FTC Issues Final Version of Revised Health Breach Notification Rule

The Federal Trade Commission (FTC) announced a final rule on April 26, 2024 that updates its Health Breach Notification Rule (HBNR). Importantly for advertisers, per the rule, the FTC considers a breach to include a covered entity’s unauthorized disclosure of personal health records to third party advertising networks and technology platforms like Facebook and Google for targeted advertising. Per HBNR, covered entities are required to notify individuals in the event of a breach of unsecured personally identifiable health data. In the event of a breach of covered data at a third party that provides services to vendors of PHRs or PHR-related entities, agencies are required to notify the PHR vendor or PHR-related entity in the event of a breach

...

Login to access member-exclusive content

Not a 4As member yet? Don't miss out. Learn more about joining a growing community of 600+ forward-thinking member agencies.

Join