{"id":4786,"date":"2022-09-22T20:05:38","date_gmt":"2022-09-23T01:05:38","guid":{"rendered":"https:\/\/blogs.luc.edu\/compliance\/?p=4786"},"modified":"2022-09-22T20:05:38","modified_gmt":"2022-09-23T01:05:38","slug":"imperative-progress-in-your-data-privacy-and-protection","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=4786","title":{"rendered":"Imperative Progress in Your Data Privacy and Protection"},"content":{"rendered":"<p><em>Amanda Scott<\/em><\/p>\n<p><em>Associate Editor<\/em><\/p>\n<p><em>Loyola University Chicago School of Law, JD 2024<\/em><\/p>\n<p>In June 2022, a draft of a bipartisan bicameral bill known as the <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">American Data Privacy and Protection Act was introduced<\/a>. This bill was proposed as a replacement to current laws to further protect and strengthen federal data privacy and protection regulations. This Act serves as a melting pot for pre-existing state-level data privacy and protection laws. The guidelines created by this bill include providing consumers with foundational data privacy rights, strengthening oversight mechanisms, and establishing meaningful enforcement. Moreover, this bill was regarded as \u201canother major step in putting people back in control of their data and strengthening our nation\u2019s privacy and data security protection\u201d by the <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">Energy and Commerce Committee <\/a>Chair Frank Pallone, D-N.J., Ranking Member Cathy McMorris Rodgers, R-Wash., in addition to Subcommittee on Consumer Protection and Commerce leaders Jan Schakowsky, D-Ill., and Gust Bilirakis, R-Fla.<\/p>\n<p><!--more--><\/p>\n<p><strong>What the Act protects<\/strong><\/p>\n<p>The American Data Privacy and Protection Act (ADPPA) is structured to protect data that is known as \u201c<a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">covered<\/a>.\u201d <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">Covered<\/a> data is defined as information that either identifies an individual or is linked or reasonably linkable in any capacity to an individual. Within this <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">umbrella term<\/a> lies mass amounts of personal data, notably including health records. This is suggestive that the proposed Act would provide individuals with rights over their personal healthcare data. Inclusive of this is the autonomy to have data deleted, restricted, or corrected. Yet, the <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">Act<\/a> does not protect government entities, including de-identified data, employee data, and publicly available information. This Act does however reach \u201c<a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">sensitive covered data<\/a>.\u201d Sensitive covered data is any information regarding health records from the past, present, or future. In essence, this <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">bill<\/a> requires affirmative express consent before an ADPPA-covered entity is allowed to collect and process healthcare data or transfer it to another entity. This provides people with nearly outright control of their healthcare records. On a grand scale, ADPPA-covered entities will have their data significantly more guarded.<\/p>\n<p><strong>Transparent consumer data rights<\/strong><\/p>\n<p>Protection of consumer data in the healthcare field and beyond begins with consumer awareness and transparency. The Commission is set to publish this Act within <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">90 days<\/a> of it being enacted, detailing each provision, and providing updates. This includes elaboration on how the <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">Act<\/a> details individual data ownership and control, the right to consent and object, data protections for children and minors, third-party collecting entities, civil rights and algorithms, data security and protection of covered data, small business protections, and unified opt-out mechanisms. Among this <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">data<\/a> is the transfer of precise geolocation, browsing history, and physical activity collected from devices. By providing total transparency with this extensive information, the ADPPA is striving to allow for all consumers to have more education and therefore more control over their data. Largely, the proposed Act is designed to enhance the protection of consumer data rights and be transparent about what data is collected.<\/p>\n<p><strong>Corporate accountability and applicability<\/strong><\/p>\n<p>The ADPPA is structured to protect consumers by creating a deeper sense of accountability and enforceability for those responsible for data transmission. Regarding corporate accountability, this <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">Act<\/a> details executive responsibility, service providers and third parties, technical compliance programs, the commission-approved compliance guidelines, and digital content forgeries. This is immensely important in holding hospitals accountable for upholding healthcare data privacy. An additional step the ADPPA has taken towards accomplishing this goal is requiring <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">privacy policies<\/a> to be made public, including those that entail the entity\u2019s data collection, processing, and transfer activities. This is yet another way the Act is designed to provide transparency. Furthermore, entities which are <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">ADPPA-covered<\/a> would be unable to deny someone a service or product because they refused to waive any privacy rights.<\/p>\n<p>In like manner, this <a href=\"https:\/\/energycommerce.house.gov\/sites\/democrats.energycommerce.house.gov\/files\/documents\/BILLS-117hr8152ih.pdf\">Act<\/a> emphasizes enforcement by all levels ranging from the federal trade commission, state attorneys general, and individuals. It also touches on the relationship between federal and state laws as well as severability, COPPA, authorization of appropriations, and effective date. Regarding healthcare organizations, those entities which are compliant with <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">HIPAA<\/a> are viewed as compliant with the ADPPA. However, they are only compliant in relation with the laws covering the <a href=\"https:\/\/www.hipaajournal.com\/american-data-privacy-and-protection-act\/\">data<\/a>. While, as of September 2022, this bill has not yet been passed, bills of its kind and those of similar nature are positive steps froward in strengthening personal and healthcare data security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Amanda Scott Associate Editor Loyola University Chicago School of Law, JD 2024 In June 2022, a draft of a bipartisan bicameral bill known as the American Data Privacy and Protection Act was introduced. This bill was proposed as a replacement to current laws to further protect and strengthen federal data privacy and protection regulations. This &#8230;<br \/><a class=\"read-more-link btn btn-outline-secondary\" href=\"https:\/\/blogs.luc.edu\/compliance\/?p=4786\">Read more<\/a><\/p>\n","protected":false},"author":119,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[571,1205,1623],"class_list":["post-4786","post","type-post","status-publish","format-standard","hentry","category-hipaa-health-information","tag-data-privacy","tag-journal-of-regulatory-compliance","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/4786","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/119"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4786"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/4786\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}