Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Health Data Policy topic
No spam. Unsubscribe anytime.
Committee advances health-data bill with new re-identification protections after debate on cybersecurity and opt-outs
Summary
After debate and public comment about privacy and cyber-risk, a House committee on March 4 adopted Amendment 1 to HB 199 (requiring a department plan to prevent re-identification) and then favorably recommended the bill as amended to the House; members expressed concerns about cybersecurity safeguards and citizen opt-out enforcement.
Get email alerts on the Health Data Policy topic
No spam. Unsubscribe anytime.
A House committee on March 4 adopted Amendment 1 and then favorably recommended HB 199, a department-request bill to extend and strengthen Utah's Health Data Authority Act and add new privacy protections.
Representative Thurston described the bill as a response to an audit recommending better strategic planning, privacy protocols and clearer operational use of the state's longstanding health-data collections. Department witnesses said the program helps answer policy questions — from fluoridation impacts to cost drivers in health care — while the bill would require a strategic plan and set stricter limits on sharing direct identifiers.
Kyle Lund, the department's data director, told the committee the program already prioritizes releasing "the minimum necessary" data under HIPAA safe-harbor standards and that the bill clarifies sharing only for authorized public entities. Department officials said most routine requests can be met with de-identified or limited datasets.
Committee members pressed the department on cybersecurity and re-identification risks after public commenters recounted identity-theft experiences. "We have to make sure that that is consciously front of mind," the sponsor said when describing Amendment 1, which requires the department to publish actions to prevent individual re-identification as part of its strategic plan. The committee adopted Amendment 1 by voice vote.
Some committee members remained concerned about expanding data sharing without added cybersecurity guarantees; one member requested a 'hold' to negotiate further protections but that procedural motion failed on a tie vote. On a subsequent roll call, the committee voted 5–3 to favorably recommend HB 199 as amended to the full House; three members voted against moving the bill forward.
Supporters said a strengthened, transparent strategic plan would improve use of existing data to detect fraud, measure costs and inform policy. Critics and several members asked for clearer, enumerated cybersecurity assurances and operational detail to ensure opt-outs are enforced and to limit re-identification risk.
The bill will now proceed to the House for consideration with the committee-adopted re-identification planning requirement.
