1 | 1 | | BILL AS INTRODUCED S.74 |
---|
2 | 2 | | 2025 Page 1 of 30 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | VT LEG #379087 v.1 |
---|
6 | 6 | | S.74 1 |
---|
7 | 7 | | Introduced by Senators Lyons, Gulick and Harrison 2 |
---|
8 | 8 | | Referred to Committee on 3 |
---|
9 | 9 | | Date: 4 |
---|
10 | 10 | | Subject: Health; health information; data privacy 5 |
---|
11 | 11 | | Statement of purpose of bill as introduced: This bill proposes to regulate the 6 |
---|
12 | 12 | | collection, sharing, and selling of consumer health data in Vermont. 7 |
---|
13 | 13 | | An act relating to the collection, sharing, and selling of consumer health 8 |
---|
14 | 14 | | data 9 |
---|
15 | 15 | | It is hereby enacted by the General Assembly of the State of Vermont: 10 |
---|
16 | 16 | | Sec. 1. 18 V.S.A. chapter 42B is amended to read: 11 |
---|
17 | 17 | | 42B. HEALTH CARE PRIVACY 12 |
---|
18 | 18 | | Subchapter 1. Disclosure of Protected Health Information 13 |
---|
19 | 19 | | § 1881. DISCLOSURE OF PROTECTED HEALTH INFORMATION 14 |
---|
20 | 20 | | PROHIBITED 15 |
---|
21 | 21 | | * * * 16 |
---|
22 | 22 | | Subchapter 2. Vermont My Health My Data Act 17 |
---|
23 | 23 | | § 1891a. SHORT TITLE 18 |
---|
24 | 24 | | This subchapter shall be known and may be cited as the “Vermont My 19 |
---|
25 | 25 | | Health My Data Act.” 20 BILL AS INTRODUCED S.74 |
---|
26 | 26 | | 2025 Page 2 of 30 |
---|
27 | 27 | | |
---|
28 | 28 | | |
---|
29 | 29 | | VT LEG #379087 v.1 |
---|
30 | 30 | | § 1891b. FINDINGS AND INTENT 1 |
---|
31 | 31 | | (a) Findings. The General Assembly finds that: 2 |
---|
32 | 32 | | (1) The residents of Vermont regard their privacy as a fundamental right 3 |
---|
33 | 33 | | and an essential element of their individual freedom. Fundamental privacy 4 |
---|
34 | 34 | | rights have long been and continue to be integral to protecting Vermonters and 5 |
---|
35 | 35 | | to safeguarding our democratic republic. 6 |
---|
36 | 36 | | (2) Information related to an individual’s health conditions or attempts 7 |
---|
37 | 37 | | to obtain health care services is among the most personal and sensitive 8 |
---|
38 | 38 | | categories of data collected. Vermonters expect that their health data is 9 |
---|
39 | 39 | | protected under laws like the Health Insurance Portability and Accountability 10 |
---|
40 | 40 | | Act of 1996 (HIPAA). However, HIPAA only covers health data collected by 11 |
---|
41 | 41 | | specific health care entities, including most health care providers. Health data 12 |
---|
42 | 42 | | collected by noncovered entities, including certain applications and websites, 13 |
---|
43 | 43 | | are not afforded the same protections. This act works to close the gap between 14 |
---|
44 | 44 | | consumer knowledge and industry practice by providing stronger privacy 15 |
---|
45 | 45 | | protections for all of Vermont consumers’ health data. 16 |
---|
46 | 46 | | (b) Intent. By enacting this subchapter, it is the intent of the General 17 |
---|
47 | 47 | | Assembly to provide heightened protections for Vermonters’ health data by: 18 |
---|
48 | 48 | | (1) requiring additional disclosures and consumer consent regarding the 19 |
---|
49 | 49 | | collection, sharing, and use of their health data; 20 BILL AS INTRODUCED S.74 |
---|
50 | 50 | | 2025 Page 3 of 30 |
---|
51 | 51 | | |
---|
52 | 52 | | |
---|
53 | 53 | | VT LEG #379087 v.1 |
---|
54 | 54 | | (2) empowering consumers with the right to have their health data 1 |
---|
55 | 55 | | deleted; 2 |
---|
56 | 56 | | (3) prohibiting the selling of consumer health data without valid 3 |
---|
57 | 57 | | authorization signed by the consumer; and 4 |
---|
58 | 58 | | (4) making it unlawful to utilize a geofence around a facility that 5 |
---|
59 | 59 | | provides health care services. 6 |
---|
60 | 60 | | § 1891c. DEFINITIONS 7 |
---|
61 | 61 | | As used in this subchapter: 8 |
---|
62 | 62 | | (1) “Abortion” means any medical treatment intended to induce the 9 |
---|
63 | 63 | | termination of, or to terminate, a clinically diagnosable pregnancy except for 10 |
---|
64 | 64 | | the purpose of producing a live birth. 11 |
---|
65 | 65 | | (2) “Affiliate” means a legal entity that shares common branding with 12 |
---|
66 | 66 | | another legal entity and controls, is controlled by, or is under common control 13 |
---|
67 | 67 | | with another legal entity. For purposes of this definition, “control” or 14 |
---|
68 | 68 | | “controlled” means any one or more of the following: 15 |
---|
69 | 69 | | (A) ownership of, or the power to vote, more than 50 percent of the 16 |
---|
70 | 70 | | outstanding shares of any class of voting security of a company; 17 |
---|
71 | 71 | | (B) control in any manner over the election of a majority of the 18 |
---|
72 | 72 | | directors or of individuals exercising similar functions; or 19 |
---|
73 | 73 | | (C) the power to exercise controlling influence over the management 20 |
---|
74 | 74 | | of a company. 21 BILL AS INTRODUCED S.74 |
---|
75 | 75 | | 2025 Page 4 of 30 |
---|
76 | 76 | | |
---|
77 | 77 | | |
---|
78 | 78 | | VT LEG #379087 v.1 |
---|
79 | 79 | | (3) “Area agency on aging” has the same meaning as in 33 V.S.A. 1 |
---|
80 | 80 | | § 6203. 2 |
---|
81 | 81 | | (4) “Authenticate” means to use reasonable means to determine that a 3 |
---|
82 | 82 | | request to exercise any of the rights afforded in this chapter is being made by 4 |
---|
83 | 83 | | or on behalf of the consumer who is entitled to exercise those consumer rights 5 |
---|
84 | 84 | | with respect to the consumer health data at issue. 6 |
---|
85 | 85 | | (5) “Biometric data” means data that is generated from the measurement 7 |
---|
86 | 86 | | or technological processing of an individual’s physiological, biological, or 8 |
---|
87 | 87 | | behavioral characteristics and that identifies a consumer, whether individually 9 |
---|
88 | 88 | | or in combination with other data. Biometric data includes: 10 |
---|
89 | 89 | | (A) imagery of the iris, retina, fingerprint, face, hand, palm, vein 11 |
---|
90 | 90 | | patterns, and voice recordings, from which an identifier template can be 12 |
---|
91 | 91 | | extracted; and 13 |
---|
92 | 92 | | (B) keystroke patterns or rhythms and gait patterns or rhythms that 14 |
---|
93 | 93 | | contain identifying information. 15 |
---|
94 | 94 | | (6) “Collect” means to buy, rent, access, retain, receive, acquire, infer, 16 |
---|
95 | 95 | | derive, or otherwise process consumer health data in any manner. 17 |
---|
96 | 96 | | (7)(A) “Consent” means a clear affirmative act that signifies the 18 |
---|
97 | 97 | | consumer’s freely given, specific, informed, opt-in, voluntary, and 19 |
---|
98 | 98 | | unambiguous agreement, which may include written consent provided by 20 |
---|
99 | 99 | | electronic means. 21 BILL AS INTRODUCED S.74 |
---|
100 | 100 | | 2025 Page 5 of 30 |
