1 | 1 | | GOVERNMENT OF THE DISTRICT OF COLUMBIA |
---|
2 | 2 | | OFFICE OF THE ATTORNEY GENERAL |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | |
---|
6 | 6 | | ATTORNEY GENERAL |
---|
7 | 7 | | BRIAN L. SCHWALB |
---|
8 | 8 | | 400 Sixth Street, N .W., Washington, DC 20001, (202) 727- 3400, Fax (202) 730-0484 |
---|
9 | 9 | | |
---|
10 | 10 | | |
---|
11 | 11 | | |
---|
12 | 12 | | |
---|
13 | 13 | | |
---|
14 | 14 | | July 12, 2024 |
---|
15 | 15 | | |
---|
16 | 16 | | The Honorable Phil Mendelson |
---|
17 | 17 | | Chairman, Council of the District of Columbia |
---|
18 | 18 | | John A. Wilson Building |
---|
19 | 19 | | 1350 Pennsylvania Avenue, N.W. |
---|
20 | 20 | | Washington, D.C. 20004 |
---|
21 | 21 | | |
---|
22 | 22 | | Dear Chairman Mendelson: |
---|
23 | 23 | | |
---|
24 | 24 | | I write to transmit the “Consumer Health Information Privacy Protection (CHIPPA) Act of 2024,” for |
---|
25 | 25 | | consideration and enactment by the Council of the District of Columbia. |
---|
26 | 26 | | |
---|
27 | 27 | | Personal health data that is uploaded to online platforms like company websites, search engines, apps, and |
---|
28 | 28 | | even social media is being collected, shared, and sold to third parties without the consumer’s consent or |
---|
29 | 29 | | knowledge. While most people believe that the federal Health Insurance Portability and Accountability |
---|
30 | 30 | | Act of 1996 (“HIPAA”) protects all personal health data from being shared without consent or knowledge, |
---|
31 | 31 | | it only applies to data collected by a “covered entity,” such as health insurers, hospitals, and healthcare |
---|
32 | 32 | | providers. It does not extend to personal health information shared by non-covered entities. For example, |
---|
33 | 33 | | health devices, apps, Apple Watch, and patient support groups fall outside of HIPAA regulation. |
---|
34 | 34 | | |
---|
35 | 35 | | This legislation will ensure regulated entities that obtain, collect, share, and sell consumer personal health |
---|
36 | 36 | | data are responsible, transparent, and held accountable to the consumer. CHIPPA will do the following: |
---|
37 | 37 | | |
---|
38 | 38 | | 1. Require regulated entities to establish and make publicly available a consumer health data privacy |
---|
39 | 39 | | policy governing the collection, use, sharing, and sale of consumer health data. |
---|
40 | 40 | | 2. Require that regulated entities obtain the consumer’s informed consent before collecting and |
---|
41 | 41 | | sharing their personal health data. |
---|
42 | 42 | | 3. Establish a consumer’s right to access and choose whether and how their personal health data is |
---|
43 | 43 | | used by a regulated entity. |
---|
44 | 44 | | 4. Establish additional protections and consumer authorizations for the sale of personal health data. |
---|
45 | 45 | | 5. Require regulated entities to only collect health data that is necessary for the purposes disclosed to |
---|
46 | 46 | | the consumers and to only use, share, and retain the consumer health data for that purpose. |
---|
47 | 47 | | 6. Prohibit the establishment of geofences around places where health services are delivered under |
---|
48 | 48 | | specified circumstances. |
---|
49 | 49 | | 7. Make violations unfair and deceptive trade practices. |
---|
50 | 50 | | |
---|
51 | 51 | | I ask that the Council enact this legislation to ensure that everyone, regardless of whether they are a patient |
---|
52 | 52 | | seeking health care services, a consumer signing- up for a fitness app, or purchasing an item online, know s |
---|
53 | 53 | | why, how, and to whom their personal health data is being used, shared, and sold. If you have any 2 |
---|
54 | 54 | | |
---|
55 | 55 | | questions, please contact me or Deputy Attorney General for Policy and Legislative Affairs Candyce |
---|
56 | 56 | | Phoenix at (202) 788- 2066 or Candyce.Phoenix@dc.gov. |
---|
57 | 57 | | |
---|
58 | 58 | | Sincerely, |
---|
59 | 59 | | |
---|
60 | 60 | | |
---|
61 | 61 | | Brian L. Schwalb |
---|
62 | 62 | | Attorney General for the District of Columbia |
---|
63 | 63 | | 2 |
---|
64 | 64 | | 3 |
---|
65 | 65 | | 4 |
---|
66 | 66 | | 5 |
---|
67 | 67 | | 6 |
---|
68 | 68 | | 7 |
---|
69 | 69 | | 8 |
---|
70 | 70 | | 9 |
---|
71 | 71 | | IO |
---|
72 | 72 | | 11 |
---|
73 | 73 | | 12 |
---|
74 | 74 | | 13 |
---|
75 | 75 | | 14 |
---|
76 | 76 | | 15 |
---|
77 | 77 | | 16 |
---|
78 | 78 | | :Iiz ~//4---- |
---|
79 | 79 | | ~ n Phil Mendelson |
---|
80 | 80 | | at the request |
---|
81 | 81 | | of the Attorney General |
---|
82 | 82 | | A BILL |
---|
83 | 83 | | IN THE COUNCIL OF THE DISTRICT OF COLUMBIA |
---|
84 | 84 | | 17 To require regulated entities that collect consumer health data to have a consumer health data |
---|
85 | 85 | | 18 privacy policy containing specific information about its collection, use and sharing of |
---|
86 | 86 | | 19 consumer health data and post it on the home page of their website, to prohibit regulated |
---|
87 | 87 | | 20 entities from contracting with processors, affiliates, or third parties to process consumer |
---|
88 | 88 | | 21 health data in a manner inconsistent with the policy, to require regulated entities to obtain |
---|
89 | 89 | | 22 consumer consent before collecting consumer health data after providing the consumer |
---|
90 | 90 | | 23 with requests for consent containing specified information, to limit a regulated entity's |
---|
91 | 91 | | 24 collection and sharing of consumer health data to the purposes contained in the |
---|
92 | 92 | | 25 consumer's consent, to establish a consumer's right to obtain information about consumer |
---|
93 | 93 | | 26 health infonnation collected and shared, to withdraw consent for collection and sharing, |
---|
94 | 94 | | 27 and to obtain deletion of info1mation collected and shared, to require a valid consumer |
---|
95 | 95 | | 28 authorization before consumer health data may be sold, to prohibit the establishment of |
---|
96 | 96 | | 29 geofences around places where health services are delivered under specified |
---|
97 | 97 | | 30 circumstances, to make violations of this act unfair and deceptive trade practices, and to |
---|
98 | 98 | | 3 I exclude certain types of data collection and data sharing from the operation of the act. |
---|
99 | 99 | | 32 |
---|
100 | 100 | | 33 |
---|
101 | 101 | | BE IT ENACTED BY THE COUNCIL OF THE DISTRICT OF COLUMBIA, That this |
---|
102 | 102 | | 34 act may be cited as the "Consumer Health Information Privacy Protection (CHIPP A) Act of |
---|
103 | 103 | | 35 2024". |
---|
104 | 104 | | 36 Sec. 2. Definitions |
---|
105 | 105 | | 37 |
---|
106 | 106 | | 38 For the purposes of this act, the term: |
---|
107 | 107 | | 39 |
---|
108 | 108 | | 40 ( 1) "Abortion" means the termination of a pregnancy for purposes other than producing a |
---|
109 | 109 | | 41 live birth. 2 |
---|
110 | 110 | | 42 (2) “Affiliate” means a legal entity that shares common branding with another legal entity |
---|
111 | 111 | | |
---|
112 | 112 | | 43 and controls, is controlled by, or is under common control with another legal entity. For purposes |
---|
113 | 113 | | |
---|
114 | 114 | | 44 of this definition, “control” or “controlled” means: |
---|
115 | 115 | | |
---|
116 | 116 | | 45 (A) Ownership of, or the power to vote, more than 50 percent of the outstanding |
---|
117 | 117 | | |
---|
118 | 118 | | 46 shares of any class of voting security of a company; |
---|
119 | 119 | | |
---|
120 | 120 | | 47 (B) Control in any manner over the election of a majority of the directors or of |
---|
121 | 121 | | |
---|
122 | 122 | | 48 individuals exercising similar functions; or |
---|
123 | 123 | | |
---|
124 | 124 | | 49 (C) The power to exercise controlling influence over the management of a |
---|
125 | 125 | | |
---|
126 | 126 | | 50 company. |
---|
127 | 127 | | |
---|
128 | 128 | | 51 (3) “Authenticate” means to use reasonable means to determine that a request to exercise |
---|
129 | 129 | | |
---|
130 | 130 | | 52 any of the rights afforded in this act is being made by, or on behalf of, the consumer who is |
---|
131 | 131 | | 53 entitled to exercise such consumer rights with respect to the consumer health data at issue. |
---|
132 | 132 | | 54 (4) “Biometric data” means data that is generated from the measurement or technological |
---|
133 | 133 | | 55 processing of an individual’s physiological, biological, or behavioral characteristics and that |
