Bill

Bill > SB2273


IL SB2273

IL SB2273
HEALTH DATA PRIVACY ACT


summary

Introduced
02/07/2025
In Committee
04/11/2025
Crossed Over
Passed
Dead

Introduced Session

104th General Assembly

Bill Summary

Creates the Protect Health Data Privacy Act. Provides that a regulated entity shall disclose and maintain a health data privacy policy that clearly and conspicuously discloses specified information. Sets forth provisions concerning health data privacy policies. Provides that a regulated entity shall not collect, share, or store health data, except in specified circumstances. Provides that it is unlawful for any person to sell or offer to sell health data concerning an individual without first obtaining valid authorization from the individual. Provides that a valid authorization to sell individual health data must contain specified information; a copy of the signed valid authorization must be provided to the individual; and the seller and purchaser of health data must retain a copy of all valid authorizations for sale of health data for 6 years after the date of its signature or the date when it was last in effect, whichever is later. Sets forth provisions concerning the consent required for collection, sharing, and storage of health data. Provides that an individual has the right to withdraw consent from the processing of the individual's health data. Provides that it is unlawful for a regulated entity to engage in discriminatory practices against individuals solely because they have not provided consent to the processing of their health data or have exercised any other rights provided by the provisions or guaranteed by law. Sets forth provisions concerning an individual's right to confirm whether a regulated entity is collecting, selling, sharing, or storing any of the individual's health data; an individual's right to have the individual's health data that is collected by a regulated entity deleted; prohibitions regarding geofencing; and individual health data security. Provides that any person aggrieved by a violation of the provisions shall have a right of action in a State circuit court or as a supplemental claim in federal district court against an offending party. Provides that the Attorney General may enforce a violation of the provisions as an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act. Defines terms. Makes a conforming change in the Consumer Fraud and Deceptive Business Practices Act.

AI Summary

This bill establishes comprehensive privacy protections for health data in Illinois, creating the Protect Health Data Privacy Act. The legislation requires regulated entities (businesses processing health data in Illinois) to disclose detailed health data privacy policies that clearly explain what data is collected, how it's used, and with whom it's shared. The bill mandates that businesses can only collect, process, or sell an individual's health data with explicit, informed consent, and provides individuals with several key rights, including the ability to confirm what health data is being collected about them, request deletion of their data, and withdraw consent at any time. The bill prohibits discriminatory practices against individuals who choose not to share their health data and restricts businesses from using geofencing technologies around healthcare facilities to track or collect data about individuals seeking health services. Importantly, the law allows individuals who believe their health data privacy rights have been violated to seek legal recourse, with potential damages ranging from $1,000 to $5,000 per violation, depending on whether the violation was negligent or intentional. The Attorney General is also empowered to enforce the act, treating violations as deceptive business practices. The bill applies to businesses operating in Illinois and aims to give residents greater control and transparency over their sensitive health information.

Committee Categories

Government Affairs

Sponsors (1)

Last Action

Rule 2-10 Committee Deadline Established As March 27, 2026 (on 03/13/2026)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...