IL HB3494 | 2025-2026 | 104th General Assembly
Status
Spectrum: Partisan Bill (Democrat 1-0)
Status: Introduced on February 7 2025 - 25% progression
Action: 2025-02-07 - Filed with the Clerk by Rep. Ann M. Williams
Text: Latest bill text (Introduced) [HTML]
Status: Introduced on February 7 2025 - 25% progression
Action: 2025-02-07 - Filed with the Clerk by Rep. Ann M. Williams
Text: Latest bill text (Introduced) [HTML]
Summary
Creates the Protect Health Data Privacy Act. Provides that a regulated entity shall disclose and maintain a health data privacy policy that clearly and conspicuously discloses specified information. Sets forth provisions concerning health data privacy policies. Provides that a regulated entity shall not collect, share, or store health data, except in specified circumstances. Provides that it is unlawful for any person to sell or offer to sell health data concerning an individual without first obtaining valid authorization from the individual. Provides that a valid authorization to sell individual health data must contain specified information; a copy of the signed valid authorization must be provided to the individual; and the seller and purchaser of health data must retain a copy of all valid authorizations for sale of health data for 6 years after the date of its signature or the date when it was last in effect, whichever is later. Sets forth provisions concerning the consent required for collection, sharing, and storage of health data. Provides that an individual has the right to withdraw consent from the processing of the individual's health data. Provides that it is unlawful for a regulated entity to engage in discriminatory practices against individuals solely because they have not provided consent to the processing of their health data or have exercised any other rights provided by the provisions or guaranteed by law. Sets forth provisions concerning an individual's right to confirm whether a regulated entity is collecting, selling, sharing, or storing any of the individual's health data; an individual's right to have the individual's health data that is collected by a regulated entity deleted; prohibitions regarding geofencing; and individual health data security. Provides that any person aggrieved by a violation of the provisions shall have a right of action in a State circuit court or as a supplemental claim in federal district court against an offending party. Provides that the Attorney General may enforce a violation of the provisions as an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act. Defines terms. Makes a conforming change in the Consumer Fraud and Deceptive Business Practices Act.
Title
HEALTH DATA PRIVACY ACT
Sponsors
History
Date | Chamber | Action |
---|---|---|
2025-02-07 | House | Filed with the Clerk by Rep. Ann M. Williams |
Code Citations
Illinois State Sources
Type | Source |
---|---|
Summary | https://www.ilga.gov/legislation/BillStatus.asp?DocNum=3494&GAID=18&DocTypeID=HB&SessionID=114&GA=104 |
Text | https://www.ilga.gov/legislation/104/HB/10400HB3494.htm |