Loading chat...

NJ A2297

Bill

Status

Introduced

1/13/2026

Primary Sponsor

Margie Donlon

Click for details

Origin

General Assembly

2026-2027 Regular Session

AI Summary

  • Requires regulated entities to maintain and publish a consumer health data privacy policy disclosing categories of data collected, sources, sharing practices, and third-party recipients, with affirmative consent needed for any collection or sharing beyond disclosed purposes.

  • Grants consumers the right to confirm data collection, access their health data including lists of third parties who received it, withdraw consent, and request deletion within 45 days of submitting a request.

  • Prohibits the sale of consumer health data without valid written authorization that includes specific disclosures, expires after one year, and cannot be combined with other documents or conditioned on receiving goods/services.

  • Bans geofencing within 2,000 feet of healthcare facilities for purposes of identifying, tracking, or targeting consumers seeking health services.

  • Exempts HIPAA-covered entities, financial institutions subject to Gramm-Leach-Bliley, nonprofit organizations, government agencies, and institutions of higher education from the act's requirements.

Legislative Description

Establishes certain data privacy protection requirements for consumer health data, health care providers, and patients.

Health

Last Action

Introduced, Referred to Assembly Health Committee

1/13/2026

Committee Referrals

Health1/13/2026

Full Bill Text

No bill text available