• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

FTC Strengthens Health Data Breach Notification Rule to Protect Consumers

by Fred Pennic 04/29/2024 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

What You Should Know: 

– The Federal Trade Commission (FTC) has finalized significant changes to the Health Breach Notification Rule (HBNR), aiming to improve consumer protection in the digital age.

– These updates clarify the rule’s application to modern technologies like health apps and expand the information healthcare providers must disclose in the event of a data breach.

Key Updates to Health Breach Notification Rule Summary

  • Focus on Health Apps and Emerging Technologies: The revised rule clarifies its application to health apps and similar technologies not covered by the Health Insurance Portability and Accountability Act (HIPAA). This ensures these platforms are held accountable for safeguarding health data.
  • Expanded Breach Definition: The rule now encompasses unauthorized access or disclosure of identifiable health information, providing broader protection for consumers.
  • Clearer Scope and Definitions: Definitions like “PHR identifiable health information,” “covered healthcare provider,” and “healthcare services or supplies” have been revised for better clarity. Additionally, the revised definition of “PHR related entity” specifies that only entities accessing or sending unsecured health data to a personal health record qualify.
  • Enhanced Consumer Notifications: The final rule mandates covered entities to provide more detailed breach notifications to consumers. This includes disclosing the identity of any third parties who acquired unsecured health data during the breach.
  • Electronic Notification Options: The updated rule allows for wider use of email and other electronic means to deliver clear and effective breach notifications.
  • Revised Timing Requirements: The FTC notification timeframe is adjusted for breaches impacting 500 or more individuals. Covered entities must now notify the FTC simultaneously with sending notifications to affected individuals, with a deadline of 60 calendar days after the breach discovery.
  • Improved Readability: The revised rule simplifies language for better comprehension and promotes compliance.

Effective Date and Additional Actions

These changes will take effect 60 days after publication in the Federal Register. The FTC remains vigilant in protecting consumer data security, with recent enforcement actions against companies like GoodRx and Easy Healthcare (Premom app) for violating the HBNR. While the Commission approved the final rule with a 3-2 vote, dissenting statements were issued by Commissioners Holyoak and Ferguson.

The FTC offers resources to educate consumers about their rights and how to report scams and unfair business practices. 

“Protecting consumers’ sensitive health data is a high priority for the FTC,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection. “With the increasing use of health apps and connected devices, the updated HBNR will ensure it keeps pace with changes in the health marketplace.”

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Cybersecurity

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

 Selecting the Right EMR: A Practical Guide to Streamlining Your Practice and Enhancing Patient Care

Selecting the Right EMR: A Practical Guide to Streamlining Your Practice and Enhancing Patient Care

Featured Interview

Virta Health CEO: GLP-1s Didn’t Kill Weight Watchers, Its Broken Model Did

Most-Read

White House Event Unveils CMS Health Tech Ecosystem Initiative

White House Event Unveils CMS Health Tech Ecosystem Initiative

Digital Health Faces Q2'25 Pullback: Funding Falls to 5-Year Low, But AI Dominates and $1B+ IPOs Emerge

Healthcare Investment Shifts in 1H 2025: AI Remains a Bright Spot Amidst Fundraising Decline

Digital Health Faces Q2'25 Pullback: Funding Falls to 5-Year Low

Digital Health Faces Q2’25 Pullback: Funding Falls to 5-Year Low

Beyond the Hype: Building AI Systems in Healthcare Where Hallucinations Are Not an Option

Beyond the Hype: Building AI Systems in Healthcare Where Hallucinations Are Not an Option

Health IT Sector Navigates Policy Turbulence with Resilient M&A

Health IT’s New Chapter: IPOs Return, Resilient M&A, Valuations Rise in 1H 2025

PwC Report: US Medical Cost Trend to Remain Elevated at 8.5% in 2026

PwC Report: US Medical Cost Trend to Remain Elevated at 8.5% in 2026

Philips Launches ECG AI Marketplace, Partnering with Anumana to Enhance Cardiac Care with AI-Powered Diagnostics

Philips Launches ECG AI Marketplace, Partnering with Anumana to Enhance Cardiac Care with AI-Powered Diagnostics

WeightWatchers Emerges from Bankruptcy, Launches New Menopause Program

WeightWatchers Emerges from Bankruptcy, Launches New Menopause Program

CMS Finalizes New Interoperability and Prior Authorization Rule

CMS Proposes 2026 Physician Fee Schedule Rule: Boosting Primary Care, Cutting Waste, and Modernizing Payments

Beyond SaaS: How Agent as a Service is Transforming Healthcare Automation

Beyond SaaS: How Agent as a Service is Transforming Healthcare Automation

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |