Health Breach Notification Rule
Final rule.
CFR Part: "16 CFR Part 318"
RIN Number: "RIN 3084-AB56"
Citation: "89 FR 47028"
Page Number: "47028"
"Rules and Regulations"
Agency: "
SUMMARY: The
DATES: The amendments are effective
ADDRESSES: Relevant portions of the record of this proceeding, including this document, are available at https://www.ftc.gov and https://www.regulations.gov.
FOR FURTHER INFORMATION CONTACT:
SUPPLEMENTARY INFORMATION: The amendments: (1) clarify the Rule's scope, including its coverage of developers of many health applications ("apps"); (2) clarify what it means for a vendor of personal health records to draw PHR identifiable health information from multiple sources; (3) revise the definition of breach of security to clarify that a breach of security includes data security breaches and unauthorized disclosures; (4) revise the definition of PHR related entity; (5) modernize the method of notice; (6) expand the content of the notice; (7) alter the Rule's timing requirement for notifying the
I. Background
FOOTNOTE
FOOTNOTE 2 Health Ins. Portability and Accountability Act, Public Law 104-191, 110 Stat. 1936 (1996). END FOOTNOTE
Specifically, section 13407 of the Recovery Act created certain protections for "personal health records" or "PHRs," /3/ electronic records of PHR identifiable health information on an individual that can be drawn from multiple sources and that are managed, shared, and controlled by or primarily for the individual. /4/
FOOTNOTE 3 42 U.S.C. 17937. END FOOTNOTE
FOOTNOTE 4 42 U.S.C. 17921(11). END FOOTNOTE
FOOTNOTE 5 74 FR 42962 (
The Rule the Commission issued in 2009 ("2009 Rule") requires vendors of personal health records and PHR related entities to provide: (1) notice to consumers whose unsecured PHR identifiable health information has been breached; (2) notice to the Commission; and (3) notice to prominent media outlets /6/ serving a State or jurisdiction, in cases where 500 or more residents are confirmed or reasonably believed to have been affected by a breach. /7/ The Rule also requires third party service providers (i.e., those companies that provide services such as billing, data storage, attribution, or analytics) to vendors of personal health records and PHR related entities to provide notification to such vendors and entities following the discovery of a breach. /8/
FOOTNOTE 6 The Recovery Act does not limit this notice to particular types of media. Thus, an entity can satisfy the requirement to notify "prominent media outlets" by, for example, disseminating press releases to a number of media outlets, including internet media in appropriate circumstances, where most of the residents of the relevant State or jurisdiction get their news. This will be a fact-specific inquiry that will depend on what media outlets are "prominent" in the relevant jurisdiction. 74 FR 42974. END FOOTNOTE
FOOTNOTE 7 16 CFR 318.3, 318.5. END FOOTNOTE
FOOTNOTE 8 Id.
The 2009 Rule requires notice to individuals "without unreasonable delay and in no case later than 60 calendar days" after discovery of a data breach. /9/ If the breach affects 500 or more individuals, notice to the
FOOTNOTE 9 Id.
FOOTNOTE 10 Id.
FOOTNOTE 11 Fed.
FOOTNOTE 12 Fed.
The 2009 Rule applies only to breaches of "unsecured" health information, which the Rule defines as health information that is not secured through technologies or methodologies specified by the
FOOTNOTE 13 Per HHS guidance, electronic health information is "secured" if it has been encrypted according to certain specifications set forth by HHS, or if the media on which electronic health information has been stored or recorded is destroyed according to HHS specifications. See 74 FR 19006; see also
FOOTNOTE 14 45 CFR 164.400 through 164.414. END FOOTNOTE
Since the Rule's issuance, apps and other direct-to-consumer health technologies, such as fitness trackers and wearable blood pressure monitors, have become commonplace. /15/ Further, as an outgrowth of the COVID-19 pandemic, consumer use of such health-related technologies has increased significantly. /16/
FOOTNOTE 15 See, e.g., Kokou Adzo,
FOOTNOTE 16 See id. See also
In
FOOTNOTE 17 85 FR 31085 (
FOOTNOTE 18 Comments are available at https://www.regulations.gov/docket/FTC-2020-0045/comments. END FOOTNOTE
Many of the commenters in 2020 encouraged the Commission to clarify that the Rule applies to apps and similar technologies. /19/ In fact, no commenter opposed this type of clarification regarding the Rule's coverage of health apps. Several commenters pointed out examples of health apps that have abused users' privacy, such as by disclosing sensitive health information without consent. /20/ Several commenters noted the urgency of this issue, as consumers have further embraced digital health technologies during the COVID-19 pandemic. /21/ Commenters argued the Commission should take additional steps to protect unsecured PHR identifiable health information that is not covered by HIPAA, both to prevent harm to consumers /22/ and to level the competitive playing field among companies dealing with the same health information. /23/ To that end, commenters not only urged the Commission to revise the Rule, but also to increase its enforcement efforts. /24/
FOOTNOTE 19 E.g., Am. Health Info. Mgmt. Ass'n ("AHIMA") at 2;
FOOTNOTE 20
FOOTNOTE 21 Lisa McKeen at 2-3;
FOOTNOTE 22 Georgia Morgan; Am. Acad. of Ophthalmology at 2-3 (arguing that consumers do not know all the ways their data is being used by third parties, and the downstream consequences of data being used in this way may ultimately erode a patient's privacy and willingness to disclose information to his or her physician); Coll. of Healthcare Info. Mgmt. Exec.'s ("CHIME") at 3 (arguing that apps' privacy practices impact the patient-provider relationship because providers do not know what technologies are sufficiently trustworthy for their patients); AMA at 2-3 (expressing concern that patients share less health data with health care providers, perhaps because of "spillover from privacy and security breaches"). END FOOTNOTE
FOOTNOTE 23
FOOTNOTE 24
A. The Commission's 2021 Policy Statement
On
FOOTNOTE 25 Statement of the
FOOTNOTE 26 16 CFR 318.2. END FOOTNOTE
The Commission explained that PHR identifiable health information includes individually identifiable health information created or received by a health care provider, /27/ and that "health care providers" include any entities that "furnish[ ] health care services or supplies." /28/ Because these health app purveyors furnish health care services to their users through the mobile applications they provide, the information held in the app is PHR identifiable health information, and therefore many health app purveyors likely qualify as vendors of personal health records. /29/
FOOTNOTE 27 Id.
FOOTNOTE 28 Id.
FOOTNOTE 29 See Policy Statement at 1. END FOOTNOTE
The Policy Statement further explained that the statute directing the
FOOTNOTE 30 The Policy Statement provided this example: "[I]f a blood sugar monitoring app draws health information only from one source (e.g., a consumer's inputted blood sugar levels), but also takes non-health information from another source (e.g., dates from your phone's calendar), it is covered under the Rule." Id. at 2. END FOOTNOTE
FOOTNOTE 31 16 CFR 318.2. END FOOTNOTE
FOOTNOTE 32 Policy Statement at 2. In the Statement of Basis and Purpose to the 2009 Final Rule published in the
B. Enforcement History
In 2023, the Commission brought its first enforcement actions under the Rule against vendors of personal health records. In
FOOTNOTE 33 United States v.
In its complaint, the Commission alleged that between 2017 and 2020,
FOOTNOTE 34 In addition, the Commission alleged
Similarly, on
FOOTNOTE 35 United States v.
Having considered the public comments on the regulatory review notification and its Policy Statement, on
FOOTNOTE 36 88 FR 37819 ("2023 NPRM"). END FOOTNOTE
* First, the Commission proposed to revise several definitions in order to clarify the Rule and better explain its application to health apps and similar technologies not covered by HIPAA. Consistent with this objective, the NPRM modified the definition of "PHR identifiable health information" and added two new definitions ("health care provider" and "health care services or supplies"). These proposed changes were consistent with a number of public comments supporting the Rule's coverage of these technologies.
* Second, the Commission proposed to revise the definition of "breach of security" to clarify that a breach of security includes an unauthorized acquisition of PHR identifiable health information in a personal health record that occurs as a result of a data security breach or an unauthorized disclosure.
* Third, the Commission proposed to revise the definition of "PHR related entity" in two ways. Consistent with its proposal to clarify that the Rule applies to health apps, the Commission first proposed clarifying the definition of "PHR related entity" to make clear that the Rule covers entities that offer products and services through the online services, including mobile applications, of vendors of personal health records. In addition, the Commission proposed revising the definition of "PHR related entity" to provide that entities that access or send unsecured PHR identifiable health information to a personal health record--rather than entities that access or send any information to a personal health record--are PHR related entities.
* Fourth, the Commission proposed to clarify what it means for a personal health record to draw PHR identifiable health information from multiple sources.
* Fifth, in response to public comments expressing concern that mailed notice is costly and not consistent with how consumers interact with online technologies like health apps, the Commission proposed to revise the Rule to authorize electronic notice in additional circumstances. Specifically, the proposed Rule adjusted the language in the "method of notice section" and added a new definition of the term "electronic mail." The proposed Rule also required that any notice delivered by electronic mail be "clear and conspicuous," a newly defined term, which aligns closely with the definition of "clear and conspicuous" codified in the
FOOTNOTE 37 16 CFR 313.3(b). The
* Sixth, the Commission proposed to expand the required content of the notice to individuals, to require that consumers whose unsecured PHR identifiable health information has been breached receive additional important information, including information regarding the potential for harm from the breach and protections that the notifying entity is making available to affected consumers. In addition, the proposed Rule included exemplar notices, which entities subject to the Rule could use to notify consumers in terms that are easy to understand.
* Seventh, in response to public comments, the Commission proposed to make a number of changes to improve the Rule's readability. Specifically, the Commission proposed to include explanatory parentheticals for internal cross-references, add statutory citations in relevant places, consolidate notice and timing requirements in single sections, respectively, of the Rule, and add a new section that plainly states the penalties for non-compliance.
The NPRM also included a section discussing several alternatives the Commission considered but did not propose. Although the Commission did not put forth any proposed modifications on those issues, the Commission nonetheless sought public comment on them.
The Commission received approximately 120 comments in response to the NPRM from a wide spectrum of stakeholders, including consumers, consumer groups, trade associations, think tanks, policy organizations, private sector entities, and members of
FOOTNOTE 38 Comments are available at https://www.regulations.gov/document/FTC-2023-0037-0001/comment. END FOOTNOTE
The Commission believes the amendments are consistent with the language and intent of the Recovery Act, address the concerns raised by the public comments in response to the NPRM, and will ensure the Rule remains current in the face of changing business practices and technological developments.
II. Analysis of the Final Rule
The following discussion analyzes the amendments to the Rule.
A. Clarification of Entities Covered
1. The Commission's Proposal To Clarify the Entities Covered
The Commission proposed changes to several definitions in
The Commission explained that this proposed definition covers traditional health information (such as diagnoses or medications), health information derived from consumers' interactions with apps and other online services (such as health information generated from tracking technologies employed on websites or mobile applications or from customized records of website or mobile application interactions), as well as emergent health data (such as health information inferred from non-health-related data points, such as location and recent purchases). The Commission sought comment as to whether any further amendment of the definition was needed to clarify the scope of data covered.
Second, the NPRM proposed to define the term "health care provider" that appears in the proposed definition of "PHR identifiable health information" ("is created or received by a health care provider"). The Commission proposed to define this term in a manner similar to the definition of "health care provider" found in 42 U.S.C. 1320d(3) (and referenced in 42 U.S.C. 1320d(6), which is directly referenced in section 13407 of the Recovery Act), to mean a provider of services (as defined in 42 U.S.C. 1395x(u)), a provider of medical or other health services (as defined in 42 U.S.C. 1395x(s)), or any other entity furnishing health care services or supplies. The Commission observed that this proposed definition, which is consistent with the statutory scheme, differs from, but does not contradict, the definitions or interpretations adopted by HHS. The Commission sought comment on defining this term more broadly than the term is used in other contexts.
Third, the NPRM proposed to define "health care services or supplies" (the final term in the definition of "health care provider") to include any online service, such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools. The Commission explained that this change clarified that the Rule applies generally to online services, including websites, apps, and internet-connected devices that provide health care services or supplies, and clarified that the Rule covers online services related not only to medical issues (by including in the definition terms such as "diseases, diagnoses, treatment, medications") but also wellness issues (by including in the definition terms such as "fitness, sleep, and diet").
The Commission explained that these proposed changes to the definitions clarified that developers of health apps and similar technologies providing "health care services or supplies" qualify as "health care providers," such that any individually identifiable health information these products collect or use would constitute "PHR identifiable health information" covered by the Rule. The Commission explained that these proposed changes further clarified that a mobile health application can be a "personal health record" covered by the Rule and the developers of such applications can be "vendors of personal health records."
2. Public Comments Regarding the Commission's Proposal To Clarify the Entities Covered
The Commission received numerous comments on the application of the Rule to health apps and similar technologies. A substantial number of commenters supported the Rule's application to health apps and similar technologies not covered by HIPAA as necessary in light of the explosion of health apps and the associated dangers to the privacy and security of consumers' health information. /39/ Notably, support for the Commission's proposals came from a variety of commenters--industry associations, /40/ businesses, /41/ members of
FOOTNOTE 39 See generally, Am. Acad. of Fam. Physicians ("AAFP"); AHIP; AHIMA; Ass'n of Health Info. Outsourcing Serv.'s ("AHIOS"); AMA; Am. Med. Informatics Ass'n ("AMIA"); ANI; Anonymous 1; Anonymous 2; Anonymous 3; Anonymous 4; Anonymous 9; Anonymous 10; Anonymous 11 ; Anonymous 14; Am. Osteopathic Ass'n ("AOA");
FOOTNOTE 40 E.g., AAFP, AHIMA, AHIOS, AMA, AMIA, AOA; Network Advert. Initiative ("NAI"). END FOOTNOTE
FOOTNOTE 41 E.g., Mozilla; MRO;
FOOTNOTE 42 See Members of the
FOOTNOTE 43 E.g., CDD; CDT; EFF;
FOOTNOTE 44 Ella Balasa;
FOOTNOTE 45 Anonymous 1; Anonymous 2; Anonymous 3; Anonymous 4; Anonymous 5; Anonymous 6; Anonymous 9; Anonymous 10; Anonymous 11; Anonymous 14. END FOOTNOTE
FOOTNOTE 46 See, e.g., AAFP at 1-2; AHIMA at 2; AHIOS at 2; Anonymous 5 at 1; AOA at 1; Am. Speech-Language-Hearing Ass'n ("ASHA") at 1; Am. Psychiatric Ass'n ("APA") at 1; CDT at 3-4; CHIME at 2; EFF at 1; Generation Patient at 1;
FOOTNOTE 47 AHIMA at 2; Anonymous 5 at 1; ASHA at 1; EFF at 1; WEDI at 2. One commenter, a software company that assists digital health companies with legal compliance, argued that three factors, in particular, support greater protection for digital health data: (1) consumers mistakenly believe HIPAA covers all health data; (2) there is a culture within some digital health companies that favors rapid adoption of products to secure venture capital even when compliance infrastructure is lacking; and (3) digital health products deal with sensitive data and inherently present a greater privacy risk given their heavy reliance on data and data exchange compared to traditional medicine. Tranquil Data at 1. END FOOTNOTE
FOOTNOTE 48 Confidentiality Coal. at 2; Consumer Rep.'s at 4. END FOOTNOTE
FOOTNOTE 49 See, e.g., AAFP at 2. One commenter, an industry coalition focused on health IT and health care information exchange, emphasized a significant privacy problem adjacent to the Rule: whether HIPAA covered entities should warn patients about the privacy risks associated with health apps and what the Federal government can do to apply equal privacy protections to health data, notwithstanding HIPAA's limitations. See WEDI at 3. One commenter supported the proposed changes but argued the Commission should work with
FOOTNOTE 50 Ella Balasa at 2; PharmedOut at 1. END FOOTNOTE
FOOTNOTE 51 Light Collective at 5. END FOOTNOTE
FOOTNOTE 52 EFF at 2. END FOOTNOTE
FOOTNOTE 53 Texas Med. Ass'n ("TMA") at 1-2. END FOOTNOTE
Although many commenters expressed support for the proposed changes, several business coalitions, industry associations and individual firms opposed the changes, which, they argued, are inconsistent with
FOOTNOTE 54 See, e.g., Ass'n of Nat'l
FOOTNOTE 55 Priv. for Am. at 2-3; Chamber at 6-7; Health Innovation All. ("HIA") at 1. See also Advanced Med. Tech. Ass'n ("AdvaMed") at 1 (recommending the Commission adopt a privacy framework pursuant to the advanced notice of proposed rulemaking (R111004) regarding commercial surveillance and data security (87 FR 51273,
FOOTNOTE 56 CCIA at 4. END FOOTNOTE
Some commenters opposed to the changes also argued that the revised definitions would reduce choice and access in the marketplace, /57/ stifle innovation, /58/ or create disincentives for advertising /59/ because (1) firms would risk initiating breaches by sharing user data with their partners and (2) in accepting data from health apps, partners such as advertising and analytics firms would risk being covered by the Rule. /60/ According to some commenters, placing such strictures on the advertising and service provider ecosystem would raise prices (by, for example, undermining ad-supported services) and thereby harm competition. /61/ One commenter argued that while robust protections for consumer health data are needed, the Rule should not be a vehicle for such protections, because it will result in over-notification of consumers (who have largely learned to disregard breach notices) and be a barrier to legislative change on privacy and data security issues more generally. /62/ Another commenter argued against a breach notification rule altogether, asserting that the Commission should instead focus on requiring robust data security practices to prevent breaches in the first instance. /63/
FOOTNOTE 57 Am. Telemedicine Ass'n ("ATA Action") at 1. END FOOTNOTE
FOOTNOTE 58 TechNet at 1-2; CTA at 5. END FOOTNOTE
FOOTNOTE 59 ANA at 3. END FOOTNOTE
FOOTNOTE 60 Priv. for Am. at 3. END FOOTNOTE
FOOTNOTE 61 E.g., ANA at 3; Priv. for Am. at 1, 3-4. END FOOTNOTE
FOOTNOTE 62 World Priv F. ("WPF") at 4. END FOOTNOTE
FOOTNOTE 63 HIA at 2. END FOOTNOTE
Some commenters specifically addressed the proposed changes to the definitions of "PHR identifiable health information" and the new definitions of "health care provider" and "health care services or supplies." First, a number of comments addressed the scope of "PHR identifiable health information." Some commenters urged greater breadth, arguing, for example, that the definition of "PHR identifiable health information" should be expanded to include other types of data, such as data about an individual--not just data provided by or on behalf of an individual. /64/ Other commenters urged the Commission to state expressly that its definition encompasses particular types of information, such as unique persistent identifiers /65/ or information about sexual health /66/ or substance use or treatment. /67/ By contrast, some commenters urged the Commission to narrow the definition or otherwise clarify its limits, by, for example, exempting data relating to clinical research or trials /68/ or data that has been de-identified. /69/
FOOTNOTE 64 Consumer Rep.'s at 3. END FOOTNOTE
FOOTNOTE 65 Id. END FOOTNOTE
FOOTNOTE 66 BPC at 1-2;
FOOTNOTE 67 Legal Action Ctr. & Opioid Pol'y Inst. at 1-2. END FOOTNOTE
FOOTNOTE 68 Soc'y for Clinical Rsch. Sites ("SCRS") at 1. END FOOTNOTE
FOOTNOTE 69 Future of Priv. F. ("FPF") at 3. END FOOTNOTE
Relatedly, some commenters urged the Commission to create a definition of or standard for "identifiable data," "de-identification" or "de-identified data," /70/ such as by adopting HHS's de-identification standard, /71/ or by stating that information is identifiable if it is "reasonably linkable to an identified or identifiable individual." /72/ Commenters argued that clarifying what constitutes "identifiable" data is necessary both because of the increasing ability for de-identified data to be re-identified /73/ and because the market needs clarity to enable uninhibited flow of de-identified health data for research, public health, and commercial activities. /74/ Indeed, according to one commenter, failure to clarify the standard could complicate or chill public health research and other innovation. /75/ One commenter argued that an objective standard of "reasonable linkability" is better than what the commenter described as the Rule's knowledge-based standard (i.e., whether the company has a reasonable basis to believe it can be used to identify an individual). /76/ One commenter urged the Commission to issue a new notice of proposed rulemaking on the issue of de-identification alone. /77/
FOOTNOTE 70 SCRS at 2; Chamber at 7; EPIC at 7-9; FPF at 3-4, LAB at 2; MRO at 4;
FOOTNOTE 71 LAB at 2; Network at 3; SCRS at 2. END FOOTNOTE
FOOTNOTE 72 FPF at 3. END FOOTNOTE
FOOTNOTE 73 SCRS at 2. END FOOTNOTE
FOOTNOTE 74 FPF at 3; Network at 3-4. END FOOTNOTE
FOOTNOTE 75 Network at 3. END FOOTNOTE
FOOTNOTE 76 FPF at 3. END FOOTNOTE
FOOTNOTE 77 Chamber at 7. END FOOTNOTE
Second, many commenters specifically addressed the Commission's proposed new definition of "health care provider." One commenter applauded the Commission's revised definition of "health care provider," arguing that taking a crabbed view of that or related terms would lead to further fragmentation of health data, which is already fragmented by HIPAA's limited purview. /78/ Another commenter noted the Commission's definition of "health care provider" is simply a logical outgrowth of how consumers interact with health apps: consumers look to health apps to provide health-related services--the quintessential function of a health care provider. /79/
FOOTNOTE 78 CDT at 11. END FOOTNOTE
FOOTNOTE 79 Confidentiality Coal. at 3-4. END FOOTNOTE
Other commenters, however, raised concerns that the proposed definition of "health care provider" is confusing in its departure from HIPAA's terminology or is otherwise overbroad. /80/ Some commenters argued this departure from the traditional meaning of the term is not what
FOOTNOTE 80 AAFP at 2-3; AdvaMed at 3-4; AHIP at 2; AMA at 2-3; ATA Action at 1;
FOOTNOTE 81 ANA at 5; ATA Action at 1;
FOOTNOTE 82
FOOTNOTE 83 WPF at 7. END FOOTNOTE
FOOTNOTE 84 AHIP at 2. END FOOTNOTE
FOOTNOTE 85 AMA at 3. END FOOTNOTE
FOOTNOTE 86 AHIP at 2. END FOOTNOTE
FOOTNOTE 87 Datavant at 2. END FOOTNOTE
FOOTNOTE 88 AAFP at 2-3. END FOOTNOTE
Several comments also expressed concern with the final phrase of the definition of "health care provider" ("any other entity furnishing health care services or supplies"), as overly broad and confusing. Commenters argued its breadth (and the breadth of the accompanying definition of "health care services or supplies") would have perverse results, turning retailers of tennis shoes, shampoo, or vitamins into entities covered by the Rule, which is not what
FOOTNOTE 89 ANA at 7-8; CCIA at 4; CHI at 3-4; CTA at 7-8; SIIA at 2. END FOOTNOTE
FOOTNOTE 90 ANA at 3; SIIA at 1. END FOOTNOTE
Several commenters urged the Commission to address this problem by dropping the phrase "any other entity furnishing health care services or supplies" entirely--or at least excising the word "supplies"--from the definition of "health care provider." /91/ One commenter recommended replacing the phrase with a different phrase: "any other person or organization who furnishes, bills, or is paid for health care in the normal course of business." /92/ Another commenter recommended expressly excluding retailers. /93/ Commenters requested further clarification of certain terms within the definition of "health care provider," including the terms "furnishing" /94/ and "health care." /95/ And another commenter argued a better approach would be to jettison the definitions of "health care provider" and "health care services and supplies" entirely and instead apply the Rule to any entity that "promotes its offering as addressing, improving, tracking or informing matters about a consumer's health." /96/
FOOTNOTE 91 AdvaMed at 4; CHI at 4; CTA at 9; TechNet at 2. END FOOTNOTE
FOOTNOTE 92 AdvaMed at 4. END FOOTNOTE
FOOTNOTE 93 CTA at 8-9. END FOOTNOTE
FOOTNOTE 94 EPIC at 2. END FOOTNOTE
FOOTNOTE 95 AdvaMed at 3 (urging the Commission to define "health care" and "health care provider" as in 45 CFR 160.103). END FOOTNOTE
FOOTNOTE 96 WPF at 10. END FOOTNOTE
Third, some commenters addressed the proposed definition of "health care services or supplies." /97/ Several commenters requested more clarity as to what constitutes an "online service," /98/ as nearly all commercial activities have some online presence. /99/ Several commenters recommended deleting the final phrase of the definition ("or that provides other health-related services or tools") to limit the definition's breadth. /100/ Conversely, some commenters urged the Commission to reinforce its breadth, by expressly stating that "health care services or supplies" include services related to "wellness" /101/ or to specific health conditions, such as substance abuse disorder diagnosis, treatment, medication, recurrence of use ("relapse") and recovery. /102/
FOOTNOTE 97 AdvaMed at 3; AAFP at 3; AHIP at 3; Priv. for Am. at 6-7. END FOOTNOTE
FOOTNOTE
FOOTNOTE 99 WPF at 8. END FOOTNOTE
FOOTNOTE 100 NAI at 4. END FOOTNOTE
FOOTNOTE 101 EPIC at 4. END FOOTNOTE
FOOTNOTE 102 Legal Action Ctr. & Opioid Pol'y Inst. at 3. END FOOTNOTE
3. The Commission Adopts the Proposed Changes To Clarify the Entities Covered
After considering the comments received, the Commission adopts the proposed changes to the Rule (with only non-substantive, organizational improvements noted below) to clarify that the Rule applies to mobile health applications and similar technologies. The Commission agrees with the substantial number of comments, from many different types of entities and individuals, who argued that such clarification is necessary in light of changing technology (i.e., the mass adoption of health apps) and the privacy and data security risks to consumer health data collected by that technology. The Commission also agrees with commenters who argued that the proposed changes to the Rule are consistent with the Recovery Act, which was intended to bolster breach notifications for consumer health data that falls outside HIPAA. Although the Commission agrees with commenters who argue that consumer health data should enjoy substantial and unfragmented privacy protections, this Rule addresses breach notification, not omnibus privacy protections. While this rulemaking does not address omnibus privacy protections, the Commission observes that companies collecting or holding consumers' sensitive health data should engage in many of the practices commenters described, such as imposing data retention limits, enabling deletion options, and preventing breaches through robust privacy and data security practices. /103/
FOOTNOTE 103 In the 2009 Final Rule, the Commission similarly underscored the importance of maintaining protections for health information, stating: "In addition, as noted in the NPRM, the Commission expects entities that collect and store unsecured PHR identifiable health information to maintain reasonable security measures, including breach detection measures, which should assist them in discovering breaches in a timely manner." 74 FR 42971 n.93 (2009). END FOOTNOTE
The Commission is not persuaded that applying the Rule to health apps and similar technologies will have deleterious consequences for individual firms or competition or result in over-notification of consumers. Importantly, the only obligation the Rule imposes is to notify the Commission, consumers, and, in some cases, the media of a breach of unsecured PHR identifiable health information. As noted in the NPRM, many State laws already impose similar, or significantly broader, data breach obligations. /104/ Moreover, firms can avoid notification costs entirely by avoiding breaches--by reducing the amount of unsecured PHR identifiable health information they access and maintain (which can be achieved by securing PHR identifiable health information), by de-identifying health information, and by implementing other privacy and data security measures appropriate to the sensitivity of the data.
FOOTNOTE 104 88 FR 37832 n.103. END FOOTNOTE
The Commission carefully considered the arguments commenters raised that the definitional changes depart from the language or spirit of the Recovery Act. The Commission does not agree. The definitions hew closely to the language of the Recovery Act and to the definitions directly referenced by the Recovery Act in section 1171(6) of the Social Security Act, 42 U.S.C. 1320d(6). As many commenters noted, while health apps did not exist when
For these reasons, the Commission is adopting the proposed definitions, with minor clarifications. First, the Commission has retained the definition of "PHR identifiable health information" as set out in the NPRM, with non-substantive organizational changes noted below. In response to comments that the definition of "PHR identifiable health information" should be broader, the Commission notes the definition, which closely follows the statutory language, already encompasses most of the categories of data that commenters identified. For example, unique, persistent identifiers (such as unique device and mobile advertising identifiers), when combined with health information, constitute "PHR identifiable health information," if these identifiers can be used to identify or re-identify an individual. Moreover, "PHR identifiable health information" encompasses information about sexual health and substance abuse disorders, because the information "relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual." The Recovery Act states PHR identifiable health information is information provided "by or on behalf of the individual," so the Commission declines to change this phrase to "about," as one commenter suggested. /105/ The Commission notes, however, that information provided "by or on behalf of the individual" will encompass much information "about" an individual, as the consumer is the original source of most data; many inferences "about" the individual originate from information provided "by or on behalf of the individual."
FOOTNOTE 105 Consumer Rep.'s at 4. END FOOTNOTE
The Commission does not agree with commenters who sought to narrow the definition of PHR identifiable health information out of concern for the Rule's overall breadth. The Commission notes that liability under the Rule does not arise from a single definition. While data used for public health research, for example, may, in some instances, meet the definition of "PHR identifiable health information," the firm using that data is subject to the Rule only if other conditions are met (i.e., the firm is an entity covered by the Rule).
The Commission declines to create a new definition of "de-identified data" or another similar term, because the definition of de-identification is already embedded in the second part of the definition of PHR identifiable health information ("that identifies the individual or with respect to which there is a reasonable basis to believe that the information can be used to identify the individual"). Where there is no "reasonable basis to believe that the information can be used to identify the individual," the information is not identifiable; rather, it is de-identified. If data has been de-identified according to standards set forth by HHS, then there is not a "reasonable basis to believe that the information can be used to identify the individual," as the definition of PHR identifiable health information requires. Because the Commission's standard is consistent with HHS's, the Commission's Rule poses no impediment to health-related research or other flows of de-identified data. The Commission does not view the existing language as a subjective standard that turns on a company's knowledge, as one commenter suggested; by requiring a "reasonable basis to believe" that the information is not identifiable, the Rule creates an objective standard. Whether such reasonable basis exists will depend on whether the data can reasonably be linked to an individual consumer. There is no need for a supplemental notice of proposed rulemaking on this issue, as the Commission is not changing this aspect of the Rule, which closely follows the statute. /106/
FOOTNOTE 106 42 U.S.C. 17937(f)(2). END FOOTNOTE
Second, the Commission is modifying the proposed definition of "health care provider" to "covered health care provider" to distinguish that term from interpretations of the term "health care provider" in other contexts, which may be more limited in scope. As commenters requested, the Commission affirms its definition of "covered health care provider" is unique to the Rule; it does not bear on the meaning of "health care provider" as used in other regulations enforced by other government agencies. The Commission adopts this change merely to dispel confusion in terminology; the Commission is not making any substantive change from the definition as proposed. The Commission does not need to state expressly, either in this definition or elsewhere, that the Rule's notification requirements do not apply to HIPAA-covered entities and their business associates, as
FOOTNOTE 107 The definition of "covered health care provider" in
Third, the Commission is adopting the proposed definition of "health care services or supplies," with one minor modification: the Commission has substituted the word "means" for "includes" to avoid implying greater breadth than the Commission intends. The Commission adopts this change merely to dispel confusion about undue breadth; the Commission does not intend any substantive change from the definition proposed. The Commission otherwise affirms the proposed definition without change. The Commission believes the term "online service" in the definition of "health care services or supplies" is sufficiently clear because of the examples of "online services" given within the definition itself: website, mobile application, or internet-connected device. Providing an exhaustive list of what constitutes an online service would prevent the definition from being sufficiently flexible to account for future innovation in types of online services. The Commission also retains the catch-all "or that provides other health-related services or tools" for the same reason: to ensure the Rule's language can accommodate future changes in technology. There is no undue breadth, because that phrase's meaning is in the context of the preceding phrase ("provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet").
In response to some commenters' concerns that the proposed Rule's definition of "health care provider" and "health care services or supplies" would impermissibly cause the Rule to cover retailers of general-purpose items like tennis shoes, shampoo, or vitamins, the Commission disagrees this would necessarily be the case. A threshold inquiry under the Rule is whether an entity is a "vendor of personal health records," which the Recovery Act defines as "an entity . . . that offers or maintains a personal health record." /108/ The Recovery Act usage of the term "vendor of" in connection with "personal health records" underscores that entities that are not in the business of offering or maintaining (e.g., selling, marketing, providing, or promoting) a health-related product or service are not covered--in other words, they are not "vendors" of personal health records. Thus, to be a vendor of personal health records under the Rule, an app, website, or online service must provide an offering that relates more than tangentially to health. /109/
FOOTNOTE 108 42 U.S.C. 17921(18); see also 42 U.S.C. 17937. END FOOTNOTE
FOOTNOTE 109 At least one commenter urged a somewhat similar interpretation, contending that a relevant inquiry in determining whether a service offers a personal health record is "the terms under which a product or service is offered to consumers. If an entity promotes its offering as addressing, improving, tracking, or informing matters about a consumer's health, then that entity's offering would be subject to the rule. Thus, any product or services that tracks or addresses physical activity, blood pressure, heart rate, digestion, strength, genetics, sleep, weight, allergies, pain, and similar characteristics would be subject to a PHR rule." See WPF at 10. END FOOTNOTE
The Commission notes a general retailer (one that sells food products, children's toys, garden supplies, healthcare products (such as pregnancy tests), or apparel (such as maternity clothes)) offering consumers an app to purchase and access purchases of these products--by itself--would not make the retailer a vendor of personal health records. In this scenario, purchase information relating to certain items--such as a pregnancy test or maternity clothes from a retailer--may reveal information about that person's health. While this purchase information may be PHR identifiable health information, the retailer in this scenario is not a vendor of personal health records because the app is only tangentially related to health. The Commission notes, however, there may be scenarios where a general-purpose retailer described above may become a vendor of personal health records under the Rule, such as where the retailer offers an app with features or functionalities that are sold, marketed, or promoted as more than tangentially relating to health.
In addition, the Commission reiterates a personal health record must be an electronic record of PHR identifiable health information on an individual, must have the technical capacity to draw information from multiple sources, and must be managed, shared, and controlled by or primarily for the individual. The Commission also notes that purchases of items at a brick and mortar retailer where there is no app, website, or online service to access or track that purchase information electronically is not a personal health record, because there is no electronic record at issue. Contrary to the assertions of some commenters, these definitions do not result in undue breadth, because they do not function in isolation. The Commission provides the following examples to illustrate the interplay of these definitions with the definition of "personal health record":
* Example 1: Health advice app or website A, which is not covered by HIPAA, provides information to consumers about various medical conditions. Its function is purely informational; it does not provide any mechanism through which the consumer may track or record information. Health advice app or website A is not a personal health record, because it is not an electronic record of PHR identifiable health information on an individual.
* Example 2: Health advice app or website B, which is not covered by HIPAA, provides information to consumers about various medical conditions and provides a symptom tracker, available to consumers who log into the site with a username and password, in which consumers may input symptoms and receive potential diagnoses. Health advice app or website B is an electronic record of PHR identifiable health information on an individual, because its information is provided by the individual, it identifies the individual (via username and password), it relates to the individual's health conditions (the symptoms), and is received by a health care provider (i.e., the entity providing the site itself, as that entity is furnishing the health care service of an online service that provides mechanisms to track symptoms). However, health advice app or website B is not a personal health record to the extent the site does not have the technical capacity to draw information from multiple sources (i.e., if the consumer is its only source of information).
* Example 3: Health advice website C, which is not covered by HIPAA, functions in the same way as health advice app or website B, except that it collects geolocation data via an application programming interface ("API"). For the reasons stated in Example 2, it is an electronic record of PHR identifiable health information on an individual. It also has the technical capacity to draw information from multiple sources (consumer inputs and collection of geolocation data through the API. It is managed primarily for the individual (i.e., to provide the individual health advice). Therefore, health advice app or website C is a personal health record.
* Example 4: Health advice app or website D, which is not covered by HIPAA, functions in the same way as health advice app or website B, except that it also draws information from a data broker and connects that information to some of its individual users to provide them with more accurate diagnostic suggestions. For the reasons stated in Example 2, it is an electronic record of PHR identifiable health information on an individual. It also has the technical capacity to draw information from multiple sources (the consumer and the data broker) and is managed by or primarily for the individual. Therefore, health advice app or website D is a personal health record.
Whether a health app or other electronic record constitutes a personal health record (and is therefore subject to the Rule) is a fact-intensive inquiry whose outcome depends not only on the nature of the information contained in that record, but also on numerous other factors, such as its "technical capacity," its source(s) of information, and its relationship to the individual.
Finally, the Commission notes a non-substantive, organizational change relating to the definition of "PHR identifiable health information." In the 2023 NPRM, the Commission proposed revising "PHR identifiable health information" by importing language from section 1171(6) of the Social Security Act, 42 U.S.C. 1320d(6), which is referenced directly in section 13407 of the Recovery Act. To hew more closely to the organization of the Recovery Act, and to preserve the word "includes" in the phrase "includes information that is provided by or on behalf of the individual," the Commission revised slightly the order of the elements in the definition of "PHR identifiable health information."
B. Clarification of What It Means for a Personal Health Record To Draw Information From Multiple Sources
1. The Commission's Proposal Regarding What It Means for a Personal Health Record To Draw Information From Multiple Sources
The Commission proposed amending the definition of the term "personal health record" to clarify what it means for a personal health record to draw information from multiple sources. Under the 2009 Rule, a personal health record is defined as an electronic record of PHR identifiable health information that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual. Under the Commission's proposed definition, a "personal health record" would be defined as an electronic record of PHR identifiable health information on an individual that has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual.
Changing the phrase "that can be drawn from multiple sources" to "has the technical capacity to draw information from multiple sources" serves several purposes. First, it clarifies a product is a personal health record if it can draw information from multiple sources, even if the consumer elects to limit information to a single source only, in a particular instance. For example, a depression management app that accepts consumer inputs of mental health states and has the technical capacity to sync with a wearable sleep monitor is a personal health record, even if some customers choose not to sync a sleep monitor with the app. Thus, whether an app qualifies as a personal health record would not depend on the prevalence of consumers' use of a particular app feature, like sleep monitor-syncing. Instead, the analysis of the Rule's application would be straightforward: either the app has the technical means (e.g., the application programming interface or API) to draw information from multiple sources, or it does not. Next, adding the phrase "technical capacity to draw information" clarifies a product is a personal health record if it can draw any information from multiple sources, even if it only draws health information from one source. This change further clarifies the Commission's interpretation of the Recovery Act, as explained in the Policy Statement. /110/
FOOTNOTE 110 Policy Statement at 2. END FOOTNOTE
The Commission sought public comment as to whether this revised language sufficiently clarifies the Rule's application to developers and purveyors of products that have the technical capacity to draw information from more than one source. The Commission invited comment on its interpretation that an app is a personal health record because it has the technical capacity to draw information from multiple sources, even if particular users of the app choose not to enable the syncing features. The Commission also requested comment about whether an app (or other product) should be considered a personal health record even if it only draws health information from one place (in addition to non-health information drawn elsewhere); or only draws identifiable health information from one place (in addition to non-identifiable health information drawn elsewhere). The Commission further requested comment about whether the Commission's bright-line rule (apps with the "technical capacity to draw information" are covered) should be adjusted to take into account consumer use, such as where no consumers (or only a de minimis number) use a feature, and about the likelihood of such scenarios. For example, the Commission offered an example of an app that might have the technical capacity to draw information from multiple sources, but its API is entirely or mostly unused, either because it remains a Beta feature, has not been publicized, or is not popular.
2. Public Comments Regarding What It Means for a Personal Health Record To Draw Information From Multiple Sources
Many commenters supported the Commission's proposal amending the definition of a "personal health record." /111/ Commenters noted, for instance, this change would help to ensure that many services that collect PHR identifiable health information are covered by the Commission's Rule, /112/ and would help to promote greater privacy and security for health information, /113/ while still "hewing to the limitations of the statute." /114/ Some commenters noted without this change, developers of personal health records (such as app developers) might have incentives to design their products in ways that would intentionally skirt the Rule's requirements (such as by restricting a consumer's ability to import data from other sources). /115/ Others noted the importance of the Rule covering apps with the technical capacity to draw information from multiple sources even where such capacity is not used by the consumer. /116/
FOOTNOTE 111 Ella Balasa at 1; TMA at 4 (arguing that "PHRs include applications with the technical capacity to draw information from multiple sources, regardless of the patient's preference to activate the technical capability."); Consumer Rep.'s at 6; AAFP at 3; AHIMA at 4-5; AMA at 4; CHIME at 4; CDT at 13; AOA at 3. END FOOTNOTE
FOOTNOTE 112 AHIMA at 4-5. END FOOTNOTE
FOOTNOTE 113 AAFP at 3. END FOOTNOTE
FOOTNOTE 114 Consumer Reports at 5-6. END FOOTNOTE
FOOTNOTE 115 AHIP at 2-3; CDT at 13 (arguing that changes remove "incentives for companies to technically design products and services to not trigger the HBNR to avoid any need to provide consumer notice."). END FOOTNOTE
FOOTNOTE 116 AHIOS at 4;
Other commenters opposed this proposal. /117/ Some argued the proposed clarification regarding what drawing information from multiple sources means runs counter to
FOOTNOTE 117 NAI at 6 (urging that the Commission make clear that a personal health record is one that "not only has the technical capacity to draw PHR identifiable health information from multiple sources, but that it also has the functionality and actually does incorporate data from multiple sources."); ANA at 7; ACLA at 1-2. END FOOTNOTE
FOOTNOTE 118 NAI at 6. END FOOTNOTE
FOOTNOTE 119 Chamber at 4-5; Priv. for Am. at 5-6; NAI at 6. END FOOTNOTE
FOOTNOTE 120 CCIA at 6. END FOOTNOTE
FOOTNOTE 121 CTA at 11; AdvaMed at 5; CHI at 5. END FOOTNOTE
FOOTNOTE 122 CHI at 5 (asking the Commission to clarify that an "app having the ability to draw from multiple sources with some changes to the app's coding/APIs is not within this definition's threshold."); ACLA at 1 (arguing "[i]f a feature is unused by individuals 'because it remains a Beta feature,' then in fact it does not have the 'technical capacity' to draw an individual's information from other sources, unless and until its functionality has been enabled by the vendor. The mere possibility that an application vendor might sometime in the future enable that functionality should not bring the electronic record within the scope of the definition of 'personal health record.' ") (emphasis in original); CTA at 11 (arguing Rule should instead have bright-line test that assesses whether the app actually draws health information from multiple sources); AdvaMed at 5 (arguing the Commission should decline to adopt multiple sources changes because it could cause confusion and potentially sweep in apps or services with features that have not been made available to consumers, such as APIs connected to the PHR that have not been publicized). END FOOTNOTE
FOOTNOTE 123 WPF at 9. END FOOTNOTE
FOOTNOTE 124
FOOTNOTE 125
FOOTNOTE 126 AHIOS at 4; MRO at 4. END FOOTNOTE
Another commenter expressed concern the proposed change could sweep in services that draw any information from multiple sources, regardless of whether that information is identifiable health information. /127/
FOOTNOTE 127 NAI at 6. END FOOTNOTE
3. The Commission Adopts the Proposed Changes Clarifying What It Means for a Personal Health Record To Draw Information From Multiple Sources
After considering the comments received, the Commission adopts the proposed amendment without change. This amendment will help clarify the types of entities covered by the Rule. The definition does not create undue breadth or deviate from Congressional intent; rather, the changes are consistent with the language of the Recovery Act, and only serve to give meaning to the phrase "can be drawn" in the Recovery Act in a way that is consistent with the current state of technology. They are also necessary to keep pace with technological change, which has enabled firms to offer consumers mobile electronic records of their health information that contain numerous integrations. To illustrate the intended meaning of the proposed revisions to the term "personal health record," the Commission reiterates examples from the 2023 NPRM of two non-HIPAA covered diet and fitness apps available for consumer download in an app store. Under the amended Rule, each is a personal health record.
* Example 1: Diet and fitness app Y allows users to sync their app with third-party wearable fitness trackers. Diet and fitness app Y has the technical capacity to draw identifiable health information both from the user (e.g., name, weight, height, age) and the fitness tracker (e.g., user's name, miles run, heart rate), even if some users elect not to connect the fitness tracker.
* Example 2: Diet and fitness app Y has the ability to pull information from the user's phone calendar via the calendar API to suggest personalized healthy eating options. Diet and fitness app Y has the technical capacity to draw identifiable health information from the user (e.g., name, weight, height, age) and non-health information (e.g., calendar entry info, location, and time zone) from the user's calendar.
As these examples make clear, and in response to one commenter's concern that the changes would sweep in services that do not draw any health information, /128/ the Commission notes the Rule still requires drawing PHR identifiable health information from at least one source to count as a personal health record.
FOOTNOTE 128 NAI at 6. END FOOTNOTE
The Commission declines to make other requested changes to the definition of personal health record. First, the Commission declines to include an express exemption for HIPAA-covered entities within the definition of personal health record because
FOOTNOTE 129 See, e.g., 16 CFR 318.1(a) (Rule "does not apply to HIPAA-covered entities, or to any other entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity."); see also 16 CFR 318.2 (exempting business associates and HIPAA-covered entities from the Rule's definitions of "PHR related entity" and "vendor of personal health records."). END FOOTNOTE
FOOTNOTE 130 ACLA at 1-2; CTA at 11; AdvaMed at 5. END FOOTNOTE
Further, and importantly, the Rule is triggered only by breaches of unsecured PHR identifiable health information and does not apply to information that is protected or "secured" through the use of a technology or methodology specified by the Secretary of
FOOTNOTE 131 Per HHS guidance, electronic health information is "secured" if it has been encrypted according to certain specifications set forth by HHS, or if the media on which electronic health information has been stored or recorded is destroyed according to HHS specifications. See 74 FR 19006; see also
Third, the Commission declines, as one commenter requested, /132/ to expressly exempt scenarios where a change is required to an app's coding to draw information from another source. The Commission notes, however, it does not intend to cover instances where an app can draw from multiple sources only through changes to the design or underlying software code and where the app developer does not implement those changes.
FOOTNOTE 132 CHI at 5 (asking the Commission to clarify that an "app having the ability to draw from multiple sources with some changes to the app's coding/APIs is not within this definition's threshold."). END FOOTNOTE
In addition, the Commission declines to remove from the definition of personal health record the requirement that it be "managed, shared, and controlled by or primarily for the individual." This language mirrors the Recovery Act's statutory definition of personal health record. /133/ Further, this language provides a boundary to the definition. Even if a website or app has the technical capacity to draw information from multiple sources (for example, because it has integrations for advertising or analytics), it must still be "managed, shared, and controlled by or primarily for the individual" to be covered by the Rule.
FOOTNOTE 133 42 U.S.C. 17921(11). END FOOTNOTE
Generally, a personal health record is an electronic record of an individual's health information by which the individual maintains access to the information and may have, for example, the ability to manage, track, control, or participate in his or her own health care. If these elements are not present, the website or app may not be "managed, shared, and controlled by or primarily for the individual," and would not, therefore, constitute a personal health record.
C. Clarification Regarding Types of Breaches Subject to the Rule
1. The Commission's Proposals
a. The Commission's Proposal Regarding "Breach of Security"
The Commission proposed a definitional change to clarify that a breach of security under the Rule encompasses unauthorized acquisitions that occur as a result of a data breach or an unauthorized disclosure. The Commission's proposal underscores that a breach of security is not limited to data exfiltration, and includes unauthorized disclosures (such as, but not limited to, a company's unauthorized sharing or selling of consumers' information to third parties that is inconsistent with the company's representations to consumers). The Rule previously defined "breach of security" as the acquisition of unsecured PHR identifiable health information of an individual in a personal health record without the authorization of the individual, which language mirrored the definition of "breach of security" in section 13407(f)(1) of the Recovery Act.
Accordingly, consistent with the Recovery Act definition, the Policy Statement,
The NPRM, like the 2009 Rule, continued to include a rebuttable presumption for unauthorized access to an individual's data; it stated when there is unauthorized access to data, unauthorized acquisition will be presumed unless the entity that experienced the breach "has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information."
b. The Commission's Related Proposal To Not Define the Term "Authorization" in the Rule
In the 2023 NPRM, the Commission stated it had considered defining the term "authorization," which appears in
The Commission considered defining "authorization" to mean the affirmative express consent of the individual and then defining "affirmative express consent" consistent with State laws that define consent, such as the California Consumer Privacy Rights Act, Cal. Civ. Code 1798.140(h). /134/ Such changes would have ensured notification is required anytime there is acquisition of unsecured PHR identifiable health information without the individual's affirmative express consent for that acquisition--such as when an app discloses unsecured PHR identifiable health information to another company, having obtained nominal "consent" from the individual by using a small, greyed-out, pre-selected checkbox following a page of dense legalese.
FOOTNOTE 134 As noted in the 2023 NPRM, the Commission considered defining "affirmative express consent" as any freely given, specific, informed, and unambiguous indication of an individual's wishes demonstrating agreement by the individual, such as by a clear affirmative action, following a clear and conspicuous disclosure to the individual, apart from any "privacy policy," "terms of service," "terms of use," or other similar document, of all information material to the provision of consent. Acceptance of a general or broad terms of use or similar document that contains descriptions of agreement by the individual along with other, unrelated information, does not constitute affirmative express consent. Hovering over, muting, pausing, or closing a given piece of content does not constitute affirmative consent. Likewise, agreement obtained through use of user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice, does not constitute affirmative express consent. See 88 FR 37830 n.78. END FOOTNOTE
The Commission did not, however, propose to define "authorization" because (1) the 2009 Rule Commentary already provided guidance on the types of disclosures the Commission considers to be "unauthorized"; /135/ (2) recent Commission orders, such as the Commission's enforcement actions against
FOOTNOTE 135 See, e.g., 74 FR 42967. END FOOTNOTE
FOOTNOTE 136 United States v.
The Commission sought public comment about:
* Whether the commentary above and
* To the extent that including such definitions would be appropriate, the definitions of "authorization" and "affirmative express consent," as described above, and the extent to which such definitions are consistent with the language and purpose of the Recovery Act.
* What constitutes an acceptable method of authorization, particularly when unauthorized sharing is occurring. /137/
FOOTNOTE 137 For example, the Commission sought comment about when a vendor of personal health records or a PHR-related entity is sharing information covered by the Rule, is it acceptable for that entity to obtain the individual's authorization to share that information when an individual clicks "agree" or "accept" in connection with a pre-checked box disclosing such sharing? Is it sufficient if an individual agrees to terms and conditions disclosing such sharing but that individual is not required to review the terms and conditions? Or is it sufficient if an individual uses a health app that discloses in its privacy policy that such sharing occurs, but the app knows via technical means that the individual never interacts with the privacy policy? See 88 FR 37832. END FOOTNOTE
* Whether there are certain types of sharing for which authorization by consumers is implied because such sharing is expected and/or necessary to provide a service to consumers.
2. Public Comments
a. Public Comments Regarding "Breach of Security"
Many commenters supported the Commission's proposed amendment to the definition of "breach of security." /138/ One commenter noted the change is consistent with the broad definition of "breach of security" in the Recovery Act, which refers explicitly to the acquisition of PHR identifiable health information without the authorization of an individual (rather than the authorization of an entity holding the data, as is the case where a breach involves data theft or exfiltration). /139/ Commenters also noted the amendment would ensure notice, accountability, and regulatory oversight, regardless of the underlying cause of the unauthorized acquisition. /140/ Commenters noted that breaches encompass more than just cybersecurity intrusions. /141/ Commenters also argued that a company's voluntary unauthorized disclosure can be just as damaging as data theft. /142/ For instance, a commenter noted that unauthorized disclosures of health information may cause embarrassment, perpetuate stigma about patients' conditions, deter patients from seeking care, interfere in the patient-physician relationship, or impact patients' employment. /143/ Moreover, voluntary, unauthorized disclosures increase the risk of additional unauthorized acquisition and sharing of this information among bad actors. /144/
FOOTNOTE 138 See, e.g., TMA at 3;
FOOTNOTE 139 Consumer Rep.'s at 4. END FOOTNOTE
FOOTNOTE
FOOTNOTE 141 AMA at 4; CDT at 11-12; EPIC at 5. END FOOTNOTE
FOOTNOTE 142 AAFP at 3; CDT at 11-12. END FOOTNOTE
FOOTNOTE 143 AOA at 2. END FOOTNOTE
FOOTNOTE 144 AHIMA at 3. END FOOTNOTE
Some commenters supported expanding or changing the definition further. Specifically, some commenters urged the Commission to amend the definition to encompass (1) exceeding authorized access or use of PHR identifiable health information, such as where a company collects data for one purpose, but later uses or discloses that data for a second, undisclosed purpose; /145/ or (2) the collection or retention of PHR identifiable health information beyond what is necessary to provide the associated service to an individual consumer. /146/ One commenter asked the Commission to clarify that the Rule would be triggered by unauthorized use of or access to information derived from PHR identifiable health information, and to define the phrase acquisition. /147/
FOOTNOTE 145 FPF at 12-15. END FOOTNOTE
FOOTNOTE 146 EPIC at 5-7;
FOOTNOTE 147 Mozilla at 6-7. END FOOTNOTE
Some commenters, however, urged the Commission to not amend the definition at all. These commenters expressed concern the amendment would cause the Rule to exceed what
FOOTNOTE 148 Chamber at 6; Priv. for Am. at 2-5; ANA at 6-7. END FOOTNOTE
FOOTNOTE 149 SIIA at 3; CTA at 13-14. END FOOTNOTE
FOOTNOTE 150 CCIA at 4-5, 7 (arguing that requiring notification for unauthorized disclosures could cause consumers to worry in the absence of harm, such as where it is "typical" to disclose such information.) END FOOTNOTE
FOOTNOTE 151 CTA at 13-14. END FOOTNOTE
FOOTNOTE 152 Id. at 14-16. END FOOTNOTE
FOOTNOTE 153 TechNet at 3; Chamber at 7; CCIA at 5-6. END FOOTNOTE
Some commenters also urged that the Commission adopt carve-outs so that certain conduct would not be deemed breaches of security under the Rule. Commenters requested exemptions consistent with or found in HIPAA or under State breach notification laws, such as exemptions for disclosures to certain types of entities or for certain purposes, or where there is inadvertent or unintentional access, use, or disclosure. /154/ Commenters also proposed safe harbors for companies that implement recognized security or privacy safeguards; /155/ and one commenter proposed safe harbors that would apply where data is shared with "affiliated businesses," where there is inadvertent but "good-faith" access by a company employee, where a company makes good faith efforts to inform consumers of disclosures to third parties, and where companies take steps to contractually limit downstream uses of the data. /156/ Other commenters expressed support for exempting disclosures of PHR identifiable health information to public health authorities for public health purposes, noting the amended definition could discourage such disclosures. /157/
FOOTNOTE 154 CHI at 4 (stating the
FOOTNOTE 155 DirectTrust at 1-2. END FOOTNOTE
FOOTNOTE 156 ATA Action at 2. END FOOTNOTE
FOOTNOTE 157
b. Public Comments Regarding Defining "Authorization"
Commenters were divided as to whether the Commission should define "authorization." Some commenters supported defining "authorization" to provide greater guidance to companies, to promote transparency, and to discourage buried or inconspicuous disclosures relating to health information, or approaches to consent that are not meaningful because they are confusing or coercive. /158/ To further regulatory consistency, some commenters supported adding a definition of "authorization" that is consistent with how that term is defined in other health-related laws, such as under HIPAA /159/ or State health privacy laws that define consent or authorization (such as the California Consumer Privacy Rights Act /160/ or the
FOOTNOTE 158 AHIP at 4; Light Collective at 4; MRO at 2-3; Mozilla at 4;
FOOTNOTE 159 AdvaMed at 7 (arguing that any definition of "authorization" or "affirmative express consent" should take into account the necessity for medical technologies and medical technology companies to be able to operate and communicate under standards consistent with those governing HIPAA covered entities and others in the health care ecosystem. These standards permit certain uses and disclosures of individually identifiable health information without express consent where necessary for the provision of timely and effective health care); MRO at 3; AHIMA at 7-8. END FOOTNOTE
FOOTNOTE 160 AHIOS at 3. END FOOTNOTE
FOOTNOTE 161 Consumer Rep.'s at 9. END FOOTNOTE
By contrast, some commenters opposed defining the term--or opposed a requirement under the Rule that entities be required to get authorization before disclosing PHR identifiable health information. /162/ Commenters argued that
FOOTNOTE 162 HIA at 2 (arguing that "[r]outine disclosures of data should be allowed in certain contexts without additional need for authorizations"); CTA at 16-17; AdvaMed at 7-8; ACLA at 6; Confidentiality Coal. at 4-5. END FOOTNOTE
FOOTNOTE 163 Confidentiality Coal. at 4-5. END FOOTNOTE
FOOTNOTE 164 CTA at 16-17 (arguing that the Rule does not allow the Commission to impose "substantive consent requirements" that would be burdensome and "likely not administrable for many companies."). END FOOTNOTE
FOOTNOTE 165 SIIA at 4. END FOOTNOTE
FOOTNOTE 166 CHI at 7. END FOOTNOTE
Some commenters endorsed other approaches that would exempt from any requirement of affirmative express consent certain types of disclosures of PHR identifiable health information, such as to service providers, data processors, and entities that assist with combatting fraud and promoting safety. /167/ Some commenters urged a disclosure be deemed authorized if the disclosure is consistent with a company's privacy notices or policies or where applicable State privacy laws require affirmative consent or provide for the right to opt-out, without the need to define affirmative express consent under the Rule. /168/ One commenter argued that authorization should be met when a consumer agrees to opt-in to certain data sharing, such as by clicking a box proximate to a disclosure of material terms. /169/
FOOTNOTE 167 FPF at 10 (arguing that "an organization may share information with a service provider operating on their behalf to provide storage; may share information to protect the safety or vital interests of an individual or react to a public health emergency; or to protect themselves against security incidents and fraud. In each of these situations, data protection laws typically invoke a variety of non-consent measures, including data minimization, transparency, notice to the end-user or the regulator, and opportunities to object."); Chamber at 7. END FOOTNOTE
FOOTNOTE 168 Confidentiality Coal. at 4-5; SIIA at 4; CHI at 7. END FOOTNOTE
FOOTNOTE 169 CTA at 17. END FOOTNOTE
3. The Commission Adopts the Proposed Changes to the Definition of "Breach of Security"
After carefully considering the public comments, the Commission adopts the proposed amendment without change. The final rule definition is consistent with the statutory definition in the Recovery Act, the Policy Statement, /170/ and recent Commission enforcement actions under the Rule. The Commission notes the statutory definition in the Recovery Act is sufficiently broad to cover both cybersecurity intrusions as well as a company's intentional but unauthorized disclosures of consumers' PHR identifiable health information to third party companies. In addition, the Commission finds persuasive the comment noting the Recovery Act's definition of "breach of security" refers to the acquisition PHR identifiable health information without the authorization of an individual, rather than the authorization of the entity holding the data. /171/ The definition is also consistent with public comments received by the Commission in 2020 (when the Commission announced its regular, ten-year review of the Rule and requested public comments about potential Rule changes /172/ ), which urged the Commission to clarify what constitutes an unauthorized acquisition under the Rule. /173/ Importantly, the amendment to the definition of "breach of security" in
FOOTNOTE 170 The Commission's Policy Statement makes clear that "[i]ncidents of unauthorized access, including sharing of covered information without an individual's authorization, triggers notification obligations under the Rule," and that a breach "is not limited to cybersecurity intrusions or nefarious behavior." Policy Statement at 2. END FOOTNOTE
FOOTNOTE 171 Consumer Rep.'s at 5 (noting "the Recovery Act frames breaches of security in relation to individuals, rather than to vendors of personal health records or PHR related entities," and defines breach of security as "acquisition of such information without the authorization of the individual.") END FOOTNOTE
