FTC Health Breach Notification Rule
The FTC Health Breach Notification Rule (16 CFR Part 318) requires vendors of personal health records (PHR) and PHR-related entities to notify individuals, the FTC, and in some cases the media following a breach of unsecured personally identifiable health information. Updated in 2024 to clarify applicability to health apps, wearables, and other digital health technologies not covered by HIPAA.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Compliance and Enforcement
SEC compliance and enforcement actions
| Code | Title |
|---|---|
| BOSE-8 | Terms of Service Enforcement |
| BOSE-9 | Civil Penalties for Non-Reporting |
| CA-AODA-CE-01 | Accessibility Compliance Report |
| CA-AODA-CE-02 | Accessibility Policy and Plan |
| CA-AODA-CE-03 | Enforcement |
| CDR-13 | ACCC Enforcement |
| CDR-14 | OAIC Privacy Enforcement |
| DMA-ART11 | Compliance Reporting |
| DMA-ART13 | Anti-Circumvention |
| DMA-ART14 | Obligation to Inform About Concentrations |
| DMA-ART15 | Profiling Audit |
| DMA-ART8 | Compliance Measures |
| EAR-COMP-01 | Export Compliance Programme |
| EAR-COMP-02 | Screening Requirements |
| EAR-COMP-03 | Enforcement and Penalties |
| EU-EAA-CE-01 | Conformity Assessment |
| EU-EAA-CE-02 | Market Surveillance |
| EU-EAA-CE-03 | Consumer Complaints and Enforcement |
| EU-NIS2-EN-CE-01 | Supervisory Framework |
| EU-NIS2-EN-CE-02 | Supply Chain and SBOM |
| EU-NIS2-EN-CE-03 | Penalties |
| EUDR-CE-01 | Due Diligence Statements |
| EUDR-CE-02 | Country Benchmarking |
| EUDR-CE-03 | Penalties |
| HBNR-ENF-01 | Record-Keeping Requirements |
| HBNR-ENF-02 | FTC Enforcement Authority |
| HBNR-ENF-03 | State Attorney General Enforcement |
| NDB-DATA-BREACH-PLAN | Data breach response plan |
| NDB-S26WR | Commissioner-directed notification |
| PSTI-CMP-01 | Statement of Compliance |
| PSTI-CMP-02 | Importer and Distributor Obligations |
| PSTI-CMP-03 | Enforcement and Penalties |
| US-ITAR-EAR-CE-01 | Compliance Programme |
| US-ITAR-EAR-CE-02 | Violation Reporting |
| US-ITAR-EAR-CE-03 | Penalties |
| US-SEC-DA-CE-01 | Platform Compliance |
| US-SEC-DA-CE-02 | Custody and Reporting |
| US-SEC-DA-CE-03 | Enforcement Actions |
Notification Requirements
Timing, content, and methods for breach notifications
| Code | Title |
|---|---|
| HBNR-NOT-01 | Individual Notification |
| HBNR-NOT-02 | FTC Notification |
| HBNR-NOT-03 | Media Notification |
| HBNR-NOT-04 | Notification Content Requirements |
| HBNR-NOT-05 | Third-Party Service Provider Obligations |
Scope and Definitions
Defines nursing personnel as all categories of persons providing nursing care and services, wherever they work.
| Code | Title |
|---|---|
| 64.2001 | Basis and Purpose |
| 64.2003 | Definitions |
| 64.2004 | Customer Approval Mechanisms |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| ILO-C149-01 | Article 1 — Definition of nursing personnel covering all categories providing nursing care and services |
Maps to 646 other frameworks
Frequently Asked Questions
What is FTC Health Breach Notification Rule?
FTC Health Breach Notification Rule is a compliance framework from United States with 3 domains and 50 controls. The FTC Health Breach Notification Rule (16 CFR Part 318) requires vendors of personal health records (PHR) and PHR-related entities to notify individuals, the FTC, and in some cases the media following a breach of unsecured personally identifiable health information. Updated in 2024 to clarify applicability to health apps, wearables, and other digital health technologies not covered by HIPAA. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FTC Health Breach Notification Rule have?
FTC Health Breach Notification Rule has 50 controls organised across 3 domains. The largest domains are Compliance and Enforcement (38 controls), Scope and Definitions (7 controls), Notification Requirements (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FTC Health Breach Notification Rule map to?
FTC Health Breach Notification Rule maps to 646 other compliance frameworks. The top mapping partners are US SEC Digital Assets and Crypto Regulatory Framework (32% coverage), Notifiable Data Breaches Scheme (Australia) (32% coverage), EU NIS2 Directive — Energy Sector Cybersecurity Requirements (Directive 2022/2555) (32% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with FTC Health Breach Notification Rule compliance?
Start your FTC Health Breach Notification Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FTC Health Breach Notification Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required