HB3494 creates the Protect Health Data Privacy Act, a new Illinois privacy law focused on health-related information collected by businesses and other non-governmental entities that process health data. The bill requires covered entities to publish a clear health data privacy policy, limits when they may collect, use, share, store, or sell health data, and generally requires affirmative, opt-in consent before processing health data except where strictly necessary to provide a requested product or service. It also bars the sale of health data without a separate valid authorization, sets detailed content requirements for that authorization, and gives individuals the right to withdraw consent.
The bill also creates individual rights to confirm whether a regulated entity is handling a person’s health data, to request deletion of that data, and to receive notice when data is shared with processors or third parties. It includes restrictions on geofencing near health care facilities, security and data-minimization requirements, and limits on disclosures to government agencies and law enforcement except in specified circumstances such as a valid warrant or other lawful request. Enforcement would be available both through a private right of action and by the Illinois Attorney General under the Consumer Fraud and Deceptive Business Practices Act.
HB3494 would add a new Article/Section 2HHHH to the Consumer Fraud and Deceptive Business Practices Act and create a standalone statutory framework governing health data privacy in Illinois. It would impose new compliance obligations on regulated entities doing business in the state or offering products or services to Illinois residents, while carving out certain entities already covered by HIPAA, GLBA, and specified insurance and government-related confidentiality regimes. The bill would also create new civil remedies, including statutory damages, attorney’s fees, injunctive relief, and Attorney General enforcement authority.
No committee transcripts or recorded votes were provided, so there is no direct evidence of legislative debate or formal support/opposition in the available record. Based on the bill text alone, the measure appears strongly privacy-protective and consumer-oriented, with a clear emphasis on limiting commercial use of sensitive health information and giving individuals control over consent, deletion, and disclosure. The overall framing suggests a policy goal of expanding privacy rights rather than loosening regulation.
The most likely points of contention are the bill’s broad restrictions on data collection, sharing, and sale; its requirement for affirmative consent; and its private right of action with statutory damages, all of which could increase compliance and litigation exposure for businesses that handle health-related data. Another likely area of debate is the scope of the definition of “health data,” which reaches information derived from non-health data and used in advertising, marketing, or health-service provision, potentially covering a wide range of digital and location-based activity. The geofencing ban and limits on law-enforcement access may also draw concern from technology, advertising, and public-safety stakeholders, while consumer privacy advocates would likely support those provisions.