insured and over-exposed.
Even those who are already compliant shouldn't breathe too easily. The California Dental Association is currently warning its members about upcoming HIPAA rule changes. This serves as a reminder that compliance isn't a destination you reach; it’s an endless cycle of updating folders because someone in Washington decided to tweak the definition of 'disclosure'.
The dental practices will be those most affected by these granular shifts. They are often small operations with limited administrative staff who view HIPAA as something they checked off five years ago during their initial setup. Now, they'll have to revisit their Business Associate Agreements and likely pay a consultant several thousand pounds to tell them that their current filing system is insufficient.
The real question for the industry isn't whether these gaps will be closed