ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

16 CFR Part 318 — Health Breach Notification Rule

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
commercialfederaltradecommissionpractices
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 16, 318, part 318, 16 cfr 318, 16 cfr part 318, commercial, practices, federal trade commission, regulations under specific acts of congress

PART 318—HEALTH BREACH NOTIFICATION RULE Authority: 42 U.S.C. 17937 and 17953. Source: 74 FR 42980, Aug. 25, 2009, as amended at 89 FR 47054, May 30, 2024, unless otherwise noted. § 318.1 Purpose and scope. (a) This part, which shall be called the “Health Breach Notification Rule,” implements section 13407 of the American Recovery and Reinvestment Act of 2009, 42 U.S.C. 17937. This part applies to foreign and domestic vendors of personal health records, PHR related entities, and third party service providers, irrespective of any jurisdictional tests in the Federal Trade Commission (FTC) Act, that maintain information of U.S. citizens or residents. This part does not apply to HIPAA-covered entities, or to any other entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity. (b) This part preempts State law as set forth in section 13421 of the American Recovery and Reinvestment Act of 2009, 42 U.S.C 17951. § 318.2 Definitions. Breach of security Business associate Clear and conspicuous (1) Reasonably understandable. (i) Present the information in the notice in clear, concise sentences, paragraphs, and sections; (ii) Use short explanatory sentences or bullet lists whenever possible; (iii) Use definite, concrete, everyday words and active voice whenever possible; (iv) Avoid multiple negatives; (v) Avoid legal and highly technical business terminology whenever possible; and (vi) Avoid explanations that are imprecise and readily subject to different interpretations. (2) Designed to call attention. (i) Use a plain-language heading to call attention to the notice; (ii) Use a typeface and type size that are easy to read; (iii) Provide wide margins and ample line spacing; (iv) Use boldface or italics for key words; and (v) In a form that combines your notice with other information, use distinctive type size, style, and graphic devices, such as shading or sidebars, when you combine your notice with other information. The notice should stand out from any accompanying text or other visual elements so that it is easily noticed, read, and understood. (3) Notices on websites or within-application messaging. (i) Place the notice on a screen that consumers frequently access, such as a page on which transactions are conducted; or (ii) Place a link on a screen that consumers frequently access, such as a page on which transactions are conducted, that connects directly to the notice and is labeled appropriately to convey the importance, nature and relevance of the notice. Covered health care provider Electronic mail Health care services or supplies HIPAA-covered entity Personal health record (PHR) PHR identifiable health information (1) Relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual; and (i) Identifies the individual; or (ii) With respect to which there is a reasonable basis to believe that the information can be used to identify the individual; and (2) Is created or received by a: (i) Covered health care provider; (ii) Health plan (as defined in 42 U.S.C. 1320d(5)); (iii) Employer; or (iv) Health care clearinghouse (as defined in 42 U.S.C. 1320d(2)); and (3) With respect to an individual, includes information that is provided by or on behalf of the individual. PHR related entity (1) Offers products or services through the website, including any online service, of a vendor of personal health records; (2) Offers products or services through the websites, including any online service, of HIPAA-covered entities that offer individuals personal health records; or (3) Accesses unsecured PHR identifiable health information in a personal health record or sends unsecured PHR identifiable health information to a personal health record. State Third party service provider (1) Provides services to a vendor of personal health records in connection with the offering or maintenance of a personal health record or to a PHR related entity in connection with a product or service offered by that entity; and (2) Accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured PHR identifiable health information as a result of such services. Unsecured Vendor of personal health records § 318.3 Breach notification requirement. (a) In general. (1) Notify each individual who is a citizen or resident of the United States whose unsecured PHR identifiable health information was acquired by an unauthorized person as a result of such breach of security; (2) Notify the Federal Trade Commission; and (3) Notify prominent media outlets serving a State or jurisdiction, following the discovery of a breach of security, if the unsecured PHR identifiable health information of 500 or more residents of such State or jurisdiction is, or is reasonably believed to have been, acquired during such breach. (b) Third party service providers. (c) Breaches treated as discovered. § 318.4 Timeliness of notification. (a) In general. (b) Timing of notice to FTC. (c) Burden of proof. (d) Law