---|
101 | 101 | | |
---|
102 | 102 | | |
---|
103 | 103 | | VT LEG #379087 v.1 |
---|
104 | 104 | | (B) “Consent” shall not be obtained by: 1 |
---|
105 | 105 | | (i) a consumer’s acceptance of a general or broad terms-of-use 2 |
---|
106 | 106 | | agreement or a similar document that contains descriptions of personal data 3 |
---|
107 | 107 | | processing along with other unrelated information; 4 |
---|
108 | 108 | | (ii) a consumer hovering over, muting, pausing, or closing a given 5 |
---|
109 | 109 | | piece of content; or 6 |
---|
110 | 110 | | (iii) a consumer’s agreement obtained through the use of deceptive 7 |
---|
111 | 111 | | designs. 8 |
---|
112 | 112 | | (8)(A) “Consumer” means a natural person who meets one or both of 9 |
---|
113 | 113 | | the following conditions: 10 |
---|
114 | 114 | | (i) the person is a Vermont resident; or 11 |
---|
115 | 115 | | (ii) the person’s consumer health data is collected in Vermont. 12 |
---|
116 | 116 | | (B) “Consumer” means a natural person who acts only in an 13 |
---|
117 | 117 | | individual or household context, however identified, including by any unique 14 |
---|
118 | 118 | | identifier. The term does not include an individual acting in an employment 15 |
---|
119 | 119 | | context. 16 |
---|
120 | 120 | | (9)(A) “Consumer health data” means personal information that is 17 |
---|
121 | 121 | | linked or reasonably linkable to a consumer and that identifies the consumer’s 18 |
---|
122 | 122 | | past, present, or future physical or mental health status. 19 |
---|
123 | 123 | | (B) For purposes of this definition, physical or mental health status 20 |
---|
124 | 124 | | includes: 21 BILL AS INTRODUCED S.74 |
---|
125 | 125 | | 2025 Page 6 of 30 |
---|
126 | 126 | | |
---|
127 | 127 | | |
---|
128 | 128 | | VT LEG #379087 v.1 |
---|
129 | 129 | | (i) individual health conditions, treatment diseases, or diagnosis; 1 |
---|
130 | 130 | | (ii) social, psychological, behavioral, and medical interventions; 2 |
---|
131 | 131 | | (iii) health-related surgeries or procedures; 3 |
---|
132 | 132 | | (iv) use or purchase of prescribed medication; 4 |
---|
133 | 133 | | (v) bodily functions, vital signs, symptoms, or measurements of 5 |
---|
134 | 134 | | the information described in this subdivision (B); 6 |
---|
135 | 135 | | (vi) diagnoses or diagnostic testing, treatment, or medication; 7 |
---|
136 | 136 | | (vii) gender-affirming care information; 8 |
---|
137 | 137 | | (viii) reproductive or sexual health information; 9 |
---|
138 | 138 | | (ix) biometric data; 10 |
---|
139 | 139 | | (x) genetic data; 11 |
---|
140 | 140 | | (xi) precise location information that could reasonably indicate a 12 |
---|
141 | 141 | | consumer’s attempt to acquire or receive health services or supplies; 13 |
---|
142 | 142 | | (xii) data that identifies a consumer seeking health care services; 14 |
---|
143 | 143 | | or 15 |
---|
144 | 144 | | (xiii) any information that a regulated entity or a small business, 16 |
---|
145 | 145 | | or its respective processor, processes to associate or identify a consumer with 17 |
---|
146 | 146 | | the data described in subdivisions (i)–(xii) of this subdivision (B) that is 18 |
---|
147 | 147 | | derived or extrapolated from nonhealth information, such as proxy, derivative, 19 |
---|
148 | 148 | | inferred, or emergency data by any means, including algorithms or machine 20 |
---|
149 | 149 | | learning. 21 BILL AS INTRODUCED S.74 |
---|
150 | 150 | | 2025 Page 7 of 30 |
---|
151 | 151 | | |
---|
152 | 152 | | |
---|
153 | 153 | | VT LEG #379087 v.1 |
---|
154 | 154 | | (C) “Consumer health data” does not include personal information 1 |
---|
155 | 155 | | that is used to engage in public or peer-reviewed scientific, historical, or 2 |
---|
156 | 156 | | statistical research in the public interest that adheres to all other applicable 3 |
---|
157 | 157 | | ethics and privacy laws and is approved, monitored, and governed by an 4 |
---|
158 | 158 | | institutional review board, human subjects research ethics review board, or a 5 |
---|
159 | 159 | | similar independent oversight entity that determines that the regulated entity or 6 |
---|
160 | 160 | | the small business has implemented reasonable safeguards to mitigate privacy 7 |
---|
161 | 161 | | risks associated with research, including any risks associated with 8 |
---|
162 | 162 | | reidentification. 9 |
---|
163 | 163 | | (10) “Deceptive design” means a user interface designed or manipulated 10 |
---|
164 | 164 | | with the effect of subverting or impairing user autonomy, decision making, or 11 |
---|
165 | 165 | | choice. 12 |
---|
166 | 166 | | (11) “Deidentified data” means data that cannot reasonably be used to 13 |
---|
167 | 167 | | infer information about, or otherwise be linked to, an identified or identifiable 14 |
---|
168 | 168 | | consumer, or a device linked to such consumer, if the regulated entity or the 15 |
---|
169 | 169 | | small business that possesses the data does all of the following: 16 |
---|
170 | 170 | | (A) takes reasonable measures to ensure that the data cannot be 17 |
---|
171 | 171 | | associated with a consumer; 18 |
---|
172 | 172 | | (B) publicly commits to process the data only in a deidentified 19 |
---|
173 | 173 | | fashion and not to attempt to reidentify the data; and 20 BILL AS INTRODUCED S.74 |
---|
174 | 174 | | 2025 Page 8 of 30 |
---|
175 | 175 | | |
---|
176 | 176 | | |
---|
177 | 177 | | VT LEG #379087 v.1 |
---|
178 | 178 | | (C) contractually obligates any recipients of the data to satisfy the 1 |
---|
179 | 179 | | criteria set forth in this subdivision (11). 2 |
---|
180 | 180 | | (12) “Gender-affirming care information” means personal information 3 |
---|
181 | 181 | | relating to seeking or obtaining past, present, or future gender-affirming health 4 |
---|
182 | 182 | | care services. “Gender-affirming care information” includes: 5 |
---|
183 | 183 | | (A) precise location information that could reasonably indicate a 6 |
---|
184 | 184 | | consumer’s attempt to acquire or receive gender-affirming health care services; 7 |
---|
185 | 185 | | (B) efforts to research or obtain gender-affirming health care 8 |
---|
186 | 186 | | services; or 9 |
---|
187 | 187 | | (C) any gender-affirming care information that is derived, 10 |
---|
188 | 188 | | extrapolated, or inferred, including from nonhealth information such as proxy, 11 |
---|
189 | 189 | | derivative, inferred, emergent, or algorithmic data. 12 |
---|
190 | 190 | | (13) “Gender-affirming health care services” has the same meaning as in 13 |
---|
191 | 191 | | 1 V.S.A. § 150. 14 |
---|
192 | 192 | | (14) “Genetic data” means any data, regardless of its format, that 15 |
---|
193 | 193 | | concerns a consumer’s genetic characteristics. “Genetic data” includes: 16 |
---|
194 | 194 | | (A) raw sequence data that result from the sequencing of a 17 |
