Tuesday, September 1, 2026
Overview
Kirk Nahra of WilmerHale, one of the nation’s leading healthcare privacy experts, explains why the Health Insurance Portability and Accountability Act is not an overall healthcare privacy rule—it reaches only covered entities such as doctors, hospitals, pharmacies, health insurers, and their business associates, leaving wearables, mobile health apps, personal health records, patient support groups, and social media outside it—and how post-Dobbs consumer health data laws, state comprehensive privacy laws, and HIPAA-like state statutes now sweep in location, income, and marital status as health data, producing what Nahra calls “a growing mess” and “too much law without a coherent overall approach.”
Speaker(s)
Kirk Nahra, Partner, WilmerHale; Co-Chair AI Practice & Cybersecurity & Privacy Practice
Keywords
HIPAA • covered entities and business associates • health data outside HIPAA • consumer health data laws • My Health My Data Act • Dobbs-related state laws • CCPA exemptions • CMIA • inferences about health • location data as health information • national privacy law • “what health information is not protected by HIPAA”
B-CLE Recording (CLE: $50) | Youtube Recording | Resource(s) | Speaker Bio(s) & Contact Info
Download the interview/transcript and slides here!
Interview/Transcript
This interview/transcript is the final of a three part series on Health Care Privacy 101. On September 1, 2026, Kirk Nahra of WilmerHale addresses health care privacy beyond HIPPA.
Wayne Stacy 00:29
Welcome, everyone, to the Berkeley Center for Law and Technology’s Expert Series webcast. We have a session three today of a really interesting series of programs. You know we don’t try to do long programs, but this material is so broad, and there’s so much here. We had to break this up, and Kirk was nice enough to donate time to us to make this happen. So, everyone, again, you’ve got Kirk Nahra from WilmerHale, he is not only a partner at WilmerHale, if you look at his bio, basically every leadership position in cybersecurity and privacy practice he holds. So, you get one of the nation’s leading experts on this in one of the more prickly areas of privacy law that I can imagine. So, with that, Kirk, I want to turn this over to you and let you lead us into session three of our program.
Kirk Nahra 01:32
Great, Wayne. Thank you. Thank you very much. I appreciate the kind introduction. I was reminded of a recent program I did where I was introduced with you know nice stuff, and somebody said I was the leading expert on HIPAA [Health Insurance Portability and Accountability Act] in the United States, if not the world. And I turned to the audience and I said, I’m pretty sure there’s nobody in Bolivia that’s better on HIPAA than I. So, I thought that was sort of an unuseful way to expand my knowledge there. But all right. So, here’s what we’re going to do today. We have talked so far in the first two sessions that Wayne mentioned about both the history of the HIPAA rules, why HIPAA isn’t everything in healthcare privacy, how we got to where it is today, give you a sense of what the primary provisions of HIPAA are, but to really give you a sense of its scope, both in terms of where it does apply, but equally as important in where it doesn’t apply. So, what we’re going to focus on today is, you know, in a somewhat cursory way, because this could be, you know, a multi session discussion on its own. We’re going to try to put the HIPAA in the context of the overall field of healthcare privacy, the growing body of law, particularly in the United States, often at the state level, not entirely at the state level, where we’re seeing more and more regulation of healthcare privacy issues that is not HIPAA. It’s different from HIPAA in general, and I’ll hope to explain this to you over the course of the next half hour or so. I think the field is becoming a growing mess. That continues to be the case and is increasing as more and more laws are getting passed, so I think it’s in fact getting worse. I do think we’ll talk about a little bit today. I am at the point in thinking about this field where I am meaningfully concerned that the overall law of healthcare privacy is actually getting in the way of having a good working healthcare system. Something we should obviously be concerned about. Privacy law is designed to provide protections for individuals and certain rights that they have. However, if the exercise of those rights or the provisions of new law to protect those rights results in a bad or a worse healthcare system, I don’t think that’s necessarily a win, or at least it’s a much more complicated discussion than we’re having today. So that’s the bad news. Field is a growing mess. The good news is I’m still looking for the good news. So we’re not necessarily there yet. But again, I want to give you a sense of where we are in this discussion today, why I’m even talking about it in this way.
