FTC Health Breach Notification Rule
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
HBNR: 2024 Amendments - Mobile Apps, Connected Devices, Reproductive Health and Cross-App Tracking
FTC HBNR 2024 Final Rule Amendments (effective 29 July 2024 + 25 April 2025 for delayed elements). KEY EXPANSIONS: (1) MOBILE HEALTH APPS + CONNECTED DEVICES: explicit coverage of consumer-facing health apps + wearables + fitness trackers + sleep monitors + smart scales + connected medical devices even if not marketed as PHR; (2) NEW BREACH DEFINITION: explicitly includes UNAUTHORIZED DISCLOSURE to (a) ADVERTISING/MARKETING networks; (b) 3rd-party SDKs (e.g. Meta Pixel + Google Tag Manager + analytics SDKs) collecting health information without user authorization; (c) DATA BROKERS; (d) CROSS-APP TRACKING of health information; (e) RE-IDENTIFICATION of supposedly de-identified data; (3) REPRODUCTIVE HEALTH DATA: heightened sensitivity + alignment with post-Dobbs (June 2022) state-law abortion-restriction concerns + data subpoena risks; period-tracker + fertility apps + pregnancy apps + re
- Mobile app + connected device inventory
- Marketing-network/SDK audit
- Reproductive-health data classification
- Re-identification + cross-app risk assessment
- Mobile app coverage gap
- Marketing/SDK disclosure unaudited
- Reproductive-health data not classified
- Re-identification risk not assessed
HBNR: Breach Notification to Individuals (16 CFR 318.3, 318.4, 318.5) - 60-Day Timeline + Content + Method
16 CFR 318.3 + 318.4 + 318.5. INDIVIDUAL NOTIFICATION REQUIREMENT (318.3(a)): PHR vendor or PHR-related entity must notify each affected individual WITHOUT UNREASONABLE DELAY + IN NO CASE LATER THAN 60 CALENDAR DAYS after the date of DISCOVERY of the breach. DISCOVERY (318.4): a breach is treated as discovered as of the date the entity FIRST KNEW or REASONABLY SHOULD HAVE KNOWN of the breach; entities must conduct REASONABLE DILIGENCE in detecting + investigating; KNOWLEDGE imputed across the organization (any employee + agent + contractor with knowledge). METHOD OF INDIVIDUAL NOTICE (318.5(a)): (1) WRITTEN NOTICE via first-class mail to last known address + or EMAIL if affirmatively consented; (2) NEXT-OF-KIN notice if individual is deceased or cannot be reasonably contacted; (3) SUBSTITUTE NOTICE if insufficient contact information OR more than 10 affected persons - via prominent websi
- Notice procedure + 60-day SLA tracking
- Notification method options
- Notice template + content adequacy review
- 60-day SLA missed
- Method limited or inappropriate
- Content incomplete or technical
- No multi-language consideration
HBNR: Definitions (16 CFR 318.2) - PHR, Identifiable Health Information, Breach, Healthcare Provider
16 CFR 318.2 definitions. PERSONAL HEALTH RECORD (PHR): an electronic record of PHR IDENTIFIABLE HEALTH INFORMATION on an individual that can be drawn from MULTIPLE SOURCES + is managed + shared + controlled by or primarily for the individual. PHR IDENTIFIABLE HEALTH INFORMATION: information identifying an individual + relating to the past + present + or future physical or mental health condition, the provision of healthcare, or payment for the provision of healthcare (the 2024 amendments expanded this definition to clarify mobile-app + connected-device + sensor data). BREACH OF SECURITY: acquisition of unsecured PHR identifiable health information without authorization of the individual; the 2024 amendments EXPLICITLY INCLUDE: (a) UNAUTHORIZED DISCLOSURE to advertising + marketing + analytics networks + 3rd-party SDKs + data brokers; (b) RE-IDENTIFICATION OR LINKAGE of data that the ent
- Definition mapping document
- Encryption + destruction standards adoption (NIST 800-111/52/88)
- Marketing/SDK disclosure log
- Definitions not updated post-2024
- Marketing/SDK disclosures unaddressed
- Encryption + destruction substandard
HBNR: Enforcement, Coordination with HIPAA / State Laws and 2024-2025 Status
HBNR coordination with adjacent federal + state regimes. HIPAA (45 CFR Parts 160 + 164): the HIPAA Breach Notification Rule (45 CFR Subpart D) covers HIPAA-covered entities + business associates; HBNR fills the gap for non-HIPAA-covered consumer health apps + wearables; HIPAA-covered entities should track when activities may fall outside HIPAA scope (e.g. consumer-facing apps offered alongside healthcare services). 21st CENTURY CURES ACT + INFORMATION BLOCKING RULE (45 CFR Part 171): coordinates with HBNR for healthcare-provider-facing apps + EHI exchange. STATE HEALTH DATA LAWS: (a) WASHINGTON MY HEALTH MY DATA ACT (MHMD, Ch. 19.373 RCW) - 2023 + 2024 + applies to consumer health data including mobile app + wearable + fitness data; covers more than HBNR + with private right of action; (b) CONNECTICUT HEALTH DATA ACT - 2023; (c) NEVADA SB 370 health data privacy law; (d) DELAWARE + NEW J
- Multi-regime compliance map
- State health data law inventory + applicability
- FTC Section 5 exposure assessment
- HIPAA + HBNR overlap unclear
- State health data laws not tracked
- FTC Section 5 risk not addressed
- Cross-border privacy regimes overlooked
HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encryption per NIST 800-111/52 + access controls + DLP) + DETECT (monitoring + alerting + 60-day discovery clock + SDK audit) + RESPOND (60-day individual notification + 10-day FTC + media + TPSP coordination) + RECOVER (records + lessons learned + annual log). NIST SP 800-66 IMPLEMENTING THE HIPAA SECURITY RULE: companion guidance for healthcare-related security practices - applicable to HBNR even though HBNR is not HIPAA - via best-practice safeguards. ISO/IEC 27001:2022 + ISO/IEC 27701:2019: ISMS + PIMS structure for HBNR program implementation. ISO/IEC 27799:2016: Health Informatics Information Security Management (sector-specific e
- NIST CSF + 800-66 crosswalk
- ISO 27001/27701/27799 implementation
- SOC 2 reports for TPSPs
- HIPAA-voluntary alignment evidence
- Crosswalk not maintained
- Multi-framework alignment gaps
- SOC 2 reports stale for TPSPs
16 CFR 318.7-318.9 enforcement + coordination + status. ENFORCEMENT AUTHORITY (318.7): the FTC enforces the HBNR + may impose civil penalties up to USD 51,744 PER VIOLATION (2025 figure - adjusted annually for inflation per the Federal Civil Penalties Inflation Adjustment Act); each affected individual + each day of continuing violation can be a separate violation. NO PRIVATE RIGHT OF ACTION: HBNR does not create a private right of action + but consumers may file complaints with the FTC + state attorneys general + or state consumer protection authorities. HIPAA COORDINATION (318.8): entities subject to HIPAA Breach Notification Rule (45 CFR Subpart D) are NOT subject to HBNR; entities may be SUBJECT TO BOTH if they operate both HIPAA-covered + non-HIPAA-covered activities (e.g. a healthcare provider also offering consumer-facing health app); HIPAA notification preempts HBNR notification
- Compliance program + penalty risk assessment
- HIPAA cross-reference + dual-regime policy
- State law inventory + most-stringent compliance
- Effective date readiness
- FTC penalty risk underestimated
- HIPAA dual coverage misclassified
- State law overlap not addressed
- 2024 effective date missed
HBNR compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL or CHIEF PRIVACY OFFICER - HBNR + state-law + HIPAA + GDPR + multi-regime coordination; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - encryption + access controls + monitoring + detection; (c) INCIDENT RESPONSE LEAD - 60-day clock + FTC 10-day SLA + media notification coordination; (d) RECORDS MANAGER - documentation + retention + annual log preparation; (e) THIRD-PARTY MANAGER - TPSP contracts + due diligence + breach notification chains; (f) PR + COMMUNICATIONS - media notification + crisis communications. OPERATIONAL CONTROLS: (a) DETECTION + MONITORING - SIEM + DLP + endpoint monitoring + app instrumentation; (b) DUE DILIGENCE on 3rd-party SDKs + advertising-network integrations + cross-app tracking - regular audit + opt-out + consent management; (c) ENCRYPTION at rest + in transit per NIST 80
- Role inventory + RACI
- Detection + monitoring stack + SDK audit reports
- Notification template + infrastructure tests
- TPSP playbook + drill records
- Roles undefined
- Detection gaps
- Notification infrastructure untested
- TPSP coordination ad-hoc
HBNR 2024-2025 implementation status + FTC enforcement cases. STATUS: 2024 Final Rule effective 29 July 2024 + 25 April 2025 for delayed elements; FTC has published enforcement priorities + sample guidance + the FTC Health Breach Notification online form. RECENT FTC ENFORCEMENT (2022-2025 - cases under both HBNR + FTC Section 5(a)): GoodRx (USD 1.5M civil penalty + USD 0M consumer remediation 2023 - advertising-pixel + Facebook + Google + Snapchat + Pinterest health data disclosure); BetterHelp (USD 7.8M consumer remediation 2023 - mental health data disclosure to advertising networks); Premom (USD 100K civil penalty 2023 - fertility-app data sharing); Easy Healthcare (Premom parent + USD 200K 2024 - reproductive-health-data); 1Health (USD 5K + 23andMe-related practices); other cases involving Meta Pixel + Google Tag Manager use on healthcare websites. ANTICIPATED 2025-2026 ENFORCEMENT:
- 2024 Final Rule implementation evidence
- Case-law tracking + lessons learned
- Anticipated-area readiness + risk assessment
- Advertising-pixel + SDK inventory + audit
- 2024 Final Rule implementation incomplete
- Enforcement-case lessons not adopted
- Anticipated-area readiness gap
- Advertising-pixel + SDK audit absent
HBNR: FTC and Media Notification (16 CFR 318.5(c) + 318.6) - 500+ Threshold and Annual Log
16 CFR 318.5(c) FTC notification + 318.6 media notification. FTC NOTIFICATION (318.5(c)): for breaches affecting 500 OR MORE INDIVIDUALS, the entity must notify the FTC IMMEDIATELY + IN NO EVENT LATER THAN 10 BUSINESS DAYS after discovery using the FTC's online notification form at https://www.ftc.gov/health-breach-notification; the notification must include the entity name + contact information + a brief description + dates of breach + dates of discovery + types of information involved + number of individuals affected + steps the entity has taken. ANNUAL LOG (318.5(c)(2)): for breaches affecting FEWER THAN 500 INDIVIDUALS, the entity may keep an annual log + submit the log to the FTC within 60 calendar days following the end of each calendar year (typically by 1 March). MEDIA NOTIFICATION (318.6): for breaches affecting 500 OR MORE INDIVIDUALS IN A STATE OR JURISDICTION + the entity mus
- FTC online form submission procedure
- Annual log template + Q1 submission
- Media notification procedure
- Combined notification timing
- FTC 10-day SLA missed
- Annual log not maintained
- Media notification skipped
- Notifications out of sync
HBNR: Scope and Applicability (16 CFR 318.1, 318.2) - PHR Vendors and PHR-Related Entities
16 CFR 318.1 purpose + scope. APPLICABILITY: applies to (1) VENDORS OF PERSONAL HEALTH RECORDS (PHR) - entities offering PHR product or service to consumers + that obtain consumer health information from other sources (e.g. cross-source aggregation); (2) PHR-RELATED ENTITIES - entities offering products + services through a PHR vendor or that interact with a PHR vendor + that obtain consumer health information; (3) THIRD-PARTY SERVICE PROVIDERS to PHR vendors or PHR-related entities (with limited obligations); (4) post-2024 AMENDMENTS expanded to MOBILE HEALTH APPS + CONNECTED DEVICES even if not marketed as PHR. EXCLUSIONS: (a) HIPAA-COVERED ENTITIES (health plans + healthcare clearinghouses + healthcare providers conducting standard transactions electronically + business associates) - these are covered by the HIPAA Breach Notification Rule (45 CFR Subpart D); (b) BUSINESS ASSOCIATES of
- Applicability assessment + entity-type determination
- HIPAA cross-reference + non-overlap analysis
- TPSP designation + agreements
- Misclassified as HIPAA covered (gap)
- TPSP obligations missed
- Mobile health app excluded from scope when amendments require coverage
HBNR: Third-Party Service Provider Obligations (16 CFR 318.3(b))
16 CFR 318.3(b) third-party service provider (TPSP) obligations. THIRD-PARTY SERVICE PROVIDER (TPSP): any entity that provides services to or processes data on behalf of a PHR vendor or PHR-related entity + including cloud providers + analytics providers + marketing platforms + SDK providers + data processors. TPSP NOTIFICATION DUTY: if a TPSP becomes aware of a breach of security of unsecured PHR identifiable health information that the TPSP holds + maintains + or otherwise has access to, the TPSP must notify the PHR vendor or PHR-related entity it serves WITHOUT UNREASONABLE DELAY + NO LATER THAN 60 CALENDAR DAYS after discovery. NOTIFICATION CONTENT: must include identification of each individual whose unsecured PHR identifiable health information was acquired during the breach. IMPLICATIONS: TPSPs must (a) have a documented incident response procedure with PHR-vendor + PHR-related-en
- TPSP IR procedure + customer notification
- Upstream contract clauses
- Coordination playbook
- TPSP IR procedure missing
- Upstream notification untimely or inadequate
- Contract clauses absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.