---|
195 | 195 | | consumer’s complete extracted deoxyribonucleic acid (DNA) or a portion of 18 |
---|
196 | 196 | | the extracted DNA; 19 |
---|
197 | 197 | | (B) genotypic and phenotypic information that results from analyzing 20 |
---|
198 | 198 | | the raw sequence data; and 21 BILL AS INTRODUCED S.74 |
---|
199 | 199 | | 2025 Page 9 of 30 |
---|
200 | 200 | | |
---|
201 | 201 | | |
---|
202 | 202 | | VT LEG #379087 v.1 |
---|
203 | 203 | | (C) self-reported health data that a consumer submits to a regulated 1 |
---|
204 | 204 | | entity or a small business and that is analyzed in connection with the 2 |
---|
205 | 205 | | consumer’s raw sequence data. 3 |
---|
206 | 206 | | (15) “Geofence” means technology that uses global positioning 4 |
---|
207 | 207 | | coordinates, cell tower connectivity, cellular data, radio frequency 5 |
---|
208 | 208 | | identification, Wi-Fi data, or any other form of spatial or location detection, 6 |
---|
209 | 209 | | individually or in combination, to establish a virtual boundary around a 7 |
---|
210 | 210 | | specific physical location or to locate a consumer within a virtual boundary. 8 |
---|
211 | 211 | | (16) “Health care service” means any service provided to a person to 9 |
---|
212 | 212 | | assess, measure, improve, or learn about a person’s mental or physical health, 10 |
---|
213 | 213 | | including: 11 |
---|
214 | 214 | | (A) individual health conditions, status, diseases, or diagnoses; 12 |
---|
215 | 215 | | (B) social, psychological, behavioral, and medical interventions; 13 |
---|
216 | 216 | | (C) health-related surgeries or procedures; 14 |
---|
217 | 217 | | (D) use or purchase of medication; 15 |
---|
218 | 218 | | (E) bodily functions, vital signs, symptoms, or measurements of the 16 |
---|
219 | 219 | | information described in this subdivision (16); 17 |
---|
220 | 220 | | (F) diagnoses or diagnostic testing, treatment, or medication; 18 |
---|
221 | 221 | | (G) reproductive health services; or 19 |
---|
222 | 222 | | (H) gender-affirming health care services. 20 BILL AS INTRODUCED S.74 |
---|
223 | 223 | | 2025 Page 10 of 30 |
---|
224 | 224 | | |
---|
225 | 225 | | |
---|
226 | 226 | | VT LEG #379087 v.1 |
---|
227 | 227 | | (17) “Homepage” means the introductory page of an internet website 1 |
---|
228 | 228 | | and any internet web page on which personal information is collected. In the 2 |
---|
229 | 229 | | case of an online service such as a mobile application, “homepage” means the 3 |
---|
230 | 230 | | application’s platform page or download page, and a link within the 4 |
---|
231 | 231 | | application, such as from the application configuration or the “about,” 5 |
---|
232 | 232 | | “information,” or “settings” page. 6 |
---|
233 | 233 | | (18) “Person” means, where applicable, a natural person, corporation, 7 |
---|
234 | 234 | | trust, unincorporated association, or partnership. The term does not include a 8 |
---|
235 | 235 | | government agency, tribal nation, or a contracted service provider when 9 |
---|
236 | 236 | | processing consumer health data on behalf of a government agency. 10 |
---|
237 | 237 | | (19)(A) “Personal information” means information that identifies or is 11 |
---|
238 | 238 | | reasonably capable of being associated or linked, directly or indirectly, with a 12 |
---|
239 | 239 | | particular consumer. “Personal information” includes data associated with a 13 |
---|
240 | 240 | | persistent unique identifier, such as a cookie ID, an IP address, a device 14 |
---|
241 | 241 | | identifier, or any other form of persistent unique identifier. 15 |
---|
242 | 242 | | (B) “Personal information” does not include publicly available 16 |
---|
243 | 243 | | information or deidentified data. 17 |
---|
244 | 244 | | (20) “Precise location information” means information derived from 18 |
---|
245 | 245 | | technology, including global positioning system level latitude and longitude 19 |
---|
246 | 246 | | coordinates and other mechanisms, that directly identifies the specific location 20 |
---|
247 | 247 | | of an individual with precision and accuracy within a radius of 1,850 feet. 21 BILL AS INTRODUCED S.74 |
---|
248 | 248 | | 2025 Page 11 of 30 |
---|
249 | 249 | | |
---|
250 | 250 | | |
---|
251 | 251 | | VT LEG #379087 v.1 |
---|
252 | 252 | | “Precise location information” does not include the content of communications 1 |
---|
253 | 253 | | or any data generated by or connected to advanced utility metering 2 |
---|
254 | 254 | | infrastructure systems or equipment for use by a utility. 3 |
---|
255 | 255 | | (21) “Process” or “processing” means any operation or set of operations 4 |
---|
256 | 256 | | performed on consumer health data. 5 |
---|
257 | 257 | | (22) “Processor” means a person who processes consumer health data 6 |
---|
258 | 258 | | on behalf of a regulated entity or a small business. 7 |
---|
259 | 259 | | (23)(A) “Publicly available information” means information that: 8 |
---|
260 | 260 | | (i) is lawfully made available through federal, state, or municipal 9 |
---|
261 | 261 | | government records or widely distributed media; and 10 |
---|
262 | 262 | | (ii) a regulated entity or a small business has a reasonable basis to 11 |
---|
263 | 263 | | believe a consumer has lawfully made available to the general public. 12 |
---|
264 | 264 | | (B) “Publicly available information” does not include any biometric 13 |
---|
265 | 265 | | data collected about a consumer by a business without the consumer’s consent. 14 |
---|
266 | 266 | | (24)(A) “Regulated entity” means any legal entity that: 15 |
---|
267 | 267 | | (i) conducts business in Vermont, or produces or provides 16 |
---|
268 | 268 | | products or services that are targeted to consumers in Vermont; and 17 |
---|
269 | 269 | | (ii) alone or jointly with others, determines the purpose and means 18 |
---|
270 | 270 | | of collecting, processing, sharing, or selling of consumer health data. 19 BILL AS INTRODUCED S.74 |
---|
271 | 271 | | 2025 Page 12 of 30 |
---|
272 | 272 | | |
---|
273 | 273 | | |
---|
274 | 274 | | VT LEG #379087 v.1 |
---|
275 | 275 | | (B) “Regulated entity” does not mean government agencies or 1 |
---|
276 | 276 | | contracted service providers when processing consumer health data on behalf 2 |
---|
277 | 277 | | of a government agency. 3 |
---|
278 | 278 | | (25)(A) “Reproductive or sexual health information” means personal 4 |
---|
279 | 279 | | information relating to seeking or obtaining past, present, or future 5 |
---|
280 | 280 | | reproductive or sexual health services. 6 |
---|
281 | 281 | | (B) “Reproductive or sexual health information” includes: 7 |
---|
282 | 282 | | (i) precise location information that could reasonably indicate a 8 |
---|
283 | 283 | | consumer’s attempt to acquire or receive reproductive or sexual health 9 |
---|
284 | 284 | | services; 10 |
---|