Kirk Nahra 04:19
So just a reminder: HIPAA applies to lots of entities. If you tried to put together a slide of everyone who is subject to HIPAA, it’s you know virtually all doctors, it’s all hospitals, it’s all pharmacies, it’s all health insurers, it’s all service providers to those companies called business associates. So, if you’re an accounting firm, you’re a law firm, or a technology firm, and your client is a hospital or health institute, you are subject to HIPAA rules. And most employers who provide health insurance benefits to their employees also have some coverage under the HIPAA rules. That’s very broad. At the same time, it is not a full overall healthcare privacy rule. It applies to healthcare information only where the specific defined categories of covered entities are involved. That’s mostly healthcare providers and health insurers. So, we’ve always known from the beginning of the HIPAA rules, the first session tried to explain why that’s the case, but we’ve always known that there have been gaps where there are entities that have lots of healthcare privacy, or healthcare data, excuse me, not privacy information, healthcare data, but aren’t covered by the HIPAA rules. What we’ve seen in the last few years, it’s been a continuing process, and it you know started the day the HIPAA rules went into effect, is we do see more and more information in growing categories that’s out where this health information outside of HIPAA. Some examples of that: there are websites that gather and distribute healthcare information without the involvement of a covered entity. There are lots of, for example, medical information companies. You can think of them. I don’t need to name any particular company, but you can do research on, you know, how do I know if I have diabetes? And it’ll pop up a number of websites that collect information and have studies and have, you know, common sense information about you can learn about how do I know if I have diabetes? Not covered by the HIPAA rules, generally. There are something called personal health records. These are usually pieces of software that a consumer, an individual, can use to collect that person’s own health records. Think of it as an electronic version of what your parents had as a filing cabinet in their office, where they kept medical records. Particularly useful for people with chronic conditions. Particularly useful for people who have, you know, kids with health challenges, for example. Generally, not subject to the HIPAA rules. There are community and patient support groups all over the country. You know, breast cancer patients of Greater Washington, D.C. You know, community support groups, nonprofits — you know, lots of different disease states. They exist all over the country. None of them are subject to the HIPAA rules. More and more mobile apps see those new ones every day. Wearables, your Apple Watch, your Fitbit has lots of health information about you. Your Apple Watch has a growing range of things that it can do that are health related, but you got your Apple Watch because you went to the Apple store and you bought an Apple Watch. It did not have anything to do with your doctor or your hospital or your health insurer. And then most of the information that’s on, you know, the tech companies have social media. You go on Facebook and you say, Wish me luck. I’m going in for ankle surgery next week. Again, none of that’s protected by the HIPAA rules.
Kirk Nahra 07:43
We are also seeing a related issue that complicates some of this discussion. We are seeing lots of situations where there is information that exists and is created outside of the healthcare system that’s being brought into the healthcare system for use in healthcare activities. Covered entities, again, hospitals, health insurers in particular, are gathering all kinds of data about their patients and their customers and their insureds from outside the healthcare system and bringing it in and then using it for healthcare purposes. A couple of examples just to give you a sense of what I’m talking about, there’s an article that I’ve been using for many years from the New York Times. When a health plan knows how you shop, health plan prediction models using consumer data from data brokers, including income, marital status, and number of cars, to predict emergency room use and urgent care needs. Now, we could have a discussion about income as a health factor. We understand that discussion at the same time. You all know rich people who are sick and poor people who are healthy. So income is at best an indirect indicator. Marital status, maybe that has something to do with your mental health, but it’s hard to see why that’s a health factor. Number of cars. Number of cars. That became a relevant factor for predicting emergency room use and urgent care. Again, I don’t know why that is, but I can tell you there are people doing research that come with these conclusions, and I can tell you that nobody set out to study those three pieces of data. They studied 100 pieces of data and learned that those three happen to have something to do with these healthcare-related situations. So, just very complicated ideas when you’ve got all this information that isn’t really health-related, doesn’t come from the healthcare system, but being brought into the healthcare system. When the data broker collects your marital status or your number of cars. We’re also starting to see more and more legal developments that are turning that information potentially into healthcare information because it might be used to make inferences about you. That’s going to be one of the complicating factors in the overall field that we are doing at this point.