---|
134 | 134 | | |
---|
135 | 135 | | 56 identifies a consumer, whether individually or in combination with other data. Biometric data |
---|
136 | 136 | | |
---|
137 | 137 | | 57 includes: |
---|
138 | 138 | | |
---|
139 | 139 | | 58 (A) Imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and |
---|
140 | 140 | | 59 voice recordings, from which an identifier template can be extracted; and |
---|
141 | 141 | | 60 (B) Keystroke patterns or rhythms and gait patterns or rhythms that contain |
---|
142 | 142 | | 61 identifying information. |
---|
143 | 143 | | 62 (5) “Clear and conspicuous” means a disclosure that is easily noticeable and easily |
---|
144 | 144 | | 63 understandable by the consumer and does not contain any statements that are inconsistent with, |
---|
145 | 145 | | 64 or in mitigation of any other statements or disclosures provided by the regulated entity. 3 |
---|
146 | 146 | | 65 “Clear and conspicuous” requires the information to be reasonably accessible to |
---|
147 | 147 | | |
---|
148 | 148 | | 66 consumers with disabilities, taking into account industry standards for online disclosures. |
---|
149 | 149 | | |
---|
150 | 150 | | 67 (6) “Collect” means to buy, rent, access, retain, receive, acquire, infer, derive, or |
---|
151 | 151 | | |
---|
152 | 152 | | 68 otherwise process consumer health data in any manner. |
---|
153 | 153 | | |
---|
154 | 154 | | 69 (7) “Consent” means a clear affirmative act that signifies a consumer’s freely given, |
---|
155 | 155 | | |
---|
156 | 156 | | 70 specific, informed, opt-in, voluntary, and unambiguous agreement, following a clear and |
---|
157 | 157 | | |
---|
158 | 158 | | 71 conspicuous disclosure to the individual, which shall consist of written consent or consent |
---|
159 | 159 | | |
---|
160 | 160 | | 72 provided by electronic means. For the purposes of this act “consent” shall not include: |
---|
161 | 161 | | |
---|
162 | 162 | | 73 (A) A consumer’s acceptance of a general or broad terms-of-use agreement or a |
---|
163 | 163 | | |
---|
164 | 164 | | 74 similar document that contains descriptions of personal data processing along with other |
---|
165 | 165 | | |
---|
166 | 166 | | 75 unrelated information; |
---|
167 | 167 | | 76 (B) A consumer’s hovering over, muting, pausing, or closing a given piece of |
---|
168 | 168 | | 77 electronic content; or |
---|
169 | 169 | | 78 (C) A consumer’s agreement obtained through the use of deceptive designs. |
---|
170 | 170 | | |
---|
171 | 171 | | 79 (8) “Consumer” means a natural person acting in an individual or household capacity, |
---|
172 | 172 | | |
---|
173 | 173 | | 80 however identified, including by any unique identifier, who is a District of Columbia (“District”) |
---|
174 | 174 | | |
---|
175 | 175 | | 81 resident or whose consumer health data is collected in the District. “Consumer” does not include |
---|
176 | 176 | | 82 an individual acting in the course of their employment. |
---|
177 | 177 | | 83 (9) “Consumer health data” means personal information that is linked or can reasonably |
---|
178 | 178 | | 84 be linked to a consumer and that identifies the consumer’s past, present, or future physical or |
---|
179 | 179 | | 85 mental health status. “Consumer health data” does not include personal information that is used |
---|
180 | 180 | | 86 to engage in public or peer-reviewed scientific, historical, or statistical research in the public |
---|
181 | 181 | | 87 interest that adheres to all other applicable ethics and privacy laws and is approved, monitored, 4 |
---|
182 | 182 | | 88 and governed by an institutional review board, human subjects research ethics review board, or a |
---|
183 | 183 | | |
---|
184 | 184 | | 89 similar independent oversight entity that determines that the regulated entity or the small |
---|
185 | 185 | | |
---|
186 | 186 | | 90 business has implemented reasonable safeguards to mitigate privacy risks associated with |
---|
187 | 187 | | |
---|
188 | 188 | | 91 research, including any risks associated with reidentification. |
---|
189 | 189 | | |
---|
190 | 190 | | 92 (10) “Deceptive design” means a user interface designed or manipulated with the effect |
---|
191 | 191 | | |
---|
192 | 192 | | 93 of subverting or impairing user autonomy, decision making, or choice. “Any practice that the |
---|
193 | 193 | | |
---|
194 | 194 | | 94 Federal Trade Commission refers to as a “dark pattern” is presumed a deceptive design. |
---|
195 | 195 | | |
---|
196 | 196 | | 95 (11) “Deidentified data” means data that cannot reasonably be used to infer information |
---|
197 | 197 | | |
---|
198 | 198 | | 96 about, or otherwise be linked to, an identified or identifiable consumer, or a device linked to such |
---|
199 | 199 | | |
---|
200 | 200 | | 97 a consumer. “Deidentified data” includes consumer health data in the possession of a regulated |
---|
201 | 201 | | |
---|
202 | 202 | | 98 entity where the regulated entity: |
---|
203 | 203 | | 99 (A) Takes reasonable measures to ensure that such data cannot be associated with |
---|
204 | 204 | | 100 a consumer; |
---|
205 | 205 | | 101 (B) Publicly commits to maintain and process the data in a deidentified fashion |
---|
206 | 206 | | |
---|
207 | 207 | | 102 and to not attempt to reidentify the data, except that the regulated entity may attempt to |
---|
208 | 208 | | |
---|
209 | 209 | | 103 reidentify the information solely for the purpose of determining whether its deidentification |
---|
210 | 210 | | |
---|
211 | 211 | | 104 processes satisfy the requirements of this paragraph; and |
---|
212 | 212 | | 105 (C) Contractually obligates any recipients of such data to maintain the data in a |
---|
213 | 213 | | 106 deidentified fashion. |
---|
214 | 214 | | 107 (12) “Gender-affirming care information” means personal information relating to seeking |
---|
215 | 215 | | 108 or obtaining past, present, or future gender-affirming care services. “Gender-affirming care |
---|
216 | 216 | | 109 information” includes: 5 |
---|
217 | 217 | | 110 (A) Precise location information that could reasonably indicate a consumer’s |
---|
218 | 218 | | |
---|
219 | 219 | | 111 attempt to acquire or receive gender-affirming care services; |
---|
220 | 220 | | |
---|
221 | 221 | | 112 (B) Efforts to research or obtain gender-affirming care services; or |
---|
222 | 222 | | |
---|
223 | 223 | | 113 (C) Any information related to seeking or obtaining past, present, or future |
---|
224 | 224 | | |
---|
225 | 225 | | 114 gender-affirming care services that is derived, extrapolated, or inferred, including from non- |
---|
226 | 226 | | |
---|
227 | 227 | | 115 health information, such as proxy, derivative, inferred, emergent, or algorithmic data. |
---|
228 | 228 | | |
---|
229 | 229 | | 116 (13) “Gender-affirming care services” means health services or products that support and |
---|
230 | 230 | | |
---|
231 | 231 | | 117 affirm an individual’s gender identity, including social, psychological, behavioral, cosmetic, |
---|
232 | 232 | | |
---|
233 | 233 | | 118 medical, or surgical interventions. “Gender-affirming care services” includes treatments for |
---|
234 | 234 | | |
---|
235 | 235 | | 119 gender dysphoria, gender-affirming hormone therapy, and gender-affirming surgical procedures. |
---|
236 | 236 | | |
---|
237 | 237 | | 120 (14) “Genetic data” or “genetic information” means any data, regardless of its format, |
---|
238 | 238 | | 121 that concerns a consumer’s genetic characteristics. “Genetic data” or “genetic information” |
---|
239 | 239 | | 122 includes: |
---|
240 | 240 | | 123 (A) Raw sequence data that result from the sequencing of a consumer's complete |
---|
241 | 241 | | |
---|
242 | 242 | | 124 extracted deoxyribonucleic acid (“DNA”) or a portion of the extracted DNA; |
---|
243 | 243 | | |
---|
244 | 244 | | 125 (B) Genotypic and phenotypic information that results from analyzing the raw |
---|
245 | 245 | | |
---|
246 | 246 | | 126 sequence data; and |
---|
247 | 247 | | 127 (C) Self-reported health data that a consumer submits to a regulated entity and |
---|
248 | 248 | | 128 that is analyzed in connection with consumer's raw sequence data. |
---|
249 | 249 | | 129 (15) “Geofence” means technology that uses global positioning coordinates, cell tower |
---|
250 | 250 | | 130 connectivity, cellular data, radio frequency identification, Wi-fi data, or any other form of spatial |
---|
251 | 251 | | 131 or location detection to establish a virtual boundary around a specific physical location, or to 6 |
---|
252 | 252 | | 132 locate a consumer within a virtual boundary. For purposes of this definition, “geofence” means a |
---|
253 | 253 | | |
---|
254 | 254 | | 133 virtual boundary that is 2,000 feet or less from the perimeter of the physical location. |
---|
255 | 255 | | |
---|
256 | 256 | | 134 (16) “Health care services” means any service provided to a person to assess, measure, |
---|
257 | 257 | | |
---|
258 | 258 | | 135 improve, or learn about a person's mental or physical health, including: |
---|
259 | 259 | | |
---|
260 | 260 | | 136 (A) Individual health conditions, status, diseases, or diagnoses; |
---|
261 | 261 | | |
---|
262 | 262 | | 137 (B) Social, psychological, behavioral, and medical interventions; |
---|
263 | 263 | | |
---|
264 | 264 | | 138 (C) Health-related surgeries or procedures; |
---|
265 | 265 | | |
---|
266 | 266 | | 139 (D) Use or purchase of medication; |
---|
267 | 267 | | |
---|
268 | 268 | | 140 (E) Bodily functions, vital signs, symptoms, or measurements of the information |
---|
269 | 269 | | |
---|
270 | 270 | | 141 described in this paragraph; |
---|
271 | 271 | | |
---|
272 | 272 | | 142 (F) Diagnoses or diagnostic testing, treatment, or medication; |
---|
273 | 273 | | 143 (G) Reproductive health care services; or |
---|
274 | 274 | | 144 (H) Gender-affirming care services. |
---|
275 | 275 | | 145 (17) “Homepage” means the introductory page of an internet website and any internet |
---|
276 | 276 | | |
---|
277 | 277 | | 146 webpage where personal information is collected. In the case of an online service, such as a |
---|
278 | 278 | | |
---|
279 | 279 | | 147 mobile application, homepage means the application's platform page or download page, and a |
---|
280 | 280 | | |
---|
281 | 281 | | 148 link within the application, such as from the application configuration, “about,” “information,” or |
---|
282 | 282 | | 149 settings page. |
---|
283 | 283 | | 150 (18) “Person” means an individual, firm, corporation, partnership, cooperative, |
---|
284 | 284 | | 151 association, or any other organization, legal entity, or group of individuals however organized, |
---|
285 | 285 | | 152 including agents thereof. The term “person” includes a regulated entity, third party, affiliate, or |
---|
286 | 286 | | 153 processor. The term “person or entity” shall not include the government of the United States, the 7 |
---|
287 | 287 | | 154 District of Columbia government, or any of the agencies or instrumentalities of either |
---|
288 | 288 | | |
---|
289 | 289 | | 155 government. |
---|
290 | 290 | | |
---|
291 | 291 | | 156 (19) “Personal information” means information that identifies or is reasonably capable of |
---|
292 | 292 | | |
---|
293 | 293 | | 157 being associated or linked, directly or indirectly, to a particular consumer. “Personal |
---|
294 | 294 | | |
---|
295 | 295 | | 158 information” includes data associated with a persistent unique identifier, such as a cookie ID, an |
---|
296 | 296 | | |
---|
297 | 297 | | 159 IP address, a device identifier, an advertising ID, or any other form of persistent unique |
---|
298 | 298 | | |
---|
299 | 299 | | 160 identifier. “Personal information” does not include publicly available information or deidentified |
---|
300 | 300 | | |
---|
301 | 301 | | 161 data. |
---|
302 | 302 | | |
---|
303 | 303 | | 162 (20) “Physical or mental health status” includes: |
---|
304 | 304 | | |
---|
305 | 305 | | 163 (A) Individual health conditions, treatment, diseases, or diagnoses; |
---|
306 | 306 | | |
---|
307 | 307 | | 164 (B) Social, psychological, behavioral, and medical interventions; |
---|
308 | 308 | | 165 (C) Health-related surgeries or procedures; |
---|
309 | 309 | | 166 (D) Use or purchase of prescribed medications; |
---|
310 | 310 | | 167 (E) Bodily functions, vital signs, symptoms, or measurements of the information |
---|
311 | 311 | | |
---|
312 | 312 | | 168 described in this paragraph; |
---|
313 | 313 | | |
---|
314 | 314 | | 169 (F) Diagnoses or diagnostic testing, treatment, or medication; |
---|
315 | 315 | | |
---|
316 | 316 | | 170 (G) Gender-affirming care information; |
---|
317 | 317 | | 171 (H) Reproductive or sexual health information; |
---|
318 | 318 | | 172 (I) Biometric data; |
---|
319 | 319 | | 173 (J) Genetic data; |
---|
320 | 320 | | 174 (K) Precise location information that could reasonably indicate a consumer's |
---|
321 | 321 | | 175 attempt to acquire or receive health services or supplies; |
---|
322 | 322 | | 176 (L) Data that identifies a consumer seeking health care services; or 8 |
---|
323 | 323 | | 177 (M) Any information that a regulated entity, or their processor, processes to |
---|
324 | 324 | | |
---|
325 | 325 | | 178 associate or identify a consumer with the data described in this paragraph that is derived or |
---|
326 | 326 | | |
---|
327 | 327 | | 179 extrapolated from non-health information (such as proxy, derivative, inferred, or emergent data |
---|
328 | 328 | | |
---|
329 | 329 | | 180 by any means, including algorithms or machine learning). |
---|
330 | 330 | | |
---|
331 | 331 | | 181 (21) “Precise location information” means information derived from technology and that |
---|
332 | 332 | | |
---|
333 | 333 | | 182 is used or intended to be used to locate a consumer within a radius of 1,750 feet. |
---|
334 | 334 | | |
---|
335 | 335 | | 183 (22) “Process” or “processing” means any operation or set of operations performed on |
---|
336 | 336 | | |
---|
337 | 337 | | 184 consumer health data. |
---|
338 | 338 | | |
---|
339 | 339 | | 185 (23) “Processor” means a person that processes consumer health data on behalf of a |
---|
340 | 340 | | |
---|
341 | 341 | | 186 regulated entity. |
---|
342 | 342 | | |
---|
343 | 343 | | 187 (24) “Publicly available information” means information about a consumer that a |
---|
344 | 344 | | 188 regulated entity has reasonable cause to believe the consumer has lawfully made available to the |
---|
345 | 345 | | 189 general public through federal, state, or municipal government records or widely distributed |
---|
346 | 346 | | 190 media. “Publicly available information” does not include any biometric data collected about a |
---|
347 | 347 | | |
---|
348 | 348 | | 191 consumer by a business without the consumer’s consent. |
---|
349 | 349 | | |
---|
350 | 350 | | 192 (25) “Regulated entity” means any legal entity, including its agents, that conducts |
---|
351 | 351 | | |
---|
352 | 352 | | 193 business in the District or produces or provides products or services that are targeted to |
---|
353 | 353 | | 194 consumers in the District and that alone or jointly with others, determines the purpose and means |
---|
354 | 354 | | 195 of collecting, processing, sharing, or selling consumer health data. “Regulated entity” does not |
---|
355 | 355 | | 196 include government agencies, tribal nations, or contracted service providers when processing |
---|
356 | 356 | | 197 consumer health data on behalf of a government agency. 9 |
---|
357 | 357 | | 198 (26) “Reproductive or sexual health information” means personal information relating to |
---|
358 | 358 | | |
---|
359 | 359 | | 199 seeking or obtaining past, present, or future reproductive or sexual health services. |
---|
360 | 360 | | |
---|
361 | 361 | | 200 “Reproductive or sexual health information” includes: |
---|
362 | 362 | | |
---|
363 | 363 | | 201 (A) Precise location information that could reasonably indicate a consumer's |
---|
364 | 364 | | |
---|
365 | 365 | | 202 attempt to acquire or receive reproductive or sexual health services; |
---|
366 | 366 | | |
---|
367 | 367 | | 203 (B) Efforts to research or obtain reproductive or sexual health services; or |
---|
368 | 368 | | |
---|
369 | 369 | | 204 (C) Any reproductive or sexual health information that is derived, extrapolated, or |
---|
370 | 370 | | |
---|
371 | 371 | | 205 inferred, including from non-health information (such as proxy, derivative, inferred, emergent, or |
---|
372 | 372 | | |
---|
373 | 373 | | 206 algorithmic data). |
---|
374 | 374 | | |
---|
375 | 375 | | 207 (27) “Reproductive or sexual health services” means health services or products that |
---|
376 | 376 | | |
---|
377 | 377 | | 208 support or relate to a consumer's reproductive system or sexual well-being including: |
---|
378 | 378 | | 209 (A) Individual health conditions, status, diseases, or diagnoses; |
---|
379 | 379 | | 210 (B) Social, psychological, behavioral, and medical interventions; |
---|
380 | 380 | | 211 (C) Health-related surgeries or procedures including abortions; |
---|
381 | 381 | | |
---|
382 | 382 | | 212 (D) Use or purchase of medication including medications for the purposes of |
---|
383 | 383 | | |
---|
384 | 384 | | 213 abortion; |
---|
385 | 385 | | |
---|
386 | 386 | | 214 (E) Bodily functions, vital signs, symptoms, or measurements of the information |
---|
387 | 387 | | 215 described in this paragraph; |
---|
388 | 388 | | 216 (F) Diagnoses or diagnostic testing, treatment, or medication; and |
---|
389 | 389 | | 217 (G) Medical or nonmedical services related to and provided in conjunction with |
---|
390 | 390 | | 218 an abortion, including associated diagnostics, counseling, supplies, and follow-up services. |
---|
391 | 391 | | 219 (28) “Sell” or “sale” means the exchange of consumer health data for monetary or other |
---|
392 | 392 | | 220 valuable consideration. “Sell” or “sale” does not include the exchange of consumer health data 10 |
---|
393 | 393 | | 221 for monetary or other valuable consideration to a third party as an asset that is part of a merger, |
---|
394 | 394 | | |
---|
395 | 395 | | 222 acquisition, bankruptcy, or other transaction in which the third party assumes control of all or |
---|
396 | 396 | | |
---|
397 | 397 | | 223 part of the regulated entity's assets and that complies with the requirements and obligations of a |
---|
398 | 398 | | |
---|
399 | 399 | | 224 regulated entity in this act. |
---|
400 | 400 | | |
---|
401 | 401 | | 225 (29) “Share” or “sharing” means to release, disclose, disseminate, divulge, make |
---|
402 | 402 | | |
---|
403 | 403 | | 226 available, provide access to, license, or otherwise communicate orally, in writing, or by |
---|
404 | 404 | | |
---|
405 | 405 | | 227 electronic or other means, consumer health data to a third party or affiliate. The term “share” or |
---|
406 | 406 | | |
---|
407 | 407 | | 228 “sharing” does not include: |
---|
408 | 408 | | |
---|
409 | 409 | | 229 (A) The disclosure of consumer health data by a regulated entity to a processor |
---|
410 | 410 | | |
---|
411 | 411 | | 230 when such sharing is to provide goods or services in a manner consistent with the purpose for |
---|
412 | 412 | | |
---|
413 | 413 | | 231 which the consumer health data was collected and is disclosed pursuant to a binding contract |
---|
414 | 414 | | 232 between the regulated entity and the processor; |
---|
415 | 415 | | 233 (B) The disclosure of consumer health data to a third party with whom the |
---|
416 | 416 | | 234 consumer has a direct relationship when: |
---|
417 | 417 | | |
---|
418 | 418 | | 235 (i) The consumer has requested the disclosure for purpose of obtaining a |
---|
419 | 419 | | |
---|
420 | 420 | | 236 product or service from the third party; |
---|
421 | 421 | | |
---|
422 | 422 | | 237 (ii) The regulated entity maintains control and ownership of the data; and |
---|
423 | 423 | | 238 (iii) The third party uses the consumer health data only at the direction of |
---|
424 | 424 | | 239 the regulated entity and in a manner consistent with the purpose for which the consumer |
---|
425 | 425 | | 240 provided the data and consented to its release; or |
---|
426 | 426 | | 241 (C) The disclosure or transfer of personal data to a third party as an asset that is |
---|
427 | 427 | | 242 part of a merger, acquisition, bankruptcy, or other transaction in which the third party assumes 11 |
---|
428 | 428 | | 243 control of all or part of the regulated entity's assets and complies with the requirements and |
---|
429 | 429 | | |
---|
430 | 430 | | 244 obligations of a regulated entity in this act. |
---|
431 | 431 | | |
---|
432 | 432 | | 245 (30) “Third party” means an entity other than a consumer, regulated entity, processor, or |
---|
433 | 433 | | |
---|
434 | 434 | | 246 affiliate of the regulated entity. “Third party” includes a person who purchases consumer health |
---|
435 | 435 | | |
---|
436 | 436 | | 247 data. |
---|
437 | 437 | | |
---|
438 | 438 | | 248 Sec. 3. (a) A regulated entity shall maintain a consumer health data privacy policy that |
---|
439 | 439 | | |
---|
440 | 440 | | 249 clearly and conspicuously discloses: |
---|
441 | 441 | | |
---|
442 | 442 | | 250 (1) The categories of consumer health data collected; |
---|
443 | 443 | | |
---|
444 | 444 | | 251 (2) The purposes for which the consumer health data is collected, including how |
---|
445 | 445 | | |
---|
446 | 446 | | 252 the data will be used; |
---|
447 | 447 | | |
---|
448 | 448 | | 253 (3) The categories of sources from which the consumer health data is collected; |
---|
449 | 449 | | |
---|
450 | 450 | | 254 (4) The categories of consumer health data that are shared; |
---|
451 | 451 | | |
---|
452 | 452 | | 255 (5) A list of the categories of third parties and the specific affiliates with whom |
---|
453 | 453 | | |
---|
454 | 454 | | 256 the regulated entity shares the consumer health data, whether actively or passively, and the |
---|
455 | 455 | | |
---|
456 | 456 | | 257 purposes for such sharing; |
---|
457 | 457 | | |
---|
458 | 458 | | 258 (6) The length of time the regulated entity intends to retain each category of |
---|
459 | 459 | | |
---|
460 | 460 | | 259 consumer health data, or if that is not possible, the criteria used to determine that period; |
---|
461 | 461 | | |
---|
462 | 462 | | 260 provided that a regulated entity shall not retain a consumer’s consumer health data for each |
---|
463 | 463 | | |
---|
464 | 464 | | 261 disclosed purpose for which the personal information was collected for longer than is reasonably |
---|
465 | 465 | | |
---|
466 | 466 | | 262 necessary for that disclosed purpose; and |
---|
467 | 467 | | 263 (7) How a consumer can exercise the rights provided in section 5 of this act. |
---|
468 | 468 | | 264 (b) A regulated entity shall prominently publish a link to its consumer health data |
---|
469 | 469 | | 265 privacy policy on its homepage. 12 |
---|
470 | 470 | | 266 (c) It is a violation of this act for a regulated entity to contract with a processor, affiliate, |
---|
471 | 471 | | |
---|
472 | 472 | | 267 or third party to process consumer health data in a manner or for a purpose that is inconsistent |
---|
473 | 473 | | |
---|
474 | 474 | | 268 with the regulated entity's consumer health data privacy policy. |
---|
475 | 475 | | |
---|
476 | 476 | | 269 Sec. 4. (a) A regulated entity shall not collect any consumer health data unless it first |
---|
477 | 477 | | |
---|
478 | 478 | | 270 obtains consent from the consumer for such collection for a specified purpose. The request for |
---|
479 | 479 | | |
---|
480 | 480 | | 271 consent shall clearly and conspicuously disclose: |
---|
481 | 481 | | |
---|
482 | 482 | | 272 (1) The categories of consumer health data collected; |
---|
483 | 483 | | |
---|
484 | 484 | | 273 (2) The purpose of the collection of the consumer health data, including the |
---|
485 | 485 | | |
---|
486 | 486 | | 274 specific ways in which it will be used; |
---|
487 | 487 | | |
---|
488 | 488 | | 275 (3) The length of time the regulated entity intends to retain each category of |
---|
489 | 489 | | |
---|
490 | 490 | | 276 consumer health data, or if that is not possible, the criteria used to determine that period provided |
---|
491 | 491 | | 277 that a regulated entity shall not retain a consumer’s consumer health data for each disclosed |
---|
492 | 492 | | 278 purpose for which the personal information was collected for longer than is reasonably necessary |
---|
493 | 493 | | 279 for that disclosed purpose; and |
---|
494 | 494 | | |
---|
495 | 495 | | 280 (4) How the consumer can withdraw consent from future collection of the |
---|
496 | 496 | | |
---|
497 | 497 | | 281 consumer's health data. |
---|
498 | 498 | | |
---|
499 | 499 | | 282 (b) A regulated entity shall not share any consumer health data unless it first obtains |
---|
500 | 500 | | 283 consent from the consumer for such sharing for a specified purpose. This consent for sharing |
---|
501 | 501 | | 284 shall be separate and distinct from the consent obtained to collect consumer health data. The |
---|
502 | 502 | | 285 request for consent shall clearly and conspicuously disclose: |
---|
503 | 503 | | 286 (1) The categories of consumer health data shared; |
---|
504 | 504 | | 287 (2) The purpose of the sharing of the consumer health data, including the specific |
---|
505 | 505 | | 288 ways in which it will be used; 13 |
---|
506 | 506 | | 289 (3) The categories of entities with whom the consumer health data is shared; and |
---|
507 | 507 | | |
---|
508 | 508 | | 290 (4) How the consumer can withdraw consent from future sharing of the |
---|
509 | 509 | | |
---|
510 | 510 | | 291 consumer's health data. |
---|
511 | 511 | | |
---|
512 | 512 | | 292 (d) A regulated entity shall not collect, use, or share additional categories of consumer |
---|
513 | 513 | | |
---|
514 | 514 | | 293 health data not disclosed in the consumer health data privacy policy without first disclosing the |
---|
515 | 515 | | |
---|
516 | 516 | | 294 additional categories and obtaining the consumer's consent prior to the collection, use, or sharing |
---|
517 | 517 | | |
---|
518 | 518 | | 295 of such consumer health data. |
---|
519 | 519 | | |
---|
520 | 520 | | 296 (e) A regulated entity shall not collect, use, or share consumer health data for additional |
---|
521 | 521 | | |
---|
522 | 522 | | 297 purposes not disclosed in the consumer health data privacy policy without first disclosing the |
---|
523 | 523 | | |
---|
524 | 524 | | 298 additional purposes and obtaining the consumer's consent prior to the collection, use, or sharing |
---|
525 | 525 | | |
---|
526 | 526 | | 299 of such consumer health data. |
---|
527 | 527 | | 300 (f) A regulated entity’s collection, use, retention, disclosure, and sharing of a consumer’s |
---|
528 | 528 | | 301 consumer health data shall be reasonably necessary and proportionate to achieve the purposes for |
---|
529 | 529 | | 302 which the consumer health data was collected or processed, or for another disclosed purpose that |
---|
530 | 530 | | |
---|
531 | 531 | | 303 is compatible with the context in which the consumer health data was collected, and not further |
---|
532 | 532 | | |
---|
533 | 533 | | 304 processed in a manner that is incompatible with those purposes. |
---|
534 | 534 | | |
---|
535 | 535 | | 305 (g) A regulated entity that shares or otherwise discloses consumer health data with an |
---|
536 | 536 | | 306 affiliate, processor, or third party shall enter into a binding contract with the affiliate, processor, |
---|
537 | 537 | | 307 or third party that specifies how the processor, affiliate, or third party may receive, use, manage, |
---|
538 | 538 | | 308 and store the consumer health data it receives from regulated entity and contractually obligates |
---|
539 | 539 | | 309 the affiliate, processor, or third party to comply with the requirements and obligations in this act. 14 |
---|
540 | 540 | | 310 (h) It is a violation of this act for a regulated entity to contract with a processor to process |
---|
541 | 541 | | |
---|
542 | 542 | | 311 consumer health data in a manner or for a purpose that is inconsistent with the consent a |
---|
543 | 543 | | |
---|
544 | 544 | | 312 consumer has given for the collection, use, or sharing of data. |
---|
545 | 545 | | |
---|
546 | 546 | | 313 (i) A regulated entity shall not unlawfully discriminate against a consumer for exercising |
---|
547 | 547 | | |
---|
548 | 548 | | 314 any rights included in this act. |
---|
549 | 549 | | |
---|
550 | 550 | | 315 Sec. 5. (a) A consumer has the right to confirm whether a regulated entity is collecting, |
---|
551 | 551 | | |
---|
552 | 552 | | 316 sharing, or selling consumer health data concerning the consumer. The regulated entity shall |
---|
553 | 553 | | |
---|
554 | 554 | | 317 provide the consumer with access to such data as expeditiously as possible and without |
---|
555 | 555 | | |
---|
556 | 556 | | 318 unreasonable delay. This information shall include a list of all third parties and affiliates with |
---|
557 | 557 | | |
---|
558 | 558 | | 319 whom the regulated entity has shared or sold the consumer health data, and an active email |
---|
559 | 559 | | |
---|
560 | 560 | | 320 address or other online mechanism that the consumer may use to contact these third parties. |
---|
561 | 561 | | 321 (b) A consumer has the right to withdraw consent from the regulated entity's collection |
---|
562 | 562 | | 322 and sharing of consumer health data related to the consumer. |
---|
563 | 563 | | 323 (c) A consumer has the right to have consumer health data related to the consumer |
---|
564 | 564 | | |
---|
565 | 565 | | 324 deleted from the database of the regulated entity and any other entity to which the regulated |
---|
566 | 566 | | |
---|
567 | 567 | | 325 entity has shared or sold the consumer health data. The consumer may exercise this right by |
---|
568 | 568 | | |
---|
569 | 569 | | 326 requesting the deletion pursuant to subsection (g) of this section. |
---|
570 | 570 | | 327 (d) A regulated entity that receives a consumer's request to delete any consumer health |
---|
571 | 571 | | 328 data concerning the consumer shall: |
---|
572 | 572 | | 329 (1) Delete the consumer health data from its records, including all parts of the |
---|
573 | 573 | | 330 regulated entity's network, including archived or backup systems; and |
---|
574 | 574 | | 331 (2) Notify all affiliates, processors, and third parties with whom the regulated |
---|
575 | 575 | | 332 entity has shared or sold consumer health data of the deletion request. 15 |
---|
576 | 576 | | 333 (e) Each affiliate, processor, and third party that receives notice of a consumer's deletion |
---|
577 | 577 | | |
---|
578 | 578 | | 334 request shall honor the consumer's deletion request and delete the consumer health data from its |
---|
579 | 579 | | |
---|
580 | 580 | | 335 records according to the same requirements applicable to a regulated entity. |
---|
581 | 581 | | |
---|
582 | 582 | | 336 (f) If consumer health data that a consumer requests to be deleted is stored on archived or |
---|
583 | 583 | | |
---|
584 | 584 | | 337 backup systems, the request for deletion may be delayed for up to 6 months from the |
---|
585 | 585 | | |
---|
586 | 586 | | 338 authentication of the deletion request to enable restoration of the archived or backup systems. |
---|
587 | 587 | | |
---|
588 | 588 | | 339 (g) A consumer may exercise the rights set forth in this section by submitting a request, at |
---|
589 | 589 | | |
---|
590 | 590 | | 340 any time, to a regulated entity. Such a request may be made by a secure and reliable means |
---|
591 | 591 | | |
---|
592 | 592 | | 341 established by the regulated entity and clearly and conspicuously described in its consumer |
---|
593 | 593 | | |
---|
594 | 594 | | 342 health data privacy policy. The method shall take into account the ways in which consumers |
---|
595 | 595 | | |
---|
596 | 596 | | 343 normally interact with the regulated entity, the need for secure and reliable communication of |
---|
597 | 597 | | 344 such requests, and the ability of the regulated entity to authenticate the identity of the consumer |
---|
598 | 598 | | 345 making the request. A regulated entity shall not require a consumer to create a new account to |
---|
599 | 599 | | 346 exercise consumer rights under this section but may require a consumer to use an existing |
---|
600 | 600 | | |
---|
601 | 601 | | 347 account. |
---|
602 | 602 | | |
---|
603 | 603 | | 348 (h) If a regulated entity is unable to authenticate the request using commercially |
---|
604 | 604 | | |
---|
605 | 605 | | 349 reasonable efforts, the regulated entity is not required to comply with a deletion request under |
---|
606 | 606 | | 350 this section and may request that the consumer provide additional information reasonably |
---|
607 | 607 | | 351 necessary to authenticate the consumer and the consumer's request. |
---|
608 | 608 | | 352 (i) The regulated entity shall provide information in response to a consumer request at |
---|
609 | 609 | | 353 least twice during any 12-month period upon request of the consumer and without charge to the |
---|
610 | 610 | | 354 consumer. If requests from a consumer are manifestly unfounded, excessive, or repetitive, the |
---|
611 | 611 | | 355 regulated entity may charge the consumer a reasonable fee to cover the administrative costs of 16 |
---|
612 | 612 | | 356 complying with the request or decline to act on the request. The regulated entity shall bear the |
---|
613 | 613 | | |
---|
614 | 614 | | 357 burden of demonstrating the manifestly unfounded, excessive, or repetitive nature of the request. |
---|
615 | 615 | | |
---|
616 | 616 | | 358 (j) A regulated entity shall comply with a deletion request without undue delay, and in all |
---|
617 | 617 | | |
---|
618 | 618 | | 359 cases within 45 days of receipt of the request. A regulated entity shall promptly take steps to |
---|
619 | 619 | | |
---|
620 | 620 | | 360 authenticate a consumer request, but these steps shall not extend the regulated entity's duty to |
---|
621 | 621 | | |
---|
622 | 622 | | 361 comply with the consumer's request within 45 days of receipt. The regulated entity may extend |
---|
623 | 623 | | |
---|
624 | 624 | | 362 the response period once for 45 additional days when reasonably necessary, taking into account |
---|
625 | 625 | | |
---|
626 | 626 | | 363 the complexity and number of the consumer's requests, if the regulated entity informs the |
---|
627 | 627 | | |
---|
628 | 628 | | 364 consumer of any such extension within the initial 45-day response period, together with the |
---|
629 | 629 | | |
---|
630 | 630 | | 365 reason for the extension. |
---|
631 | 631 | | |
---|
632 | 632 | | 366 (k) A regulated entity shall establish a process for a consumer to appeal the regulated |
---|
633 | 633 | | 367 entity's refusal to take action on a request within a reasonable period of time after the consumer's |
---|
634 | 634 | | 368 receipt of the decision. The availability of the appeal process shall be clearly and conspicuously |
---|
635 | 635 | | 369 included in the regulated entity’s consumer health data privacy policy. Within 45 days of receipt |
---|
636 | 636 | | |
---|
637 | 637 | | 370 of an appeal, a regulated entity shall inform the consumer in writing of any action taken or not |
---|
638 | 638 | | |
---|
639 | 639 | | 371 taken in response to the appeal, including a written explanation of the reasons for the decisions. |
---|
640 | 640 | | |
---|
641 | 641 | | 372 If the appeal is denied, the regulated entity shall also provide the consumer with an online |
---|
642 | 642 | | 373 mechanism, if available, or other method through which the consumer may contact the attorney |
---|
643 | 643 | | 374 general to submit a complaint. |
---|
644 | 644 | | |
---|
645 | 645 | | 375 (l) If a regulated entity dissolves or terminates its operations, the regulated entity shall |
---|
646 | 646 | | |
---|
647 | 647 | | 376 delete all consumer health data from its records, including any archived or back-up systems and |
---|
648 | 648 | | |
---|
649 | 649 | | 377 provide each consumer whose data has been shared with or sold to a processor, affiliate, or third 17 |
---|
650 | 650 | | 378 party with a notice of how the consumer can contact the processors, affiliates, or third parties to |
---|
651 | 651 | | |
---|
652 | 652 | | 379 request deletion of their information. |
---|
653 | 653 | | |
---|
654 | 654 | | 380 Sec. 6. A regulated entity shall: |
---|
655 | 655 | | |
---|
656 | 656 | | 381 (a) Restrict access to consumer health data by the employees, affiliates, processors, and |
---|
657 | 657 | | 382 third parties of such regulated entity to only those employees, affiliates, processors, and third |
---|
658 | 658 | | 383 parties for which access is necessary to further the purposes for which the consumer provided |
---|
659 | 659 | | |
---|
660 | 660 | | 384 consent or where necessary to provide a product or service that the consumer to whom such |
---|
661 | 661 | | |
---|
662 | 662 | | 385 consumer health data relates has requested from such regulated entity; and |
---|
663 | 663 | | |
---|
664 | 664 | | 386 (b) Establish, implement, and maintain administrative, technical, and physical data |
---|
665 | 665 | | |
---|
666 | 666 | | 387 security practices that, at a minimum, satisfy reasonable standard of care within the regulated |
---|
667 | 667 | | |
---|
668 | 668 | | 388 entity's industry to protect the confidentiality, integrity, and accessibility of consumer health data |
---|
669 | 669 | | |
---|
670 | 670 | | 389 appropriate to the volume and nature of the consumer health data at issue. |
---|
671 | 671 | | |
---|
672 | 672 | | 390 Sec. 7. (a) A processor, affiliate, or third party may receive, use, or process consumer |
---|
673 | 673 | | |
---|
674 | 674 | | 391 health data only pursuant to a binding contract with the regulated entity that specifies how the |
---|
675 | 675 | | |
---|
676 | 676 | | 392 processor, affiliate, or third party may receive, use, manage, and store the consumer health data it |
---|
677 | 677 | | |
---|
678 | 678 | | 393 receives from regulated entity. |
---|
679 | 679 | | |
---|
680 | 680 | | 394 (b) A processor, affiliate, or third party shall not further share or sell consumer health |
---|
681 | 681 | | 395 data it has received from a regulated entity with any other person or entity. |
---|
682 | 682 | | |
---|
683 | 683 | | 396 (c) A processor, affiliate, or third party shall assist the regulated entity by appropriate |
---|
684 | 684 | | 397 technical and organizational measures, insofar as this is possible, in fulfilling the regulated |
---|
685 | 685 | | 398 entity's obligations under this act. |
---|
686 | 686 | | |
---|
687 | 687 | | 399 (d) If a processor, affiliate or third party fails to adhere to the regulated entity's |
---|
688 | 688 | | |
---|
689 | 689 | | 400 contractual requirements or receives, uses, manages, or stores consumer health data in a manner 18 |
---|
690 | 690 | | 401 that is outside the scope of the contract with the regulated entity, the processor, affiliate, or third |
---|
691 | 691 | | |
---|
692 | 692 | | 402 party shall be considered a regulated entity with regard to such data and shall be subject to all the |
---|
693 | 693 | | |
---|
694 | 694 | | 403 requirements of this act. |
---|
695 | 695 | | |
---|
696 | 696 | | 404 Sec. 8. (a) It is unlawful for any person to sell or offer to sell consumer health data |
---|
697 | 697 | | |
---|
698 | 698 | | 405 related to a consumer without first obtaining valid authorization from the consumer. This |
---|
699 | 699 | | |
---|
700 | 700 | | 406 authorization shall be separate and distinct from the consent obtained to collect or share |
---|
701 | 701 | | |
---|
702 | 702 | | 407 consumer health data required under section 4 of this act. |
---|
703 | 703 | | |
---|
704 | 704 | | 408 (b) A valid authorization to sell consumer health data shall be a written or electronic |
---|
705 | 705 | | 409 document consistent with this section. It shall be in plain language and contain the following: |
---|
706 | 706 | | |
---|
707 | 707 | | 410 (1) The specific consumer health data concerning the consumer that the person |
---|
708 | 708 | | |
---|
709 | 709 | | 411 intends to sell; |
---|
710 | 710 | | |
---|
711 | 711 | | 412 (2) The name and contact information of the person selling the consumer health |
---|
712 | 712 | | |
---|
713 | 713 | | 413 data; |
---|
714 | 714 | | |
---|
715 | 715 | | 414 (3) The name and contact information of the regulated entity that originally |
---|
716 | 716 | | |
---|
717 | 717 | | 415 collected the consumer health data; |
---|
718 | 718 | | |
---|
719 | 719 | | 416 (4) The name and contact information of the person purchasing the consumer |
---|
720 | 720 | | 417 health data from the seller identified in paragraph (2) of this subsection; |
---|
721 | 721 | | |
---|
722 | 722 | | 418 (5) A description of the purpose for the sale, including how the consumer health |
---|
723 | 723 | | |
---|
724 | 724 | | 419 data will be gathered and how it will be used by the purchaser identified in paragraph (4) of this |
---|
725 | 725 | | |
---|
726 | 726 | | 420 subsection when sold; |
---|
727 | 727 | | |
---|
728 | 728 | | 421 (6) A statement that the provision of goods or services may not be conditioned on |
---|
729 | 729 | | |
---|
730 | 730 | | 422 the consumer signing the valid authorization; 19 |
---|
731 | 731 | | 423 (7) A statement that the consumer has a right to revoke the valid authorization at |
---|
732 | 732 | | |
---|
733 | 733 | | 424 any time and a description of how to submit a revocation; |
---|
734 | 734 | | |
---|
735 | 735 | | 425 (8) An expiration date for the valid authorization that is no later than one year |
---|
736 | 736 | | |
---|
737 | 737 | | 426 after the date the consumer signs the valid authorization; and |
---|
738 | 738 | | |
---|
739 | 739 | | 427 (9) The signature or e-signature of the consumer and date. |
---|
740 | 740 | | |
---|
741 | 741 | | 428 (c) An authorization shall be invalid if it contains any of the following defects: |
---|
742 | 742 | | |
---|
743 | 743 | | 429 (1) The expiration date has passed; |
---|
744 | 744 | | |
---|
745 | 745 | | 430 (2) The authorization does not contain all the information required under this |
---|
746 | 746 | | |
---|
747 | 747 | | 431 section; |
---|
748 | 748 | | |
---|
749 | 749 | | 432 (3) The consumer has revoked the authorization; |
---|
750 | 750 | | |
---|
751 | 751 | | 433 (4) The authorization has been combined with other documents to create a |
---|
752 | 752 | | 434 compound authorization; or |
---|
753 | 753 | | |
---|
754 | 754 | | 435 (5) The provision of goods or services is conditioned on the consumer signing the |
---|
755 | 755 | | |
---|
756 | 756 | | 436 authorization. |
---|
757 | 757 | | |
---|
758 | 758 | | 437 (d) The seller shall obtain the valid authorization from the consumer and provide copies |
---|
759 | 759 | | |
---|
760 | 760 | | 438 to the consumer and the purchaser. |
---|
761 | 761 | | |
---|
762 | 762 | | 439 (e) The seller and purchaser of consumer health data shall retain a copy of all valid |
---|
763 | 763 | | |
---|
764 | 764 | | 440 authorizations for sale of consumer health data for 6 years from the date of the consumer’s |
---|
765 | 765 | | |
---|
766 | 766 | | 441 signature or the date when it was last in effect, whichever is later. |
---|
767 | 767 | | |
---|
768 | 768 | | 442 (f) A person may sell consumer health data only pursuant to a binding contract between |
---|
769 | 769 | | 443 the person selling the consumer health data and the person purchasing the consumer health data |
---|
770 | 770 | | 444 that identifies the purpose and use of the consumer health data and contractually obligates the 20 |
---|
771 | 771 | | 445 person purchasing the consumer health data to comply with the applicable requirements and |
---|
772 | 772 | | |
---|
773 | 773 | | 446 obligations in this act. |
---|
774 | 774 | | |
---|
775 | 775 | | 447 (g) The person who purchases consumer health data shall only use, retain, and share a |
---|
776 | 776 | | |
---|
777 | 777 | | 448 consumer’s health data in a manner compatible with purpose and use identified in a valid |
---|
778 | 778 | | |
---|
779 | 779 | | 449 authorization from a consumer. |
---|
780 | 780 | | |
---|
781 | 781 | | 450 Sec. 9. It is unlawful for any person to implement a geofence around an entity that |
---|
782 | 782 | | |
---|
783 | 783 | | 451 provides in-person health care services where the geofence is used to: |
---|
784 | 784 | | |
---|
785 | 785 | | 452 (a) Identify or track consumers seeking health care services; |
---|
786 | 786 | | |
---|
787 | 787 | | 453 (b) Collect consumer health data; or |
---|
788 | 788 | | |
---|
789 | 789 | | 454 (c) Send notifications, messages, or advertisements to consumers related to their |
---|
790 | 790 | | |
---|
791 | 791 | | 455 consumer health data or health care services. |
---|
792 | 792 | | |
---|
793 | 793 | | 456 Sec. 10. A violation of this act is an unfair and deceptive trade practice pursuant to D.C. |
---|
794 | 794 | | 457 Official Code § 28-3904. |
---|
795 | 795 | | |
---|
796 | 796 | | 458 Sec. 11. (a) This chapter does not apply to: |
---|
797 | 797 | | |
---|
798 | 798 | | 459 (1) Information that meets the definition of: |
---|
799 | 799 | | |
---|
800 | 800 | | 460 (A) Health information protected under the federal Health Insurance |
---|
801 | 801 | | |
---|
802 | 802 | | 461 Portability and Accountability Act of 1996 (“HIPAA”), approved August 21, 1996 (Pub. L. 104- |
---|
803 | 803 | | |
---|
804 | 804 | | 462 191; 110 Stat. 1936), and related regulations; |
---|
805 | 805 | | |
---|
806 | 806 | | 463 (B) Patient identifying information collected, used, or disclosed in |
---|
807 | 807 | | |
---|
808 | 808 | | 464 accordance with 42 C.F.R. Part 2 and section 131 of the ADAMHA Reorganization Act, |
---|
809 | 809 | | 465 approved July 10, 1992 (106 Stat. 368: 42 U.S.C. § 290dd- 2); |
---|
810 | 810 | | |
---|
811 | 811 | | 466 (C) The following research-related information: 21 |
---|
812 | 812 | | 467 (i) Identifiable private information under the federal policy for the |
---|
813 | 813 | | |
---|
814 | 814 | | 468 protection of human subjects pursuant to 45 C.F.R. Part 46; |
---|
815 | 815 | | |
---|
816 | 816 | | 469 (ii) Identifiable private information that is otherwise information |
---|
817 | 817 | | |
---|
818 | 818 | | 470 collected as part of human subjects research pursuant to the good clinical practice guidelines |
---|
819 | 819 | | |
---|
820 | 820 | | 471 issued by the international council for harmonization; |
---|
821 | 821 | | |
---|
822 | 822 | | 472 (iii) Information made private for the protection of human subjects |
---|
823 | 823 | | |
---|
824 | 824 | | 473 under 21 C.F.R. Parts 50 and 56; or |
---|
825 | 825 | | |
---|
826 | 826 | | 474 (iv) Personal data used or shared in research conducted in |
---|
827 | 827 | | |
---|
828 | 828 | | 475 accordance with one or more of the requirements in this paragraph; |
---|
829 | 829 | | |
---|
830 | 830 | | 476 (D) Information or documents created for purposes of the federal Health |
---|
831 | 831 | | |
---|
832 | 832 | | 477 Care Quality Improvement Act of 1986, approved November 14, 1986 (100 Stat. 3784; 42 |
---|
833 | 833 | | |
---|
834 | 834 | | 478 U.S.C. § 11101), and related regulations; |
---|
835 | 835 | | |
---|
836 | 836 | | 479 (E) Patient safety work product under 42 C.F.R. Part 3 and section 2 of the |
---|
837 | 837 | | |
---|
838 | 838 | | 480 Patient Safety and Quality Improvement Act of 2005, approved July 29, 2005 (119 Stat. 424; 42 |
---|
839 | 839 | | |
---|
840 | 840 | | 481 U.S.C.§§ 299b-21 - 299b-26); |
---|
841 | 841 | | |
---|
842 | 842 | | 482 (F) Information that is deidentified in accordance with 45 C.F.R. Part 164, |
---|
843 | 843 | | 483 and derived from any of the health care-related information listed in subsection (a)(1) of this |
---|
844 | 844 | | 484 section; |
---|
845 | 845 | | |
---|
846 | 846 | | 485 (2) Information originating from, and intermingled to be indistinguishable with, |
---|
847 | 847 | | |
---|
848 | 848 | | 486 information under paragraph (1) of this subsection that is maintained by: |
---|
849 | 849 | | |
---|
850 | 850 | | 487 (A) A covered entity or business associate as defined by HIPAA and |
---|
851 | 851 | | |
---|
852 | 852 | | 488 related regulations; 22 |
---|
853 | 853 | | 489 (B) A program or a qualified service organization under 42 C.F.R. Part 2 |
---|
854 | 854 | | |
---|
855 | 855 | | 490 and section 131 of the ADAMHA Reorganization Act, approved July 10, 1992 (106 Stat. 368: 42 |
---|
856 | 856 | | |
---|
857 | 857 | | 491 U.S.C. § 290dd- 2); and |
---|
858 | 858 | | |
---|
859 | 859 | | 492 (3) Information used only for public health activities and purposes as described in |
---|
860 | 860 | | |
---|
861 | 861 | | 493 45 C.F.R. §. 164.512 or that is part of a limited data set that is used, disclosed, and maintained in |
---|
862 | 862 | | |
---|
863 | 863 | | 494 the manner required by 45 C.F.R. § 164.514; |
---|
864 | 864 | | |
---|
865 | 865 | | 495 (b) Personal information that is governed by and collected, used, or disclosed pursuant to |
---|
866 | 866 | | 496 the following regulations, parts, titles, or acts, is exempt from this chapter: |
---|
867 | 867 | | |
---|
868 | 868 | | 497 (1) The Gramm- Leach-Bliley Act, approved November 12, 1999 (113 Stat. 1338; |
---|
869 | 869 | | |
---|
870 | 870 | | 498 15 U.S.C. § 6801 et seq..) and implementing regulations; |
---|
871 | 871 | | |
---|
872 | 872 | | 499 (2) Part C of Title XI of the Social Security Act, approved August 21, 1996 (110 |
---|
873 | 873 | | |
---|
874 | 874 | | 500 Stat. 1936; 42 U.S.C. § 1320d et seq.); |
---|
875 | 875 | | |
---|
876 | 876 | | 501 (3) The Fair Credit Reporting Act, approved May 29, 1968 (82 Stat. 146; 15 |
---|
877 | 877 | | |
---|
878 | 878 | | 502 U.S.C. § 1681 et seq.); |
---|
879 | 879 | | |
---|
880 | 880 | | 503 (4) The Family Educational Rights and Privacy Act, approved August 21, 1974 |
---|
881 | 881 | | |
---|
882 | 882 | | 504 (88 Stat. 57; (20 U.S.C. § 1232g) and 34 C.F.R. Part 99. |
---|
883 | 883 | | |
---|
884 | 884 | | 505 (c) The obligations imposed on regulated entities and processors under this act do not |
---|
885 | 885 | | |
---|
886 | 886 | | 506 restrict a regulated entity's or processor's ability to collect, use, or disclose consumer health data |
---|
887 | 887 | | |
---|
888 | 888 | | 507 to prevent, detect, protect against, or respond to security incidents, identity, theft, fraud, |
---|
889 | 889 | | |
---|
890 | 890 | | 508 harassment, malicious or deceptive activities, or any activity that is illegal under District or |
---|
891 | 891 | | |
---|
892 | 892 | | 509 federal law; preserve the integrity or security of systems; or investigate, |
---|
893 | 893 | | |
---|
894 | 894 | | 510 report, or prosecute those responsible for any such action that is illegal under District or federal |
---|
895 | 895 | | |
---|
896 | 896 | | 511 law. 23 |
---|
897 | 897 | | 512 (d) If a regulated entity or processor processes consumer health data pursuant to |
---|
898 | 898 | | |
---|
899 | 899 | | 513 subsection (c) of this section, such entity bears the burden of demonstrating that such processing |
---|
900 | 900 | | |
---|
901 | 901 | | 514 qualifies for the exemption and complies with the requirements of this section. |
---|
902 | 902 | | |
---|
903 | 903 | | 515 Sec. 12. D.C. Official Code § 28-3904 is amended as follows: |
---|
904 | 904 | | |
---|
905 | 905 | | 516 (a) Subsection (kk) is amended by striking the word “or” at the end. |
---|
906 | 906 | | |
---|
907 | 907 | | 517 (b) Subsection (ll) is amended by striking the period at the end and inserting the phrase “; |
---|
908 | 908 | | |
---|
909 | 909 | | 518 or” in its place. |
---|
910 | 910 | | |
---|
911 | 911 | | 519 (c) A new subsection (mm) is added to read as follows: |
---|
912 | 912 | | |
---|
913 | 913 | | 520 “(mm) violate any provision of the Consumer Health Information Privacy Protection Act |
---|
914 | 914 | | |
---|
915 | 915 | | 521 of 2024.”. |
---|
916 | 916 | | |
---|
917 | 917 | | 522 Sec. 13. Fiscal impact statement. |
---|
918 | 918 | | |
---|
919 | 919 | | 523 The Council adopts the fiscal impact statement in the committee report as the fiscal |
---|
920 | 920 | | 524 impact statement required by section 4a of the General Legislative Procedures Act of 1975, |
---|
921 | 921 | | 525 approved October 16, 2006 (120 Stat. 2038; D.C. Official Code § 1-301.47a). |
---|
922 | 922 | | |
---|
923 | 923 | | 526 Sec. 14. Effective date. |
---|
924 | 924 | | |
---|
925 | 925 | | 527 This act shall take effect following approval by the Mayor (or in the event of a veto by |
---|
926 | 926 | | |
---|
927 | 927 | | 528 the Mayor, action by the Council to override the veto), a 30-day period of congressional review |
---|
928 | 928 | | |
---|
929 | 929 | | 529 as provided in section 602(c)(1) of the District of Columbia Home Rule Act, approved December |
---|
930 | 930 | | |
---|
931 | 931 | | 530 24, 1973 (87 Stat. 813; D.C. Official Code § 1-206.02(c)(1)), and publication in the District of |
---|
932 | 932 | | |
---|
933 | 933 | | 531 Columbia Register. |
---|
934 | 934 | | |
---|
935 | 935 | | 532 1350 Pennsylvania Avenue, N.W., Suite 409, Washington, D.C. 20004 Phone: (202) 724-5524 Email: megan.browder@dc.gov |
---|
936 | 936 | | |
---|
937 | 937 | | GOVERNMENT OF THE DISTRICT OF COLUMBIA |
---|
938 | 938 | | OFFICE OF THE ATTORNEY GENERAL |
---|
939 | 939 | | |
---|
940 | 940 | | |
---|
941 | 941 | | BRIAN L. SCHWALB |
---|
942 | 942 | | ATTORNEY GENERAL |
---|
943 | 943 | | Legal Counsel Division |
---|
944 | 944 | | |
---|
945 | 945 | | |
---|
946 | 946 | | |
---|
947 | 947 | | MEMORANDUM |
---|
948 | 948 | | |
---|
949 | 949 | | TO: |
---|
950 | 950 | | FROM: |
---|
951 | 951 | | |
---|
952 | 952 | | DATE: |
---|
953 | 953 | | Candyce Phoenix |
---|
954 | 954 | | Deputy Attorney General for Policy and Legislative Affairs |
---|
955 | 955 | | Megan D. Browder |
---|
956 | 956 | | Deputy Attorney General |
---|
957 | 957 | | Legal Counsel Division |
---|
958 | 958 | | |
---|
959 | 959 | | July 11, 2024 |
---|
960 | 960 | | |
---|
961 | 961 | | SUBJECT: Legal Sufficiency Review of Draft Bill the "Consumer Health |
---|
962 | 962 | | Information Privacy Protection Act (CHIPPA) of 2024” |
---|
963 | 963 | | (AE-24-294) |
---|
964 | 964 | | |
---|
965 | 965 | | |
---|
966 | 966 | | |
---|
967 | 967 | | |
---|
968 | 968 | | This is to Certify that this Office has reviewed the above- referenced |
---|
969 | 969 | | legislation and has found it to be legally sufficient. If you have any questions |
---|
970 | 970 | | regarding this certification, please do not hesitate to contact me at (202) 724-5524. |
---|
971 | 971 | | |
---|
972 | 972 | | |
---|
973 | 973 | | |
---|
974 | 974 | | |
---|
975 | 975 | | Megan D. Browder 1350 Pennsylvania Avenue, N.W., Suite 409, Washington, D.C. 20004 Phone (202) 724-5524 Email: megan.browder@dc.gov |
---|
976 | 976 | | |
---|
977 | 977 | | GOVERNMENT OF THE DISTRICT OF COLUMBIA |
---|
978 | 978 | | O |
---|
979 | 979 | | FFICE OF THE ATTORNEY GENERAL |
---|
980 | 980 | | Brian L. Schwalb PRIVILEGED AND CONFIDENTIAL |
---|
981 | 981 | | Attorney General ATTORNEY-CLIENT COMMUNICATION |
---|
982 | 982 | | |
---|
983 | 983 | | Legal Counsel Division |
---|
984 | 984 | | |
---|
985 | 985 | | |
---|
986 | 986 | | MEMORANDUM |
---|
987 | 987 | | |
---|
988 | 988 | | TO: Candyce Phoenix |
---|
989 | 989 | | Deputy Attorney General for Policy and Legislative Affairs |
---|
990 | 990 | | |
---|
991 | 991 | | FROM: Megan D. Browder |
---|
992 | 992 | | Deputy Attorney General |
---|
993 | 993 | | Legal Counsel Division |
---|
994 | 994 | | |
---|
995 | 995 | | DATE: July 11, 2024 |
---|
996 | 996 | | |
---|
997 | 997 | | SUBJECT: Legal Sufficiency Review of Draft Bill the “Consumer Health Information Privacy |
---|
998 | 998 | | Protection Act (CHIPPA) of 2024” |
---|
999 | 999 | | (AE-24-294) |
---|
1000 | 1000 | | |
---|
1001 | 1001 | | |
---|
1002 | 1002 | | This memorandum responds to your request that the Legal Counsel Division conduct a legal |
---|
1003 | 1003 | | sufficiency review of the “Consumer Health Information Privacy Protection Act (CHIPPA) of |
---|
1004 | 1004 | | 2024 (“bill”). |
---|
1005 | 1005 | | |
---|
1006 | 1006 | | The bill would establish privacy protections for consumer health data provided to entities that are |
---|
1007 | 1007 | | not covered by the federal Health Insurance Portability and Accountability Act of 1996 |
---|
1008 | 1008 | | (“HIPAA”), approved August 21, 1996 (Pub. L. 104-191; 110 Stat. 1936). Among other things, it |
---|
1009 | 1009 | | would require regulated entities to establish and make available a consumer health data privacy |
---|
1010 | 1010 | | policy governing the collection, use, sharing, and sale of consumer health data. It would also |
---|
1011 | 1011 | | require these entities to obtain the consumer’s informed consent to the collection and sharing |
---|
1012 | 1012 | | of consumer health data and require additional protections and consumer authorizations for the |
---|
1013 | 1013 | | sale of protected data. |
---|
1014 | 1014 | | |
---|
1015 | 1015 | | The Legal Counsel Division worked with OAG’s Office of Consumer Protection to develop and |
---|
1016 | 1016 | | draft the bill, and the attached version is legally sufficient. |
---|
1017 | 1017 | | 1 |
---|
1018 | 1018 | | I have therefore provided a Certificate |
---|
1019 | 1019 | | of Legal Sufficiency, which you should include in your legislative package when you submit it to |
---|
1020 | 1020 | | the Council. Please also remember that you must obtain a fiscal impact statement from the |
---|
1021 | 1021 | | Chief Financial Officer to accompany the legislation. |
---|
1022 | 1022 | | |
---|
1023 | 1023 | | 1 |
---|
1024 | 1024 | | We have advised further clarity be added to the bill’s section 4(i), which prohibits a regulated entity from |
---|
1025 | 1025 | | “unlawfully discriminat[ing] against a consumer for exercising any rights” included in the law. It is unclear what |
---|
1026 | 1026 | | unlawful discrimination means in this context. We will continue to work with OCP to draft amending language. |
---|
1027 | 1027 | | 2 |
---|
1028 | 1028 | | If you have any questions about this memorandum, please contact Laurie Ensworth, Senior |
---|
1029 | 1029 | | Assistant Attorney General, Legal Counsel Division, at (202) 724-5537, or me at (202) 724-5524. |
---|
1030 | 1030 | | |
---|
1031 | 1031 | | MDB/lae |
---|