FTC Health Breach Notification Rule
HBNR: Scope and Applicability (16 CFR 318.1, 318.2) - PHR Vendors and PHR-Related Entities

FTC Health Breach Notification Rule HBNR-Scope-PHR-Vendor: Scope, PHR Vendor and PHR-Related Entity Applicability (16 CFR 318.1)

16 CFR 318.1 purpose + scope. APPLICABILITY: applies to (1) VENDORS OF PERSONAL HEALTH RECORDS (PHR) - entities offering PHR product or service to consumers + that obtain consumer health information from other sources (e.g. cross-source aggregation); (2) PHR-RELATED ENTITIES - entities offering products + services through a PHR vendor or that interact with a PHR vendor + that obtain consumer health information; (3) THIRD-PARTY SERVICE PROVIDERS to PHR vendors or PHR-related entities (with limited obligations); (4) post-2024 AMENDMENTS expanded to MOBILE HEALTH APPS + CONNECTED DEVICES even if not marketed as PHR. EXCLUSIONS: (a) HIPAA-COVERED ENTITIES (health plans + healthcare clearinghouses + healthcare providers conducting standard transactions electronically + business associates) - these are covered by the HIPAA Breach Notification Rule (45 CFR Subpart D); (b) BUSINESS ASSOCIATES of HIPAA-covered entities (similarly covered by HIPAA); (c) information NOT identifiable per the rule definitions. JURISDICTIONAL EFFECT: applies to entities collecting + processing health information from US consumers + including foreign entities subject to FTC jurisdiction.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.