This week, the Federal Trade Commission (FTC) and the U.S. Department of Health & Human Services (HHS) issued new regulations requiring health care providers, vendors of personal health records and related entities to notify individuals following a breach in the privacy of their personal health information. The notification regulations implement provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as part of American Recovery and Reinvestment Act of 2009 (ARRA).
The HHS regulations require health care providers, health plans and other entities covered by the Health Insurance Portability & Accountability Act (HIPAA) to notify individuals, the HHS Secretary, and in certain cases the media, in the event of a security breach individual health information. Additionally, the new regulations require business associates of HIPAA-covered entities to notify covered entities in the event of a security breach. The FTC regulations apply to entities that are not otherwise subject to the HIPAA privacy and security requirements. The FTC regulations require entities that collect consumer health information, such as vendors of personal health records, to inform consumers of any breach of individually identifiable health information.
HHS Press Release: HHS
HHS Breach Notification Interim Final Regulation: HHS Regulation
FTC Press Release: Press Release
FTC Federal Register Notice Text: Federal Register