Kirk Nahra 09:58
So, we started off talking about HIPAA and what it is and why it exists the way it is. There was a point in time where, if you wanted to call yourself a healthcare privacy expert, 90 or 95 percent of what you needed to know was actually the HIPAA rules. It was never everything, but it was certainly most of it. It’s still the biggest single thing. I don’t think you want to pretend you are a healthcare privacy expert if you don’t know how the HIPAA rule works, but at the same time, it is certainly not sufficient at this point to just understand HIPAA. Let me give you a sense of this growing body of law, and then we’ll go into some more detail on a couple of these categories. First of all, there are laws in a handful of states, California and Texas being the leading examples, where they have state laws that I call HIPAA-like laws. They were written after the HIPAA rules went into effect. They use a lot of the HIPAA words, but these laws are very confusing and very complicated. They use HIPAA words to apply to people who aren’t doctors, hospitals, and health insurers — it’s very hard to read them and understand what somebody who’s covered by the HIPAA rules should do. What’s different? What’s harder than HIPAA? If it’s less, if it’s less stringent than HIPAA, it shouldn’t apply at all. These rules, these laws, apply to lots of people that aren’t subject to HIPAA and don’t really even have anything directly to do with the healthcare system, so it’s a very bizarre, very complicated set of laws. We are starting to see state comprehensive privacy laws. You’ll learn about those in other kinds of privacy discussions. Those laws all have application to healthcare data and entities that have healthcare data almost exclusively companies who are not subject to the HIPAA rules, but fill in lots of gaps for things that are not regulated by HIPAA. There also are state laws in virtually every state that apply to certain kinds of what we call sensitive conditions. This might be mental health. This might be substance abuse. Might be cancer-related issues. It might be HIV-related issues. All of these laws had a sort of period of time where they tended to be passed. The HIV laws, as you might expect, were not passed in 1950. They weren’t passed in 2015. They were passed at a particular point in time where HIV issues were starting to arise, we didn’t yet have HIPAA rules. We didn’t have appropriate federal protection. Lots of nervousness about privacy protections there, so they were created for a reason. They may or may not still make sense today. We are seeing a variety of state laws related to responding to the Dobbs decision from the Supreme Court on reproductive rights, those are both what we call non-HIPAA consumer health data laws, like the Washington My Health My Data law, as well as a wide variety of laws in other states that are designed to provide additional protections for reproductive rights information. Then we have a separate body of law on medical research, which is applicable to people who participate in clinical trials or whose data is being used in connection with clinical trials. Those rules are both U.S. and global rules. We have a wide variety of other federal laws. We have a Part Two substance abuse rule that goes back again to the 1970s before we had HIPAA, may or may not still make sense today. We have the Americans with Disabilities Act [ADA], which oddly enough became perhaps the primary federal rule that was relevant in connection with COVID issues because so much of COVID was leading to workplace issues, and then you of course have international principles and standards where the law is fundamentally different in every other country in the world on healthcare privacy than it is in the United States.
Kirk Nahra 13:52
So, what we’re seeing in the law, and where part of the complication is coming from, is that we are seeing a growing breadth in what the law treats as healthcare information. Growing breadth of what data can be used or useful in health information, and therefore is often restricted by some of these laws, both for providing healthcare and in a marketing context. And, as you start broadening out what is considered healthcare information, it becomes, in my mind, harder and harder to start thinking of healthcare data as more sensitive than other data. If we start including, for example, your marital status, your number of cars, and your income as healthcare data, and we also start to include what you watch on television and what you buy in the grocery store and things like that. It gets really hard to say that that’s healthcare information that deserves a higher level of sensitivity in the same way that perhaps your HIV or your substance abuse information is. So we have this idea that certainly some healthcare information is more sensitive than other information. Some may not be more sensitive than other information. Some of it may even be other information that you could be used in the healthcare context, and that’s part of the complication. We’ll try to explain how that works in the body of law.
Kirk Nahra 15:15
Let me give you a sense of one of these categories. They’re called consumer health laws. These laws were driven in the first instance by the Dobbs decision, but they do not only apply to reproductive rights information. These laws so far have explicitly excluded entities who are subject to the HIPAA rules. That creates its own kinds of complication, but it applies much broader in terms of what information is there, including imposing restrictions on data that can lead to inferences about your health. So you can probably imagine why, for example, a marketing team would want to know whether you’re active at the gym, whether you buy healthy or unhealthy foods at the grocery store, whether you’ve started buying pants that are three sizes larger than they used to be, whether you buy books about healthy eating, healthy activity, or you know something, so you can understand that. But as soon as you start including that data as healthcare data, because there could be an inference about your health becomes really broad, really hard to distinguish that from other data. We are seeing impacts on that in connection with clinical trials to becoming harder and harder to find patients. And in fact, there are a number of pharmaceutical companies who, specifically because of this law in the state of Washington, have decided not to do clinical trials related to Washington patients because they can’t find the patients in compliance with these laws.This law also applies to location data. That was also actually one of the premises of the law was they didn’t want law enforcement to be able to track a person’s location to an abortion facility, but the way that law was written is really interesting. If this law, which is a Washington state law, was applicable in Washington, D.C. where I live and work, and I’m speaking to you today from Washington, D.C. as I am speaking to you today, my location data under this law would be treated as healthcare information. It would be treated as healthcare information because the George Washington University Hospital is next door to my office building. You may be able to hear the sirens. We’ve had a number of them while we’re recording this. But the idea that when I sit in my office and I speak on my Zoom calls and I type my emails, that my location data is health information simply because there’s a hospital next door is bizarre. Almost every George Washington University student every day their location data is treated as health information because of where the hospital is, but it’s not healthcare information under any rational sense. But that law treats it as healthcare information.
Kirk Nahra 18:01
Another category tried to protect reproductive rights information by requiring, for example, segregation of data, so that it made it harder for law enforcement to subpoena that information. There’s a California law in particular that goes in that direction and requires, or at least companies have been viewing the only way to comply with that law as is to segregate the reproductive rights information. But if you start to drill into that a little bit more, and here’s the example I use: if you take a random sampling of 1000 women in California, the number of them who are going to be involved in a criminal abortion investigation might be one, might be two, could easily be zero. However, I can tell you that the number of those women in California who are going to be at health risk because their medical records are going to be incomplete because it excludes their reproductive rights information — that’s going to be close to 1,000. And so, what we’re seeing is state legislatures who have a perfectly appropriate goal, protecting reproductive rights information, but the way they’re doing it is having unintended consequences of making other kinds of risks. And I think that what we’re seeing is state legislators who just aren’t thinking broadly enough about the implications of their decisions. So lots of challenges at that point in connection with those kinds of issues.So if you think about how these laws fit together, particularly the state laws, I’m going to use the California Consumer Privacy Act [CCPA] as an example. If you are a California resident, here’s how your healthcare information is protected today. First of all, some of your information is protected by HIPAA. If your doctor has it, your hospital has it, your health insurer has it. And if your information is protected by HIPAA, it’s not covered by the CCPA at all. There’s a California HIPAA-like law that I mentioned, it’s called the California Confidentiality of Medical Information Act (CMIA). Again, if you’re subject to that law, pretty confusing to figure out if you’re subject to that law. But if you are subject to that law, it’s also exempted from CCPA. If you’re involved in medical research, privacy issues are governed by the medical research rules, also exempted from CCPA. Then you have CCPA, which will cover health information if it’s not subject to exemptions from one, two, and three. But that’s all kinds of companies that have other kinds of healthcare information. So it’s a gap-filling law for healthcare, but it doesn’t fill all of the gaps. For example, those patient support groups that are community health groups, community support groups — they’re nonprofits. They’re not covered by any of these rules, so it still doesn’t cover those rules. And for its early years, this changed in the last couple years, but in the early years of CCPA, it didn’t apply to employer and employee information. So, if you had a doctor’s note from why you missed work. You had a Family and Medical Leave Act [FMLA] situation. You had an injury at work that required workers’ compensation. You had a disability claim. All of those things were information that your employer had as an employer, not covered by HIPAA, not covered by any of these other rules, and unique among the state comprehensive privacy laws. Today CCPA protects that information, but again, it creates a whole different set of rules for that. The other states that have comprehensive privacy laws don’t apply to that healthcare information held by your employer at all.
