S 3097, the Health Information Privacy Reform Act, updates privacy rules for health data by requiring new federal regulations that harmonize with existing HIPAA and HITECH standards. It directly affects healthcare providers, insurers, and technology companies handling health information by mandating clearer privacy rules, stricter breach notifications, and new requirements for patient access to records. Key provisions include requiring written consent for selling health data, banning HIPAA protections for wellness app data (like step counts), and clarifying when health data can be shared without patient permission. The bill also establishes standardized rules for de-identifying health data and requires companies to notify patients if their health data is no longer protected under HIPAA. These changes aim to strengthen patient control over health information while aligning with modern data practices.
This bill requires the FCC to establish a vetting process for applicants seeking high-cost universal service fund money to deploy rural broadband networks. It mandates that applicants must demonstrate technical, financial, and operational capabilities through detailed proposals, including documentation showing they can meet performance standards and have a viable business plan. The FCC must evaluate these proposals against established technical standards (like those from the Digital Opportunity Data Collection) and the applicant's history of complying with broadband funding requirements. Penalties for failing to meet pre-authorization requirements must be at least $9,000 per violation or 30% of the funding amount. The bill directly affects entities applying for new broadband funding under the universal service program.
This bill requires the Department of Homeland Security (DHS) to keep all personal information from DACA applications confidential. It prohibits sharing this data with U.S. Immigration and Customs Enforcement (ICE), U.S. Customs and Border Protection (CBP), or state/local law enforcement for any purpose other than administering the DACA program. Limited exceptions allow sharing only to prevent fraud, address specific national security threats, or investigate felonies unrelated to immigration status. The law directly protects DACA applicants and recipients by preventing their personal details from being used against them by law enforcement.
The MAPWaters Act of 2025 requires federal agencies managing public waterways (like the National Park Service and Forest Service) to digitize and publish online specific data about access restrictions. This includes seasonal closures, speed zones, equipment rules, boat ramp locations, and fishing restrictions (like no-take zones) within 5 years of enactment. The law mandates public updates at least twice yearly for access data and in real time for fishing restrictions, while excluding irrigation canals and sensitive archaeological sites. It directly affects recreational users, anglers, and boaters by making federal waterway access information more accessible through standardized digital maps. The bill does not alter existing fishing regulations or jurisdiction over navigable waters.
The Artificial Intelligence Civil Rights Act of 2025 requires developers and deployers of AI systems that make decisions affecting "consequential actions" (such as employment, housing, healthcare, education, and credit) to conduct pre-deployment evaluations and annual impact assessments by independent auditors. The bill mandates transparency requirements including clear disclosures to individuals about how AI is used in decision-making, establishes a right to human alternatives for significant AI-driven decisions, and prohibits discrimination based on protected characteristics like race, gender, or disability. It creates enforcement mechanisms through the Federal Trade Commission, state attorneys general, and private lawsuits, with penalties including civil penalties of up to 4% of annual revenue. The act also requires developers to provide explanations for AI-driven decisions and sets standards for data collection to prevent harm and ensure fairness in critical life areas.
S 2850, the Protecting Legislators and Survivors of Sexual Assault and Domestic Violence from Doxing and Political Violence Act, would protect Members of Congress, their immediate family members, designated legislative employees, and survivors of domestic violence or sexual assault from having sensitive personal information publicly shared. The bill defines "covered information" to include home addresses, phone numbers, email addresses, social security numbers, license plate numbers, and details about children's schools or daily routines. It requires government agencies to remove this information from public records within 72 hours of a request and prohibits data brokers from selling or trading this information. Businesses and websites must also remove covered information upon request, with exceptions for news reporting and information voluntarily shared by the individual.
HR 3218, the Reproductive Data Privacy and Protection Act, requires law enforcement and government agencies to swear under oath that they will not use reproductive or sexual health information in investigations or legal proceedings. It amends federal wiretap laws (18 U.S.C. § 2518) and communication disclosure rules (18 U.S.C. § 2703) to mandate this protection. The bill defines "reproductive or sexual health information" broadly to include details about abortion, contraception, IVF, pregnancy, sexual health conditions, and related medical services. This directly affects law enforcement, courts, and service providers by legally restricting how sensitive health data can be used in investigations. The law aims to prevent government use of such data to target individuals seeking or providing reproductive care.
The Roadway Safety Modernization Act of 2025 requires states to integrate predictive safety tools - like data analytics and telematics - into federal highway safety programs to identify risks, evaluate projects, and improve planning. It directs the Department of Transportation to issue guidelines on data privacy, security, and validating these tools to ensure reliability. The bill also defines "intelligent freight transportation systems" to include technologies that enhance freight safety on highways. These changes apply directly to states administering highway safety funds and federal agencies like the Federal Highway Administration.
This bill amends the National Labor Relations Act to protect worker privacy during union elections. It requires employers to provide labor organizations with a voter list containing only employees' names and one optional contact detail (like email or phone number) within two business days of an election approval, in a searchable electronic format. The bill also prohibits labor organizations from selling or misusing this contact information for political purposes or after an election concludes. These provisions directly affect employers (who must provide lists), labor organizations (who receive and must handle data responsibly), and employees (whose personal information is protected).
This bill would protect Members of Congress, their immediate family members, designated congressional employees, and candidates for Congress from having their personal information publicly disclosed. It requires government agencies to remove protected information - including home addresses, phone numbers, school schedules, and geolocation data - from public records within 72 hours of a request. The bill also prohibits data brokers and businesses from selling or displaying this protected information online without consent, with exceptions for news reporting and information voluntarily shared by the individual. Individuals affected by violations would have the right to seek legal action to enforce the law.