CiberLATAMbywhalemate

US Senate advances HIPRA, water cyber bills

HIPRA moved out of Senate committee, while the GUARD Financial Data Act added new rules on minimization, opt-out, access

Whalemate Labs · AI-assisted researchPublished:Updated 5 min read

The Senate advanced HIPRA, while the GUARD Financial Data Act tracking added new requirements on minimization, continuous opt-out, access and deletion of financial data. Meanwhile, the Water Cyber Shield Act and Josh Gottheimer’s bill for water and electric utilities remain under consideration.

Update August 23, 2026: Legislative tracking for the GUARD Financial Data Act added substantive requirements beyond the 1999 GLBA framework, including data minimization rules, continuous opt-out, limits on aggregator use of credentials, greater transparency, access, deletion and opt-in for sensitive financial information. HIPRA was also updated after it cleared the Senate HELP Committee by a unanimous vote.

The U.S. Senate moved the Health Information Privacy Reform Act, or HIPRA, while Amy Klobuchar and Adam Schiff introduced the Water Cyber Shield Act to strengthen cybersecurity for drinking water and wastewater infrastructure. At the same time, Josh Gottheimer introduced a bipartisan bill to create a CISA rapid-response and threat-notification service for small and mid-sized water and electric utilities.

What happened to HIPRA in the Senate?

The Senate HELP Committee voted unanimously, 22-0, to send HIPRA out of committee and into the next stage of the legislative process. The bill, led by Bill Cassidy and Maggie Hassan, remains focused on protecting private health data and imposing stricter rules on minimization, retention and de-identification.

The proposal says regulated entities and service providers would not be allowed to collect, process or retain applicable health information beyond what is reasonably necessary, with narrow exceptions to complete requested transactions, comply with the law, prevent fraud and conduct research overseen by an institutional review board, or IRB.

HIPRA also raises the de-identification standard. For data to count as de-identified under the new law, the safe harbor method under HIPAA would no longer be enough on its own. At least an expert determination would also be required. The bill further instructs the Department of Health and Human Services, HHS, to issue implementing regulations within 18 months of enactment.

An independent legal analysis warned that once the bill cleared committee, companies that collect, use or monetize consumer health data, including wearables, health apps, AI developers and data brokers, should review the draft’s impact on minimization, retention, authorization, geolocation, deletion and de-identification.

What changes for drinking water and wastewater?

The Water Cyber Shield Act would extend federal cyber incident reporting requirements to state and local drinking water and wastewater systems that are currently exempt from notification duties. According to the announcement by Klobuchar and Schiff, the bill would align those systems with CIRCIA’s future reporting obligations.

According to the analysis cited, the bill would also tie water and wastewater utilities to the strict reporting requirements expected under CIRCIA’s future rule, and bring cybersecurity into their resilience planning frameworks.

In the version already released, the Environmental Protection Agency, or EPA, would retain authority to assess water systems for cyber risk and require fixes from utilities when problems are identified. The EPA would also be expected to work with CISA and NIST to set baseline cybersecurity standards for drinking water systems, using a tiered approach based on each system’s risk and capacity.

The proposal also says states with sufficient capacity could take primary responsibility for enforcing those requirements, and it sets aside $300 million a year, routed through the Drinking Water and Clean Water State Revolving Funds, to support cybersecurity upgrades at utilities.

Klobuchar’s announcement added that cybersecurity assessments for large water systems would be folded into existing resilience planning, and that sensitive cybersecurity information submitted by utilities would be shielded from public disclosure.

What is Gottheimer proposing for smaller utilities?

Josh Gottheimer announced on August 12, 2026, a bipartisan bill, the Securing Our Critical Infrastructure Act, to create a dedicated CISA rapid-response and threat-notification service aimed specifically at small and mid-sized water and electric utilities in the United States. The measure is co-sponsored by Don Bacon, Zach Nunn, Hilary Scholten and Greg Landsman.

The text calls for a single point of contact at CISA to provide immediate notice of active threats and operational support to systems with fewer resources. The goal is to speed up incident response and focus federal assistance on utilities that do not always have their own security teams.

What changed in financial privacy?

Tracking for H.R. 8398, the GUARD Financial Data Act, added substantive obligations beyond the 1999 GLBA framework. Those include data minimization rules, ongoing consumer opt-out rights, limits on financial data aggregators’ use of access credentials, stronger transparency requirements around processing purposes, new rights to access and delete data, and express opt-in consent for handling or disclosing sensitive financial information.

The change broadens the financial privacy debate beyond traditional GLBA protections, since the bill tracking now spells out operational limits on collection, use and disclosure, along with additional consumer rights for entities and aggregators that handle financial information.

What is next for privacy and age verification?

Another active front in Congress is the SCREEN Act, approved by the Senate Commerce Committee in a 15-13 vote, although the vote was technically stalled because there were not enough members physically present for quorum. The bill is still alive pending another procedural vote.

The measure would require almost any website with sexually explicit content to verify each user’s age with real identity data before granting access. It would also ban self-certification through checkbox confirmations and require third-party identity verification services. Additional coverage said the text also targets IP addresses and VPNs as part of the verification flow, which would expand its operational impact on services with sensitive or geographically blocked content.

The Electronic Frontier Foundation warned that mandatory age-verification systems tend to move down the technology stack and end up covering more services and users.

What other initiatives are still moving?

The Congressional Research Service said the United States still does not have a comprehensive federal data privacy law, although some members of Congress have introduced broad privacy bills with minimization and transparency obligations for data collection practices that are still moving through the process. That group includes AI and minors-related proposals such as the Youth AI Privacy Act, which would bar chatbot operators from processing minors’ personal data for profiling or algorithm training, along with the CHATBOT Act, the KIDS Act and the SAFE BOTs Act.

In the same legislative track, the SAFE Act is listed as a Senate committee bill with no vote scheduled, and its last recorded action was referral to the Judiciary Committee.

Sources

View all