Page Content | Main Menu | Section Menu | Support Us | Contact Us
Center for Democracy and Technology
Working for Democratic Values in a Digital Age
Support CDT
Contact Us
PolicyBeta - Digital Policy in Process
This Section

A mixed bag: The FTC’s final health information breach notification rule

August 19th, 2009 by Harley Geiger

Yesterday, the Federal Trade Commission (FTC) released its final rule on health breach notification. The rule sets guidelines for vendors of personal health records (PHRs) on how and when to notify consumers when their health information has been breached.

PHRs are typically Internet-based programs that enable consumers to collect, retain and share their personal health information. A defining characteristic of PHRs is the high level of control consumers exert over information in the PHR. The FTC final rule applies to PHRs that are operated by entities that are not covered by HIPAA, such as Google and Microsoft. Other PHRs are operated by health care providers that are covered under HIPAA laws, like hospitals; the Dept. of Health and Human Services (HHS) is expected issue separate final breach notification rules for these PHRs very soon.

CDT submitted comments to the FTC’s proposed rule in June 09. The FTC’s final rule implements most, although not all, of CDT’s recommendations. Among CDT’s recommendations that the FTC agreed to implement in its final rule:
- The FTC and HHS rules on health data breach notification must be harmonized,
- Privacy and security protections should apply both to data in storage and in transit,
- This rule represents an appropriate expansion of the FTC’s traditional consumer protection authority,
- Breach notices should be issued from the entity with the closest direct relationship to the consumer, and only one notice per breach, and
- Companies’ disclosures regarding how consumers’ information is used must give consumers meaningful choices and not be buried in lengthy privacy policies.

The FTC rule differs from CDT’s recommendations in two important areas, however: how companies determine whether a breach has occurred, and whether de-identified data or limited data sets count as personal health information for which notification must be issued in the event of a breach.

The FTC final rule would require companies to notify consumers if PHR information is acquired without the authorization of the consumer. The FTC also established a presumption of acquisition when the information is accessed without authorization. Companies may rebut that presumption, however, with evidence showing that the information could not “reasonably�? have been acquired, and therefore avoid having to notify consumers about the breach. This would be an internal decision on the part of the company. In CDT’s comments to the proposed rule, we recommended against giving companies such broad discretion to determine whether acquisition took place, arguing that those companies have financial and reputational incentives to avoid notification. Although sensitive to this concern, the FTC decided to leave the rebuttable presumption in the rule without modification.

The FTC’s proposed rule contained an exception to notification requirements for if the data breached was “de-identified�?. Under HIPAA, “de-identified data�? is data stripped of a list of specific identifiers, such as names, birth dates, zip codes, employers, etc. CDT argued against excepting “de-identified data�? due to the risk of re-identification; research shows that a small percentage of the population could be re-identified if “de-identified�? information was combined with other data sets, like voter rolls. This percentage is likely to increase as data analysis tools grow stronger and more information is made publicly available online. The FTC decided against eliminating the exception for “de-identified�? data, but did reject calls to include an exception for “limited data sets�?, which is another HIPAA standard that strips fewer identifiers from the data (and therefore has a much higher risk of re-identification) than “de-identified data�?.

The FTC and HHS will revisit some of these issues, such as company disclosures and consumer authorizations, in less than a year in a study mandated by Congress on privacy and security. CDT will issue reports on the most pressing areas to inform the report in coming months.


This entry was posted on Wednesday, August 19th, 2009 at 5:01 pm and is filed under CDT. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

One Response to “A mixed bag: The FTC’s final health information breach notification rule”

  1. HHS Issues Breach Notification Rule on Heels of FTC Rule « Free Expression Network Says:

    [...] about the FTC rule and CDT’s comments to that rulemaking, please see our previous blog post, here.) CDT recommended that HHS work with the FTC to ensure that Personal Health Records (PHRs) have [...]

Leave a Reply

About the Blog

    PolicyBeta is a forum for CDT experts to discuss news and developments in the technology policy arena. Visitors are encouraged to comment on the blog or email the authors.

    Our goal with PolicyBeta is to foster thoughtful discussion regarding technology policy as it relates to civil liberties and democratic values. While we encourage comments, we must insist that they be focused, relevant and written in a tone that is respectful of other posters. For more information, please feel free to contact PolicyBeta editor Brock Meeks.

    Check the main CDT site for complete, up-to-date information on CDT initiatives and activities.

Search Blog
       Top
Privacy Policy | Feedback