Skip to main content
Category: Privacy Regulations

Health Breach Notification Rule

Also known as: HBNR, FTC Health Breach Notification Rule, 16 CFR Part 318
Simply put

The Health Breach Notification Rule is a U.S. Federal Trade Commission rule that requires certain companies handling personal health records to tell consumers when their unsecured health information has been exposed in a breach. It applies to businesses that are not covered by HIPAA, such as vendors of personal health record products and related entities. It is important not to confuse this rule with the separate HIPAA Breach Notification Rule administered by the U.S. Department of Health and Human Services, which applies to HIPAA-covered entities.

Formal definition

The Health Breach Notification Rule, codified at 16 CFR Part 318 and enforced by the FTC, requires vendors of personal health records (PHR), PHR-related entities, and third-party service providers to notify affected consumers, and in certain cases others, following a breach of security involving unsecured personally identifiable health information. The Rule applies to foreign and domestic vendors of personal health records and is distinct from HIPAA's Breach Notification Rule, which is administered by HHS and obligates HIPAA-covered entities (and, through separate provisions, business associates) to notify individuals when unsecured protected health information (PHI) is breached. The two regimes address complementary but non-overlapping populations of entities; the FTC Rule generally targets entities that fall outside HIPAA's scope. This entry does not detail notification timing, content requirements, thresholds, enforcement mechanics, or the technical criteria for what renders information 'unsecured'; those elements are governed by the specific text of each rule and associated guidance and should be consulted directly.

Why it matters

The Health Breach Notification Rule addresses a gap in U.S. health data protection: many companies that collect and manage personal health information fall outside the scope of HIPAA. Vendors of personal health record (PHR) products, PHR-related entities, and their third-party service providers may hold sensitive health data yet not qualify as HIPAA-covered entities or business associates. Without the FTC Rule, consumers using these products could face breaches of their health information with no corresponding federal notification obligation. The Rule ensures that these non-HIPAA entities must inform affected consumers when unsecured personally identifiable health information is exposed.

A frequent and consequential error among compliance professionals is treating the FTC Health Breach Notification Rule and the HIPAA Breach Notification Rule as interchangeable, or assuming that one satisfies the other. They are administered by different agencies, the FTC for the Health Breach Notification Rule and the U.S. Department of Health and Human Services for the HIPAA Breach Notification Rule, and they apply to complementary but non-overlapping populations of entities. Misidentifying which regime governs a given product or service can lead an organization to notify under the wrong framework, or to conclude incorrectly that no notification obligation exists at all.

Determining applicability therefore requires a careful analysis of an entity's role and its relationship to health data, rather than an assumption that any organization handling health information is automatically a HIPAA-covered entity. Organizations that build consumer-facing health applications and services outside the traditional healthcare delivery context should assess whether they fall within the FTC Rule's scope. This entry does not resolve that classification for any specific organization; it identifies the distinction that must be drawn.

Who it's relevant to

Vendors of Personal Health Record Products
Companies that offer consumer-facing personal health record products should evaluate whether they qualify as vendors of PHR under the FTC Rule. Because the Rule applies to both foreign and domestic vendors, non-U.S. companies serving U.S. consumers should not assume they are exempt. This assessment is distinct from determining HIPAA coverage.
PHR-Related Entities and Third-Party Service Providers
Entities that interact with or provide services to personal health record products may fall within the Rule's scope as PHR-related entities or third-party service providers. These organizations should determine their specific role, as the notification obligations and to whom notice is directed can differ by role.
Compliance and Privacy Officers Determining Regulatory Scope
Privacy and compliance professionals must first establish which regime governs a given product or service, since an organization outside HIPAA's scope may still be subject to the FTC Rule. Correctly identifying the applicable rule is a prerequisite to any breach response planning; this classification should be evidenced and documented rather than assumed.
HIPAA-Covered Entities Assessing Boundary Cases
HIPAA-covered entities and their advisors should be aware that certain products or offerings may fall outside HIPAA and instead under the FTC Rule. Because the two regimes address complementary but non-overlapping populations, organizations operating both HIPAA-covered functions and consumer health products should analyze each offering separately rather than applying a single framework across the board.

Inside HBNR

Scope of covered entities
The Health Breach Notification Rule is a U.S. Federal Trade Commission rule that applies to vendors of personal health records and related entities that are not covered by HIPAA. It is distinct from the HIPAA Breach Notification Rule administered by the U.S. Department of Health and Human Services; the two address different populations of organizations and should not be treated as interchangeable.
Triggering event
The rule is triggered by a breach of security involving identifiable health information held or maintained by an entity within its scope. Whether a given incident meets the definition of a triggering breach depends on the specific facts and how the rule defines the relevant information, and this assessment should be made against the rule text rather than by analogy to other regimes.
Notification obligations
Where the rule applies, affected individuals generally must be notified following a qualifying breach, and notification to the Federal Trade Commission is also contemplated. The precise timing, content, and method requirements are set by the rule; this entry does not restate specific deadlines or thresholds, which should be verified against the current rule text.
Relationship to other regimes
The rule sits within the broader U.S. patchwork of breach notification requirements. It does not displace HIPAA obligations for HIPAA-covered entities and business associates, nor does it substitute for state breach notification laws or non-U.S. frameworks such as the EU GDPR or UK GDPR, which have their own separate breach notification concepts and timelines.

