View Rule

View EO 12866 Meetings Printer-Friendly Version     Download RIN Data in XML

FTC RIN: 3084-AB56 Publication ID: Spring 2021 
Title: Health Breach Notification Rule 
Abstract:

On May 22, 2020, the Commission initiated periodic review of the Health Breach Notification Rule (Rule). 85 FR 31085 (May 22, 2020). The comment period closed on August 20, 2020. The Commission staff is reviewing comments and intends to submit a recommendation to the Commission by Fall 2021.

This Rule requires vendors of personal health records (PHR) and PHR-related entities to provide: (1) notice to consumers whose unsecured PHR identifiable health information was acquired by an unauthorized person as a result of a breach; and (2) notice to the Commission. Under the Rule, PHR vendors and PHR-related entities must notify both the FTC and affected consumers "without unreasonable delay and in no case later than 60 calendar days" after discovery of the breach. Among other information, the notices must provide consumers with steps they can take to protect themselves from harm.

The FTC's Rule applies only to health information that is not secured through technologies specified by the Department of Health and Human Services (HHS). Also, the FTC's Rule does not apply to businesses or organizations covered by the Health Insurance Portability and Accountability Act (HIPAA). Entities covered by HIPAA must comply with HHS’ breach notification rule in the event of a security breach.

 
Agency: Federal Trade Commission(FTC)  Priority: Substantive, Nonsignificant 
RIN Status: Previously published in the Unified Agenda Agenda Stage of Rulemaking: Prerule Stage 
Major: Undetermined  Unfunded Mandates: No 
CFR Citation: 16 CFR 318   
Legal Authority: sec. 13407 of the American Recovery and Reinvestment Act of 2009   
Legal Deadline:  None
Timetable:
Action Date FR Cite
Rule Review; Request for Comments  05/22/2020  85 FR 31085   
Rule Review Comment Period End  08/22/2020 
Recommendation to Commission   08/00/2021 
Regulatory Flexibility Analysis Required: Undetermined  Government Levels Affected: None 
Small Entities Affected: Businesses  Federalism: No 
Included in the Regulatory Plan: No 
RIN Information URL: https://www.ftc.gov/news-events/press-releases/2020/05/ftc-seeks-comment-part-review-health-breach-notification-rule  
RIN Data Printed in the FR: No 
Related RINs: Previously reported as 3084-AB17 
Agency Contact:
Elisa Jillson
Attorney
Federal Trade Commission
600 Pennsylvania Avenue NW,
Washington, DC 20580
Phone:202 326-3001
Email: ejillson@ftc.gov