FTC Health Breach Notification Rule
HBNR: Third-Party Service Provider Obligations (16 CFR 318.3(b))

FTC Health Breach Notification Rule HBNR-TPSP-Upstream-Notification: Third-Party Service Provider Obligations - Upstream Notification (16 CFR 318.3(b))

16 CFR 318.3(b) third-party service provider (TPSP) obligations. THIRD-PARTY SERVICE PROVIDER (TPSP): any entity that provides services to or processes data on behalf of a PHR vendor or PHR-related entity + including cloud providers + analytics providers + marketing platforms + SDK providers + data processors. TPSP NOTIFICATION DUTY: if a TPSP becomes aware of a breach of security of unsecured PHR identifiable health information that the TPSP holds + maintains + or otherwise has access to, the TPSP must notify the PHR vendor or PHR-related entity it serves WITHOUT UNREASONABLE DELAY + NO LATER THAN 60 CALENDAR DAYS after discovery. NOTIFICATION CONTENT: must include identification of each individual whose unsecured PHR identifiable health information was acquired during the breach. IMPLICATIONS: TPSPs must (a) have a documented incident response procedure with PHR-vendor + PHR-related-entity-customer notification; (b) maintain contracts requiring such notification flowing both ways; (c) coordinate with the PHR vendor to determine downstream notification to individuals + FTC + media; (d) provide reasonable assistance to the PHR vendor including evidence + interview availability + remediation cooperation. CONTRACTUAL: PHR vendor + PHR-related-entity contracts with TPSPs must require this notification + with adequate detail + timeline + cooperation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.