Summary
Amends Delaware’s privacy law to expand protections for automated decisions, expressly including decisions about access to health-care services. Adds contractual safeguards for third-party decision reports, including adverse-action notices and notice of qualified human-review rights, and strengthens protections for sensitive data.
Healthcare Implications
Covered organizations using personal data for automated health-care access decisions must assess applicable opt-out, notice, and human-review requirements. Coverage is limited: insurers and health carriers are exempt, as are HIPAA-protected health information and specified other clinical data. The law does not impose a blanket human-review requirement on clinical AI or insurance decisions.
Operational Implications
- For covered third-party decision reports, require contractual adverse-action notice and notice of a right to request human review where technically feasible, subject to the resident’s-best-interest exception; expands automated-decision opt-out rights.
- Covered controllers must assess qualifying risky profiling; the data-protection-assessment threshold is 50,000 consumers.