FTC Seeks to Expand Health Breach Notification Rule to Cover Non-HIPAA Health Apps

The Federal Trade Commission (FTC) has submitted a notice of proposed rulemaking, with the objective of expanding the Health Breach Notification Rule (HBNR) to include most health apps and similar technologies that are not governed by HIPAA (Health Insurance Portability and Accountability Act). The HBNR amendment proposition follows an effort to formalize the FTC’s Statement of the Commission on Breaches by Health Apps and Other Connected Devices, which was first discussed in a McGuireWoods alert on Oct. 5, 2021

The suggested changes stem from concerns related to the protection of healthcare information handled by non-HIPAA entities. Health apps and other connected devices, while increasingly prevalent in the healthcare sector, are often not overseen by any comprehensive privacy or security regulations. The proposed rule amendment by the FTC intends to fill this gap, ensuring that customers and patients have sufficient safeguards around their health data, even when handled by non-HIPAA entities.

It is worth noting that these proposed changes signify a step forward in the FTC’s effort to increase accountability in the digital healthcare environment, and it will have significant implications for health-focused technology firms and other businesses falling outside of HIPAA’s mandate.

For further information on the FTC’s proposed changes, legal professionals, corporations, and firms are advised to monitor the situation closely and stay tuned for updates.