The U.S. Department of Justice (DOJ) has rolled out its new Data Security Program (DSP), a regulatory development designed to keep bulk sensitive U.S. personal and government-related data out of the hands of foreign adversaries through export control restrictions. For the health care industry, which manages vast amounts of personal health and biometric data every day, these new restrictions on data handling and transfers are especially important.
Under the DSP, bulk U.S. sensitive personal data is broadly defined as personal health, biometric, genomic and geolocation information, in any format, collected or held by any entity where such data meets or exceeds a threshold set forth in 28 CFR Part 202.205. This covered data includes information that reveals or describes a past, present or future physical or mental condition, as well as height, weight, vital signs, allergies, treatment histories, exercise data collected by apps, and immunization records. Unlike the Health Insurance Portability and Accountability Act (HIPAA) and other current data privacy and security regulations, anonymized, pseudonymized, encrypted and de-identified data is not exempt from DSP regulations.
Therefore, health care organizations, including providers, payers, vendors and research institutions must evaluate their data practices in light of this sweeping new rule. Clients engaged in transactions involving such data, especially with cross-border data transfers involving countries of concern—currently defined as China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia and Venezuela—or involving persons associated with these countries of concern, should understand and comply with its requirements.
Affected Entities
Any health care organization, including hospitals, health systems, insurers, cloud service providers, data processing centers, medical device manufacturers, health IT vendors, life sciences companies, or academic research entities that share data across borders or work with foreign vendors, investors, or employees, should evaluate potential exposure under the DSP.
Covered Transactions
Effective April 8, 2025, the DSP restricted and prohibited U.S. entities or individuals from knowingly engaging in a covered data transaction of any government-related data or bulk U.S. sensitive personal data that involves access by a country of concern or covered person (those associated with countries of concern). To be a covered data transaction, the transaction must involve:
- data brokerage (selling or licensing health data, even if de-identified);
- a vendor agreement (partnerships with foreign service providers handling health data such as cloud storage, virtual service centers, analytics, electronic health record platforms);
- an employment agreement (foreign employees or contractors with access to health or genomic data); or
- an investment agreement (foreign investment in companies holding sensitive health data).
There are two general categories of covered transactions:
- Prohibited transactions, which generally involve certain data brokerage transactions involving countries of concern; and
- Restricted transactions, which include data transactions under vendor, employment, or investment agreements, and may require security safeguards and enhanced oversight.
Exempt Data Transactions
Data transactions exempt from DSP restrictions include routine patient communications, informational materials, commercial financial transactions, U.S. government public health activities, and federally-funded research programs. However, each must be carefully assessed on a case-by-case basis.
Compliance Considerations
The DSP imposes a new layer of regulation to data sharing and storage practices and places a significant compliance burden on all U.S. health care organizations, even those not directly transacting business with a country of concern or covered person. To meet compliance obligations, health care entities should consider the following:
- Inventory and classify sensitive data holdings, especially any involving biometric or genomic data, to determine if data covered by DSP regulations is implicated
- Review vendor, research and investor contracts for affiliations with countries of concern that could lead to prohibited data access and identify any prohibited or restricted transactions
- Be aware when hiring individuals associated with countries of concern as their access to sensitive data might be restricted
- Review data licensing agreements to ensure licensee compliance
- Evaluate necessity to meet Cybersecurity and Infrastructure Security Agency requirements, and implement data compliance programs
- Designate a senior-level manager to oversee DSP compliance
- Conduct regular staff training
- Maintain records and conduct annual audits
Enforcement and Legal Assistance
The DOJ’s 90-day leniency period for enforcement ended July 8, 2025, and they have signaled enforcement by their National Security Division will be strict with both civil and criminal penalties for violations. Therefore, consider retaining legal counsel to help determine whether the DSP’s prohibitions and restrictions apply. Knowledgeable counsel can also help identify impacted data flows, review and revise contracts, structure compliant transactions, advise on recordkeeping and reporting requirements, interact with government agencies if necessary, and provide compliance advice on other regulatory frameworks.
A printer-friendly version of this information can be found here.
Attorneys and practice areas related to this topic include:
Jonathan M. Joseph
Rachel V. Rogers
Health Care
This item has been provided as an informational service and does not constitute legal counsel or advice, which can only be rendered in the context of specific factual situations. If a legal issue should arise, please contact an attorney listed or retain the assistance of other competent legal counsel. Case results depend on a variety of factors unique to each case and results do not guarantee or predict a similar result in any future case undertaken.
