Skip to content

Evidence request lists

FTC Health Breach Notification Rule

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

HBNR: 2024 Amendments - Mobile Apps, Connected Devices, Reproductive Health and Cross-App Tracking

HBNR-2024-Amendments-Mobile-Apps-Repro
2024 Amendments - Mobile Apps, Connected Devices, Reproductive Health and Cross-App Tracking

FTC HBNR 2024 Final Rule Amendments (effective 29 July 2024 + 25 April 2025 for delayed elements). KEY EXPANSIONS: (1) MOBILE HEALTH APPS + CONNECTED DEVICES: explicit coverage of consumer-facing health apps + wearables + fitness trackers + sleep monitors + smart scales + connected medical devices even if not marketed as PHR; (2) NEW BREACH DEFINITION: explicitly includes UNAUTHORIZED DISCLOSURE to (a) ADVERTISING/MARKETING networks; (b) 3rd-party SDKs (e.g. Meta Pixel + Google Tag Manager + analytics SDKs) collecting health information without user authorization; (c) DATA BROKERS; (d) CROSS-APP TRACKING of health information; (e) RE-IDENTIFICATION of supposedly de-identified data; (3) REPRODUCTIVE HEALTH DATA: heightened sensitivity + alignment with post-Dobbs (June 2022) state-law abortion-restriction concerns + data subpoena risks; period-tracker + fertility apps + pregnancy apps + re

Artefacts an auditor will ask for
  • Mobile app + connected device inventory
  • Marketing-network/SDK audit
  • Reproductive-health data classification
  • Re-identification + cross-app risk assessment
Where this commonly fails
  • Mobile app coverage gap
  • Marketing/SDK disclosure unaudited
  • Reproductive-health data not classified
  • Re-identification risk not assessed

HBNR: Breach Notification to Individuals (16 CFR 318.3, 318.4, 318.5) - 60-Day Timeline + Content + Method

HBNR-IndividualNotice-60Day
Notice to Individuals - 60-Day Discovery Clock + Content + Method (16 CFR 318.3, 318.4, 318.5)

16 CFR 318.3 + 318.4 + 318.5. INDIVIDUAL NOTIFICATION REQUIREMENT (318.3(a)): PHR vendor or PHR-related entity must notify each affected individual WITHOUT UNREASONABLE DELAY + IN NO CASE LATER THAN 60 CALENDAR DAYS after the date of DISCOVERY of the breach. DISCOVERY (318.4): a breach is treated as discovered as of the date the entity FIRST KNEW or REASONABLY SHOULD HAVE KNOWN of the breach; entities must conduct REASONABLE DILIGENCE in detecting + investigating; KNOWLEDGE imputed across the organization (any employee + agent + contractor with knowledge). METHOD OF INDIVIDUAL NOTICE (318.5(a)): (1) WRITTEN NOTICE via first-class mail to last known address + or EMAIL if affirmatively consented; (2) NEXT-OF-KIN notice if individual is deceased or cannot be reasonably contacted; (3) SUBSTITUTE NOTICE if insufficient contact information OR more than 10 affected persons - via prominent websi

Artefacts an auditor will ask for
  • Notice procedure + 60-day SLA tracking
  • Notification method options
  • Notice template + content adequacy review
Where this commonly fails
  • 60-day SLA missed
  • Method limited or inappropriate
  • Content incomplete or technical
  • No multi-language consideration

HBNR: Definitions (16 CFR 318.2) - PHR, Identifiable Health Information, Breach, Healthcare Provider

HBNR-Definitions-PHR-Identifiable-Breach
Definitions - PHR, Identifiable Health Information, Breach of Security, Healthcare Provider (16 CFR 318.2)

16 CFR 318.2 definitions. PERSONAL HEALTH RECORD (PHR): an electronic record of PHR IDENTIFIABLE HEALTH INFORMATION on an individual that can be drawn from MULTIPLE SOURCES + is managed + shared + controlled by or primarily for the individual. PHR IDENTIFIABLE HEALTH INFORMATION: information identifying an individual + relating to the past + present + or future physical or mental health condition, the provision of healthcare, or payment for the provision of healthcare (the 2024 amendments expanded this definition to clarify mobile-app + connected-device + sensor data). BREACH OF SECURITY: acquisition of unsecured PHR identifiable health information without authorization of the individual; the 2024 amendments EXPLICITLY INCLUDE: (a) UNAUTHORIZED DISCLOSURE to advertising + marketing + analytics networks + 3rd-party SDKs + data brokers; (b) RE-IDENTIFICATION OR LINKAGE of data that the ent

Artefacts an auditor will ask for
  • Definition mapping document
  • Encryption + destruction standards adoption (NIST 800-111/52/88)
  • Marketing/SDK disclosure log
Where this commonly fails
  • Definitions not updated post-2024
  • Marketing/SDK disclosures unaddressed
  • Encryption + destruction substandard

HBNR: Enforcement, Coordination with HIPAA / State Laws and 2024-2025 Status

HBNR-Coord-HIPAA-State-MHMD-Sectoral
Coordination with HIPAA, State My Health My Data Acts and Other Sectoral Federal Laws

HBNR coordination with adjacent federal + state regimes. HIPAA (45 CFR Parts 160 + 164): the HIPAA Breach Notification Rule (45 CFR Subpart D) covers HIPAA-covered entities + business associates; HBNR fills the gap for non-HIPAA-covered consumer health apps + wearables; HIPAA-covered entities should track when activities may fall outside HIPAA scope (e.g. consumer-facing apps offered alongside healthcare services). 21st CENTURY CURES ACT + INFORMATION BLOCKING RULE (45 CFR Part 171): coordinates with HBNR for healthcare-provider-facing apps + EHI exchange. STATE HEALTH DATA LAWS: (a) WASHINGTON MY HEALTH MY DATA ACT (MHMD, Ch. 19.373 RCW) - 2023 + 2024 + applies to consumer health data including mobile app + wearable + fitness data; covers more than HBNR + with private right of action; (b) CONNECTICUT HEALTH DATA ACT - 2023; (c) NEVADA SB 370 health data privacy law; (d) DELAWARE + NEW J

Artefacts an auditor will ask for
  • Multi-regime compliance map
  • State health data law inventory + applicability
  • FTC Section 5 exposure assessment
Where this commonly fails
  • HIPAA + HBNR overlap unclear
  • State health data laws not tracked
  • FTC Section 5 risk not addressed
  • Cross-border privacy regimes overlooked
HBNR-Crosswalk-NIST-CSF-ISO-HIPAA
Crosswalk to NIST CSF 2.0, NIST 800-66, ISO 27001/27701, SOC 2 and HIPAA

HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encryption per NIST 800-111/52 + access controls + DLP) + DETECT (monitoring + alerting + 60-day discovery clock + SDK audit) + RESPOND (60-day individual notification + 10-day FTC + media + TPSP coordination) + RECOVER (records + lessons learned + annual log). NIST SP 800-66 IMPLEMENTING THE HIPAA SECURITY RULE: companion guidance for healthcare-related security practices - applicable to HBNR even though HBNR is not HIPAA - via best-practice safeguards. ISO/IEC 27001:2022 + ISO/IEC 27701:2019: ISMS + PIMS structure for HBNR program implementation. ISO/IEC 27799:2016: Health Informatics Information Security Management (sector-specific e

Artefacts an auditor will ask for
  • NIST CSF + 800-66 crosswalk
  • ISO 27001/27701/27799 implementation
  • SOC 2 reports for TPSPs
  • HIPAA-voluntary alignment evidence
Where this commonly fails
  • Crosswalk not maintained
  • Multi-framework alignment gaps
  • SOC 2 reports stale for TPSPs
HBNR-Enforcement-HIPAA-StateLaw-Status
Enforcement, Civil Penalties, HIPAA Coordination + State Law + Status (16 CFR 318.7, 318.8, 318.9)