285 | 285 | | (ii) efforts to research or obtain reproductive or sexual health 11 |
---|
286 | 286 | | services; or 12 |
---|
287 | 287 | | (iii) any reproductive or sexual health information that is derived, 13 |
---|
288 | 288 | | extrapolated, or inferred, including from nonhealth information, such as proxy, 14 |
---|
289 | 289 | | derivative, inferred, emergent, or algorithmic data. 15 |
---|
290 | 290 | | (26) “Reproductive or sexual health services” means health services or 16 |
---|
291 | 291 | | products that support or relate to a consumer’s reproductive system or sexual 17 |
---|
292 | 292 | | well-being, including: 18 |
---|
293 | 293 | | (A) individual health conditions, status, diseases, or diagnoses; 19 |
---|
294 | 294 | | (B) social, psychological, behavioral, and medical interventions; 20 |
---|
295 | 295 | | (C) health-related surgeries or procedures, including abortions; 21 BILL AS INTRODUCED S.74 |
---|
296 | 296 | | 2025 Page 13 of 30 |
---|
297 | 297 | | |
---|
298 | 298 | | |
---|
299 | 299 | | VT LEG #379087 v.1 |
---|
300 | 300 | | (D) use or purchase of medication, including medications for the 1 |
---|
301 | 301 | | purposes of abortion; 2 |
---|
302 | 302 | | (E) bodily functions, vital signs, symptoms, or measurements of the 3 |
---|
303 | 303 | | information described in this subdivision (26); 4 |
---|
304 | 304 | | (F) diagnoses or diagnostic testing, treatment, or medication; 5 |
---|
305 | 305 | | (G) medical or nonmedical services related to and provided in 6 |
---|
306 | 306 | | conjunction with an abortion, including associated diagnostics, counseling, 7 |
---|
307 | 307 | | supplies, and follow-up services; and 8 |
---|
308 | 308 | | (H) any other services included in the definition of “reproductive 9 |
---|
309 | 309 | | health care services” in 1 V.S.A. § 150. 10 |
---|
310 | 310 | | (27)(A) “Sell” or “sale” means the exchange of consumer health data for 11 |
---|
311 | 311 | | monetary or other valuable consideration. 12 |
---|
312 | 312 | | (B) “Sell” or “sale” does not include the exchange of consumer 13 |
---|
313 | 313 | | health data for monetary or other valuable consideration: 14 |
---|
314 | 314 | | (i) to a third party as an asset that is part of a merger, acquisition, 15 |
---|
315 | 315 | | bankruptcy, or other transaction in which the third party assumes control of all 16 |
---|
316 | 316 | | or part of the regulated entity’s or the small business’s assets and complies 17 |
---|
317 | 317 | | with the requirements and obligations in this chapter; or 18 |
---|
318 | 318 | | (ii) by a regulated entity or a small business to a processor when 19 |
---|
319 | 319 | | such exchange is consistent with the purpose for which the consumer health 20 |
---|
320 | 320 | | data was collected and the exchange was disclosed to the consumer. 21 BILL AS INTRODUCED S.74 |
---|
321 | 321 | | 2025 Page 14 of 30 |
---|
322 | 322 | | |
---|
323 | 323 | | |
---|
324 | 324 | | VT LEG #379087 v.1 |
---|
325 | 325 | | (28)(A) “Share” or “sharing” means to release, disclose, disseminate, 1 |
---|
326 | 326 | | divulge, make available, provide access to, license, or otherwise communicate 2 |
---|
327 | 327 | | orally, in writing, or by electronic or other means consumer health data by a 3 |
---|
328 | 328 | | regulated entity or a small business to a third party or affiliate. 4 |
---|
329 | 329 | | (B) The term “share” or “sharing” does not include: 5 |
---|
330 | 330 | | (i) the disclosure of consumer health data by a regulated entity or 6 |
---|
331 | 331 | | a small business to a processor when the sharing is to provide goods or 7 |
---|
332 | 332 | | services in a manner consistent with the purpose for which the consumer health 8 |
---|
333 | 333 | | data was collected and the exchange was disclosed to the consumer; 9 |
---|
334 | 334 | | (ii) the disclosure of consumer health data to a third party with 10 |
---|
335 | 335 | | whom the consumer has a direct relationship when: 11 |
---|
336 | 336 | | (I) the disclosure is for purposes of providing a product or 12 |
---|
337 | 337 | | service requested by the consumer; 13 |
---|
338 | 338 | | (II) the regulated entity or the small business maintains control 14 |
---|
339 | 339 | | and ownership of the data; and 15 |
---|
340 | 340 | | (III) the third party uses the consumer health data only at the 16 |
---|
341 | 341 | | direction of the regulated entity or the small business and consistent with the 17 |
---|
342 | 342 | | purpose for which it was collected and consented to by the consumer; or 18 |
---|
343 | 343 | | (iii) the disclosure or transfer of personal data to a third party as an 19 |
---|
344 | 344 | | asset that is part of a merger, acquisition, bankruptcy, or other transaction in 20 |
---|
345 | 345 | | which the third party assumes control of all or part of the regulated entity’s or 21 BILL AS INTRODUCED S.74 |
---|
346 | 346 | | 2025 Page 15 of 30 |
---|
347 | 347 | | |
---|
348 | 348 | | |
---|
349 | 349 | | VT LEG #379087 v.1 |
---|
350 | 350 | | the small business’s assets and complies with the requirements and obligations 1 |
---|
351 | 351 | | in this chapter. 2 |
---|
352 | 352 | | (29) “Small business” means a regulated entity that satisfies one or both 3 |
---|
353 | 353 | | of the following thresholds: 4 |
---|
354 | 354 | | (A) the entity collects, processes, sells, or shares the consumer health 5 |
---|
355 | 355 | | data of fewer than 100,000 consumers during a calendar year; or 6 |
---|
356 | 356 | | (B) the entity derives less than 50 percent of its gross revenue from 7 |
---|
357 | 357 | | the collection, processing, selling, or sharing of consumer health data and the 8 |
---|
358 | 358 | | entity controls, processes, sells, or shares consumer health data of fewer than 9 |
---|
359 | 359 | | 25,000 consumers. 10 |
---|
360 | 360 | | (30) “Third party” means an entity other than a consumer, regulated 11 |
---|
361 | 361 | | entity, processor, small business, or affiliate of the regulated entity or the small 12 |
---|
362 | 362 | | business. 13 |
---|
363 | 363 | | § 1891d. CONSUMER HEALTH DATA PRIVACY POLICY REQUIRED 14 |
---|
364 | 364 | | (a) Each regulated entity or each small business shall maintain a consumer 15 |
---|
365 | 365 | | health data privacy policy that clearly and conspicuously discloses: 16 |
---|
366 | 366 | | (1) the categories of consumer health data collected and the purpose for 17 |
---|
367 | 367 | | which the data is collected, including how the data will be used; 18 |
---|
368 | 368 | | (2) the categories of sources from which the consumer health data is 19 |
---|
369 | 369 | | collected; 20 |
---|
370 | 370 | | (3) the categories of consumer health data that is shared; 21 BILL AS INTRODUCED S.74 |
---|
371 | 371 | | 2025 Page 16 of 30 |
---|
372 | 372 | | |
---|
373 | 373 | | |
---|
374 | 374 | | VT LEG #379087 v.1 |
---|