FOOTNOTE 172 85 FR 31085 (
FOOTNOTE 173 See Public Comments in response to
FOOTNOTE 174 The 2009 Rule Commentary noted other examples illustrating that unauthorized sharing or transferring of information constitutes a breach of security, including that the unauthorized downloading or transfer of information by an employee can constitute a breach of security; that inadvertent access by an unauthorized employee reading or sharing information triggers the Rule's notification obligations; and notes that given the highly personal nature of health information, "the Commission believes that consumers would want to know if such information was read or shared without authorization." See 74 FR 42966-67. END FOOTNOTE
The Commission declines to adopt any specific exemptions or safe harbors to the definition of breach of security. Unlike the section of the Recovery Act that governs breach notifications under HIPAA, /175/
FOOTNOTE 175 42 U.S.C. 17921; see also
FOOTNOTE 176 The Rule continues to provide that, when there is unauthorized access to data, unauthorized acquisition will be presumed unless the entity that experienced the breach "has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." As noted in the 2009 Rule Commentary, the presumption was intended to address the difficulty of determining whether access to data (i.e., the opportunity to view the data) did or did not lead to acquisition (i.e., the actual viewing or reading of the data). In these situations, the Commission stated that the entity that experienced the breach is in the best position to determine whether unauthorized acquisition has taken place. In describing the rebuttable presumption, the Commission provided several examples. It noted that no breach of security has occurred if an unauthorized employee inadvertently accesses an individual's PHR and logs off without reading, using, or disclosing anything. If the unauthorized employee read the data and/or shared it, however, he or she "acquired" the information, thus triggering the notification obligation in the Rule. Similarly, the Commission provided an example of a lost laptop: If an entity's employee loses a laptop in a public place, the information would be accessible to unauthorized persons, giving rise to a presumption that unauthorized acquisition has occurred. The entity can rebut this presumption by showing, for example, that the laptop was recovered, and that forensic analysis revealed that files were never opened, altered, transferred, or otherwise compromised. See 74 FR 42966. END FOOTNOTE
4. The Commission Affirms Its Proposal Not To Define "Authorization"
After carefully considering the public comments, the Commission declines to define "authorization," as that term appears in
The Commission believes whether a disclosure is authorized under the Rule is a fact-specific inquiry that will depend on the context of the interactions between the consumer and the company; the nature, recipients, and purposes of those disclosures; the company's representations to consumers; and other applicable laws. The Commission reiterates the 2009 Rule Commentary, which states a use of data is "authorized" only where it is consistent with a company's disclosures and consumers' reasonable expectations and where there is meaningful choice in consenting to sharing--buried disclosures do not suffice. /177/
FOOTNOTE 177 The 2009 Rule Commentary states: "[g]iven the highly personal nature of health information, the Commission believes that consumers would want to know if such information was read or shared without authorization." It further states that data sharing to enhance consumers' experience with a PHR is authorized only "as long as such use is consistent with the entity's disclosures and individuals' reasonable expectations" and that "[b]eyond such uses, the Commission expects that vendors of personal health records and PHR related entities would limit the sharing of consumers' information, unless the consumers exercise meaningful choice in consenting to such sharing. Buried disclosures in lengthy privacy policies do not satisfy the standard of 'meaningful choice.' " 74 FR 42967. END FOOTNOTE
The Commission's recent enforcement actions alleging violations of the Rule against
In response to public comments seeking more guidance on what constitutes an unauthorized disclosure under the Rule, /178/ the Commission offers the following, non-exhaustive examples relating to authorization:
FOOTNOTE 178 TechNet at 4; Tranquil Data at 4. END FOOTNOTE
* Example 1--Unauthorized Disclosure (Affirmative Misrepresentation): A medication app offers a personal health record (not covered by HIPAA) which allows users to track information about their prescription medication history, such as prescription names, dosages, pharmacy and refill information, and the user's health conditions. The app voluntarily discloses PHR identifiable health information to third party companies for advertising and advertising-related analytics, in violation of the app's privacy representations to its users. The third parties that receive the PHR identifiable health information are able to use the information for their own business purposes, such as to improve the third party's own products and services, to infer information about consumers, or to compile profiles about consumers to use for targeted advertising. These disclosures are not authorized under the Rule because they are inconsistent with consumer expectations--the disclosures violate the app's privacy representations, and consumers would also not expect their PHR identifiable health information (which they input into the app to track their medications and health conditions) would be disclosed to, and used by, third party companies that use the data for their own economic benefit.
* By contrast, disclosures of PHR identifiable health information by the app in Example 1 would be authorized if made to service providers in the following circumstances: (1) the service providers assist with functions that are necessary to the operation and functioning of the medication app, or with services the consumer requested; (2) the service providers are contractually prohibited from using, sharing, or disclosing the PHR identifiable health information for any purpose beyond providing services to the medication app; and (3) the medication app's privacy notice clearly and conspicuously discloses the specific purposes for which it shares users' PHR identifiable health information with these service providers. Such authorized disclosures could include those to cloud storage providers that host user data in the health record in a secure fashion; payment processors who process user payments to the app; vendors that facilitate refill reminders or other communications from the app developer that directly relate to the provision of the personal health record or services the consumer requested; analytics providers that assist with tracking analytics relating to the app's functionality; /179/ or companies that help to detect, prevent, or mitigate fraud or security vulnerabilities. Such disclosures are authorized because they are consistent with consumer expectations. Importantly, this sharing is disclosed to consumers in a clear and conspicuous manner, and is essential, and limited to, sharing the PHR identifiable health information with service providers solely to provide users with a safe and reliable personal health record experience.
FOOTNOTE 179 This would include an analytics provider whose services are essential to the proper functioning of the app and not tied to marketing or advertising--this includes analytics tools to assist with crash reporting or to assess usage patterns (such as the frequency of use of certain features). END FOOTNOTE
* Example 2--Unauthorized Disclosure (Deceptive Omission). The medication app from Example 1 shares PHR identifiable health information with a third party for purposes of targeting consumers with ads. The app does not disclose the sharing and also fails to obtain affirmative express consent from users whose information it shares. The third party company can use the PHR identifiable health information to market and advertise--on behalf of the medication app, on behalf of other companies, or on behalf of itself. It can also use the information to improve its own products and services. Such disclosures are not authorized because they are not consistent with consumer expectations (i.e., without disclosure and without affirmative express consent, consumers would not expect that their PHR identifiable health information would be shared, sold, or otherwise exploited for a purpose other than providing the user with a personal health record, and are neither essential nor limited to sharing the PHR identifiable health information solely to provide users with a safe and reliable personal health record experience). This conclusion is also consistent with Commission enforcement actions relating to the sharing of health information (e.g.,
FOOTNOTE 180 Fed.
* Example 3--Authorized Disclosure (Public Health Reporting): A COVID-19 contact tracing app not covered by HIPAA allows users to self-report their COVID-19 diagnosis, and to notify the user's contacts of their diagnosis, or others with whom the individual may have come into physical contact. PHR identifiable health information about the individual's COVID-19 diagnosis is transmitted to public health authorities for public health-related purposes, such as public health reporting and analysis or to track areas where the virus is spreading the most rapidly. The contact tracing app discloses to users clearly and conspicuously the specific purposes for which it shares their PHR identifiable health information with public health authorities. These disclosures are authorized, and consistent with consumer expectations, because they are consistent with the company's relationship with the consumer (a PHR that allows a user to report their COVID-19 diagnosis in order to notify others) and are also appropriately disclosed.
Examples 1 and 3 provide guidance about scenarios in which limited disclosures of PHR identifiable health information are permitted without opt-in consent because it is necessary to provide a personal health record to a consumer, is consistent with consumer expectations, the sharing is disclosed to consumers, and (in the case of Example 1) the sharing is subject to protections like service provider agreements that limit the use of the data only for the purpose of providing that service to the consumer. Examples 1 and 3 are also consistent with HIPAA and State health privacy laws. /181/ For instance, HIPAA permits disclosures for treatment, payment, and operations without patient authorization.
FOOTNOTE 181 For example,
The Commission notes "breach of security" could cover more than just an unauthorized disclosure to a third party. For example, depending on the facts and scope of the authorizations, such as in the company's promises and disclosures to consumers, a "breach of security" could include unauthorized uses. There may be a "breach of security" where an entity exceeds authorized access to use PHR identifiable health information, such as where it obtains the data for one legitimate purpose, but later uses that data for a secondary purpose that was not originally authorized by the individual.
Finally, the Commission notes unauthorized access or use of derived PHR identifiable health information may also constitute a breach of security. The Commission noted in its 2023 NPRM that PHR identifiable health information includes "health information derived from consumers' interactions with apps and other online services (such as health information generated from tracking technologies employed on websites or mobile applications or from customized records of website or mobile application interactions), as well as emergent health data (such as health information inferred from non-health-related data points, such as location and recent purchases)." /182/
FOOTNOTE 182 88 FR 37823. END FOOTNOTE
D. Clarification of What Constitutes a "PHR Related Entity"
1. The Commission's Proposal Regarding "PHR Related Entity"
The NPRM proposed to revise the definition of "PHR related entity" in two ways. Consistent with its clarification that the Rule applies to health apps, the Commission proposed amending the definition of "PHR related entity" to make clear the Rule covers entities that offer products and services through the online services, including mobile applications, of vendors of personal health records. In addition, the Commission proposed revising the definition of "PHR related entity" to provide that entities that access or send unsecured PHR identifiable health information to a personal health record--rather than entities that access or send any information to a personal health record--are PHR related entities.
The Commission explained the first change (to cover online services) was necessary as websites are no longer the only means through which consumers access health information online. The Commission explained the second change--narrowing the scope of "PHR related entities" to entities that access or send unsecured PHR identifiable health information--was intended to eliminate potential confusion about the Rule's breadth and promote compliance by narrowing the scope of entities that qualify as PHR related entities. /183/ The Commission identified remote blood pressure cuffs, connected blood glucose monitors, and fitness trackers as examples of internet-connected devices that could qualify as a PHR related entity when individuals sync them with a personal health record (e.g., a health app). /184/ The Commission explained, however, that a grocery delivery service that sends information about food purchases to a diet and fitness app would not be a PHR related entity if it does not access unsecured PHR identifiable health information in a personal health record or send unsecured PHR identifiable health information to a personal health record.
FOOTNOTE 183 The proposed definition stated that a PHR related entity is an entity, other than a HIPAA-covered entity or an entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity, that (1) offers products or services through the website, including any online service, of a vendor of personal health records; (2) offers products or services through the websites, including any online services, of HIPAA-covered entities that offer individuals personal health records; or (3) accesses unsecured PHR identifiable health information in a personal health record or sends unsecured PHR identifiable health information to a personal health record. Although the Rule is only triggered when there is a breach of security involving unsecured PHR identifiable health information, the Commission explained it believed there is a benefit to revising the third prong of PHR related entity to make clear that only entities that access or send unsecured PHR identifiable health information to a personal health record--rather than entities that access or send any information to a personal health record--are PHR related entities. Otherwise, many entities could be a PHR related entity under the definition's third prong and such entities would then, in the event of a breach, need to analyze whether they experienced a reportable breach under the Rule. If an entity, per the proposed revision, does not qualify as a PHR related entity in the first place, there would be no need to consider whether it experienced a reportable breach. 88 FR 37825 n.54. END FOOTNOTE
FOOTNOTE 184 The Commission explained, for example, the maker of a wearable fitness tracker may be both a vendor of personal health records (to the extent that its tracker interfaces with its own app, which also accepts consumer inputs) and a PHR related entity (to the extent that it sends information to another company's health app). The Commission noted that regardless of whether the maker of the fitness tracker is a vendor of personal health records or a PHR related entity, its notice obligations are the same: it must notify individuals, the
The proposed Rule also revised
The Commission explained that distinguishing between third party service providers and PHR related entities would create incentives for responsible data stewardship and for de-identification because a firm would only become an entity covered by the Rule in relation to unsecured PHR identifiable health information. To the extent that firms must deal with unsecured PHR identifiable health information, PHR vendors would have incentives to select and retain service providers capable of treating data responsibly (e.g., by not engaging in any onward disclosures of data that could result in a reportable breach) and incentives to oversee their service providers to ensure ongoing responsible data stewardship (which would avoid a breach).
The Commission observed in most cases, third party service providers are likely to be non-consumer facing. The Commission noted examples of PHR related entities would include, as noted above, makers of fitness trackers and health monitors when consumers sync their devices with a mobile health app. The Commission noted further examples of third party service providers would include entities that provide support or administrative functions to vendors of personal health records and PHR related entities.
2. Public Comments Regarding "PHR Related Entity"
The Commission received numerous public comments about the changes to the definition of PHR related entity. Most commenters supported the Commission's approach. /185/ One commenter, an industry association for advertisers, noted that addition of the term "unsecured" in the definition of "PHR related entity" created a limitation on the definition's scope that counterbalances the breadth of including "any online service" in the definition. /186/ Moreover, this commenter noted, the addition of "unsecured" creates appropriate incentives for firms to secure PHR identifiable health information and to choose partners who will be good data stewards. /187/ This commenter noted that limiting the definition to "unsecured" PHR identifiable health information was consistent with the original intent of the Rule, to cover only the most sensitive types of data not covered by HIPAA. /188/
FOOTNOTE 185 ANI at 1; AAFP at 3; AHIMA at 3; AHIOS at 4; AOA at 3;
FOOTNOTE 186 NAI at 4-5. END FOOTNOTE
FOOTNOTE 187 Id. at 5. END FOOTNOTE
FOOTNOTE 188 Id. at 4. END FOOTNOTE
A few commenters proposed changes to the definition of "third party service provider" to further distinguish the term from "PHR related entity." One commenter recommended defining "third party service provider" as an entity that only processes data. /189/ This commenter argued the Commission could then impose liability on service providers for further use, sale, disclosure for incompatible purposes. /190/ Another commenter recommended aligning the definition of "third party service provider" with the definition of "business associate" under HIPAA. /191/
FOOTNOTE 189 FPF at 10. END FOOTNOTE
FOOTNOTE 190 Id. END FOOTNOTE
FOOTNOTE 191 AdvaMed at 8. END FOOTNOTE
Some commenters raised concerns that the Commission's approach did not provide sufficient clarity for companies trying to understand their obligations as either a third party service provider or PHR related entity. /192/ Some commenters requested more examples of types of firms falling within each definition (e.g., examples clearly establishing the status of health data brokers, health marketing firms, search engines, email providers, cloud storage providers) /193/ --to facilitate compliance, /194/ avoid overlapping notice requirements /195/ and to prevent a loophole through which firms may attempt to avoid obtaining consumers' authorization for data disclosures and to avoid providing breach notifications. /196/ One commenter urged the Commission to exempt from the definition of "PHR related entity" any firm that complies with the privacy and data security requirements of HIPAA. /197/
FOOTNOTE 192 SIIA at 3;
FOOTNOTE 193 AHIMA at 3-4; AMIA at 3-4; CHI at 5;
FOOTNOTE 194 SCRS at 1. END FOOTNOTE
FOOTNOTE 195 NAI at 5. END FOOTNOTE
FOOTNOTE
FOOTNOTE 197 AdvaMed at 5. END FOOTNOTE
In response to the Commission's request for comment on whether an analytics firm would be a third party service provider, many commenters responded that an analytics firm should fall within that definition /198/ for the reasons the Commission articulated: It would be confusing to consumers to receive a notice from a back-end service provider rather than the firm with whom the consumer has the relationship, and categorizing analytics firms (and firms that provide other services) as service providers will create incentives for PHR vendors and PHR related entities to choose their service providers with care. A few commenters, however, expressed concern about covering advertising, analytics, and cloud firms--and health information service providers ("HISPs") more generally--as they are unable to determine whether the data they receive contains unsecured PHR identifiable health information; only the vendor of the PHR knows what their data transmissions contain. /199/ One commenter urged the Commission to address the data recipient's unawareness of the content of the data by creating a safe harbor that exempts advertising, analytics and cloud providers that contractually limit their customers, vendors, or partners from sharing health information with them. /200/
FOOTNOTE 198 NAI at 5; TMA at 3; Consumer Rep.'s at 11. END FOOTNOTE
FOOTNOTE 199 CCIA at 7-8; CTA at 9-10; SIIA at 3;
FOOTNOTE 200 CTA at 13. END FOOTNOTE
3. The Commission Adopts the Proposed Changes to "PHR Related Entity"
After considering the comments received, the Commission adopts the proposed changes regarding "PHR related entity" without further change. The Commission affirms that (1) PHR related entities include entities offering products and services not only through the websites of vendors of personal health records, but also through any online service, including mobile applications; (2) PHR related entities encompass only entities that access or send unsecured PHR identifiable health information to a personal health record; and (3) while some third party service providers may access unsecured PHR identifiable health information in the course of providing services, this does not render the third party service provider a PHR related entity.
In response to commenters who expressed concern that certain data recipients will not be able to understand their obligations under the Rule because they are unaware of the content of the data transmissions they receive, the Commission highlights
Firms may also facilitate compliance by stipulating by contract whether transmissions of data will contain unsecured PHR identifiable health information. Both the sender and recipient of the data can monitor for compliance with those contractual agreements through the use of automated tools, internal auditing, external auditing, or other mechanisms, as appropriate to the size and sophistication of the firms and the sensitivity of the data. For example, a large advertising platform that has routinely received unsecured PHR identifiable health information, notwithstanding partners' promises not to send this information, may have different obligations to monitor the data it receives than small firms that do not engage in high-risk activities where the contract precludes sending such data and there is no history of such transmissions.
The Commission believes this approach--notice to service providers pursuant to
FOOTNOTE 201 Compl. at [Para.] 21, In the Matter of
The Commission declines to change the definition of "third party service provider" to distinguish it further from a "PHR related entity," for two reasons. First, the Commission notes the current definitions of "third party service provider" and "PHR related entity" align closely with the language prescribed by section 13407 and section 13424(b)(1)(A) of the Recovery Act. Jettisoning the current language entirely, as some commenters suggested, would not be consistent with the Recovery Act's requirements. Second, the Commission believes the current language, in conjunction with the examples provided below, will provide sufficient guidance to the market as to which types of firms fit within each definition.
