Health Breach Notification Rule
The Health Breach Notification Rule is a U.S. Federal Trade Commission rule that requires certain companies handling personal health records to tell consumers when their unsecured health information has been exposed in a breach. It applies to businesses that are not covered by HIPAA, such as vendors of personal health record products and related entities. It is important not to confuse this rule with the separate HIPAA Breach Notification Rule administered by the U.S. Department of Health and Human Services, which applies to HIPAA-covered entities.
The Health Breach Notification Rule, codified at 16 CFR Part 318 and enforced by the FTC, requires vendors of personal health records (PHR), PHR-related entities, and third-party service providers to notify affected consumers, and in certain cases others, following a breach of security involving unsecured personally identifiable health information. The Rule applies to foreign and domestic vendors of personal health records and is distinct from HIPAA's Breach Notification Rule, which is administered by HHS and obligates HIPAA-covered entities (and, through separate provisions, business associates) to notify individuals when unsecured protected health information (PHI) is breached. The two regimes address complementary but non-overlapping populations of entities; the FTC Rule generally targets entities that fall outside HIPAA's scope. This entry does not detail notification timing, content requirements, thresholds, enforcement mechanics, or the technical criteria for what renders information 'unsecured'; those elements are governed by the specific text of each rule and associated guidance and should be consulted directly.
Why it matters
The Health Breach Notification Rule addresses a gap in U.S. health data protection: many companies that collect and manage personal health information fall outside the scope of HIPAA. Vendors of personal health record (PHR) products, PHR-related entities, and their third-party service providers may hold sensitive health data yet not qualify as HIPAA-covered entities or business associates. Without the FTC Rule, consumers using these products could face breaches of their health information with no corresponding federal notification obligation. The Rule ensures that these non-HIPAA entities must inform affected consumers when unsecured personally identifiable health information is exposed.
A frequent and consequential error among compliance professionals is treating the FTC Health Breach Notification Rule and the HIPAA Breach Notification Rule as interchangeable, or assuming that one satisfies the other. They are administered by different agencies, the FTC for the Health Breach Notification Rule and the U.S. Department of Health and Human Services for the HIPAA Breach Notification Rule, and they apply to complementary but non-overlapping populations of entities. Misidentifying which regime governs a given product or service can lead an organization to notify under the wrong framework, or to conclude incorrectly that no notification obligation exists at all.
Determining applicability therefore requires a careful analysis of an entity's role and its relationship to health data, rather than an assumption that any organization handling health information is automatically a HIPAA-covered entity. Organizations that build consumer-facing health applications and services outside the traditional healthcare delivery context should assess whether they fall within the FTC Rule's scope. This entry does not resolve that classification for any specific organization; it identifies the distinction that must be drawn.
Who it's relevant to
Inside HBNR
Common questions
Answers to the questions practitioners most commonly ask about HBNR.