The Senate Just Revealed What They're Building. Nobody Flinched. HELP!
by Alexandra de Scheel, Citizens’ Council for Health Freedom
Photo by: Twila Brase
On March 5, 2026, the Senate Health, Education, Labor, and Pensions (HELP) Committee held a hearing titled “Transforming Health Care with Data.” What stood out wasn’t conflict or debate. It was an alignment.
Republicans and Democrats, regularly divided on nearly every topic, moved in the same direction here. The goal was clear and repeatedly affirmed:
Expand the flow of medical data
Connect systems across the country
Integrate artificial intelligence
Accelerate the transition to a fully interoperable digital health infrastructure
The language used to describe this push to expand and connect medical data systems was reassuring. They framed the effort as “patient empowerment,” improved coordination, and better outcomes. But for those listening closely, a different picture emerges — one that only makes sense if you understand how this system was built in the first place.
Electronic Health Records (EHRs) were not simply adopted to improve care; they were pushed into place through federal policy and mandates. Beginning in 2009, the government used financial incentives, followed by penalties, to force hospitals and physicians into government certified electronic systems. Today, nearly all hospitals are using EHRs — not because the market naturally evolved that way, but because opting out promised to be financially untenable and debilitating.
These systems were never designed just to digitize paper charts. They were structured to collect standardized data, facilitate reporting, and allow that information to move across networks. What began as recordkeeping has steadily become infrastructure.
This infrastructure is now being connected at alarmingly accelerated rates
During the hearing, Dr. Thomas Keane, M.D., who leads federal health IT efforts as the National Coordinator for Health Information Technology (ONC) described his office’s top priority using a phrase that came up repeatedly — “data liquidity,” with the goal to make health information move seamlessly across systems, providers, and platforms.
Screenshot: Senate HELP Committee Republicans, “Transforming Health Care with Data: Improving Patient Outcomes Through Next-Generation Care,” March 5, 2026, video
The federal government’s Trusted Exchange Framework and Common Agreement — TEFCA — now links approximately 70,000 health care locations and enables the exchange of more than 500 million patient records. When Dr. Keane first took office, the number was closer to 10 million. The expansion has been rapid and is ongoing.
TEFCA functions as a nationwide data-sharing backbone. Once organizations connect, information can move between them under a common framework. The system is designed to operate continuously, and in many cases, invisibly to the patient.
The assumption underlying this nearly 50-fold expansion is that more data sharing is inherently beneficial. That assumption went largely unchallenged during the hearing.
HIPAA was referenced as a safeguard, but its actual role is often misunderstood. HIPAA doesn’t protect you from this. The 1996 Health Insurance Portability and Accountability Act permits 2.2 million entities to access your medical records without your consent if those who hold your records choose to share them.
In practice, once data is inside the system, it can be distributed broadly, depending on how the organizations holding it choose to use it. TEFCA does not alter that framework; it extends it by making data exchange faster and more comprehensive.
The hearing made the endgame clear.
Dr. Keane described his vision:
“In the not so distant future, an individual with multiple chronic conditions can keep all of their health information in one secure digital place and share it instantly with a new provider, a caregiver, or even a secure, trusted app, no matter where they live or where they receive care.”
What he described is a national health dossier on every American that is accessible and shareable — operating as the ONC’s own roadmap states, “in the background” and without your written permission.
As the system expands, so does the range of participants.
Senator Tim Kaine (D-VA) applauded the fact that financial incentives pushed 96 percent of hospitals into electronic health records. He then complained that the incentives hadn’t yet reached behavioral health providers, long-term care facilities, and social services agencies. Dr. Keane assured him they’re working on it. They’ve already built a data set that allows exchange between traditional health providers, behavioral health providers, occupational providers, vocational service agencies, and housing assistance agencies.
Screenshot: Senate HELP Committee Republicans, “Transforming Health Care with Data: Improving Patient Outcomes Through Next-Generation Care,” March 5, 2026, video
When a patient is discharged from a behavioral health or substance use crisis, Dr. Keane said,
“we want to make sure that their medical information as well as their social needs are properly communicated to social service agencies, vocational health agencies, and the like.”
Read that again. Your mental health records, substance use history, and social needs — shared with housing agencies and vocational services.
Senator Kaine said the goal of the hearing was to “knock down silos that keep patient data separate.” These silos aren’t failures. These silos are the last remnants of medical privacy in America. Knocking them down doesn’t empower patients. It exposes them.
Then came the AI conversation.
Chairman Bill Cassidy (R-LA) asked the right question: When a patient uploads their medical data to an AI platform, does HIPAA protect them? Dr. Keane’s answer was clear. If a patient downloads their records and uploads them to an AI tool, that falls outside the purview of HIPAA. The AI platform is not a covered entity. HIPAA does not apply. The federal government cannot regulate what patients do with data they’ve chosen to release. Given how broadly your medical data is already shared inside HIPAA-regulated systems, this is a moot point.
Screenshot: Senate HELP Committee Republicans, “Transforming Health Care with Data: Improving Patient Outcomes Through Next-Generation Care,” March 5, 2026, video
Senator Cassidy suggested a pop-up warning might help.
A pop-up. That’s the protection Congress is considering for the most sensitive personal information Americans possess?
Here’s what was missing from the entire hearing— PATIENT CONSENT. The word appeared only in the context of what patients have already given up, or in the context of why the federal government can’t regulate data after the fact. Nobody asked whether patients had consented to having their records flow through TEFCA. They didn’t ask whether patients had agreed to become nodes in a federal health data network connecting housing agencies, vocational services, insurance companies, and AI platforms.
Senator Alsobrooks (D-MA) asked one good question in relation to AI: “Are we strengthening guardrails or weakening them?” She noted that innovation without accountability doesn’t build trust, and in health care, trust is everything. Dr. Keane assured her that the Assistant Secretary for Technology Policy office is “absolutely forensic” in examining AI. He is putting out an RFI.
Screenshot: Senate HELP Committee Republicans, “Transforming Health Care with Data: Improving Patient Outcomes Through Next-Generation Care,” March 5, 2026, video
An RFI. A request for information. With more than 500 million health records already flowing through a federal network, and more added over time, the government is only now going to ask about the security of the data?
Warnings that CCHF has shared for nearly three decades are now undeniable: the government’s electronic health record was never primarily about patient care. HIPAA opened the door to broad data sharing without written patient consent. Federal EHR policy pushed doctors and hospitals into government-certified electronic systems. TEFCA is now connecting those systems into a nationwide exchange. This hearing showed the next step: more data movement, more participants, more AI and less patient control.
You may get some convenience. They get control.
State legislators can still act. States with medical privacy laws that are stronger than HIPAA — laws that actually require patient consent for data sharing — can stop some of this. Minnesota’s Health Records Act has done it. Montana’s genetic privacy law has done it. The fight is not over.
CCHF has developed model legislation to restore patient privacy and consent, including genetic privacy protections and patient consent requirements for data sharing. If you are interested in bringing this model legislation to your state, please contact us. See CCHF’s Genetic Privacy One-Pager and the Patient Privacy and Consent One-Pager for more information. But you need to know what is being built. This hearing showed you the blueprint.








The irony that you HAVE to declare what people you want to share your health information with, denying family nember that was accidentally left off, but the WHOLE damn world has access through the system. And, I mean world. Almost every health facility we have a record with has been hacked, meaning our info is already available to no one we want to share with. The hypocrisy is rife with irony!
Senators are operating in a worldview of 'PROGRESS' - anything that is more automatic and convenient is "good". And there is no discussion of power and it's abuse when it gets concentrated, a primary feature of the Constitution being to prevent such concentration.