<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-20-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3084-AB56</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202210</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3084</CODE>
            <NAME>Federal Trade Commission</NAME>
            <ACRONYM>FTC</ACRONYM>
        </AGENCY>
        <RULE_TITLE>Health Breach Notification Rule</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>On May 22, 2020, the Commission initiated periodic review of the Health Breach Notification Rule (Rule). 85 FR 31085 (May 22, 2020). The comment period closed on August 20, 2020. The Commission staff is reviewing comments and intends to submit a recommendation to the Commission by December 2022.</p>
<p class="GPOHtml">On September 15, 2021, the Commission issued a policy statement affirming that health apps and connected devices that collect or use consumers&rsquo; health information must comply with the Health Breach Notification Rule.&nbsp;</p>
<p>This Rule requires vendors of personal health records (PHR) and PHR-related entities to provide: (1) notice to consumers who's unsecured PHR identifiable health information&nbsp;was acquired by an unauthorized person as a result of a breach; and (2) notice to the Commission. Under the Rule, PHR vendors and PHR-related entities must notify both the FTC and affected consumers "without unreasonable delay and in no case later than 60 calendar days" after discovery of the breach. Among other information, the notices must provide consumers with&nbsp;a description of the types of unsecured health information that were involved in the breach.</p>
<p>The FTC's Rule applies only to health information that is not secured through technologies specified by the Department of Health and Human Services (HHS). Also, the FTC's Rule does not apply to businesses or organizations covered by the Health Insurance Portability&nbsp;and Accountability Act (HIPAA). Entities covered by HIPAA must comply with HHS&rsquo; breach notification rule in the event of a security breach.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Substantive, Nonsignificant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Prerule Stage</RULE_STAGE>
        <MAJOR>Undetermined</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>16 CFR 318</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>sec. 13407 of the American Recovery and Reinvestment Act of 2009</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review; Request for Comments</TTBL_ACTION>
                <TTBL_DATE>05/22/2020</TTBL_DATE>
                <FR_CITATION>85 FR 31085</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review Comment Period End</TTBL_ACTION>
                <TTBL_DATE>08/22/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Policy Statement on Health Apps</TTBL_ACTION>
                <TTBL_DATE>09/15/2021</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Recommendation to Commission  </TTBL_ACTION>
                <TTBL_DATE>12/00/2022</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule</FURTHER_INFO_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <RELATED_RIN_LIST>
            <RELATED_RIN>
                <RIN>3084-AB17</RIN>
                <RIN_RELATION>Previously reported as</RIN_RELATION>
            </RELATED_RIN>
        </RELATED_RIN_LIST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Elisa</FIRST_NAME>
                <LAST_NAME>Jillson</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-3001</PHONE>
                <EMAIL>ejillson@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
            <CONTACT>
                <FIRST_NAME>Ryan</FIRST_NAME>
                <LAST_NAME>Mehm</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-2918</PHONE>
                <EMAIL>rmehm@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
