<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-21-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3084-AB56</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202310</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3084</CODE>
            <NAME>Federal Trade Commission</NAME>
            <ACRONYM>FTC</ACRONYM>
        </AGENCY>
        <RULE_TITLE>Health Breach Notification Rule</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p class="GPOHtml">On May 22, 2020, the Commission initiated periodic review of the Health Breach Notification Rule (Rule). 85 FR 31085 (May 22, 2020). The Commission requested comment on, among other things, whether changes should be made to the Rule in light of technological changes, such as the proliferation of apps and similar technologies. The comment period closed on August 20, 2020. The Commission received 26 public comments.</p>
<p>The Rule requires vendors of personal health records (PHR) and PHR-related entities to provide: (1) notice to consumers whose unsecured PHR identifiable health information was acquired by an unauthorized person as a result of a breach; (2) notice to the Commission; and (3) in some cases, the media. Under the Rule, PHR vendors and PHR- related entities must notify both the FTC and affected consumers "without unreasonable delay and in no case later than 60 calendar days" after discovery of the breach. The Rule also requires third party service providers to vendors of personal health records and PHR related entities to provide notification to such vendors and entities following the discovery of a breach.</p>
<p>The FTC's Rule applies only to health information that is not secured through technologies specified by the Department of Health and Human Services (HHS). Also, the FTC's Rule does not apply to businesses or organizations covered by the Health Insurance Portability and Accountability Act (HIPAA). Entities covered by HIPAA must comply with HHS&rsquo; breach notification rule in the event of a security breach.</p>
<p>On September 15, 2021, the Commission issued a Policy Statement underscoring that the Rule covers health apps and similar technologies. Since the issuance of the Policy Statement, the Commission has brought two enforcement actions alleging violations of the Rule.</p>
<p>Having considered the public comments from the May 2020 periodic review, the Policy Statement, and recent enforcement actions brought under the Rule, the Commission proposed on June 9, 2023, to amend the Rule, in seven ways and requested comment on the proposed changes. 88 FR 37819 (June 9, 2023). The comment period closed on August 8, 2023, and staff is reviewing the comments.</p>
<p>&nbsp;</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Substantive, Nonsignificant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>Undetermined</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>16 CFR 318</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>sec. 13407 of the American Recovery and Reinvestment Act of 2009</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review; Request for Comments</TTBL_ACTION>
                <TTBL_DATE>05/22/2020</TTBL_DATE>
                <FR_CITATION>85 FR 31085</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review Comment Period End</TTBL_ACTION>
                <TTBL_DATE>08/22/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Policy Statement on Health Apps</TTBL_ACTION>
                <TTBL_DATE>09/15/2021</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>06/09/2023</TTBL_DATE>
                <FR_CITATION>88 FR 37819</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>08/08/2023</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>FTC Staff Review of Public Comments</TTBL_ACTION>
                <TTBL_DATE>12/00/2023</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-proposes-amendments-strengthen-modernize-health-breach-notification-rulehttps://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule</FURTHER_INFO_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <RELATED_RIN_LIST>
            <RELATED_RIN>
                <RIN>3084-AB17</RIN>
                <RIN_RELATION>Previously reported as</RIN_RELATION>
            </RELATED_RIN>
        </RELATED_RIN_LIST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Elisa</FIRST_NAME>
                <LAST_NAME>Jillson</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-3001</PHONE>
                <EMAIL>ejillson@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
            <CONTACT>
                <FIRST_NAME>Ryan</FIRST_NAME>
                <LAST_NAME>Mehm</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-2918</PHONE>
                <EMAIL>rmehm@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
            <CONTACT>
                <FIRST_NAME>Ronnie</FIRST_NAME>
                <LAST_NAME>Solomon</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-2098</PHONE>
                <EMAIL>rsolomon@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