Kirk Nahra 21:33
So, I don’t know how a consumer could figure this out. No, I mean, consumers don’t understand how HIPAA works. They certainly don’t understand how six different sets of rules work. It is harder and harder, in my mind, for businesses to figure this out, including just whether the rules are even applicable to them. They don’t, you know. I think companies in this field are not generally looking to get around the rules, they’re trying to figure out what the rules are, including which rules they even have to think about, and that is very, very complicated and getting more so with each passing day. So, I think at this point, this complexity can result in more expensive healthcare, less reliable healthcare, difficulties with research, certainly challenges in building useful, effective AI, and difficulty in investing in healthcare technologies. Lots of opportunities for healthcare technology, but boy, it is hard to get a company started when you got to navigate all those issues. So it is very hard to see who this is good for at this point. I don’t think it’s good for patients or consumers. I don’t think it’s good for healthcare businesses. I could certainly say it’s good for healthcare privacy lawyers. Happy to be in that field, but again, I don’t know that full employment for healthcare privacy lawyers is generally viewed as an appropriate public policy goal. But that’s sort of where we are at this point.
Kirk Nahra 22:59
So, are we going to have a solution to this at all? Well, there’s always the possibility of a national privacy law.I would not hold your breath on that possibility. It’s been percolating around in Washington for you know more than 25 years. Very little success. Does not seem to be high on the radar screen of either political party at this point in time. However, let me be clear on what this law would do. The way we have seen drafts of a national privacy law play through have had the following approach. First of all, the healthcare industry, and when I say that, I mean sort of the HIPAA people, doctors, hospitals, pharmacies, and health insurers. They have largely been absent from the debate about a national privacy law. The goal of the healthcare industry, the HIPAA-covered healthcare industry in a national privacy law so far, has been to say to Congress exclude us from this law, and so all the major bills have excluded entities covered by HIPAA.But what that also means is that those entities then are not involved in any actual substance about what a national privacy law would say about healthcare. That leaves to other kinds of companies the role of advocating for an effective approach to healthcare privacy. All of those companies have other fish to fry in the national privacy law debate, and so what I am seeing is a situation where a national privacy law is actually likely to make things worse in the healthcare space because it’s just going to add another rule on top of everything that we have at this point, so that’s sort of where we are. Healthcare privacy law, again, my personal opinion is a growing mess. Tried to give you a sense of that today. The law is changing constantly. Most of the law that I’ve talked about today, the Washington law, the Dobbs related laws, the state comprehensive laws, etc. Most of that law is less than five years old. There are laws being passed every year and often, you know, on a month-to-month basis. There are now varying standards for different entities who have the same information but have it in different contexts. We have lots of different laws covering the same kinds of information, depending on who’s holding it. We have growing confusion about what health information even means, and particularly why it should be protected more than other kinds of data. We are seeing certain examples, both at the federal level. Footnote that may be the last administration more than the current administration, but at the federal level and at the state level, where we’ve had cases where it’s very hard to see what the underlying law that somebody is accused of violating is, and I think it is making things very complicated for investing in new ideas in healthcare. Very hard for startups to understand this. It’s very hard for startups to figure out where they fit into this regulatory structure.