16 CFR 318.7-318.9 enforcement + coordination + status. ENFORCEMENT AUTHORITY (318.7): the FTC enforces the HBNR + may impose civil penalties up to USD 51,744 PER VIOLATION (2025 figure - adjusted annually for inflation per the Federal Civil Penalties Inflation Adjustment Act); each affected individual + each day of continuing violation can be a separate violation. NO PRIVATE RIGHT OF ACTION: HBNR does not create a private right of action + but consumers may file complaints with the FTC + state attorneys general + or state consumer protection authorities. HIPAA COORDINATION (318.8): entities subject to HIPAA Breach Notification Rule (45 CFR Subpart D) are NOT subject to HBNR; entities may be SUBJECT TO BOTH if they operate both HIPAA-covered + non-HIPAA-covered activities (e.g. a healthcare provider also offering consumer-facing health app); HIPAA notification preempts HBNR notification

Artefacts an auditor will ask for
  • Compliance program + penalty risk assessment
  • HIPAA cross-reference + dual-regime policy
  • State law inventory + most-stringent compliance
  • Effective date readiness
Where this commonly fails
  • FTC penalty risk underestimated
  • HIPAA dual coverage misclassified
  • State law overlap not addressed
  • 2024 effective date missed
HBNR-Implementation-Roadmap-Org
HBNR Compliance Program Implementation - Organizational Roles, Detection, Incident Response, Records

HBNR compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL or CHIEF PRIVACY OFFICER - HBNR + state-law + HIPAA + GDPR + multi-regime coordination; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - encryption + access controls + monitoring + detection; (c) INCIDENT RESPONSE LEAD - 60-day clock + FTC 10-day SLA + media notification coordination; (d) RECORDS MANAGER - documentation + retention + annual log preparation; (e) THIRD-PARTY MANAGER - TPSP contracts + due diligence + breach notification chains; (f) PR + COMMUNICATIONS - media notification + crisis communications. OPERATIONAL CONTROLS: (a) DETECTION + MONITORING - SIEM + DLP + endpoint monitoring + app instrumentation; (b) DUE DILIGENCE on 3rd-party SDKs + advertising-network integrations + cross-app tracking - regular audit + opt-out + consent management; (c) ENCRYPTION at rest + in transit per NIST 80

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Detection + monitoring stack + SDK audit reports
  • Notification template + infrastructure tests
  • TPSP playbook + drill records
Where this commonly fails
  • Roles undefined
  • Detection gaps
  • Notification infrastructure untested
  • TPSP coordination ad-hoc
HBNR-Status-2024-2025-Enforcement-Cases
HBNR Implementation Status, 2024-2025 FTC Enforcement Cases and Anticipated Amendments

HBNR 2024-2025 implementation status + FTC enforcement cases. STATUS: 2024 Final Rule effective 29 July 2024 + 25 April 2025 for delayed elements; FTC has published enforcement priorities + sample guidance + the FTC Health Breach Notification online form. RECENT FTC ENFORCEMENT (2022-2025 - cases under both HBNR + FTC Section 5(a)): GoodRx (USD 1.5M civil penalty + USD 0M consumer remediation 2023 - advertising-pixel + Facebook + Google + Snapchat + Pinterest health data disclosure); BetterHelp (USD 7.8M consumer remediation 2023 - mental health data disclosure to advertising networks); Premom (USD 100K civil penalty 2023 - fertility-app data sharing); Easy Healthcare (Premom parent + USD 200K 2024 - reproductive-health-data); 1Health (USD 5K + 23andMe-related practices); other cases involving Meta Pixel + Google Tag Manager use on healthcare websites. ANTICIPATED 2025-2026 ENFORCEMENT:

Artefacts an auditor will ask for
  • 2024 Final Rule implementation evidence
  • Case-law tracking + lessons learned
  • Anticipated-area readiness + risk assessment
  • Advertising-pixel + SDK inventory + audit
Where this commonly fails
  • 2024 Final Rule implementation incomplete
  • Enforcement-case lessons not adopted
  • Anticipated-area readiness gap
  • Advertising-pixel + SDK audit absent

HBNR: FTC and Media Notification (16 CFR 318.5(c) + 318.6) - 500+ Threshold and Annual Log

HBNR-FTC-Media-Notice-500Threshold
FTC + Media Notification - 500+ Individual Threshold (16 CFR 318.5(c), 318.6)

16 CFR 318.5(c) FTC notification + 318.6 media notification. FTC NOTIFICATION (318.5(c)): for breaches affecting 500 OR MORE INDIVIDUALS, the entity must notify the FTC IMMEDIATELY + IN NO EVENT LATER THAN 10 BUSINESS DAYS after discovery using the FTC's online notification form at https://www.ftc.gov/health-breach-notification; the notification must include the entity name + contact information + a brief description + dates of breach + dates of discovery + types of information involved + number of individuals affected + steps the entity has taken. ANNUAL LOG (318.5(c)(2)): for breaches affecting FEWER THAN 500 INDIVIDUALS, the entity may keep an annual log + submit the log to the FTC within 60 calendar days following the end of each calendar year (typically by 1 March). MEDIA NOTIFICATION (318.6): for breaches affecting 500 OR MORE INDIVIDUALS IN A STATE OR JURISDICTION + the entity mus

Artefacts an auditor will ask for
  • FTC online form submission procedure
  • Annual log template + Q1 submission
  • Media notification procedure
  • Combined notification timing
Where this commonly fails
  • FTC 10-day SLA missed
  • Annual log not maintained
  • Media notification skipped
  • Notifications out of sync

HBNR: Scope and Applicability (16 CFR 318.1, 318.2) - PHR Vendors and PHR-Related Entities

HBNR-Scope-PHR-Vendor
Scope, PHR Vendor and PHR-Related Entity Applicability (16 CFR 318.1)

16 CFR 318.1 purpose + scope. APPLICABILITY: applies to (1) VENDORS OF PERSONAL HEALTH RECORDS (PHR) - entities offering PHR product or service to consumers + that obtain consumer health information from other sources (e.g. cross-source aggregation); (2) PHR-RELATED ENTITIES - entities offering products + services through a PHR vendor or that interact with a PHR vendor + that obtain consumer health information; (3) THIRD-PARTY SERVICE PROVIDERS to PHR vendors or PHR-related entities (with limited obligations); (4) post-2024 AMENDMENTS expanded to MOBILE HEALTH APPS + CONNECTED DEVICES even if not marketed as PHR. EXCLUSIONS: (a) HIPAA-COVERED ENTITIES (health plans + healthcare clearinghouses + healthcare providers conducting standard transactions electronically + business associates) - these are covered by the HIPAA Breach Notification Rule (45 CFR Subpart D); (b) BUSINESS ASSOCIATES of

Artefacts an auditor will ask for
  • Applicability assessment + entity-type determination
  • HIPAA cross-reference + non-overlap analysis
  • TPSP designation + agreements
Where this commonly fails
  • Misclassified as HIPAA covered (gap)
  • TPSP obligations missed
  • Mobile health app excluded from scope when amendments require coverage

HBNR: Third-Party Service Provider Obligations (16 CFR 318.3(b))

HBNR-TPSP-Upstream-Notification
Third-Party Service Provider Obligations - Upstream Notification (16 CFR 318.3(b))

16 CFR 318.3(b) third-party service provider (TPSP) obligations. THIRD-PARTY SERVICE PROVIDER (TPSP): any entity that provides services to or processes data on behalf of a PHR vendor or PHR-related entity + including cloud providers + analytics providers + marketing platforms + SDK providers + data processors. TPSP NOTIFICATION DUTY: if a TPSP becomes aware of a breach of security of unsecured PHR identifiable health information that the TPSP holds + maintains + or otherwise has access to, the TPSP must notify the PHR vendor or PHR-related entity it serves WITHOUT UNREASONABLE DELAY + NO LATER THAN 60 CALENDAR DAYS after discovery. NOTIFICATION CONTENT: must include identification of each individual whose unsecured PHR identifiable health information was acquired during the breach. IMPLICATIONS: TPSPs must (a) have a documented incident response procedure with PHR-vendor + PHR-related-en

Artefacts an auditor will ask for
  • TPSP IR procedure + customer notification
  • Upstream contract clauses
  • Coordination playbook
Where this commonly fails
  • TPSP IR procedure missing
  • Upstream notification untimely or inadequate
  • Contract clauses absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.