FTC Proposes Amendments to Health Breach Notification Rule
Time 2 Minute Read

On May 18, 2023, the Federal Trade Commission announced it is seeking comment to proposed changes to the Health Breach Notification Rule (the “Rule”). The Rule requires  vendors of personal health records (“PHR”), PHR-related entities and service providers to these entities, to notify consumers and the FTC (and, in some cases, the media) in the event of a breach of unsecured identifiable health information, including cybersecurity intrusions and other instances of unauthorized access. By clarifying the Rule’s scope and applicability, and by modernizing allowable methods of notice, the proposed amendments seek to update the Rule to account for technological change since the Rule’s issuance, which includes the proliferation of health apps and connected devices, and the emergence of a widespread market for health data.

Specifically, the FTC’s proposed amendments would: (1) clarify the Rule’s scope, revising several definitions to explain the Rule’s applicability to health apps and similar technologies not covered by HIPAA; (2) amend the definition of “breach of security” to clarify that it includes data security breaches and unauthorized disclosures; (3) revise the definition of “PHR-related entity” to clarify that only entities that access or send unsecured PHR-identifiable health information to a personal health record qualify as PHR-related entities; (4) clarify what it means for a vendor of personal health records to draw PHR-identifiable health information from multiple sources; (5) modernize the allowable methods of consumer notice by authorizing the expanded use of email and other electronic notices; (6) expand the required content of consumer notices; and (7) improve the Rule’s readability.

Public comments on the amendments will be due 60 days after the amendments’ publication in the Federal Register.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page