Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Health Data Governance topic

No spam. Unsubscribe anytime.

Committee hears proposed changes to health data authority law, including longer repeal and stronger privacy safeguards

6685338 · October 15, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislators and DHHS staff described a draft bill to extend the Health Data Authority Act repeal date, require a strategic plan for data collection and strengthen privacy measures such as opt-outs and limits on identifiable data.

A state legislator and Department of Health and Human Services staff briefed the Health and Human Services Committee on a draft bill that would revise the Health Data Authority Act to strengthen privacy protections, require strategic planning for data collection and move the statutory repeal date farther into the future.

Representative Thurston said the proposal responds to a legislative audit and prior sunset review and is intended to address gaps in strategic direction and privacy. DHHS data staff described specific changes: “The bill before you has a few key changes. The first is just to move that repeal date currently drafted in is moving it from 2026 to 2036,” an agency official told the committee.

The department said the bill would replace the existing health data plan requirement with a required strategic plan to clarify why each dataset is collected, who provides it, how it will be used and how it will be protected. Staff described prior audit findings that the dataset was underutilized and noted examples where the all-payer claims database and hospital discharge data have informed policy questions, including counts used to study dental cavities and hormone-related therapy prevalence.

On privacy, staff said the program already uses de-identification and strict review for requests that would release identifiable information. One staff member said the department reviewed nearly 292 recent use cases and found that about 99% “involved de-identified data,” and that identifiable releases are rare and subject to a rigorous institutional review board and departmental approvals.

Committee members asked about opt-in/opt-out procedures, which the presenters said are possible and are contemplated in the draft; staff said federal rules allow opt-in in some instances and institutional-review-board-reviewed exceptions in others. Officials also described data coverage: hospital discharge data is a census (reported by hospital administrators) and is comprehensive; the all-payer claims database covers an estimated 60–70% of the population because federal law preempts collection from certain payers and does not capture the uninsured.

The presentation was informational; the sponsor said he sought feedback rather than a committee vote at the meeting.