Regulations › US federal

FTC HBNR

FTC Health Breach Notification Rule

In force health breach notification
WhenIn effect since 24 September 2009
Who enforces itFederal Trade Commission
Who it applies toVendors of personal health records and health apps not covered by HIPAA.

Breach notice for health apps and similar services outside HIPAA, where unauthorized sharing counts as a breach.

The law in brief

The FTC's Health Breach Notification Rule requires vendors of personal health records and related entities that are not covered by HIPAA to notify people, the FTC and sometimes the media after a breach of health information. It fills the gap left by HIPAA for health apps, fitness trackers, connected devices and similar services.

Amendments effective 29 July 2024 made clear that health apps are covered and that a breach includes an unauthorized disclosure the company itself makes, such as sharing health data with advertising platforms without authorization, not only a cyberattack.

Who it applies to

  • Vendors of personal health records: services that offer an electronic record of health information that can be drawn from multiple sources and is managed by or for the individual, including many health and wellness apps.
  • PHR related entities that offer products or services through a vendor's website or app, or that access or send information to a personal health record.
  • Third-party service providers to these entities, which must notify the entity they serve.
  • HIPAA-covered entities and business associates are excluded, because HIPAA's own breach rules apply to them.

Unauthorized disclosure is a breach

A breach of security includes an unauthorized acquisition of identifiable health information, including one resulting from a disclosure the entity itself makes without the individual's authorization.

What it requires

Notify individuals within 60 days

Notify each affected individual without unreasonable delay and no later than 60 calendar days after discovering the breach.

Notify the FTC

For breaches involving 500 or more individuals, notify the FTC at the same time as individuals. For fewer, keep a log and report to the FTC within 60 days after the end of the calendar year.

Notify the media for large breaches

Notify prominent media outlets serving a state or jurisdiction when a breach involves more than 500 residents of it.

Service providers notify their clients

Third-party service providers notify the entity they serve after discovering a breach, so it can notify individuals.

People's rights

Affected individuals must receive a notice describing the breach, the information involved, steps they can take, and what the company is doing, by email or first-class mail and in some cases through substitute notice.

Enforcement and penalties

Civil penalties per violation, adjusted for inflation each year, which the FTC can seek in federal court. The FTC has brought actions against health apps that shared health data with advertisers, and violations can also be charged as unfair or deceptive practices.

What to do first

  1. Decide whether you are a personal health record vendor or related entity, and confirm HIPAA does not apply.
  2. Map every flow of health information, including pixels, SDKs and analytics.
  3. Treat unauthorized sharing as a breach: get authorization before any disclosure outside your stated purposes.
  4. Prepare notices that meet the rule's content requirements.
  5. Set up the FTC and media notice process for breaches of 500 or more people.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources