Sensitive Healthcare Information

Biometric data faces new limits in Rhode Island

The bill would put fingerprints, iris scans and other identifying traits under the same privacy rules as sensitive health data. Firms could not quietly add new collection or sharing uses without a clear opt-in.

2 min read·495 words·View source
Biometric data faces new limits in Rhode Island
1 / 3
Photo by Cedric Fauntleroy on Pexels

Rhode Island’s proposal goes beyond clinic records and into the data businesses gather from devices and websites. It would require clearer notices, stronger consent and more limits on sharing covered health information.

  • Covers biometric data like fingerprints, voice patterns and gait
  • Reaches reproductive, sexual and gender-affirming care information
  • Would require disclosure and affirmative consent for new uses of covered data
  • Related companies with shared branding would not get a free pass
  • People looking up reproductive care, sexual health services or gender-affirming care could soon have more control over the digital trail they leave behind

People looking up reproductive care, sexual health services or gender-affirming care could soon have more control over the digital trail they leave behind. lawmakers are adding a new chapter to Title 23, the , and it is aimed at companies that collect consumer health data from ers.

That matters because the bill is not limited to medical records inside a clinic. It reaches consumer health data, biometric data and related information that can identify a person or reveal sensitive health interests, including precise location data tied to care-seeking behavior.

What the new line covers

The bill treats biometric data as information generated from a person’s physical, biological or behavioral traits that can identify them, alone or with other data. The list is broad: iris imagery, fingerprints, voice patterns, vein patterns, keystroke rhythms and even gait can fall inside it.

Consumer health data is defined just as widely. It includes reproductive or sexual health information, gender-affirming care information and data inferred from other information, which means a company could not simply say it never asked the question if it learned the answer another way. The proposal also defines an affiliate as a legal entity that shares common branding and controls, is controlled by, or is under common control with another entity.

Consent becomes the gate

The practical effect is simple enough to recognize even if the legal language is dense. If a company wants to gather, use or share covered health data for additional purposes, it would have to disclose that use first and get affirmative consent. The bill also says a company’s privacy policy would need to spell out what it collects, where it gets it, what it shares and which third parties and affiliates can see it.

It also defines authenticate as using reasonable means to verify that a request is coming from the consumer, or from someone authorized to act for that consumer. That detail matters because it is the difference between a real request for control and a form letter from someone claiming to speak for you. For privacy-minded users, the proposal is trying to replace default data sharing with a clearer choice about who gets access to the most personal parts of a person’s life.

Sources

Synthesized from 12 verified citationsSynthesized by AI linked to original documents.

goflashCover everything