Bill
Bill > A6164
NJ A6164
NJ A6164Establishes certain data privacy protection requirements for consumer health data, health care providers, and patients.
summary
Introduced
12/04/2025
12/04/2025
In Committee
12/04/2025
12/04/2025
Crossed Over
Passed
Dead
01/12/2026
01/12/2026
Introduced Session
2024-2025 Regular Session
Bill Summary
This bill establishes certain data privacy protection requirements for consumer health data, health care providers, and patients. The bill defines a "regulated entity" to mean any legal entity that: conducts business in New Jersey, or produces or provides products or services that are targeted to consumers in New Jersey; and alone or jointly with others, determines the purpose and means of collecting, processing, sharing, or selling of consumer health data. "Regulated entity" does not mean a government agency, tribal nation, or contracted service provider when processing consumer health data on behalf of the government agency. Under the bill, each regulated entity in the State is to maintain a consumer health data privacy policy that details how data may be collected and shared and how consumer can exercise their rights provided by the bill concerning consumer health data. "Consumer health data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. The bill establishes certain requirements for regulated entities to collect, share, and sell consumer health data, which includes requiring consumers to provide consent or authorization in order for a regulated entity to collect, share, or sell any consumer health data. Under the bill, consumers will have certain rights concerning their consumer health data, including: confirming which data is being collected, shared, or sold; withdrawing consent for the collection, sharing, or sale of the data; or requesting the deletion of the data. The bill establishes certain requirements for regulated entities to process any requests for the deletion of a consumer's consumer health data. The bill requires a regulated entity to restrict access to consumer health data as necessary and to establish certain data security practice to protect consumer health data. The bill provides that a processer may process consumer health data only pursuant to a binding contract between the processor and the regulated entity that sets forth the processing instructions and limits the actions the processor may take with respect to the consumer health data it processes on behalf of the regulated entity. The bill prohibits any person from implementing a geofence around an entity that provides in-person health care services where such geofence would be used to: identify or track consumers seeking health care services; collect consumer health data from consumers; or send notifications, messages, or advertisements to consumers related to their consumer health data or health care services. The bill provides that any violation of bill's provisions will be considered an unlawful practice in violation of P.L.1960, c.39 (C.56:8-1 et seq.) The bill outlines certain entities and types of information and data that are exempted from the provisions of the bill. The bill provides that nothing in the bill's provisions is to construed to restrict a regulated entity's or processor's ability for the collection, use, or disclosure of consumer health data to prevent, detect, protect against, or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activities, or any activity that is illegal under State law or federal law; preserve the integrity or security of systems; or investigate, report, or prosecute those responsible for any such action that is illegal under State law or federal law, except that such entity bears the burden of demonstrating that such processing qualifies for the exemption provided under the bill.
AI Summary
This bill establishes comprehensive data privacy protection requirements for consumer health data in New Jersey, creating strict rules for how businesses (referred to as "regulated entities") can collect, use, share, and sell sensitive health information. The bill requires regulated entities to maintain a clear privacy policy, obtain explicit consumer consent before collecting or sharing health data, and provide consumers with rights to access, confirm, withdraw consent for, and delete their health data. Notably, the bill prohibits implementing geofences around healthcare facilities to track or collect health-related information and requires detailed authorization for selling consumer health data, including specific consent documentation. The legislation covers a broad range of health-related information, from medical conditions and treatments to reproductive health services and genetic data, and applies to businesses conducting business in New Jersey or targeting New Jersey consumers. The bill provides consumers with robust protections, including the right to know what health data is being collected, the ability to request deletion, and safeguards against discriminatory practices. Violations of the bill's provisions will be considered unlawful practices, subject to potential legal penalties, with some exemptions for specific types of organizations and data uses.
Committee Categories
Health and Social Services
Sponsors (2)
Last Action
Introduced, Referred to Assembly Health Committee (on 12/04/2025)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
| Document Type | Source Location |
|---|---|
| State Bill Page | https://www.njleg.state.nj.us/bill-search/2024/A6164 |
| BillText | https://pub.njleg.gov/Bills/2024/A6500/6164_I1.HTM |
Loading...