Common questions

Answers to the questions practitioners most commonly ask about HBNR.

Is the Health Breach Notification Rule the same as HIPAA's breach notification requirements?
No. The Health Breach Notification Rule is a distinct regime administered by the U.S. Federal Trade Commission that generally applies to certain vendors of personal health records and related entities that are not covered by HIPAA. HIPAA's breach notification provisions apply to HIPAA covered entities and their business associates. Confusing the two is a common error: an organization may fall under one, the other, both, or neither depending on its role and the nature of the data it handles. This entry does not resolve which regime applies to a specific organization; that determination depends on the entity's function and legal classification, and typically warrants legal review.
Does breaching health information automatically trigger a notification obligation under this Rule?
Not necessarily. Notification obligations generally depend on whether the entity falls within the Rule's scope and whether the incident meets the Rule's definition of a triggering event. An organization outside the Rule's coverage would look to other applicable frameworks instead. Being 'health-related' does not by itself place an incident under this Rule, and the existence of a security incident does not always equate to a reportable breach under any single regime. Scope and trigger analysis should be assessed against the specific regulatory text and, where relevant, other overlapping obligations such as state breach laws or HIPAA, which are out of scope for this entry.
How should an organization determine whether it falls within the scope of the Health Breach Notification Rule?
Scope determination generally turns on the organization's function relative to personal health records and its regulatory classification, particularly whether it is already subject to HIPAA. Because the same data can sit under different regimes depending on who holds it and why, entities typically document their role, the categories of data processed, and the basis for any conclusion about coverage. This is properly a legal and compliance analysis rather than a purely technical one, and demonstrable, evidence-based reasoning is generally expected under accountability principles. This entry does not provide a definitive scoping test for any given organization.
What evidence should an organization retain to demonstrate compliance with breach notification obligations under this Rule?
Under accountability expectations generally applied to governance and compliance frameworks, stated intent is insufficient; organizations typically need demonstrable evidence. That commonly includes records of incident detection and assessment, the reasoning behind whether an incident was treated as a triggering event, notification timelines and content, and the identities or categories of parties notified. Retaining decision documentation is particularly important where an organization concludes that no notification was required. This entry does not specify mandated retention periods or the exact form of records required, which should be confirmed against the applicable regulatory text.
How does this Rule interact with other breach notification obligations an organization may already have?
An organization can be subject to multiple, overlapping notification regimes simultaneously, and compliance with one does not generally satisfy the others. Depending on the entity and data involved, obligations under HIPAA, state breach notification laws, or non-U.S. frameworks may apply in parallel. Each regime typically has its own scope, triggers, timelines, and notification recipients. Coordinating these obligations, and reconciling differing definitions and deadlines, is an implementation challenge that this entry does not resolve; the mechanics of each parallel regime are out of scope here.
Where should responsibility for breach notification decisions sit within an organization?
Accountability for notification decisions is generally best assigned to a defined role or function rather than left implicit, so that assessment, decision-making, and documentation are clearly owned. In practice this often involves coordination between compliance, legal, and information security functions, since determining whether an incident is a triggering event bridges governance and security concerns. Security teams typically surface and contain incidents, while the legal and compliance assessment of notification obligations is a governance responsibility. This entry does not prescribe a specific organizational structure or job title, and appropriate assignment depends on the entity's size, structure, and regulatory exposure.

Common misconceptions

The Health Breach Notification Rule and the HIPAA Breach Notification Rule are the same thing.
They are separate instruments administered by different U.S. authorities and directed at different sets of entities. The Health Breach Notification Rule generally addresses entities outside HIPAA's coverage, whereas the HIPAA rule applies to covered entities and business associates. Determining which applies requires analyzing the entity's status rather than assuming overlap.
Encrypting or tokenizing the health information means a breach never needs to be reported under this rule.
Applying encryption or tokenization does not automatically remove information from the rule's scope or convert it into non-personal data. Whether a security measure affects notification obligations depends on how the rule defines a breach and treats such measures, and that analysis should be done against the rule text rather than assumed.
Complying with this rule satisfies all breach notification duties an organization may have.
Compliance with the Health Breach Notification Rule addresses only its own requirements. An organization may still face separate obligations under state breach laws, HIPAA where applicable, or non-U.S. frameworks. Meeting one regime's notification requirement generally does not guarantee compliance with the others.

Best practices

Confirm whether your organization falls within the rule's scope by analyzing your entity status and the type of health information you hold, rather than assuming HIPAA or a state law is the only applicable regime.
Maintain a mapping of the different breach notification obligations that may apply to a single incident, including this rule, HIPAA where relevant, applicable state laws, and any non-U.S. frameworks, so that overlapping duties are handled together.
Establish an incident response process that includes a documented assessment step to determine whether a security incident meets the rule's definition of a triggering breach, evaluated against the current rule text.
Do not rely on encryption or tokenization alone as a basis for concluding that notification is unnecessary; document the analysis of how any such controls interact with the rule's definitions.
Retain demonstrable evidence of breach assessments, notification decisions, and the reasoning behind them, since accountability generally requires documented proof rather than stated intent.
Verify current notification timing, content, and recipient requirements against the authoritative rule text before responding to an incident, and treat this entry as scoping the concept rather than providing specific deadlines or thresholds.