CiberLATAMbywhalemate

US Congress weighs CISA, PROOF and health privacy

Congress faces CISA deadlines and new bills on cyber threat sharing, federal surveillance and health data.

Whalemate Labs · AI-assisted researchPublished:3 min read

Key provisions of the 2015 Cybersecurity Information Sharing Act, which let federal agencies and private companies exchange threat data in the United States, are set to expire on December 11, 2026 if Congress does not act. At the same time, the PROOF Act is moving through the legislative agenda, the PRIVACY Act is under debate on federal surveillance, and S.3097 on health data remains in process.

Key provisions of the 2015 Cybersecurity Information Sharing Act, which allow threat information to be shared between federal agencies and private companies in the United States, are scheduled to expire on December 11, 2026 if Congress does not act. At the same time, lawmakers are weighing renewal of those rules, a bill on federal data surveillance, and a privacy overhaul for health information, with no clear legislative outcome yet.

What is happening with the 2015 CISA?

According to Legis1.com, the core provisions of CISA expire on December 11, 2026 unless Congress renews, changes, or lets them lapse. Security Magazine also reported that the House approved a temporary extension through that date, so the framework remains in place only on a transitional basis.

Legis1.com says several options are being discussed on Capitol Hill, including renewing the cyber threat information-sharing rules, adding privacy and liability reforms, or allowing the law to expire. The same coverage warns that if the provisions lapse, explicit liability and disclosure protections would also disappear, protections that currently encourage companies and critical infrastructure operators to share indicators with the government.

What is moving on data privacy?

ConsentPixel describes the most advanced attempt at a comprehensive federal data privacy law, the ADPPA, as having passed committee in 2022, failing to reach the floor, and expiring in January 2025 without being reintroduced until September 2026. That leaves the United States, according to the same source, without a federal comprehensive law equivalent to the GDPR.

ConsentPixel adds that there is no broad federal bill at that moment with a clear path to passage in the near term, so companies must plan around a patchwork of state privacy laws at least through 2028. For multinationals with operations in Latin America, that means tracking not only federal rules, but also state requirements that can intersect with their data flows.

What does S.3097 bring on health data?

S.3097, called the Health Information Privacy Reform Act, was introduced in the Senate to modernize health information privacy with a data-type-focused approach. HealthPoint says the proposal would impose security and privacy obligations on any entity handling health data, and add rights such as erasure and written consent for marketing based on health information.

JD Supra adds that the bill advanced out of committee by a 22-0 vote and directs HHS, in consultation with the FTC, to issue privacy, security, and breach-notification standards for applicable health information not covered by HIPAA, including data from wearables, health apps, and other consumer technologies. The same coverage says it also includes minimization, access, correction, deletion, portability, and limits on transferring that information to government entities without compulsory legal process.

What do the PROOF Act and PRIVACY Act add?

The PROOF Act, identified as H.R.10326, seeks to improve the detection and prosecution of fraud in federal programs administered by state agencies, authorizing the Attorney General to request specific information and requiring security and privacy measures such as encryption, restricted access, and mandatory data destruction when investigations end.

The House page for H.Res.1530 says the resolution sets the procedure for bringing that bill to the floor, and a The Capitol Wire report adds that it requires state agencies to share specific data when requested for fraud investigations. At the same time, the Idaho State Journal reported that Russ Fulcher co-sponsored the PRIVACY Act of 2026 in September 2026, a bill that limits how federal agencies can use data generated by automatic license plate readers and cameras that capture vehicle occupants.

The official text of H.R.9716 says covered surveillance information cannot be kept for more than 30 days unless a court authorizes an additional 90 days for good cause or the data is already evidence in an ongoing criminal case. It also says that if the data is obtained or retained in violation of the warrant rule or the retention limits, it cannot be admitted as evidence in federal proceedings.

Sources

View all