HIPAA Or Not, Health Apps Must Provide Breach Notification

Fox Rothschild LLP
Contact

Fox Rothschild LLP

The Federal Trade Commission seems to be getting serious about unauthorized disclosures of data collected by health apps.  In a Policy Statement issued on September 15, 2021, the FTC says it will enforce its Health Breach Notification Rule, 16 C.F.R. Part 318 (the “Rule”):

This Policy Statement serves to clarify the scope of the Rule, and place entities on notice of their ongoing obligation to come clean about breaches.

This past January, I wrote about the FTC’s failure to require Flo Health to provide individuals with notice as required by the Rule:

Flo Health failed to notify its millions of female users that it allowed their personal and uniquely sensitive health information to be used by third parties, including Google and Facebook, for their own purposes, including advertising.

The FTC’s Policy Statement clarifies that health app developers are subject to the Rule if they are capable of drawing information from various sources, such as consumer inputs and application programming interfaces (APIs), even the health information only comes from one source.  By way of example, a consumer who inputs her glucose levels or other health-related information into an app that combines that information with non-health-related information retrieved from another source, the Rule applies.

The bottom line is that app developers that collect any health-related data, even if voluntarily and knowingly disclosed by the consumer, need to be alert to the likely applicability of the Rule and FTC’s recent enforcement stance.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide