HBNR coordination with adjacent federal + state regimes. HIPAA (45 CFR Parts 160 + 164): the HIPAA Breach Notification Rule (45 CFR Subpart D) covers HIPAA-covered entities + business associates; HBNR fills the gap for non-HIPAA-covered consumer health apps + wearables; HIPAA-covered entities should track when activities may fall outside HIPAA scope (e.g. consumer-facing apps offered alongside healthcare services). 21st CENTURY CURES ACT + INFORMATION BLOCKING RULE (45 CFR Part 171): coordinates with HBNR for healthcare-provider-facing apps + EHI exchange. STATE HEALTH DATA LAWS: (a) WASHINGTON MY HEALTH MY DATA ACT (MHMD, Ch. 19.373 RCW) - 2023 + 2024 + applies to consumer health data including mobile app + wearable + fitness data; covers more than HBNR + with private right of action; (b) CONNECTICUT HEALTH DATA ACT - 2023; (c) NEVADA SB 370 health data privacy law; (d) DELAWARE + NEW JERSEY + MINNESOTA + state-specific health data laws emerging. STATE BREACH NOTIFICATION LAWS: all 50 states + DC + territories have breach notification laws covering personal information including health information (often with specific health-data provisions); state laws may impose shorter timelines + private rights of action + larger penalties + simultaneously with HBNR. FTC ACT SECTION 5 + GENERAL UNFAIR/DECEPTIVE: even where HBNR doesn't apply + FTC Section 5(a) prohibits unfair or deceptive acts or practices + includes breach handling + privacy notice deception. EU GDPR + UK GDPR + Canadian PIPEDA + Australian Privacy Act + others may also apply for cross-border services.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.