Kirk Nahra 26:08
So overall, and again, this is sort of to summarize where we’ve been in this entire discussion over the last couple of programs. I think we’ve just lost the narrative on healthcare privacy. We started in the United States to build a law of healthcare privacy based on the premise that healthcare information was different than other kinds of information, that is a uniquely U.S. approach to healthcare privacy. If you look at other countries’ laws, you look at Europe with GDPR. Healthcare data is certainly part of GDPR. Healthcare data is treated as sensitive data under GDPR, but so is whether you are a member of a trade union, and the rules aren’t any different for healthcare versus whether you are a member of a trade union. So, I could argue that GDPR covers more healthcare information, but it is not as effective for the healthcare industry, as HIPAA is, because of the nuance in writing the HIPAA rules, that nuance has not continued through the rest of these laws, and that lack of nuance or that lack of thinking about other implications is part of the problem. So we have growing questions about what health data is and why and how it should be treated differently from other data. Most of the complications are coming from state law at this point. At the same time, I don’t think a federal law is likely to solve these problems. I think it’s likely to make things worse because, again, there’s nobody actively involved in the debate about a national privacy law who is thinking effectively about healthcare issues. It’s either people that don’t know those issues, or people who have other things on their mind, and the core entities who are involved in healthcare — the doctors, the hospitals, the health insurers — are just not involved in the debate because their view is leave us alone. So at this point, there’s just too much law without a coherent overall approach. I think that leads to real questions about whether the rules for privacy are going to get in the way of a working healthcare system, and what the implications of that will be for consumers. So that’s sort of where we are at this point. We started, you know, with a you know fairly simple premise in HIPAA. Again, reminder: HIPAA is not an overall healthcare privacy rule. It’s a healthcare privacy rule that applies to specific kinds of entities — doctors, hospitals, health insurers, etc. — but doesn’t apply to everybody. So, those rules, again, I think were written very well to deal with the healthcare industry, and thought of lots of the trade-offs and very explicitly made trade-offs when they’re writing those rules to achieve, I think, two goals at the same time: to protect privacy but also have a working, effective healthcare system. I don’t think many of the laws that have been passed in more recent years, many of which are targeted to a very particular thing, have necessarily thought about those broader implications. So that’s a lot of the concern. There are things happening in the system, you know, Washington law leading to companies pulling out of medical research in the state of Washington, for example, California Dobbs Law protecting reproductive rights information from law enforcement access, but at the same time making medical records less complete, which creates its own set of risks. So we’re seeing more and more of these problems. It’s making the healthcare system more challenging. It’s raising a lot of questions about costs and efficiency and effectiveness and reliability, and on the whole, again, I’m just concerned that we don’t have a clear cut approach to why we’re protecting healthcare privacy, what should make sense to do in protecting healthcare privacy, and how we’re going to protect that privacy in a way that still allows for an effective, efficient, useful healthcare system. Because a bad healthcare system, even if people have good privacy, a bad healthcare system is certainly not good for consumers. So that concludes part three of our program. There will certainly be opportunities in the Berkeley sessions to talk about other kinds of healthcare issues, but I hope that’s given you sort of a good basic grounding in the key issues of healthcare privacy today.
Wayne Stacy 30:29
So, Kirk, I love the way you — well, I’m not sure I love this. It terrifies me the way you frame it because it’s accurate. That it’s not just an increase in cost. It’s not just a nuisance. It’s got some real impact. It’s impacting innovation, so it’s going to hurt what we see in the future. But it’s also hurting what we’re going to get today in terms of healthcare service. So these are things that you know can’t be minimized in terms of oh, it’s just a few pennies here and there, which is often what I hear people say. That’s just a little more expense. Everybody can bear it, but that’s not ..
Kirk Nahra 31:10
Absolutely, I agree with that.
Wayne Stacy 31:11
So, well, wonderful. Well, thank you for making me nervous for the rest of the day. But it’s the kind of program, the kind of material people need to hear. So I appreciate you sharing.
Kirk Nahra 31:24
Thank you for having me.