In response to comments that requested examples of the types of firms that fall into the category of "third party service provider" or "PHR related entity," the Commission provides the following examples. The Commission believes these examples, in conjunction with the language in
* Example 1: Four separate firms provide data security, cloud computing, advertising and analytics services to a health app (a personal health record), as specified by their service provider contracts, for the health app vendor's benefit. To perform the services specified in their respective contracts, the firms access unsecured PHR identifiable health information. The firms are "third party service providers" of the vendor of the personal health record (the maker of the health app) because they provide services to a vendor of a personal health record (the maker of the health app) in connection with the offering or maintenance of the app, and they access unsecured PHR identifiable health information as a result of these services. In the event of a breach, they should abide by their obligations as third party service providers.
* Example 2: An analytics firm provides analytics services to a health app (a personal health record). The analytics firm and health app vendor do not have a customized service provider contract, although the health app vendor agrees to the analytics firm's standard terms of service. The analytics firm accesses unsecured PHR identifiable health information (device identifier and whether the consumer has paid for therapy). The analytics firm uses that data both to provide analytics services to the health app and for its own benefit, for research and development and product improvement. The analytics firm is a third party service provider to the extent that it provides analytics services to the health app for the health app's benefit because it is then providing services to a vendor of a PHR in connection with the offering of the PHR and accessing unsecured PHR identifiable health information as a result of such services. However, the analytics firm is a PHR related entity, rather than a third party service provider, to the extent that it offers its services through the health app for its own purposes (i.e., for research and development and product improvement) rather than to provide the services. In the event of a breach, the analytics firm must fulfill its notification obligations under the Rule according to which function it was performing in connection with the breach. If the functions are indistinguishable, then, pursuant to
* Example 3: A health tracking website (a personal health record) integrates a search bar branded with its maker's logo, which enables its maker (a search engine firm) to offer its services through the website. The search engine firm is a PHR related entity because it offers its services through the website, which is a personal health record. The search bar branded with its maker's logo is consumer-facing, so the consumer would not be surprised to receive a notice from that company if it experiences a reportable breach. By contrast, if the health tracking website had contracted with the search engine firm to provide back-end search services to the website (rather than offering its own branded product or service through the website), and the search engine firm had accessed unsecured PHR identifiable health information as a result of such services, it would be a third party service provider. In the event of a breach, it should abide by its obligations as a third party service provider.
* Example 4: Digital readings from a fitness tracker offered by
E. Facilitating Greater Opportunity for Electronic Notice
1. The Commission's Proposal Regarding Electronic Notice
The Commission proposed to authorize expanded use of email and other electronic means of providing clear and effective notice of a breach to consumers. In furtherance of this objective, the Commission proposed to update
FOOTNOTE 202 This model notice was attached as appendix A to the NPRM. 88 FR 37837. END FOOTNOTE
2. Public Comments Regarding Electronic Notice
Nearly every comment submitted on this proposed change supported the Commission's efforts to update the Rule to allow for greater electronic notice. /203/ One commenter noted electronic notices increase the likelihood that individuals will receive the notice, may reduce the time it takes for individuals to receive notice, and reduce the burden on entities providing notice. /204/ Many commenters also supported the Commission's efforts to provide notice via more than one channel through the new definition of "electronic mail." /205/
FOOTNOTE 203 AHIP at 5; AAFP at 3; AHIMA at 5; AHIOS at 3; Anonymous 3 at 1; Anonymous 10 at 1;
FOOTNOTE 204 AdvaMed at 5. END FOOTNOTE
FOOTNOTE 205 AAFP at 3; AHIMA at 5; Anonymous 3 at 1;
However, not all commenters agreed with the Commission's proposal and some commenters offered other suggestions. Some objected to defining "electronic mail" to mean anything more than "email," stating that electronic mail is commonly understood to mean email and nothing else. /206/ A few commenters noted that defining multiple forms of electronic notice could result in entities collecting more information than necessary (and consumers having to provide more information than needed) in order to comply with the Rule. /207/ Others preferred a single notice, arguing that multiple forms of notice is burdensome and could result in over-notification, confusion, and notice fatigue among consumers. /208/ One commenter stated the Commission should revise the definition of "electronic mail" to mean "one or more of the following that is reasonable and appropriate based on the relationship between the individual and the relevant vendor of personal health records or PHR related entity: email, text message, within-application messaging, or electronic banner." /209/ Another commenter encouraged the
FOOTNOTE 206 ACLA at 5; Mass.
FOOTNOTE 207 Consumer Rep.'s at 7-8; CTA at 22. Consumer Reports further suggested the Commission clarify that substitute notice may be effectuated under the Rule via text message, in-app messaging, or electronic banners for consumers that do not wish to share a mailing or email address. Consumer Rep.'s at 8. END FOOTNOTE
FOOTNOTE 208 AdvaMed at 6; ACLA at 5; AHIP at 5; CTA at 21-22; END FOOTNOTE
FOOTNOTE 209 AdvaMed at 6. END FOOTNOTE
FOOTNOTE 210 AHIMA at 5. END FOOTNOTE
FOOTNOTE 211 TechNet at 5. END FOOTNOTE
FOOTNOTE 212 MHDF at 10. END FOOTNOTE
FOOTNOTE 213 Id. END FOOTNOTE
FOOTNOTE 214 AHIP at 5. END FOOTNOTE
FOOTNOTE 215 CHI at 6. END FOOTNOTE
Many commenters endorsed the Commission's proposal that any notification delivered via electronic mail should be "clear and conspicuous," a newly defined term in the Rule. /216/ One commenter stated that consistent with
FOOTNOTE 216 AMA at 5; CHIME at 5; EPIC at 9. END FOOTNOTE
FOOTNOTE 217 TMA at 4. END FOOTNOTE
FOOTNOTE 218 NAI at 7. END FOOTNOTE
Regarding the model notice, nearly all who commented on this topic urged the Commission to make the model notice voluntary. /219/ One commenter suggested that using the model should be a safe harbor that shields entities from enforcement. /220/
FOOTNOTE 219 AdvaMed at 6; AHIP at 6; AMA at 6; CCIA at 7; CHI at 6; Consumer Rep.'s at 8-9; NAI at 7-8. One commenter stated that making the model notice mandatory can lead to industry consistency and it may be easier for consumers to understand the message and the contents if they are familiar with a uniform, standardized notice. AHIMA at 5. While the Commission generally agrees that uniform, consistent notices assist with consumer comprehension, the Commission declines to make the model notice compulsory because the facts and circumstances of each breach will vary. Plus,
FOOTNOTE 220 AHIP at 6. END FOOTNOTE
3. The Commission Adopts the Proposed Changes Regarding Electronic Notice
The Commission adopts without change the modifications regarding
FOOTNOTE 221 The Commission disagrees with the commenters who urged the Commission to avoid defining "electronic mail" to mean anything more than "email." ACLA at 5; MHDF at 9. The definition in
In response to concerns raised about the two-part electronic notice, the Commission agrees with commenters who stated it increases the likelihood that individuals will encounter such notices. /222/ The Commission does not agree that it is burdensome for entities to comply with this requirement. For example, an entity who complies with the notice requirement by notifying consumers via email plus posting a website notice likely would not need to expend significant additional time and resources by issuing the second part of the notice (i.e., the website notice), and any "cost" of posting such a notice is outweighed by the benefit to consumers of learning of a breach involving their health information. The Commission also is not persuaded that consumers who, for example, receive an email about a breach coupled with an in-app notice about the same breach will be confused. The Commission believes consumers will understand that such notices relate to the same incident, especially given the Rule's requirement that the notices be "clear and conspicuous." The Commission also does not find it problematic that the Rule requires notice effectuated via "electronic mail" to occur via two methods while other breach notice laws require one method. The Commission also notes while these amendments are intended to facilitate greater electronic notice, the Rule still permits notice via first-class mail. Accordingly, the contention that this Rule requires two methods of electronic notice is incorrect.
FOOTNOTE 222 AAFP at 3-4 (noting AAFP appreciates "the proposed structure of providing notice in two different electronic formats to increase the likelihood individuals will see them"); CHIME at 5 ("CHIME is supportive of the
The Commission also declines, in response to public comments, /223/ to mandate how notifications are effectuated when sent via "electronic mail," as the Commission believes it is important to not be overly prescriptive given rapidly changing technologies. The Commission emphasizes though, as described below, that the notice must satisfy the Rule's definition of "clear and conspicuous."
FOOTNOTE 223 See supra notes 210-213. END FOOTNOTE
Nor does the Commission believe, as some commenters argued, the two-part electronic notification will result in additional collections of information by notifying entities. The Commission agrees with commenters who stated entities are generally already collecting the information needed for notice via "electronic mail" and a data minimization issue does not exist. /224/
FOOTNOTE 224
In response to the commenter who suggested the
FOOTNOTE 225 See supra note 214. END FOOTNOTE
FOOTNOTE 226 74 FR 42972. END FOOTNOTE
The Commission also adopts without modification the definition of "clear and conspicuous." The Commission agrees with the commenter who indicated it is imperative that a breach notice be reasonably understandable and call attention to the significance of the information that is included in the notice. /227/ The Commission believes its definition of "clear and conspicuous" will assist in achieving this objective. The Commission declines, however, to mandate specific language for the email subject line to satisfy the Rule's "clear and conspicuous" requirement, as one commenter had suggested. /228/ The Commission emphasizes, however, that the clear and conspicuous requirement would require a notifying entity to use an email subject line that draws the reader's attention to the email notice. The Commission also declines to adopt the suggestion that the definition of "clear and conspicuous" be incorporated directly into
FOOTNOTE 227 AMA at 5. END FOOTNOTE
FOOTNOTE 228 See supra note 217. END FOOTNOTE
Turning to the model notice, /229/ as the Commission noted in the NPRM, the model was intended for entities to use, in their discretion, to notify individuals, and the Commission adopts the same position here. /230/ The model is voluntary and while the Commission believes it represents a best practice, using the model is not required to achieve compliance with the Rule.
FOOTNOTE 229 The model notice is found in appendix A. END FOOTNOTE
FOOTNOTE 230 88 FR 37827. END FOOTNOTE
The Commission declines to adopt the position that use of the model notice provides a safe harbor, although the Commission would take into consideration in an enforcement action an entity who follows the model notice. Further, the Commission notes an entity who follows the model notice can nevertheless violate the Rule in other ways. For example, an entity could follow the model notice but fail to provide timely notice. In such instances, providing a safe harbor because the entity utilized the model notice would be inappropriate.
F. Revisions to the Required Content of Notice
1. The Commission's Proposal Regarding Content of Notice
The Commission proposed five changes to the content of the notice. First, in
2. Public Comments Regarding Content of Notice
a. Proposal That Notice Include Description of Potential Harm That May Result From a Breach
The Commission's proposal to modify
FOOTNOTE 231 AAFP at 4; AMA at 6; AOA at 5; Anonymous 3; AHIOS at 3;
FOOTNOTE 232 AMA at 6. END FOOTNOTE
FOOTNOTE 233 Consumer Rep.'s at 9-10; EPIC at 10-11. END FOOTNOTE
FOOTNOTE 234 MHDF at 10-11. END FOOTNOTE
FOOTNOTE 235 Id. END FOOTNOTE
On the other hand, many commenters criticized this proposal. /236/ Some commenters argued this proposal will result in notifying entities having to speculate about potential harms that may never occur or providing a list of harms that may be incomplete. /237/ Others pointed out that notifying individuals about potential harms could cause consumer anxiety, consumer confusion, and detract from actions the individuals should take. /238/ One commenter noted the Commission's proposal might lead consumers to believe the harms listed in the notice are the only possible harms from a breach, when in fact consumers may suffer other harms not disclosed in the notice. /239/ This same commenter also noted it is opposed to entities stating there are no known harms that may result from a breach solely because a notifying entity is unaware of any specific bad outcomes. /240/
FOOTNOTE 236 AdvaMed at 6-7; AHIP at 6; ACLA at 4-5; Confidentiality Coal. at 7; CTA at 23-24; MHDF at 10; NAI at 9. END FOOTNOTE
FOOTNOTE 237 AdvaMed at 6-7; AHIP at 6; MHDF at 10; NAI at 9. END FOOTNOTE
FOOTNOTE 238 ACLA at 4-5; AMIA at 5; NAI at 9. END FOOTNOTE
FOOTNOTE 239 MHDF at 10. END FOOTNOTE
FOOTNOTE 240 Id. at 10-11. END FOOTNOTE
b. Proposal That Notice Include Full Name, Website and Contact Information of Third Parties That Acquired Unsecured PHR Identifiable Health Information
Next, the Commission proposed to amend the requirements for the notice under
FOOTNOTE 241 AAFP at 4; AHIMA at 5-6; AMA at 6; AMIA at 5; AOA at 5;
FOOTNOTE 242 ACLA at 4-5; AHIP at 6; CHI at 6;
FOOTNOTE 243 ACLA at 4-5; Confidentiality Coal. at 7. END FOOTNOTE
FOOTNOTE 244 Confidentiality Coal. at 7. END FOOTNOTE
FOOTNOTE 245 CTA at 24. END FOOTNOTE
FOOTNOTE 246 AHIP at 6. END FOOTNOTE
c. Proposal That Notice Include Description of Types of Unsecured PHR Identifiable Health Information Involved in a Breach
Third, the Commission proposed modifications to
FOOTNOTE 247 AAFP at 4; AHIMA at 6; AMA at 6; AOA at 5;
FOOTNOTE 248 Light Collective at 2. END FOOTNOTE
FOOTNOTE 249 ITRC at 2. END FOOTNOTE
d. Proposal That Notice Include Description of What Entity Is Doing To Protect Affected Individuals
Fourth, the Commission proposed revising
FOOTNOTE 250 AAFP at 4; AMA at 6; AOA at 4;
FOOTNOTE 251 AMA at 6. END FOOTNOTE
FOOTNOTE 252 AHIMA at 5-6. END FOOTNOTE
FOOTNOTE 253 Consumer Rep.'s at 9-10. END FOOTNOTE
Some commenters, however, raised concerns about this proposal. For instance, one commenter believed the Rule already encompasses this requirement and therefore the Commission's proposal could result in duplicative information being provided in the notice. /254/ Another commenter stated the
FOOTNOTE 254 Confidentiality Coal. at 7. END FOOTNOTE
FOOTNOTE 255 Light Collective at 6-7. END FOOTNOTE
e. Proposal That Notice Include Two or More Contact Procedures
Fifth, the Commission proposed amendments to
FOOTNOTE 256 AAFP at 4; AHIMA at 6; AHIP at 5; Anonymous 3 at 1; AOA at 5;
FOOTNOTE 257 AHIMA at 6. END FOOTNOTE
FOOTNOTE 258 AMA at 6. END FOOTNOTE
FOOTNOTE 259 AdvaMed at 6-7. END FOOTNOTE
3. The Commission Changes Regarding Content of Notice
a. The Commission Declines To Adopt Proposal That Notice Include Description of Potential Harm That May Result From a Breach
The Commission believes, in light of the public comments, that the downsides of requiring in the notice a description of the potential harms that may result from a breach outweigh the upsides. The Commission is concerned about requiring a consumer notice to include possible harms that may never materialize. In such cases, consumers may experience needless anxiety and take actions that are not necessary, leading to consumer frustration. The Commission also is concerned this proposal may result in entities describing potential harms so generically that the description provides minimal value to consumers, or, alternatively, that entities will provide a laundry list of potential harms, making such a list meaningless to consumers. The Commission also agrees with one commenter who noted this proposal might lead consumers to believe the harms listed in the notice are the only possible harms from a breach, when in fact consumers may suffer other harms not disclosed in the notice. /260/
FOOTNOTE 260 MHDF at 10. END FOOTNOTE
Accordingly, the Commission declines to adopt this proposal. /261/ The Commission believes the remaining elements of the content of the notice will supply individuals with sufficient information about a breach, especially given the other modifications to
FOOTNOTE 261 The Commission has updated the model notice in appendix A to reflect this change. END FOOTNOTE
b. The Commission Modifies Proposal That Notice Include Full Name, Website, and Contact Information of Third Parties That Acquired Unsecured PHR Identifiable Health Information
In light of the public comments, the Commission is modifying
FOOTNOTE 262 The Commission has updated the model notice in appendix A to reflect this change. END FOOTNOTE
Accordingly, this revised provision is intended to still provide individuals with information about who acquired their health information. Under
c. The Commission Adopts Proposal That Notice Include Description of Types of Unsecured PHR Identifiable Health Information Involved in a Breach
The Commission agrees with the many public comments supporting this proposal. /263/ The Commission concurs with the commenter who noted it is important for consumers to receive notice of the specific types of PHR identifiable health information involved in a breach, /264/ and the commenter who stated that providing affected individuals with a more expansive list of health data points implicated in a breach will help them better understand the risks they face. /265/ The Commission adopts this proposal without modification.
FOOTNOTE 263 See supra note 247. END FOOTNOTE
FOOTNOTE 264 See supra note 248. END FOOTNOTE
FOOTNOTE 265 See supra note 249. END FOOTNOTE
d. The Commission Adopts Proposal That Notice Include Description of What Entity Is Doing To Protect Affected Individuals
Several commenters supported the Commission proposal that the notice to individuals include a description of what the notifying entity is doing to protect affected individuals. /266/ The Commission concurs with the commenter who stated that informing affected individuals about the steps notifying entities are taking to protect them is important so that affected individuals know what additional actions they should take to protect themselves from potential harm. /267/ The Commission similarly agrees with the commenter who stated that knowing what the notifying entity is doing to protect affected individuals can help consumers who are considering making purchase decisions like fraud detection or credit monitoring. /268/ The Commission also agrees with the commenter who stated that requiring notifying entities to share information about what they are doing to protect affected individuals will incentivize notifying entities to take proactive measures to mitigate harms to consumers. /269/
FOOTNOTE 266 See supra note 250. END FOOTNOTE
FOOTNOTE 267 See supra note 251. END FOOTNOTE
FOOTNOTE 268 See supra note 252. END FOOTNOTE
FOOTNOTE 269 See supra note 253. END FOOTNOTE
In response to the one commenter who noted the 2009 Rule already includes this proposed requirement, /270/ the Commission notes
FOOTNOTE 270 See supra note 254. END FOOTNOTE
In response to the commenter who argued the Commission needs to help consumers understand post-breach remedies, /271/ the Commission believes this concern is addressed by the combination of
FOOTNOTE 271 See supra note 255. END FOOTNOTE
The Commission adopts proposed
e. The Commission Adopts Proposal That Notice Include Two or More Contact Procedures
In response to the comment that providing two or more contact procedures in the notice is burdensome, /272/ the Commission believes if this proposal results in any burden to notifying entities, such burden will be minimal given the ease with which compliance with this provision can be achieved, and outweighed by the benefits to consumers who will have increased options to communicate with notifying entities. Second, in response to the comment that the HIPAA Breach Notification Rule requires only one contact method, /273/ the Commission notes while there are many similarities between the
FOOTNOTE 272 See supra note 259. END FOOTNOTE
FOOTNOTE 273 Id. END FOOTNOTE
The Commission notes multiple commenters supported this proposal. /274/ Specifically, the Commission agrees with the commenter who stated multiple contact procedures enables greater opportunities for affected individuals to communicate with notifying entities. /275/ The Commission also agrees with the commenter who noted multiple contact options ensures that affected individuals from all backgrounds and technical capabilities are able to contact the notifying entity following a breach. /276/ The Commission therefore adopts proposed
FOOTNOTE 274 See supra note 256. END FOOTNOTE
FOOTNOTE 275 See supra note 258. END FOOTNOTE
FOOTNOTE 276 See supra note 257. END FOOTNOTE
G. Timing of Notice to the
1. The Commission's Proposal Regarding Timing of Notice
Although the Commission did not propose any timing changes in the NPRM, the Commission requested comments on several issues related to timing, including the timing of the notification to the
2. Public Comments Regarding Timing of Notice
Several commenters expressed support for extending the notification timeline to the
FOOTNOTE 277 AdvaMed at 9; AHIP at 7; ACLA at 3-4; ATA Action at 2; CCIA at 8; CHI at 6; CTA at 20-21; TechNet at 5. END FOOTNOTE
FOOTNOTE 278 AdvaMed at 9; ACLA at 3-4; AHIP at 7; TechNet at 5-6. END FOOTNOTE
FOOTNOTE 279 ACLA at 3-4; CTA at 19-21. END FOOTNOTE
Several commenters urged the
FOOTNOTE 280 45 CFR 164.400 through 414. END FOOTNOTE
FOOTNOTE 281 AdvaMed at 9; AHIP at 7; ACLA at 3; ATA Action at 2; TechNet at 5-6. END FOOTNOTE
FOOTNOTE 282 ACLA at 3-4. END FOOTNOTE
FOOTNOTE 283 CTA at 19-21. END FOOTNOTE
3. The Commission Adopts Changes to the Timing of Notice
Having considered the public comments, the Commission agrees with commenters who recommended that the notification timeline to the
Accordingly, the Commission is revising
As a result of this change, the Commission anticipates entities will have sufficient time to provide complete and fulsome notifications to the Commission. The Commission emphasizes, however, that notice to the
FOOTNOTE 284 As the Commission stated in the 2009 Rule Commentary, in some cases, it may be an "unreasonable delay" to wait until the 60th day to provide notification. For example, if a vendor of personal health records or PHR related entity learns of a breach, gathers all necessary information, and has systems in place to provide notification within 30 days, it would be unreasonable to wait until the 60th day to send the notice. Similarly, the Commission noted there may be circumstances where a vendor of personal health records discovers that its third party service provider has suffered a breach before the service provider notifies the vendor that the breach has occurred. In such circumstances, the vendor should begin taking steps to address the breach immediately, and should not wait until receiving notice from the service provider. 74 FR 42971 n.94 (2009). END FOOTNOTE
FOOTNOTE 285 42 U.S.C. 17932(e)(3). Like the
Finally, a small number of commenters addressed other issues related to timing, such as the timeline for providing notice to consumers or the media. The Commission believes, for the reasons stated in the commentary accompanying the 2009 NPRM and the 2009 Rule Commentary, the current timelines are appropriate to give consumers and the media timely notice without overburdening notifying firms. /286/
FOOTNOTE 286 74 FR 17918 (2009); 74 FR 42971 (2009). END FOOTNOTE
H. Proposed Changes To Improve Rule's Readability
1. The Commission Proposed Changes To Promote Readability
The Commission proposed several changes to improve the Rule's readability. Specifically, the Commission proposed to include explanatory parentheticals for internal cross-references, add statutory citations in relevant places, consolidate notice and timing requirements in single sections, and revise the Enforcement section to state more plainly the penalties for non-compliance.
2. Public Comments Regarding Readability
Commenters supported the Commission's proposed changes to improve the Rule's readability and promote comprehension by including explanatory parentheticals and statutory citations. /287/ Commenters also expressed support for the proposed changes to improve the Rule's readability and promote compliance by consolidating into single sections, respectively, the Rule's breach notification and timing requirements. /288/ Commenters also favored the proposal to modify
FOOTNOTE 287 AMA at 6;
FOOTNOTE 288 AHIMA at 7; AMA at 6-7. END FOOTNOTE
FOOTNOTE 289 AHIMA at 7; AMA at 6-7; AHIOS at 5; MRO at 4. As part of its comment, AMA recommended the
3. The Commission Adopts Changes Regarding Readability
In light of support from commenters and the Commission's belief that these proposed changes improve readability, the Commission adopts these changes without modification. /290/
FOOTNOTE 290 Relatedly, the Commission also is making a non-substantive grammatical change to
III. Paperwork Reduction Act
The Paperwork Reduction Act ("PRA"), 44 U.S.C. chapter 35, requires Federal agencies to seek and obtain
FOOTNOTE 291 44 U.S.C. 3502(3)(A)(i). END FOOTNOTE
FOOTNOTE 292 See 44 U.S.C. 3502(3)(A)(i). END FOOTNOTE
FOOTNOTE 293 Third party service providers who experience a breach are required to notify the vendor of personal health records or PHR related entity, which in turn is then required to notify consumers. The Commission expects the cost of notification to third party service providers would be small, relative to the entities that have to notify consumers. As part of the NPRM, the Commission solicited public comment on this issue and data that may be used to quantify the costs to third party service providers. The Commission did not receive any responsive submissions pertaining to this issue. END FOOTNOTE
Based on industry reports,
FOOTNOTE 294 See
FOOTNOTE 295 See AppBrain: Number of Android Apps on
FOOTNOTE 296 See Business of Apps, "App Data Report: App Store Stats, Downloads, Revenues and App Rankings," https://www.businessofapps.com/data/report-app-data/ (reporting 90,913 apps in the Apple iOS
The Commission received three comments in response to the NPRM arguing the Rule's scope is broader than apps categorized as "Health and Fitness" and the NPRM's PRA analysis therefore underestimated the number of covered entities and the resulting number of reportable breaches. /297/ As discussed above, /298/ the Commission is adopting these amendments to clarify that the Rule applies to mobile health applications and similar technologies. The Commission also highlighted several key limitations to the Rule's scope. /299/ Thus, the 193,000 covered entities is a rough proxy for all covered PHRs, because it encompasses mobile health applications categorized as "
FOOTNOTE 297 See Chamber at 2; CHI at 6-7; CCIA at 8-9. END FOOTNOTE
FOOTNOTE 298 See section II.1.c. END FOOTNOTE
FOOTNOTE 299 Id. END FOOTNOTE
FOOTNOTE 300 Indeed, one of the commenters who argued the Rule's coverage is broader than projected in the NPRM's PRA analysis acknowledged that there has been growth in the number of websites and apps since the 2009 PRA analysis estimated 700 covered entities to be covered by the Rule. Chamber at 2. Further, the approximately 193,000 covered entities may overestimate the number of covered entities, as some apps or websites may not qualify as a covered entity given the Rule's boundaries. For example, a website or app must have the technical capacity to draw information from multiple sources and that same website or app must still be "managed, shared, and controlled by or primarily for the individual" to be covered by the Rule. END FOOTNOTE
FOOTNOTE 301
FOOTNOTE 302 According to
Specifically, HHS's OCR reported 715 breaches in 2021, 719 breaches in 2022, and 733 breaches in 2023, /303/ which results in an average of 722 breaches between 2021 and 2023. Based on the 1.7 million entities that are covered by the HIPAA Breach Notification Rule /304/ and the average number of breaches for 2021-2023,
FOOTNOTE 303 See Breach Portal,
FOOTNOTE 304 In a
FOOTNOTE 305 One commenter argued that basing the NPRM's projection of the annual number of breaches on the breach incidence rate for HIPAA-covered entities is problematic because the NPRM's proposed definition of a breach of security "goes far and beyond" the HIPAA definition of a breach. CCIA at 8-9. To the extent the commenter is referring to the fact that the Rule's definition of breach of security covers unauthorized disclosures, the Commission notes the HIPAA Breach Notification Rule similarly covers unauthorized disclosures. See Breach Notification Rule,
Costs
To determine the costs for purposes of this analysis,
Estimated Annual
Estimated Annual Labor Cost:
First, to determine what information has been breached, identify the affected customers, prepare the breach notice, and make the required report to the Commission,
FOOTNOTE 306 This estimate is the sum of 40 hours of marketing managerial time (at an average wage of
The capital and non-labor costs associated with breach notifications depend upon the number of consumers contacted and whether covered firms are likely to retain the services of a forensic expert. For breaches affecting large numbers of consumers, covered firms are likely to retain the services of a forensic expert.
FOOTNOTE 307 This estimate is the sum of 40 hours of forensic expert time at a cost of
Using the data on HIPAA-covered breach notices available from HHS for the years 2018-2023,
FOOTNOTE 308 HHS Breach Data, supra note 303. This analysis uses the last six years of HHS breach data to generate the average, in order to account for the variation in number of individuals affected by breaches observed in the HHS data over time. END FOOTNOTE
Based on a recent study of data breach costs,
FOOTNOTE 309 See IBM Security, Costs of a Data Breach Report 2023 (2023), https://www.ibm.com/reports/data-breach ("2023 IBM Security Report"). The research for the 2023 IBM Security Report is conducted independently by the
FOOTNOTE 310 See 2023 IBM Security Report at 72. END FOOTNOTE
FOOTNOTE 311 Many State data breach notification statutes require notification when a breach occurs involving certain health or medical information of individuals in that State. See, e.g., Ala. Code 8-38-1 et seq.; Alaska Stat. 45.48.010 et seq.; Ariz.
IV. Regulatory Flexibility Act
The Regulatory Flexibility Act (RFA) /312/ requires that the Commission provide an Initial Regulatory Flexibility Analysis ("IRFA") with a proposed rule and a Final Regulatory Flexibility Analysis ("FRFA") with a final rule, unless the Commission certifies that the rule will not have a significant economic impact on a substantial number of small entities. As discussed in the IRFA, the Commission believes the final rule will not have a significant economic impact upon small entities.
FOOTNOTE 312 5 U.S.C. 601-612. END FOOTNOTE
In this document, the Commission largely adopts the amendments proposed in its NPRM. The Commission believes the amendments will not have a significant economic impact upon small entities, although they may affect a substantial number of small businesses. Among other things, the amendments clarify certain definitions, revise the disclosures that must accompany notice of a breach under the Rule, and modernize the methods of notice to allow additional use of electronic notice such as email by entities affected by a breach. In addition, the amendments improve the Rule's readability by clarifying cross-references and adding statutory citations. The Commission does not anticipate that these changes will add significant additional costs for entities covered by the Rule, and by authorizing electronic notice in additional circumstances, the amendments may reduce costs for many entities covered by the Rule. Therefore, the Commission certifies that the amendments will not have a significant economic impact on a substantial number of small entities. Although the Commission certifies under the RFA that the Rule will not have a significant impact on a substantial number of small entities, and hereby provides notice of that certification to the
A. Need for and Objectives of the Amendments
The objective of the amendments is to clarify existing notice obligations for entities covered by the Rule. The legal basis for the amendments is section 13407 of the Recovery Act.
B. Significant Issues Raised in Public Comments
Although the Commission received several comments that argued that the amendments would be burdensome for businesses, none argued specifically that smaller businesses in particular would be subject to special burdens. The Commission did not receive any comments filed by the Chief Counsel for Advocacy of the SBA.
C. Small Entities to Which the Amendments Will Apply
The amendments, like the current Rule, will apply to vendors of personal health records, PHR related entities, and third party service providers, including developers and purveyors of health apps, connected health devices, and similar technologies. As discussed in the Commission's PRA estimates above,
FOOTNOTE 313 2017 SUSB Annual Data Tables by Establishment Industry,
D. Projected Reporting, Recordkeeping, and Other Compliance Requirements, Including Classes of Covered Small Entities and Professional Skills Needed To Comply
The Recovery Act and the amendments contain certain reporting requirements. The amendments will clarify which entities are subject to those reporting requirements. Specifically, the Act and amendments require vendors of personal health records and PHR related entities to provide notice to consumers, the Commission, and in some cases the media in the event of a breach of unsecured PHR identifiable health information. The Act and amendments also require third party service providers to provide notice to vendors of personal health records and PHR related entities in the event of such a breach. If a breach occurs, each entity covered by the Act and amendments will expend costs to determine the extent of the breach and the individuals affected. If the entity is a vendor of personal health records or a PHR related entity, additional costs will include the costs of preparing a breach notice, notifying the Commission, compiling a list of consumers to whom a breach notice must be sent, and sending a breach notice. Such entities may incur additional costs in locating consumers who cannot be reached, and in certain cases, posting a breach notice on a website, notifying consumers through media advertisements, or sending breach notices through press releases to media outlets.
In-house costs may include technical costs to determine the extent of breaches; investigative costs of conducting interviews and gathering information; administrative costs of compiling address lists; professional/legal costs of drafting the notice; and potentially, costs for postage, web posting, and/or advertising. Costs may also include the purchase of services of a forensic expert. As discussed in the context of the PRA,
E. Significant Alternatives to the Amendments
In drafting the Rule, the Commission has made every effort to avoid unduly burdensome requirements for entities. In particular, the Commission believes that the changes to facilitate electronic notice will assist small entities by significantly reducing the costs of sending breach notices. In addition, the Commission is making available exemplar notices that entities covered by the Rule may use, in their discretion, to notify individuals. The Commission anticipates these exemplar notices will further reduce the burden on entities that are required to provide notice under the Rule. The Commission is not aware of alternative methods of compliance that will reduce the impact of the amendments on small entities, while also comporting with the Recovery Act. The statutory requirements are specific as to the timing, method, and content of notice.
V. Other Matters
Pursuant to the Congressional Review Act (5 U.S.C.
List of Subjects in 16 CFR Part 318 Breach, Consumer protection, Health, Privacy, Reporting and recordkeeping requirements, Trade practices.
Accordingly, the
PART 318--HEALTH BREACH NOTIFICATION RULE
Sec.
318.1Purpose and scope.
318.2Definitions.
318.3Breach notification requirement.
318.4Timeliness of notification.
318.5Methods of notice.
318.6Content of notice.
318.7Enforcement.
318.8Applicability date.
318.9Sunset.
Authority:42 U.S.C. 17937 and 17953.
(a) This part, which shall be called the "Health Breach Notification Rule," implements section 13407 of the American Recovery and Reinvestment Act of 2009, 42 U.S.C. 17937. This part applies to foreign and domestic vendors of personal health records, PHR related entities, and third party service providers, irrespective of any jurisdictional tests in the
(b) This part preempts State law as set forth in section 13421 of the American Recovery and Reinvestment Act of 2009, 42 U.S.C 17951.
Breach of security means, with respect to unsecured PHR identifiable health information of an individual in a personal health record, acquisition of such information without the authorization of the individual. Unauthorized acquisition will be presumed to include unauthorized access to unsecured PHR identifiable health information unless the vendor of personal health records, PHR related entity, or third party service provider that experienced the breach has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information. A breach of security includes an unauthorized acquisition of unsecured PHR identifiable health information in a personal health record that occurs as a result of a data breach or an unauthorized disclosure.
Business associate means a business associate under the Health Insurance Portability and Accountability Act, Public Law 104-191, 110 Stat. 1936, as defined in 45 CFR 160.103.
Clear and conspicuous means that a notice is reasonably understandable and designed to call attention to the nature and significance of the information in the notice.
(1) Reasonably understandable. You make your notice reasonably understandable if you:
(i) Present the information in the notice in clear, concise sentences, paragraphs, and sections;
(ii) Use short explanatory sentences or bullet lists whenever possible;
(iii) Use definite, concrete, everyday words and active voice whenever possible;
(iv) Avoid multiple negatives;
(v) Avoid legal and highly technical business terminology whenever possible; and
(vi) Avoid explanations that are imprecise and readily subject to different interpretations.
(2) Designed to call attention. You design your notice to call attention to the nature and significance of the information in it if you:
(i) Use a plain-language heading to call attention to the notice;
(ii) Use a typeface and type size that are easy to read;
(iii) Provide wide margins and ample line spacing;
(iv) Use boldface or italics for key words; and
(v) In a form that combines your notice with other information, use distinctive type size, style, and graphic devices, such as shading or sidebars, when you combine your notice with other information. The notice should stand out from any accompanying text or other visual elements so that it is easily noticed, read, and understood.
(3) Notices on websites or within-application messaging. If you provide a notice on a web page or using within-application messaging, you design your notice to call attention to the nature and significance of the information in it if you use text or visual cues to encourage scrolling down the page if necessary to view the entire notice and ensure that other elements on the website or software application (such as text, graphics, hyperlinks, or sound) do not distract attention from the notice, and you either:
(i) Place the notice on a screen that consumers frequently access, such as a page on which transactions are conducted; or
(ii) Place a link on a screen that consumers frequently access, such as a page on which transactions are conducted, that connects directly to the notice and is labeled appropriately to convey the importance, nature and relevance of the notice.
Covered health care provider means a provider of services (as defined in 42 U.S.C. 1395x(u)), a provider of medical or other health services (as defined in 42 U.S.C. 1395x(s)), or any other entity furnishing health care services or supplies.
Electronic mail means email in combination with one or more of the following: text message, within-application messaging, or electronic banner.
Health care services or supplies means any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools.
HIPAA-covered entity means a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), Public Law 104-191, 110 Stat. 1936, as defined in 45 CFR 160.103.
Personal health record (PHR) means an electronic record of PHR identifiable health information on an individual that has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual.
PHR identifiable health information means information that:
(1) Relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual; and
(i) Identifies the individual; or
(ii) With respect to which there is a reasonable basis to believe that the information can be used to identify the individual; and
(2) Is created or received by a:
(i) Covered health care provider;
(ii) Health plan (as defined in 42 U.S.C. 1320d(5));
(iii) Employer; or
(iv) Health care clearinghouse (as defined in 42 U.S.C. 1320d(2)); and
(3) With respect to an individual, includes information that is provided by or on behalf of the individual.
PHR related entity means an entity, other than a HIPAA-covered entity or an entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity, that:
(1) Offers products or services through the website, including any online service, of a vendor of personal health records;
(2) Offers products or services through the websites, including any online service, of HIPAA-covered entities that offer individuals personal health records; or
(3) Accesses unsecured PHR identifiable health information in a personal health record or sends unsecured PHR identifiable health information to a personal health record.
State means any of the several States, the
Third party service provider means an entity that:
(1) Provides services to a vendor of personal health records in connection with the offering or maintenance of a personal health record or to a PHR related entity in connection with a product or service offered by that entity; and
(2) Accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured PHR identifiable health information as a result of such services.
Unsecured means PHR identifiable information that is not protected through the use of a technology or methodology specified by the Secretary of
Vendor of personal health records means an entity, other than a HIPAA-covered entity or an entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity, that offers or maintains a personal health record.
(a) In general. In accordance with [Sec.]
(1) Notify each individual who is a citizen or resident of
(2) Notify the
(3) Notify prominent media outlets serving a State or jurisdiction, following the discovery of a breach of security, if the unsecured PHR identifiable health information of 500 or more residents of such State or jurisdiction is, or is reasonably believed to have been, acquired during such breach.
(b) Third party service providers. A third party service provider shall, following the discovery of a breach of security, provide notice of the breach to an official designated in a written contract by the vendor of personal health records or the PHR related entity to receive such notices or, if such a designation is not made, to a senior official at the vendor of personal health records or PHR related entity to which it provides services, and obtain acknowledgment from such official that such notice was received. Such notification shall include the identification of each customer of the vendor of personal health records or PHR related entity whose unsecured PHR identifiable health information has been, or is reasonably believed to have been, acquired during such breach. For purposes of ensuring implementation of this paragraph (b), vendors of personal health records and PHR related entities shall notify third party service providers of their status as vendors of personal health records or PHR related entities subject to this part. While some third party service providers may access unsecured PHR identifiable health information in the course of providing services, this does not render the third party service provider a PHR related entity.
(c) Breaches treated as discovered. A breach of security shall be treated as discovered as of the first day on which such breach is known or reasonably should have been known to the vendor of personal health records, PHR related entity, or third party service provider, respectively. Such vendor, entity, or third party service provider shall be deemed to have knowledge of a breach if such breach is known, or reasonably should have been known, to any person, other than the person committing the breach, who is an employee, officer, or other agent of such vendor of personal health records, PHR related entity, or third party service provider.
(a) In general. Except as provided in paragraph (d) of this section (exception for law enforcement), all notifications required under
(b) Timing of notice to
(c) Burden of proof. The vendor of personal health records, PHR related entity, and third party service provider involved shall have the burden of demonstrating that all notifications were made as required under this part, including evidence demonstrating the necessity of any delay.
(d) Law enforcement exception. If a law enforcement official determines that a notification, notice, or posting required under this part would impede a criminal investigation or cause damage to national security, such notification, notice, or posting shall be delayed. This paragraph (d) shall be implemented in the same manner as provided under 45 CFR 164.528(a)(2), in the case of a disclosure covered under
(a) Individual notice. A vendor of personal health records or PHR related entity that discovers a breach of security shall provide notice of such breach to an individual promptly, as described in
(1) Written notice at the last known address of the individual. Written notice may be sent by electronic mail if the individual has specified electronic mail as the primary method of communication. Any written notice sent by electronic mail must be Clear and Conspicuous. Where notice via electronic mail is not available or the individual has not specified electronic mail as the primary method of communication, a vendor of personal health records or PHR related entity may provide notice by first-class mail at the last known address of the individual. If the individual is deceased, the vendor of personal health records or PHR related entity that discovered the breach must provide such notice to the next of kin of the individual if the individual had provided contact information for his or her next of kin, along with authorization to contact them. The notice may be provided in one or more mailings as information is available.
(2) If, after making reasonable efforts to contact all individuals to whom notice is required under
(i) Through a conspicuous posting for a period of 90 days on the home page of its website; or
(ii) In major print or broadcast media, including major media in geographic areas where the individuals affected by the breach likely reside. Such a notice in media or web posting shall include a toll-free phone number, which shall remain active for at least 90 days, where an individual can learn if the individual's unsecured PHR identifiable health information may have been included in the breach.
(3) In any case deemed by the vendor of personal health records or PHR related entity to require urgency because of possible imminent misuse of unsecured PHR identifiable health information, that entity may provide information to individuals by telephone or other means, as appropriate, in addition to notice provided under paragraph (a)(1) of this section.
(b) Notice to media. As described in
(c) Notice to
Regardless of the method by which notice is provided to individuals under
(a) A brief description of what happened, including: the date of the breach and the date of the discovery of the breach, if known; and the full name or identity (or, where providing the full name or identity would pose a risk to individuals or the entity providing notice, a description) of any third parties that acquired unsecured PHR identifiable health information as a result of a breach of security, if this information is known to the vendor of personal health records or PHR related entity;
(b) A description of the types of unsecured PHR identifiable health information that were involved in the breach (such as but not limited to full name,
(c) Steps individuals should take to protect themselves from potential harm resulting from the breach;
(d) A brief description of what the entity that experienced the breach is doing to investigate the breach, to mitigate harm, to protect against any further breaches, and to protect affected individuals, such as offering credit monitoring or other services; and
(e) Contact procedures for individuals to ask questions or learn additional information, which must include two or more of the following: toll-free telephone number; email address; website; within-application; or postal address.
Any violation of this part shall be treated as a violation of a rule promulgated under section 18 of the Federal Trade Commission Act, 15 U.S.C. 57a, regarding unfair or deceptive acts or practices, and thus subject to civil penalties (as adjusted for inflation pursuant to
This part shall apply to breaches of security that are discovered on or after
If new legislation is enacted establishing requirements for notification in the case of a breach of security that apply to entities covered by this part, the provisions of this part shall not apply to breaches of security discovered on or after the effective date of regulations implementing such legislation.
By direction of the Commission, Commissioners Holyoak and Ferguson dissenting.
Secretary.
Note:The following appendices will not appear in the Code of Federal Regulations.
Appendix A--Health Breach Notification Rule Exemplar Notices
The notices below are intended to be examples of notifications that entities may use, in their discretion, to notify individuals of a breach of security pursuant to the Health Breach Notification Rule. The examples below are for illustrative purposes only. You should tailor any notices to the particular facts and circumstances of your breach. While your notice must comply with the Health Breach Notification Rule, you are not required to use the notices below.
Mobile Text Message and In-App Message Exemplars
Text Message Notification Exemplar 1
Due to a security breach on our system, the health information you shared with us through [name of product] is now in the hands of unknown attackers. Visit [add non-clickable URL] to learn what happened, how it affects you, and what you can do to protect your information. We also sent you an email with additional information.
Text Message Notification Exemplar 2
You shared health information with us when you used [product name]. We discovered that we shared your health information with third parties for [describe why the company shared the info] without your permission. Visit [add non-clickable URL] to learn what happened, how it affects you, and what you can do to protect your information. We also sent you an email with more information.
In-App Message Notification Exemplar 1
Due to a security breach on our system, the health information you shared with us through [name of product] is now in the hands of unknown attackers. This could include your [Add specifics--for example, your name, email, address, blood pressure data]. Visit [URL] to learn what happened, how it affects you, and what you can do to protect your information. We also sent you an email with additional information.
In-App Message Notification Exemplar 2
You shared health information with us when you used [product name]. We discovered that we shared your health information with third parties for [if known, describe why the company shared the info] without your permission. This could include your [Add specifics--for example, your name, email, address, blood pressure data]. Visit [URL] to learn what happened, how it affects you, and what you can do to protect your information. We also sent you an email with additional information.
Web Banner Exemplars
Web Banner Notification Exemplar 1
Due to a security breach on our system, the health information you shared with us through [name of product] is now in the hands of unknown attackers. This could include your [Add specifics--for example, your name, email, address, blood pressure data]. Visit [URL] to learn what happened, how it affects you, and what you can do to protect your information.
* Recommend: Include clear "Take action" call to action button, such as the example below:
See illustration in Original Document.
Web Banner Notification Exemplar 2
You shared health information with us when you used [product name]. We discovered that we shared your health information with third parties for [if known, describe why the company shared the info] without your permission. This could include your [Add specifics--for example, your name, email, address, blood pressure data]. Visit [URL] to learn what happened, how it affects you, and what you can do to protect your information.
* Recommend: Include clear "Take action" call to action button, such as the example below:
See illustration in Original Document.
Email Exemplars
Exemplar Email Notice 1
Email Sender: [Company] <company email>
Email Subject Line: [Company] Breach of Your Health Information
We are contacting you because an attacker recently gained unauthorized access to our system and stole health information about our customers, including you.
What happened and what it means for you
On [
What you can do to protect yourself
You can take steps now to reduce the risk of identity theft.
1. Review your medical records, statements, and bills for signs that someone is using your information. Under the health privacy law known as HIPAA, you have the right to access your medical records. Get your records and review them for any treatments or doctor visits you don't recognize. If you find any, report them to your healthcare provider in writing. Then go to www.IdentityTheft.gov/steps to see what other steps you can take to limit the damage.
Also review the Explanation of Benefits statement your insurer sends you when it pays for medical care.
Some criminals wait before using stolen information so keep monitoring your benefits and bills.
2. Review your credit reports for errors. You can get your free credit reports from the three credit bureaus at www.annualcreditreport.com or call 1-877-322-8228. Look for medical billing errors, like medical debt collection notices that you don't recognize. Report any medical billing errors to all three credit bureaus by following the "What To Do Next" steps on www.IdentityTheft.gov.
3. Sign up for free credit monitoring to detect suspicious activity. Credit monitoring detects and alerts you about activity on your credit reports. Activity you don't recognize could be a sign that someone stole your identity. We're offering free credit monitoring for two years through [name of service]. Learn more and sign up at [URL].
4. Consider freezing your credit report or placing a fraud alert on your credit report. A credit report freeze means potential creditors can't get your credit report without your permission. That makes it less likely that an identity thief can open new accounts in your name. A freeze remains in place until you ask the credit bureau to temporarily lift it or remove it.
A fraud alert will make it harder for someone to open a new credit account in your name. It tells creditors to contact you before they open any new accounts in your name or change your accounts. A fraud alert lasts for one year. After a year, you can renew it.
To freeze your credit report, contact each of the three credit bureaus, Equifax, Experian, and
To place a fraud alert, contact any one of the three credit bureaus, Equifax, Experian, and
Credit bureau contact information
Equifax, www.equifax.com/personal/credit-report-services, 1-800-685-1111
Experian, www.experian.com/help, 1-888-397-3742
Learn more about how credit report freezes and fraud alerts can protect you from identity theft or prevent further misuse of your personal information at www.consumer.ftc.gov/articles/what-know-about-credit-freezes-and-fraud-alerts.
What we are doing in response
We hired security experts to secure our system. We are working with law enforcement to find the attacker. And we are investigating whether we made mistakes that made it possible for the attackers to get in.
Learn more about the breach.
Go to [URL] to learn more about what happened and what you can do to protect yourself. If we have any updates, we will post them there.
If you have questions or concerns, call us at [telephone number], email us at [address], or go to [URL].
Sincerely,
[Role], [Company]
Exemplar Email Notice 2
Email Sender: [Company] <company email>
Email Subject Line: Unauthorized disclosure of your health informationby [Company]
We are contacting you because you use our company's app [name of app]. When you downloaded our app, we promised to keep your personal health information private. Instead, we disclosed health information about you without your approval.
What happened?
We told [insert Company name, identity, or, where providing full name or identity would pose a risk to individuals or the entity providing notice, a description of type of company] that you use our app, and between [January 10, 2024] and [March 1, 2024], we gave them your name and your email address.
We gave [insert Company name, identity, or where providing full name or identity would pose a risk to individuals or the entity providing notice, a description of type of company] this information so they could use it for advertising and marketing purposes. For example, to target you for ads for cancer drugs.
What we are doing in response
We will stop selling or sharing your health information with other companies. We will stop using your health information for advertising or marketing purposes. We have asked Company XYZ to delete your health information, but it's possible they could continue to use it for advertising and marketing.
What you can do
We made important changes to our app to fix this problem. Download the latest updates to our app then review your privacy settings. You can also contact Company XYZ to request that it delete your data.
Learn more
Learn more about our privacy and security practices at [URL]. If we have any updates, we will post them there.
If you have any questions or concerns, call us at [telephone number] or email us at [address].
Sincerely,
[Role], [Company]
Exemplar Email Notice 3
Email Sender: [Company] <company email>
Email Subject Line: [Company] Breach of Your Health Information
We are contacting you about a breach of your health information collected through the [product], a device sold by our company, [Company].
What happened?
On [March 1, 2024], we discovered that our employee had accidentally posted a database online on [February 28, 2024]. That database included your name, your credit or debit card information, and your blood pressure readings. We don't know if anyone else found the database and saw your information. If someone found the database, they could use personal information to steal your identity or make unauthorized charges in your name.
What you can do to protect yourself
You can take steps now to reduce the risk of identity theft.
1. Get your free credit report and review it for signs of identity theft. Order your free credit report at www.annualcreditreport.com. Review it for accounts and activity you don't recognize. Recheck your credit reports periodically.
2. Consider freezing your credit report or placing a fraud alert on your credit report. A credit report freeze means potential creditors can't get your credit report without your permission. That makes it less likely that an identity thief can open new accounts in your name. A freeze remains in place until you ask the credit bureau to temporarily lift it or remove it.
A fraud alert will make it harder for someone to open a new credit account in your name. It tells creditors to contact you before they open any new accounts in your name or change your accounts. A fraud alert lasts for one year. After a year, you can renew it.
To freeze your credit report, contact each of the three credit bureaus, Equifax, Experian, and
To place a fraud alert, contact any one of the three credit bureaus, Equifax, Experian, and
Credit bureau contact information
Equifax, www.equifax.com/personal/credit-report-services, 1-800-685-1111
Experian, www.experian.com/help, 1-888-397-3742
Learn more about how credit report freezes and fraud alerts can protect you from identity theft or prevent further misuse of your personal information at www.consumer.ftc.gov/articles/what-know-about-credit-freezes-and-fraud-alerts.
3. Sign up for free credit monitoring to detect suspicious activity. Credit monitoring detects and alerts you about activity on your credit reports. Activity you don't recognize could be a sign that someone stole your identity. We're offering free credit monitoring for two years through [name of service]. Learn more and sign up at [URL].
What we are doing in response
We are investigating our mistakes. We know the database shouldn't have been online and it should have been encrypted. We are making changes to prevent this from happening again.
We are working with experts to secure our system. We are reviewing our databases to make sure we store health information securely.
Learn more about the breach.
Go to [URL] to learn more about what happened and what you can do to protect yourself. If we have any updates, we will post them there.
If you have questions or concerns, call us at [telephone number], email us at [address], or go to [URL].
Sincerely,
[Role], [Company]
Appendix B--Joint Statement by FTC Chair and Commissioners
Joint Statement of Chair
Today, the
In 2009, as part of the American Recovery and Reinvestment Act ("ARRA"),
FOOTNOTE 314 Am. Recovery and Reinvestment Act of 2009, Public Law 111-5, 123 Stat. 115 (2009) at Sec. 13400 et seq. END FOOTNOTE
FOOTNOTE 315 Health Insurance Portability and Accountability Act, Public Law 104-191, 110 Stat. 1936, 2022 (1996) at Sec. 1171, codified at 42 U.S.C. 1320d. END FOOTNOTE
FOOTNOTE 316 Health Information Technology for Economic and Clinical Health Act, Public Law 111-5, Div. A, Title XIII, Subtitle D, sections 13401 and 13404 (codified at 42 U.S.C. 17937(a)) END FOOTNOTE
FOOTNOTE 317 Id. 13410(e). END FOOTNOTE
FOOTNOTE 318 Id. 13407(g)(1). END FOOTNOTE
FOOTNOTE 319 74 FR 42962 (Aug. 25, 2009). END FOOTNOTE
FOOTNOTE 320 Statement of the Commission on Breaches by Health Apps and Other Connected Devices (Sept. 15, 2021), https://www.ftc.gov/system/files/documents/public_statements/1596364/statement_of_the_commission_on_breaches_by_health_apps_and_other_connected_devices.pdf. END FOOTNOTE
FOOTNOTE 321 See, e.g., Fed. Trade Comm'n, FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising (Feb. 1, 2023), https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising; Fed. Trade Comm'n, Ovulation Tracking App Premom Will be Barred from Sharing Health Data for Advertising Under Proposed FTC Order (May 17, 2023), https://www.ftc.gov/news-events/news/press-releases/2023/05/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc. END FOOTNOTE
The dissent argues that the Commission's action "exceeds the Commission's statutory authority." /322/ But its analysis contravenes a plain reading of the statute.
FOOTNOTE 322 Dissenting Statement of Comm'rs
In the HITECH Act,
FOOTNOTE 323 Health Information Technology for Economic and Clinical Health Act, Public Law 111-5, Div. A, Title XIII, Subtitle D, section 13407 (codified at 42 U.S.C. 17937(a)). END FOOTNOTE
FOOTNOTE 324 42 U.S.C. 17937(f)(2). END FOOTNOTE
FOOTNOTE 325 42 U.S.C. 1320d(6). END FOOTNOTE
FOOTNOTE 326 See 42 U.S.C. 1395x(u) ("The term "provider of services" means a hospital, critical access hospital, rural emergency hospital, skilled nursing facility, comprehensive outpatient rehabilitation facility, home health agency, hospice program, or, for purposes of section 1395f(g) and section 1395n(e) of this title, a fund."). END FOOTNOTE
FOOTNOTE 327 42 U.S.C. 1395x(s) (listing a vast array of services, tests, supplies, and measurements, comprising over 2000 words and 15 categories, one of which has over 30 subcategories). END FOOTNOTE
FOOTNOTE 328 42 U.S.C. 1320d(3) (emphasis added). END FOOTNOTE
The term "health care services or supplies," undefined in the statute, is defined in the Final Rule as follows:
Health care services or supplies means any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools. /329/
FOOTNOTE 329 HBNR Final Rule SEC 318.2(e). END FOOTNOTE
The dissent argues that this definition violates certain canons of statutory construction. /330/ But its effort to cabin the third category of HIPAA's "health care provider" reads it out of existence, violating the canon that holds interpretations giving effect to every clause of a statute are superior to those that render distinct clauses superfluous. /331/ Specifically, the second category of "health care provider" already comprises a vast array of "provider[s] of medical and other services." /332/ If the Commission were to interpret the third category as comprising, as the dissent recommends, only "traditional forms of health care providers," this distinct provision would be entirely redundant.
FOOTNOTE 330 Dissent at 2 ("When a statute contains a list, "each word in that list presumptively has a 'similar' meaning" under the canon of noscitur a sociis. And when a general term follows a list of specific terms, the ejusdem generis canon teaches that the general term "should usually be read in light of those specific words to mean something 'similar.' " Together, these canons instruct that the final category of health care provider that includes the general term "other person" must be similar to the more specific terms that precede it." (citations omitted)). END FOOTNOTE
FOOTNOTE 331 Marx v. Gen. Revenue Corp., 568 U.S. 371, 386 (2013) (Thomas, J.) ("Finally, the canon against surplusage is strongest when an interpretation would render superfluous another part of the same statutory scheme."). END FOOTNOTE
FOOTNOTE 332 42 U.S.C. 1320(d)(3) (citing 42 U.S.C. 1395x(u)). END FOOTNOTE
The dissent's approach also fails to give meaning to other textual differences between the second and third category. The second category in the definition of "health care provider" discusses a "provider" and "medical" services. /333/ The third category, by contrast, drops the terms "provider" in favor of "person furnishing" and drops "medical" in favor of "health care." /334/ Honoring the materially different words of the statute requires us to read these two categories as covering distinct, not entirely overlapping, entities. /335/ The Final Rule faithfully follows these textual markers and identifies specific services and tools that comprise "health care services or supplies." /336/ Contrary to this plain reading of the text, the dissent claims that
FOOTNOTE 333 42 U.S.C. 1320(d)(3). END FOOTNOTE
FOOTNOTE 334 Id. END FOOTNOTE
FOOTNOTE 335 See Southwest Airlines Co. v. Saxon, 596 U.S. 450, 458 (2022) (Thomas, J.) ("Where a document has used one term in one place, and a materially different term in another, the presumption is that the different term denotes a different idea" (cleaned up)). END FOOTNOTE
FOOTNOTE 336 In addition to defining this term by identifying specific services, the Final Rule actually also narrowed the definition originally proposed in the NPRM, by eliminating "includes" from the definition. SBP at 27 ("[T]he Commission has substituted the word 'means' for 'includes' to avoid implying greater breadth than the Commission intends."). END FOOTNOTE
FOOTNOTE 337 Dissent at 3. This rejection of the text of the statute, in favor of vague speculation about what
FOOTNOTE 337 Dissent at 3. END FOOTNOTE
The dissent also notes that the Department of
FOOTNOTE 338 Dissent at 3. END FOOTNOTE
FOOTNOTE 339 That the HIPAA Privacy rule has a narrower overall scope does not change this fact. END FOOTNOTE
FOOTNOTE 340 45 CFR 160.103. END FOOTNOTE
FOOTNOTE 341 Id. (emphasis added). The dissent asserts that we "mischaracterize[] the HIPAA Privacy Rule, which only applies to HIPAA 'covered entities' and their 'business associates,'--i.e., to traditional health care providers, that do not include the broad swath of app developers the Final Rule will encompass." Dissent at 4 n.24 (internal citations omitted). It is not clear how this qualifies as a mischaracterization. Indeed, this is precisely the stated purpose of the Health Breach Notification Rule: To cover entities that HIPAA does not. The dissent also notes that we fail to recognize that HHS provides two examples of "health care." But, HHS expressly states that the definition "includes, but is not limited to" these categories. 45 CFR 160.103. In any case, the breadth of these categories further underscores the expansive scope of HHS's definition of health care. Id. END FOOTNOTE
FOOTNOTE 341 Dissent at 2. END FOOTNOTE
Notably, in its 1999 Notice of Proposed Rulemaking for the HIPAA Privacy Rule, HHS originally had proposed to define the term "health care" as constituting "the provision of care, services, or supplies. . . ." /342/ But, in its final rule, HHS eliminated the concept of "provision" in order to distinguish the broader term of "health care" from the narrower term "treatment." /343/ HHS explained: "We delete the term 'providing' from the definition [of health care] to delineate more clearly the relationship between 'treatment,' as the term is defined in
FOOTNOTE 342 Proposed Rule, Standards for Privacy of Individually Identifiable Health Information, 64 FR 59918, 60049 (Nov. 3, 1999) (emphasis added). END FOOTNOTE
FOOTNOTE 343 65 FR 82462, 82477. END FOOTNOTE
FOOTNOTE 344 Id. END FOOTNOTE
FOOTNOTE 345 45 CFR 164.501. END FOOTNOTE
FOOTNOTE 346 Dissent at 2. END FOOTNOTE
The dissent also claims that changing the phrase "can be drawn" to "has the technical capacity to draw" violates the surplusage canon because it renders the limitation meaningless as to health apps, because "virtually every app has the technical capacity to draw some information from more than one source." /347/ This argument fails for two reasons. First, as the Statement of Basis and Purpose ("SBP") explains, there are products and services that do not satisfy this requirement. /348/ Second, even if the definition did reach every health app, that would not itself suggest that the Final Rule's definition was wrongly crafted. Rather, it would reflect the rapid growth in digital applications and services related to consumers' health. /349/
FOOTNOTE 347 Dissent at 4. END FOOTNOTE
FOOTNOTE 348 SBP at 29-30. END FOOTNOTE
FOOTNOTE 349 The dissent's argument anachronistically assumes that
The practical ramifications of the dissent's legal shortcomings are significant.