enforcement exception. § 318.5 Methods of notice. (a) Individual notice. (1) Written notice at the last known address of the individual. Written notice may be sent by electronic mail if the individual has specified electronic mail as the primary method of communication. Any written notice sent by electronic mail must be Clear and Conspicuous. Where notice via electronic mail is not available or the individual has not specified electronic mail as the primary method of communication, a vendor of personal health records or PHR related entity may provide notice by first-class mail at the last known address of the individual. If the individual is deceased, the vendor of personal health records or PHR related entity that discovered the breach must provide such notice to the next of kin of the individual if the individual had provided contact information for his or her next of kin, along with authorization to contact them. The notice may be provided in one or more mailings as information is available. (2) If, after making reasonable efforts to contact all individuals to whom notice is required under § 318.3(a), through the means provided in paragraph (a)(1) of this section, the vendor of personal health records or PHR related entity finds that contact information for ten or more individuals is insufficient or out-of-date, the vendor of personal health records or PHR related entity shall provide substitute notice, which shall be reasonably calculated to reach the individuals affected by the breach, in the following form: (i) Through a conspicuous posting for a period of 90 days on the home page of its website; or (ii) In major print or broadcast media, including major media in geographic areas where the individuals affected by the breach likely reside. Such a notice in media or web posting shall include a toll-free phone number, which shall remain active for at least 90 days, where an individual can learn if the individual's unsecured PHR identifiable health information may have been included in the breach. (3) In any case deemed by the vendor of personal health records or PHR related entity to require urgency because of possible imminent misuse of unsecured PHR identifiable health information, that entity may provide information to individuals by telephone or other means, as appropriate, in addition to notice provided under paragraph (a)(1) of this section. (b) Notice to media. (c) Notice to FTC. § 318.6 Content of notice. Regardless of the method by which notice is provided to individuals under § 318.5 (regarding methods of notice), notice of a breach of security shall be in plain language and include, to the extent possible, the following: (a) A brief description of what happened, including: the date of the breach and the date of the discovery of the breach, if known; and the full name or identity (or, where providing the full name or identity would pose a risk to individuals or the entity providing notice, a description) of any third parties that acquired unsecured PHR identifiable health information as a result of a breach of security, if this information is known to the vendor of personal health records or PHR related entity; (b) A description of the types of unsecured PHR identifiable health information that were involved in the breach (such as but not limited to full name, Social Security number, date of birth, home address, account number, health diagnosis or condition, lab results, medications, other treatment information, the individual's use of a health-related mobile application, or device identifier (in combination with another data element)); (c) Steps individuals should take to protect themselves from potential harm resulting from the breach; (d) A brief description of what the entity that experienced the breach is doing to investigate the breach, to mitigate harm, to protect against any further breaches, and to protect affected individuals, such as offering credit monitoring or other services; and (e) Contact procedures for individuals to ask questions or learn additional information, which must include two or more of the following: toll-free telephone number; email address; website; within-application; or postal address. § 318.7 Enforcement. Any violation of this part shall be treated as a violation of a rule promulgated under section 18 of the Federal Trade Commission Act, 15 U.S.C. 57a, regarding unfair or deceptive acts or practices, and thus subject to civil penalties (as adjusted for inflation pursuant to § 1.98 of this chapter), and the Commission will enforce this part in the same manner, by the same means, and with the same jurisdiction, powers, and duties as are available to it pursuant to the Federal Trade Commission Act, 15 U.S.C. 41 et seq. § 318.8 Applicability date. This part shall apply to breaches of security that are discovered on or after September 24, 2009. § 318.9 Sunset. If new legislation is enacted establishing requirements for notification in the case of a breach of security that apply to entities covered by this part, the provisions of this part shall not apply to breaches of security discovered on or after the effective date of regulations implementing such legislation.

Related documents

Record · ID 506048 · SHA-256 5a0de1a31de94f35
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.