SB2273 creates the Protect Health Data Privacy Act, a new Illinois privacy law focused specifically on “health data” collected outside traditional HIPAA-covered settings. The bill requires regulated entities that process health data to publish a clear privacy policy describing what data they collect, how they use it, who they share or sell it to, how long they keep it, and how consumers can exercise their rights. It also limits collection, sharing, storage, and sale of health data to narrow circumstances, generally requiring affirmative, informed consent or a showing that the data use is strictly necessary to provide a requested product or service.
The bill gives individuals several enforceable rights over their health data, including the right to confirm whether data is being collected, sold, shared, or stored; the right to withdraw consent; and the right to request deletion, subject to specified exceptions for legal compliance, security, research, and litigation holds. It also prohibits geofencing around health care facilities for tracking or targeted advertising purposes, restricts discriminatory treatment based on a person’s refusal to consent, and limits disclosure to government agencies and law enforcement absent a warrant or the individual’s request. Enforcement is available both through private lawsuits and by the Illinois Attorney General under the Consumer Fraud and Deceptive Business Practices Act, with a conforming amendment to that Act.
The bill’s impact on state law would be significant because it adds a standalone privacy regime for health-related information and expands consumer protections beyond existing health privacy laws. It would apply to many businesses that handle health data in Illinois, including digital platforms, advertisers, data brokers, and other non-HIPAA entities, while carving out government agencies and certain entities already regulated under HIPAA, GLBA, and specified insurance laws. It also creates new compliance obligations, record-retention requirements for authorizations, and potential civil liability for violations.
Because there are no committee transcripts or recorded votes provided, there is no documented legislative debate or voting history to gauge formal sentiment. Based on the bill text alone, the measure appears strongly privacy-protective and consumer-oriented, with a clear emphasis on informed consent, data minimization, and limits on commercial exploitation of sensitive health information. The structure of the bill suggests an intent to give individuals meaningful control over health-related data practices and to deter misuse through both regulatory and private enforcement.
The main points of contention likely would involve the breadth of the definition of health data, the strict opt-in and deletion requirements, the ban on geofencing near health care locations, and the private right of action with statutory damages. Businesses that rely on analytics, targeted advertising, data sharing, or third-party processing may view the bill as operationally burdensome or overbroad, while privacy advocates would likely support the stronger consent and anti-discrimination protections. The bill also carefully preserves certain existing legal regimes, which may reduce conflict but could still raise questions about scope and compliance for entities operating across multiple regulatory frameworks.
SB2273 would add a new Article 2HHHH to the Consumer Fraud and Deceptive Business Practices Act and create a new standalone Protect Health Data Privacy Act governing non-HIPAA health data practices in Illinois. It would impose notice, consent, retention, deletion, security, anti-discrimination, and geofencing restrictions on regulated entities that conduct business in Illinois or offer products or services to Illinois residents, while exempting certain government, HIPAA-covered, GLBA-covered, and insurance-regulated entities. The bill also authorizes private lawsuits and Attorney General enforcement, making violations actionable under state consumer protection law.
No committee discussion or vote history is provided, so there is no recorded legislative sentiment to summarize from debate or roll calls. From the bill text itself, the measure reflects a strong pro-privacy, pro-consumer policy approach, emphasizing affirmative consent, transparency, and control over sensitive health information. Its design suggests support from privacy and civil liberties advocates, while likely drawing concern from industry stakeholders affected by data collection, advertising, analytics, and sharing restrictions.
Likely points of contention include the bill’s broad definition of health data, its requirement for express opt-in consent before processing or sale, the deletion and confirmation rights, and the prohibition on geofencing around health care facilities. Businesses and data intermediaries may object to the compliance burden, recordkeeping requirements, and exposure to statutory damages and private litigation. Privacy advocates would likely favor these provisions, especially the limits on sale, targeted advertising, and government access to health data without a warrant.