Just last year, the Commission brought an action against
FOOTNOTE 350 Press Release, Fed. Trade Comm'n, Ovulation Tracking App Premom Will be Barred from Sharing Health Data for Advertising Under Proposed FTC Order (May 17, 2023), https://www.ftc.gov/news-events/news/press-releases/2023/05/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc. END FOOTNOTE
Under the dissent's analysis of health care services or supplies, the developer of the Premom application--Easy Healthcare--would not be covered by the Health Breach Notification Rule. This reading would mean that when companies like Easy Healthcare suffer a breach that may divulge health information to companies located in
Lastly, the dissent claims that the Final Rule introduces ambiguity where previous there was none. But
FOOTNOTE 351 Press Release, Fed. Trade Comm'n, FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising (Feb. 1, 2023), https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising; See also, Concurring Statement of Comm'r
FOOTNOTE 352 See GoodRx, GoodRx Response to FTC Settlement (Feb. 1, 2023) ("We believe this is a novel application of the Health Breach Notification Rule by the
FOOTNOTE 353 The dissent concedes that it does support an update to the rule that provides more clarity--and specifically an update that provides clarity to show that the rule covers
FOOTNOTE 354 See, e.g., Press Release, Fed. Trade Comm'n, FTC Hits R360 and its Owner With $3.8 Million Civil Penalty Judgment for Preying on People Seeking Treatment for Addiction (May 17, 2022), https://www.ftc.gov/news-events/news/press-releases/2022/05/ftc-hits-r360-its-owner-38-million-civil-penalty-judgment-preying-people-seeking-treatment-addiction (the Commission's first action brought under the Opioid Addiction Recovery Fraud Prevention Act); Harris Jewelry, Press Release, Fed. Trade Comm'n,
We are deeply grateful to the Division of Privacy and Identity Protection for leading the Commission's work to activate the Health Breach Notification Rule and for finalizing this Rule update. In an environment rife with new and evolving threats to Americans' health data, ensuring we are faithfully harnessing all of our statutory tools to protect people from data breaches is paramount.
Dissenting Statement of Commissioner
The Health Breach Notification Rule ("Final Rule") that the Commission adopts today exceeds the Commission's statutory authority, puts companies at risk of perpetual non-compliance, and opens the Commission to legal challenge that could undermine its institutional integrity. I share the majority's goal of protecting the privacy and security of consumers' identifiable health information, /1/ and I support vigorous enforcement of laws protecting sensitive personal information with which
FOOTNOTE 1 Like the majority, and other Commissioners before me, I support federal privacy legislation, particularly where such legislation could address gaps in sector-specific laws and level the playing field for companies navigating a patchwork of laws. And like the majority, and other Commissioners before me, I care deeply about protecting the privacy and security of consumers' health information, particularly where it falls outside the bounds of the Health Insurance Portability and Accountability Act ("HIPAA"). For more than two decades, the
FOOTNOTE 2 See, e.g., Children's Online Privacy Protection Rule, 16 CFR part 312, as authorized by the Children's Online Privacy Protection Act of 1998, 15 U.S.C. 6501 et seq. END FOOTNOTE
FOOTNOTE 3 Joint Statement of Chair
The American Recovery and Reinvestment Act of 2009 ("Recovery Act") /4/ authorized the Commission to issue a rule requiring vendors of "personal health records" ("PHRs") and related entities that are not covered by HIPAA to notify individuals and the
FOOTNOTE 4 Am. Recovery and Reinvestment Act of 2009, Public Law 111-5, 123 Stat. 115 (2009). END FOOTNOTE
FOOTNOTE 5 42 U.S.C. 17937(a), (g). END FOOTNOTE
FOOTNOTE 6 74 FR 42962 (Aug. 25, 2009). END FOOTNOTE
FOOTNOTE 7 85 FR 31085 (May 22, 2020). END FOOTNOTE
FOOTNOTE 8 See Statement of the Comm'n on Breaches by Health Apps and Other Connected Devices (Sept. 15, 2021), https://www.ftc.gov/system/files/documents/public_statements/1596364/statement_of_the_commission_on_breaches_by_health_apps_and_other_connected_devices.pdf ("2021 Policy Statement"). END FOOTNOTE
FOOTNOTE 9 88 FR 37819 (June 9, 2023). END FOOTNOTE
FOOTNOTE 10 See Statement of Basis and Purpose ("SBP") accompanying the Final Rule, Section I (summarizing procedural history). END FOOTNOTE
I am encouraged that today the Commission is acting by rulemaking, as authorized by statute and following a period of notice and comment that elicited a range of views, rather than acting by fiat in a policy statement, as the Commission did in 2021. /11/ I cannot endorse any policy statement that either displaces
FOOTNOTE 11 See 2021 Policy Statement, supra note 8. END FOOTNOTE
Setting aside this troubling history, I turn to the Final Rule itself, which, unfortunately, I find equally troubling in its extension beyond the parameters established by
Some background first. Under the Recovery Act, PHR identifiable health information means "individually identifiable health information," as defined by the Social Security Act, 42 U.S.C. 1320d(6). /12/ The Social Security Act defines "individually identifiable health information" as information that is "created or received by a health care provider, health plan, employer, or health care clearinghouse." /13/ The Social Security Act then defines "health care provider" to include three categories: "[1] a provider of services (as defined in section 1395x(u) of this title), [2] a provider of medical or other health services (as defined in section 1395x(s) of this title), and [3] any other person furnishing health care services or supplies." /14/
FOOTNOTE 12 42 U.S.C. 17937(f)(2). END FOOTNOTE
FOOTNOTE 13 42 U.S.C. 1320d(6). END FOOTNOTE
FOOTNOTE 14 Id. 1320d(3). END FOOTNOTE
The Commission takes liberties with the final category in that definition ("any other person furnishing health care services or supplies") to adopt a new, capacious definition of "covered health care provider" and a new, similarly capacious definition of "health care services and supplies," whose joint effect is to sweep a large swath of apps and app developers under the purview of the Final Rule. These expansive definitions are not consistent with the statute. Under longstanding principles of statutory interpretation, the final category of provider ("any other person . . .") must be understood in relation to the first two categories ("provider of services" and "provider of medical or other health services"). /15/ When a statute contains a list, "each word in that list presumptively has a 'similar' meaning" under the canon of noscitur a sociis. /16/ And when a general term follows a list of specific terms, the ejusdem generis canon teaches that the general term "should usually be read in light of those specific words to mean something 'similar.' " /17/ Together, these canons instruct that the final category of health care provider that includes the general term "other person" must be similar to the more specific terms that precede it.
FOOTNOTE 15 See Yates v.
FOOTNOTE 16 Yates, 574 U.S. at 549. END FOOTNOTE
FOOTNOTE 17 Id. at 550. END FOOTNOTE
The first two categories of health care provider incorporate the definitions of sections 1395x(u) and 1395x(s) of the Social Security Act, respectively. /18/ The first category of provider includes "a hospital, critical access hospital, rural emergency hospital, skilled nursing facility, comprehensive outpatient rehabilitation facility, home health agency, hospice program, or . . . a fund." /19/ The second category of provider includes an extensive list (section 1395x(s) includes 17 paragraphs and over 35 subparagraphs) of medical professionals including physicians, physician assistants, nurse practitioners, clinical psychologists, clinical social workers, and others, and the specific services administered by medical professionals. /20/ These two categories comprise traditional forms of health care providers.
FOOTNOTE 18 42 U.S.C. 1320d(3). END FOOTNOTE
FOOTNOTE 19 42 U.S.C. 1395x(u). END FOOTNOTE
FOOTNOTE 20 Id. 1395x(s). END FOOTNOTE
The final category, addressing "any other person furnishing health care services or supplies," must therefore only include persons that are "similar in nature" to these first two categories. /21/ The majority argues that my "effort to cabin the third category . . . reads it out of existence, violating the canon that holds interpretations giving effect to every clause of a statute are superior to those that render distinct clauses superfluous." /22/ This application of the canon is incorrect. Requiring similarity among categories does not result in superfluity; it merely prevents interpretations that extend beyond what the text permits. A catch-all's limited application due to its context is not a reason to expand that phrase to encompass dissimilar applications.
FOOTNOTE 21 Yates, 574 U.S. at 545 (internal quotation marks omitted). END FOOTNOTE
FOOTNOTE 22 Majority Statement at 2. END FOOTNOTE
The Final Rule's definition of "covered health care provider" is not remotely similar, because it incorporates a new, astonishingly broad definition of "health care services or supplies," which means "any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools." /23/ Thus, the Commission transforms "health care provider," which both under common usage and in context of the statutory provision means entities such as physicians and hospitals, to now include any company "furnishing" a health-related app. /24/ As a result, the Final Rule creates a tautology: Health app developers may be "vendors of personal health records" by offering an app containing health information that has been created or received by a health care provider, where the health app developer is itself the health care provider that creates or receives that health information by virtue of offering the app.
FOOTNOTE 23 Final Rule at 98. END FOOTNOTE
FOOTNOTE 24 The SBP explains that an app developer (or any company "furnishing" a health app) would be covered as a health care provider because its health app is a health care service or supply. SBP at 7, 22-28. END FOOTNOTE
Notably, even though the Department of
FOOTNOTE 25 Majority Statement at 3. END FOOTNOTE
FOOTNOTE 26 See NPRM at 37823. END FOOTNOTE
FOOTNOTE 27 45 CFR 160.102 through 103. END FOOTNOTE
(1) Preventive, diagnostic, therapeutic, rehabilitative, maintenance, or palliative care, and counseling, service, assessment, or procedure with respect to the physical or mental condition, or functional status, of an individual or that affects the structure or function of the body; and
(2) Sale or dispensing of a drug, device, equipment, or other item in accordance with a prescription. /28/
FOOTNOTE 28 Id.
The Majority Statement repeatedly says that HHS defines "health care" broadly, /29/ but the language it cites provides no such support.
FOOTNOTE 29 Majority Statement at 3-4. END FOOTNOTE
Aware of this incongruency, the Commission seeks to differentiate its use of "health care provider" from that of "other government agencies." /30/ Yet the Commission provides no explanation why its definition should differ, particularly where it is unclear whether the Commission has interpretative authority over the Social Security Act's definition of health care provider and where other agencies are delegated such interpretative authority. /31/
FOOTNOTE 30 SBP at 26. END FOOTNOTE
FOOTNOTE 31 Id. at 13 (noting that HHS interprets these provisions of the Social Security Act). Cf.
The Commission also takes troubling liberties with the statute's definition of "personal health record," which are evident from a side-by-side comparison of the statute and the Final Rule:
See table in Original Document.
Under the Final Rule, a PHR need not actually draw health information from multiple sources, as the statute contemplates (because the statutory phrase "that can be drawn" modifies its immediate antecedent, "health information"). Rather, under the Final Rule, a single source of health information will render an app a PHR as long as the "PHR" has the "technical capacity" to draw some other information elsewhere. /34/ The implications of this change, in conjunction with the expansion of "health care provider," are significant. Any retailer that offers an app that tracks health-related purchases (e.g., bandages, vitamins, dandruff shampoo) may be a vendor of a PHR covered by the Rule if the app draws health information (e.g., purchasing information) from the consumer and the app has the "technical capacity" to draw any information from any other source. As the Statement of Basis and Purpose notes, commenters warned that virtually every app has the technical capacity to draw some information from more than one source. /35/ That expansive scope could be appropriate if
FOOTNOTE 32 42 U.S.C. 17921(11). END FOOTNOTE
FOOTNOTE 33 Final Rule at 99. END FOOTNOTE
FOOTNOTE 34 See SBP at 32 ("Next, adding the phrase 'technical capacity to draw information' clarifies that a product is a personal health record if it can draw any information from multiple sources, even if it only draws health information from one source."). END FOOTNOTE
FOOTNOTE 35 See id. at 34. END FOOTNOTE
FOOTNOTE 36 Scalia & Garner, supra note 15 at 174 (discussing surplusage canon). END FOOTNOTE
The Commission's expansive definitions of "covered health care provider," "health care services and supplies," and "personal health record" have a profound effect on the scope of the Rule: Most companies that offer or disseminate health-related apps or similar products would be treated as "covered health care providers" that therefore hold "PHR identifiable health information" in their apps (i.e., PHRs), such that they are vendors of PHRs--even if their app is merely health-adjacent.
Remarkably, the Commission imposes no limit on this extraordinary breadth in the Rule itself. Rather, in a post-NPRM attempt to check the scope, the Commission fashions a limiting principle: Apps are covered only if they are "more than tangentially relating to health." /37/ This extra-statutory, extra-regulatory limit has several significant problems.
FOOTNOTE 37 SBP at 28. END FOOTNOTE
First, if the majority were correct, from where would it draw the authority to impose this "more than tangentially relating to health" limitation? If
FOOTNOTE 38 See Nat'l Fed'n of Indep. Business v. Dep't of Labor, 595 U.S. 109, 117 (2022) (per curiam) ("Administrative agencies are creatures of statute. They accordingly possess only the authority that
The second problem is substantive: What does this language mean? When does an app cross the line between tangentially related to health and more than tangentially related? If a gas station with a loyalty app sells Advil, is the app only tangentially related to health and outside the Final Rule's purview? If the gas station adds Robitussin and pregnancy tests to its inventory, does it cross the line to more than tangentially related to health? If a clothing store with an e-commerce app sells a handful of maternity shirts, is the app only tangentially related to health? If the store adds more maternity clothes, nursing bras, and some anti-nausea ginger tea to its in-app offerings, is the app more than tangentially related to health? If vitamins, over-the-counter medicines, acne creams, bandages, and similar items comprise 0.1% or 1% or 10% of a superstore's inventory, when is the retailer's e-commerce app more than tangentially related to health? I see no clear answers to any of these hypotheticals in today's Final Rule, which suggests that the marketplace will see no clear answers either. /39/
FOOTNOTE 39 The expansive coverage increases the likelihood of creating unintended consequences. Will the gas station decline to add over-the-counter medicines to its inventory to avoid crossing the line of "more than tangentially related to health"? Will the clothing retailer shy away from maternity apparel? Will the e-commerce giant avoid selling bandages and dandruff shampoo? These potentially detrimental outcomes undermine a Rule intended to benefit consumers. END FOOTNOTE
The third problem is procedural. The Commission did not propose this ambiguous but impactful limitation in a Notice of Proposed Rulemaking--likely because there is no statutory basis for this newly-created language. Rather, it introduces this crucial concept for the first time in a Statement of Basis and Purpose (a purely interpretive document) as a post hoc fix to the problem the Commission itself created with its expansive definitions. As a result, the Commission did not provide notice or receive public comment on the efficacy or propriety of this limitation, depriving the public of its opportunity to meaningfully participate in the rulemaking process and depriving itself of potentially valuable input from commenters.
The final problem is that this post hoc, extra-regulatory limitation renders the Commission's burden analysis inadequate. The Paperwork Reduction Act ("PRA") requires the Commission to estimate the reportable breaches by entities covered by the Rule and compliance costs. /40/ The Regulatory Flexibility Act ("RFA") requires the Commission to assess the economic impact on small businesses. /41/ Apparently relying on the SBP's "more than tangentially related to health" limitation, the PRA and RFA analyses only address breaches by apps categorized as "
FOOTNOTE 40 See generally 44 U.S.C. 3501 et seq.; SBP at 86. END FOOTNOTE
FOOTNOTE 41 5 U.S.C. 601 through 612. END FOOTNOTE
FOOTNOTE 42 SBP at 86, 93. END FOOTNOTE
Perhaps the breath of the Final Rule would be more of a theoretical than practical concern to businesses, if they could adopt practices sufficient to avoid any breach that would trigger notice obligations under the Final Rule, or, in the event of a breach, err on the side of notification. But
FOOTNOTE 43 This may have been a sensible requirement in 2009, when the scope of the Rule was much narrower, but it has dramatic consequences in this much-expanded Rule. END FOOTNOTE
FOOTNOTE 44 Significantly, the Majority Statement is silent as to the propriety and consequences of its "tangentially related" limiting principle, likely because this approach is indefensible. END FOOTNOTE
I find the majority's liberties with the statute particularly troubling because they are unnecessary to reach health apps. Indeed, the Commission's own recent enforcement action against digital healthcare platform
FOOTNOTE 45 See Concurring Statement of Commissioner
FOOTNOTE 46 Majority Statement at 5. END FOOTNOTE
The
[FR Doc. 2024-10855 Filed 5-29-24; 8:45 am]
BILLING CODE 6750-01-P


Universal's Insurance Subsidiaries Complete 2024-2025 Reinsurance Program
Aspen Declares Dividends on Preference Shares – Form 6-K
Advisor News
- What advisors must know about accessible client documents
- Your client texted. Now what? The compliance rules advisors better know
- Helping small-business owners build, grow and exit
- Help women break through their retirement roadblocks
- Advisors await SEC decision on Vanguard fair fund distribution
More Advisor NewsAnnuity News
- Wink: Annuity sales post strong Q2, led by MYGAs and structured products
- Legacy Marketing Group partners with Malibu Life USA for annuity launch
- Best’s Market Segment Report: Global Life/Annuity Reinsurers Remained Poised for Steady Growth
- When technology becomes easy to rent, what still separates life and annuity carriers?
- Legacy Marketing Group® and Malibu Life USA Announce Distribution Partnership for New Fixed Indexed Annuity Platform
More Annuity NewsHealth/Employee Benefits News
Life Insurance News