FTC Health Breach Notification Rule
HBNR: Definitions (16 CFR 318.2) - PHR, Identifiable Health Information, Breach, Healthcare Provider

FTC Health Breach Notification Rule HBNR-Definitions-PHR-Identifiable-Breach: Definitions - PHR, Identifiable Health Information, Breach of Security, Healthcare Provider (16 CFR 318.2)

16 CFR 318.2 definitions. PERSONAL HEALTH RECORD (PHR): an electronic record of PHR IDENTIFIABLE HEALTH INFORMATION on an individual that can be drawn from MULTIPLE SOURCES + is managed + shared + controlled by or primarily for the individual. PHR IDENTIFIABLE HEALTH INFORMATION: information identifying an individual + relating to the past + present + or future physical or mental health condition, the provision of healthcare, or payment for the provision of healthcare (the 2024 amendments expanded this definition to clarify mobile-app + connected-device + sensor data). BREACH OF SECURITY: acquisition of unsecured PHR identifiable health information without authorization of the individual; the 2024 amendments EXPLICITLY INCLUDE: (a) UNAUTHORIZED DISCLOSURE to advertising + marketing + analytics networks + 3rd-party SDKs + data brokers; (b) RE-IDENTIFICATION OR LINKAGE of data that the entity treated as de-identified but is in fact re-identifiable; (c) CROSS-APP TRACKING of health information; (d) REPRODUCTIVE-HEALTH DATA scenarios where state laws have changed (post-Dobbs era). HEALTHCARE PROVIDER (2024 NEW DEFINITION): a HIPAA-defined healthcare provider OR any person furnishing healthcare services or supplies + or any person obtaining authorization payment for healthcare services + or any person furnishing supplies; the expanded definition aligns with FTC enforcement priorities. UNSECURED PHR IDENTIFIABLE HEALTH INFORMATION: information not rendered unusable + unreadable + or undecipherable to unauthorized persons through encryption (NIST SP 800-111 + 800-52) or destruction (NIST SP 800-88).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.