375 | 375 | | (4) a list of the categories of third parties and specific affiliates with 1 |
---|
376 | 376 | | whom the regulated entity or small business shares the consumer health data; 2 |
---|
377 | 377 | | and 3 |
---|
378 | 378 | | (5) how a consumer can exercise the rights provided in section 1891f of 4 |
---|
379 | 379 | | this chapter. 5 |
---|
380 | 380 | | (b) A regulated entity or small business shall prominently publish a link to 6 |
---|
381 | 381 | | its consumer health data privacy policy on its homepage. 7 |
---|
382 | 382 | | (c) A regulated entity or small business shall not collect, use, or share 8 |
---|
383 | 383 | | additional categories of consumer health data not disclosed in the consumer 9 |
---|
384 | 384 | | health data privacy policy without first disclosing the additional categories and 10 |
---|
385 | 385 | | obtaining the consumer’s affirmative consent prior to the collection, use, or 11 |
---|
386 | 386 | | sharing of the consumer health data. 12 |
---|
387 | 387 | | (d) A regulated entity or small business shall not collect, use, or share 13 |
---|
388 | 388 | | consumer health data for additional purposes not disclosed in the consumer 14 |
---|
389 | 389 | | health data privacy policy without first disclosing the additional purposes and 15 |
---|
390 | 390 | | obtaining the consumer’s affirmative consent prior to the collection, use, or 16 |
---|
391 | 391 | | sharing of the consumer health data. 17 |
---|
392 | 392 | | (e) It is a violation of this subchapter for a regulated entity or small 18 |
---|
393 | 393 | | business to contract with a processor to process consumer health data in a 19 |
---|
394 | 394 | | manner that is inconsistent with the regulated entity’s or small business’s 20 |
---|
395 | 395 | | consumer health data privacy policy. 21 BILL AS INTRODUCED S.74 |
---|
396 | 396 | | 2025 Page 17 of 30 |
---|
397 | 397 | | |
---|
398 | 398 | | |
---|
399 | 399 | | VT LEG #379087 v.1 |
---|
400 | 400 | | § 1891e. COLLECTION AND SHARING OF CONSUMER HEALTH 1 |
---|
401 | 401 | | DATA 2 |
---|
402 | 402 | | (a) A regulated entity or small business shall not collect any consumer 3 |
---|
403 | 403 | | health data except: 4 |
---|
404 | 404 | | (1) with consent from the consumer for such collection for a specified 5 |
---|
405 | 405 | | purpose; or 6 |
---|
406 | 406 | | (2) to the extent necessary to provide a product or service that the 7 |
---|
407 | 407 | | consumer to whom the consumer health data relates has requested from the 8 |
---|
408 | 408 | | regulated entity or small business. 9 |
---|
409 | 409 | | (b) A regulated entity or small business shall not share any consumer health 10 |
---|
410 | 410 | | data except: 11 |
---|
411 | 411 | | (1) with consent from the consumer for the sharing that is separate and 12 |
---|
412 | 412 | | distinct from the consent obtained to collect consumer health data; or 13 |
---|
413 | 413 | | (2) to the extent necessary to provide a product or service that the 14 |
---|
414 | 414 | | consumer to whom the consumer health data relates has requested from the 15 |
---|
415 | 415 | | regulated entity or small business. 16 |
---|
416 | 416 | | (c) Consent required under this section shall be obtained prior to the 17 |
---|
417 | 417 | | collection or sharing, as applicable, of any consumer health data, and the 18 |
---|
418 | 418 | | request for consent must clearly and conspicuously disclose: 19 |
---|
419 | 419 | | (1) the categories of consumer health data collected or shared; 20 BILL AS INTRODUCED S.74 |
---|
420 | 420 | | 2025 Page 18 of 30 |
---|
421 | 421 | | |
---|
422 | 422 | | |
---|
423 | 423 | | VT LEG #379087 v.1 |
---|
424 | 424 | | (2) the purpose of the collection or sharing of the consumer health data, 1 |
---|
425 | 425 | | including the specific ways in which it will be used; 2 |
---|
426 | 426 | | (3) the categories of entities with whom the consumer health data is 3 |
---|
427 | 427 | | shared; and 4 |
---|
428 | 428 | | (4) how the consumer can withdraw consent from future collection or 5 |
---|
429 | 429 | | sharing of the consumer’s health data. 6 |
---|
430 | 430 | | (d) A regulated entity or small business shall not unlawfully discriminate 7 |
---|
431 | 431 | | against a consumer for exercising any rights included in this chapter. 8 |
---|
432 | 432 | | § 1891f. CONSUMER RIGHTS 9 |
---|
433 | 433 | | (a) Confirmation. A consumer has the right to confirm whether a regulated 10 |
---|
434 | 434 | | entity or a small business is collecting, sharing, or selling consumer health data 11 |
---|
435 | 435 | | regarding the consumer and to access that data, including a list of all third 12 |
---|
436 | 436 | | parties and affiliates with whom the regulated entity or small business has 13 |
---|
437 | 437 | | shared or sold the consumer’s health data and an active email address or other 14 |
---|
438 | 438 | | online mechanism that the consumer may use to contact these third parties. 15 |
---|
439 | 439 | | (b) Withdrawal of consent. A consumer has the right to withdraw consent 16 |
---|
440 | 440 | | from a regulated entity’s or small business’s collection and sharing of 17 |
---|
441 | 441 | | consumer health data regarding the consumer. 18 |
---|
442 | 442 | | (c) Right to delete. A consumer has the right to have consumer health data 19 |
---|
443 | 443 | | regarding the consumer deleted and may exercise that right by informing the 20 |
---|
444 | 444 | | regulated entity or small business of the consumer’s request for deletion. 21 BILL AS INTRODUCED S.74 |
---|
445 | 445 | | 2025 Page 19 of 30 |
---|
446 | 446 | | |
---|
447 | 447 | | |
---|
448 | 448 | | VT LEG #379087 v.1 |
---|
449 | 449 | | (1) A regulated entity or small business that receives a consumer’s 1 |
---|
450 | 450 | | request to delete any consumer health data regarding the consumer shall: 2 |
---|
451 | 451 | | (A) delete the consumer health data from its records, including from 3 |
---|
452 | 452 | | all parts of the regulated entity’s or small business’s network, including 4 |
---|
453 | 453 | | archived or backup systems pursuant to subdivision (3) of this subsection (c); 5 |
---|
454 | 454 | | and 6 |
---|
455 | 455 | | (B) notify all affiliates, processors, contractors, and other third parties 7 |
---|
456 | 456 | | with whom the regulated entity or the small business has shared consumer 8 |
---|
457 | 457 | | health data of the deletion request. 9 |
---|
458 | 458 | | (2) All affiliates, processors, contractors, and other third parties that 10 |
---|
459 | 459 | | receive notice of a consumer’s deletion request shall honor the consumer’s 11 |
---|
460 | 460 | | deletion request and delete the consumer health data from its records in 12 |
---|
461 | 461 | | accordance with the requirements of this subchapter. 13 |
---|
462 | 462 | | (3) If consumer health data that a consumer requests to be deleted is 14 |
---|
463 | 463 | | stored on archived or backup systems, then the request for deletion may be 15 |
---|
464 | 464 | | delayed to enable restoration of the archived or backup systems, provided that 16 |
---|
465 | 465 | | the delay shall not exceed six months from the date of authentication of the 17 |
---|
466 | 466 | | deletion request. 18 |
---|
467 | 467 | | (d) Request requirements. 19 |
---|
468 | 468 | | (1) A consumer may exercise the rights set forth in this chapter by 20 |
---|
469 | 469 | | submitting a request to a regulated entity or small business at any time. The 21 BILL AS INTRODUCED S.74 |
---|
470 | 470 | | 2025 Page 20 of 30 |
---|
471 | 471 | | |
---|
472 | 472 | | |
---|
473 | 473 | | VT LEG #379087 v.1 |
---|
474 | 474 | | request may be made by a secure and reliable means established by the 1 |
---|
475 | 475 | | regulated entity or small business and described in its consumer health data 2 |
---|
476 | 476 | | privacy policy. The method shall take into account the ways in which 3 |
---|
477 | 477 | | consumers normally interact with the regulated entity or small business, the 4 |
---|
478 | 478 | | need for secure and reliable communication of such requests, and the ability of 5 |
---|
479 | 479 | | the regulated entity or the small business to authenticate the identity of the 6 |
---|
480 | 480 | | consumer making the request. A regulated entity or small business shall not 7 |
---|
481 | 481 | | require a consumer to create a new account in order to exercise consumer 8 |
---|
482 | 482 | | rights pursuant to this subchapter but may require a consumer to use an 9 |
---|
483 | 483 | | existing account. 10 |
---|
484 | 484 | | (2) If a regulated entity or small business is unable to authenticate the 11 |
---|
485 | 485 | | request using commercially reasonable efforts, the regulated entity or small 12 |
---|
486 | 486 | | business is not required to comply with a request to initiate an action under this 13 |
---|
487 | 487 | | section and may request that the consumer provide additional information 14 |
---|
488 | 488 | | reasonably necessary to authenticate the consumer and the consumer’s request. 15 |
---|
489 | 489 | | (3) Information provided in response to a consumer request shall be 16 |
---|
490 | 490 | | provided by a regulated entity or small business free of charge, up to twice 17 |
---|
491 | 491 | | annually per consumer. If requests from a consumer are manifestly unfounded, 18 |
---|
492 | 492 | | excessive, or repetitive, the regulated entity or small business may charge the 19 |
---|
493 | 493 | | consumer a reasonable fee to cover the administrative costs of complying with 20 |
---|
494 | 494 | | the request or decline to act on the request. The regulated entity or small 21 BILL AS INTRODUCED S.74 |
---|
495 | 495 | | 2025 Page 21 of 30 |
---|
496 | 496 | | |
---|
497 | 497 | | |
---|
498 | 498 | | VT LEG #379087 v.1 |
---|
499 | 499 | | business bears the burden of demonstrating the manifestly unfounded, 1 |
---|
500 | 500 | | excessive, or repetitive nature of the request. 2 |
---|
501 | 501 | | (4) A regulated entity or small business shall comply with a consumer’s 3 |
---|
502 | 502 | | requests under subsections (a) through (c) of this section without undue delay, 4 |
---|
503 | 503 | | but in all cases within 45 days following receipt of the request submitted 5 |
---|
504 | 504 | | pursuant to the methods described in this section. A regulated entity or small 6 |
---|
505 | 505 | | business shall promptly take steps to authenticate a consumer request; 7 |
---|
506 | 506 | | provided, however, that completion of these steps does not extend the 8 |
---|
507 | 507 | | regulated entity’s or small business’s duty to comply with the consumer’s 9 |
---|
508 | 508 | | request within 45 days following receipt of the consumer’s request. The 10 |
---|
509 | 509 | | response period may be extended once by 45 additional days when reasonably 11 |
---|
510 | 510 | | necessary, taking into account the complexity and number of the consumer’s 12 |
---|
511 | 511 | | requests, provided the regulated entity or small business informs the consumer 13 |
---|
512 | 512 | | of any such extension within the initial 45-day response period, together with 14 |
---|
513 | 513 | | the reason for the extension. 15 |
---|
514 | 514 | | (e) Consumer appeal. A regulated entity or small business shall establish a 16 |
---|
515 | 515 | | process for a consumer to appeal the regulated entity’s or small business’s 17 |
---|
516 | 516 | | refusal to take action on a request within a reasonable period of time after the 18 |
---|
517 | 517 | | consumer’s receipt of the decision. The appeal process shall be conspicuously 19 |
---|
518 | 518 | | available and similar to the process for submitting requests to initiate action 20 |
---|
519 | 519 | | pursuant to this section. Within 45 days following receipt of an appeal, a 21 BILL AS INTRODUCED S.74 |
---|
520 | 520 | | 2025 Page 22 of 30 |
---|
521 | 521 | | |
---|
522 | 522 | | |
---|
523 | 523 | | VT LEG #379087 v.1 |
---|
524 | 524 | | regulated entity or small business shall inform the consumer in writing of any 1 |
---|
525 | 525 | | action taken or not taken in response to the appeal, including a written 2 |
---|
526 | 526 | | explanation of the reasons for the decisions. If the appeal is denied, the 3 |
---|
527 | 527 | | regulated entity or small business shall also provide the consumer with an 4 |
---|
528 | 528 | | online mechanism, if available, or other method through which the consumer 5 |
---|
529 | 529 | | may contact the Office of the Attorney General to submit a complaint. 6 |
---|
530 | 530 | | § 1891g. PROTECTION OF CONSUMER HEALTH DATA 7 |
---|
531 | 531 | | A regulated entity or small business shall: 8 |
---|
532 | 532 | | (1) restrict access to consumer health data by the regulated entity’s or 9 |
---|
533 | 533 | | small business’s employees, processors, and contractors to only those 10 |
---|
534 | 534 | | employees, processors, and contractors for whom access is necessary to further 11 |
---|
535 | 535 | | the purposes for which the consumer provided consent or where necessary to 12 |
---|
536 | 536 | | provide a product or service that the consumer to whom such consumer health 13 |
---|
537 | 537 | | data relates has requested from the regulated entity or small business; and 14 |
---|
538 | 538 | | (2) establish, implement, and maintain administrative, technical, and 15 |
---|
539 | 539 | | physical data security practices that, at a minimum, satisfy reasonable 16 |
---|
540 | 540 | | standards of care within the regulated entity’s or small business’s industry to 17 |
---|
541 | 541 | | protect the confidentiality, integrity, and accessibility of consumer health data 18 |
---|
542 | 542 | | appropriate to the volume and nature of the consumer health data at issue. 19 BILL AS INTRODUCED S.74 |
---|
543 | 543 | | 2025 Page 23 of 30 |
---|
544 | 544 | | |
---|
545 | 545 | | |
---|
546 | 546 | | VT LEG #379087 v.1 |
---|
547 | 547 | | § 1891h. PROCESSORS OF CONSUMER HEALTH DATA 1 |
---|
548 | 548 | | (a) Contract required. 2 |
---|
549 | 549 | | (1) A processor may process consumer health data only pursuant to a 3 |
---|
550 | 550 | | binding contract between the processor and the regulated entity or small 4 |
---|
551 | 551 | | business that sets forth the processing instructions and limits the actions the 5 |
---|
552 | 552 | | processor may take with respect to the consumer health data it processes on 6 |
---|
553 | 553 | | behalf of the regulated entity or small business. 7 |
---|
554 | 554 | | (2) A processor may process consumer health data only in a manner that 8 |
---|
555 | 555 | | is consistent with the binding instructions set forth in the contract with the 9 |
---|
556 | 556 | | regulated entity or small business. 10 |
---|
557 | 557 | | (b) Obligation to assist. To the extent possible, a processor shall use 11 |
---|
558 | 558 | | appropriate technical and organizational measures to assist the regulated entity 12 |
---|
559 | 559 | | or small business in fulfilling the regulated entity’s and the small business’s 13 |
---|
560 | 560 | | obligations under this chapter. 14 |
---|
561 | 561 | | (c) Failure to adhere. If a processor fails to adhere to the regulated entity’s 15 |
---|
562 | 562 | | or small business’s instructions or processes consumer health data in a manner 16 |
---|
563 | 563 | | that is outside the scope of the processor’s contract with the regulated entity or 17 |
---|
564 | 564 | | small business, the processor is considered a regulated entity or small business 18 |
---|
565 | 565 | | with respect to the data and is subject to all the requirements of this chapter 19 |
---|
566 | 566 | | with regard to the data. 20 BILL AS INTRODUCED S.74 |
---|
567 | 567 | | 2025 Page 24 of 30 |
---|
568 | 568 | | |
---|
569 | 569 | | |
---|
570 | 570 | | VT LEG #379087 v.1 |
---|
571 | 571 | | § 1891i. LIMITATIONS ON SALE OF CONSUMER HEALTH DATA 1 |
---|
572 | 572 | | (a) Authorization required. It is unlawful for any person to sell or offer to 2 |
---|
573 | 573 | | sell consumer health data regarding a consumer without first obtaining valid 3 |
---|
574 | 574 | | authorization from the consumer. The sale of consumer health data must be 4 |
---|
575 | 575 | | consistent with the valid authorization signed by the consumer. This 5 |
---|
576 | 576 | | authorization shall be separate and distinct from the consent obtained to collect 6 |
---|
577 | 577 | | or share consumer health data, as required under section 1891e of this chapter. 7 |
---|
578 | 578 | | (b) Requirements of a valid authorization. A valid authorization to sell 8 |
---|
579 | 579 | | consumer health data shall be a document that is consistent with this section 9 |
---|
580 | 580 | | and is written in plain language. A valid authorization to sell consumer health 10 |
---|
581 | 581 | | data shall contain all of the following: 11 |
---|
582 | 582 | | (1) the specific consumer health data regarding the consumer that the 12 |
---|
583 | 583 | | person intends to sell; 13 |
---|
584 | 584 | | (2) the name and contact information of the person collecting and selling 14 |
---|
585 | 585 | | the consumer health data; 15 |
---|
586 | 586 | | (3) the name and contact information of the person purchasing the 16 |
---|
587 | 587 | | consumer health data from the seller identified in subdivision (2) of this 17 |
---|
588 | 588 | | subsection; 18 |
---|
589 | 589 | | (4) a description of the purpose for the sale, including how the consumer 19 |
---|
590 | 590 | | health data will be gathered and how it will be used by the purchaser identified 20 |
---|
591 | 591 | | in subdivision (3) of this subsection when sold; 21 BILL AS INTRODUCED S.74 |
---|
592 | 592 | | 2025 Page 25 of 30 |
---|
593 | 593 | | |
---|
594 | 594 | | |
---|
595 | 595 | | VT LEG #379087 v.1 |
---|
596 | 596 | | (5) a statement that the provision of goods or services shall not be 1 |
---|
597 | 597 | | conditioned on the consumer signing the valid authorization; 2 |
---|
598 | 598 | | (6) a statement that the consumer has a right to revoke the valid 3 |
---|
599 | 599 | | authorization at any time and a description of how to submit a revocation of 4 |
---|
600 | 600 | | the valid authorization; 5 |
---|
601 | 601 | | (7) a statement that the consumer health data sold pursuant to the valid 6 |
---|
602 | 602 | | authorization may be subject to redisclosure by the purchaser and may no 7 |
---|
603 | 603 | | longer be protected by this section; 8 |
---|
604 | 604 | | (8) an expiration date for the valid authorization that expires one year 9 |
---|
605 | 605 | | after the consumer signs the valid authorization; and 10 |
---|
606 | 606 | | (9) the signature of the consumer and date. 11 |
---|
607 | 607 | | (c) Invalid authorizations. An authorization is not valid if the document 12 |
---|
608 | 608 | | has any of the following defects: 13 |
---|
609 | 609 | | (1) the expiration date has passed; 14 |
---|
610 | 610 | | (2) the authorization does not contain all of the information required 15 |
---|
611 | 611 | | under this section; 16 |
---|
612 | 612 | | (3) the authorization has been revoked by the consumer; 17 |
---|
613 | 613 | | (4) the authorization has been combined with other documents to create 18 |
---|
614 | 614 | | a compound authorization; or 19 |
---|
615 | 615 | | (5) the provision of goods or services is conditioned on the consumer 20 |
---|
616 | 616 | | signing the authorization. 21 BILL AS INTRODUCED S.74 |
---|
617 | 617 | | 2025 Page 26 of 30 |
---|
618 | 618 | | |
---|
619 | 619 | | |
---|
620 | 620 | | VT LEG #379087 v.1 |
---|
621 | 621 | | (d) Copies and retention. 1 |
---|
622 | 622 | | (1) A copy of the signed valid authorization shall be provided to the 2 |
---|
623 | 623 | | consumer. 3 |
---|
624 | 624 | | (2) A seller or purchaser of consumer health data shall retain a copy of 4 |
---|
625 | 625 | | each valid authorization for the sale of consumer health data for six years from 5 |
---|
626 | 626 | | the date of its signature or the date when it was last in effect, whichever is 6 |
---|
627 | 627 | | later. 7 |
---|
628 | 628 | | § 1891j. GEOFENCES PROHIBITED 8 |
---|
629 | 629 | | It is unlawful for any person to implement a geofence to establish a virtual 9 |
---|
630 | 630 | | boundary that is within 1,850 feet of any health care facility, including any 10 |
---|
631 | 631 | | mental health facility or reproductive or sexual health facility, for the purpose 11 |
---|
632 | 632 | | of identifying, tracking, collecting data from, or sending any notification to a 12 |
---|
633 | 633 | | consumer regarding the consumer’s consumer health data. 13 |
---|
634 | 634 | | § 1891k. VIOLATIONS; ENFORCEMENT 14 |
---|
635 | 635 | | (a) A violation of this subchapter shall be deemed a violation of the 15 |
---|
636 | 636 | | Consumer Protection Act, 9 V.S.A. chapter 63. The Attorney General has the 16 |
---|
637 | 637 | | same authority to make rules, conduct civil investigations, enter into 17 |
---|
638 | 638 | | assurances of discontinuance, and bring civil actions, and private parties have 18 |
---|
639 | 639 | | the same rights and remedies, as provided under 9 V.S.A. chapter 63, 19 |
---|
640 | 640 | | subchapter 1. 20 BILL AS INTRODUCED S.74 |
---|
641 | 641 | | 2025 Page 27 of 30 |
---|
642 | 642 | | |
---|
643 | 643 | | |
---|
644 | 644 | | VT LEG #379087 v.1 |
---|
645 | 645 | | (b) Nothing in this section shall be construed to preclude or supplant any 1 |
---|
646 | 646 | | other statutory or common law remedies. 2 |
---|
647 | 647 | | § 1891l. EXEMPTIONS 3 |
---|
648 | 648 | | (a) This subchapter shall not apply to: 4 |
---|
649 | 649 | | (1) information that meets the definition of: 5 |
---|
650 | 650 | | (A) protected health information for purposes of the federal Health 6 |
---|
651 | 651 | | Insurance Portability and Accountability Act of 1996 and related regulations; 7 |
---|
652 | 652 | | (B) patient-identifying information collected, used, or disclosed in 8 |
---|
653 | 653 | | accordance with 42 C.F.R. Part 2, established pursuant to 42 U.S.C. § 290dd-2; 9 |
---|
654 | 654 | | or 10 |
---|
655 | 655 | | (C) identifiable private information for purposes of the federal policy 11 |
---|
656 | 656 | | for the protection of human subjects, 45 C.F.R. Part 46; identifiable private 12 |
---|
657 | 657 | | information that is otherwise information collected as part of human subjects 13 |
---|
658 | 658 | | research pursuant to the Good Clinical Practice Guidelines issued by the 14 |
---|
659 | 659 | | International Council for Harmonization; the protection of human subjects 15 |
---|
660 | 660 | | under 21 C.F.R. Parts 50 and 56; or personal data used or shared in research 16 |
---|
661 | 661 | | conducted in accordance with one or more of the requirements set forth in this 17 |
---|
662 | 662 | | subsection (a); 18 |
---|
663 | 663 | | (2) information and documents created specifically for, and collected 19 |
---|
664 | 664 | | and maintained as part of, the patient safety surveillance and improvement 20 |
---|
665 | 665 | | system established pursuant to chapter 43A of this title; 21 BILL AS INTRODUCED S.74 |
---|
666 | 666 | | 2025 Page 28 of 30 |
---|
667 | 667 | | |
---|
668 | 668 | | |
---|
669 | 669 | | VT LEG #379087 v.1 |
---|
670 | 670 | | (3) information and documents created for purposes of the federal 1 |
---|
671 | 671 | | Health Care Quality Improvement Act of 1986, and related regulations; 2 |
---|
672 | 672 | | (4) patient safety work product for purposes of 42 C.F.R. Part 3, 3 |
---|
673 | 673 | | established pursuant to 42 U.S.C. §§ 299b-21–299b-26; 4 |
---|
674 | 674 | | (5) information that is deidentified in accordance with the requirements 5 |
---|
675 | 675 | | for deidentification set forth in 45 C.F.R. Part 164; 6 |
---|
676 | 676 | | (6) information originating from, and intermingled so as to be 7 |
---|
677 | 677 | | indistinguishable with, information described under subdivisions (1)–(5) of 8 |
---|
678 | 678 | | this subsection that is maintained by: 9 |
---|
679 | 679 | | (A) a covered entity that is not a hybrid entity, any health care 10 |
---|
680 | 680 | | component of a hybrid entity, or a business associate as those terms are defined 11 |
---|
681 | 681 | | by the Health Insurance Portability and Accountability Act of 1996 and related 12 |
---|
682 | 682 | | regulations; 13 |
---|
683 | 683 | | (B) a health care facility or health care provider, as defined in section 14 |
---|
684 | 684 | | 9402 of this title; or 15 |
---|
685 | 685 | | (C) a program or a qualified service organization as defined by 42 16 |
---|
686 | 686 | | C.F.R. Part 2, established pursuant to 42 U.S.C. § 290dd-2; 17 |
---|
687 | 687 | | (7) information used only for public health activities and purposes as 18 |
---|
688 | 688 | | described in 45 C.F.R. § 164.512 or that is part of a limited data set, as defined, 19 |
---|
689 | 689 | | and is used, disclosed, and maintained in the manner required, by 45 C.F.R. 20 |
---|
690 | 690 | | § 164.514; or 21 BILL AS INTRODUCED S.74 |
---|
691 | 691 | | 2025 Page 29 of 30 |
---|
692 | 692 | | |
---|
693 | 693 | | |
---|
694 | 694 | | VT LEG #379087 v.1 |
---|
695 | 695 | | (8) an area agency on aging. 1 |
---|
696 | 696 | | (b) Personal information that is governed by and collected, used, or 2 |
---|
697 | 697 | | disclosed pursuant to the following regulations, parts, titles, or acts is exempt 3 |
---|
698 | 698 | | from this subchapter: 4 |
---|
699 | 699 | | (1) the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq. and 5 |
---|
700 | 700 | | implementing regulations; 6 |
---|
701 | 701 | | (2) part C of Title XI of the Social Security Act, 42 U.S.C. § 1320d et 7 |
---|
702 | 702 | | seq.; 8 |
---|
703 | 703 | | (3) the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq.; 9 |
---|
704 | 704 | | (4) the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g 10 |
---|
705 | 705 | | and 34 C.F.R. Part 99; and 11 |
---|
706 | 706 | | (5) the Vermont Health Benefit Exchange, 33 V.S.A. chapter 18, 12 |
---|
707 | 707 | | subchapter 1, and related federal laws and Vermont rules, including 45 C.F.R. 13 |
---|
708 | 708 | | § 155.260. 14 |
---|
709 | 709 | | (c) The obligations imposed on regulated entities, small businesses, and 15 |
---|
710 | 710 | | processors under this subchapter shall not be construed to restrict a regulated 16 |
---|
711 | 711 | | entity’s, small business’s, or processor’s ability to collect, use, or disclose 17 |
---|
712 | 712 | | consumer health data to prevent, detect, protect against, or respond to security 18 |
---|
713 | 713 | | incidents, identity theft, fraud, harassment, malicious or deceptive activities, or 19 |
---|
714 | 714 | | any activity that is illegal under Vermont or federal law; preserve the integrity 20 BILL AS INTRODUCED S.74 |
---|
715 | 715 | | 2025 Page 30 of 30 |
---|
716 | 716 | | |
---|
717 | 717 | | |
---|
718 | 718 | | VT LEG #379087 v.1 |
---|
719 | 719 | | or security of systems; or investigate, report, or prosecute those responsible for 1 |
---|
720 | 720 | | any such action that is illegal under Vermont or federal law. 2 |
---|
721 | 721 | | (d) If a regulated entity, small business, or processor processes consumer 3 |
---|
722 | 722 | | health data pursuant to subsection (c) of this section, that entity shall bear the 4 |
---|
723 | 723 | | burden of demonstrating that the processing qualifies for the exemption and 5 |
---|
724 | 724 | | complies with the requirements of this section. 6 |
---|
725 | 725 | | Sec. 2. EFFECTIVE DATE 7 |
---|
726 | 726 | | This act shall take effect on January 1, 2026. 8 |
---|