RegImpact
ftcenforcement· Published 11/15/2024

H&R Block; Analysis of Proposed Consent Order To Aid Public Comment

The consent agreement in this matter settles alleged violations of Federal law prohibiting unfair or deceptive acts or practices. The attached Analysis of Proposed Consent Order to Aid Public Comment describes both the allegations in the complaint and the terms of the consent order--embodied in the consent agreement--that would settle these allegations.

What this rule actually says

The FTC went after H&R Block for making false claims about its tax software and misleading people about data security. The consent order forces companies to stop making unsubstantiated claims about their products, be honest about what data they collect and how they use it, and actually implement the security practices they promise. If a founder claims their AI does something it doesn't, or says data is "encrypted" or "private" without backing it up, the FTC can treat that as an unfair or deceptive practice.

Who it applies to

  • If you make claims about your AI's capabilities (e.g., "99% accurate," "HIPAA-compliant," "military-grade security") without testing or proof—this applies to you, everywhere in the US.
  • If you collect health data, financial data, or personal information for your medical scribe, hiring tool, or support chatbot—this applies to you.
  • If you promise data security, encryption, or privacy features but don't actually implement them—this applies to you.
  • If you're selling to US customers or collecting data from them—this applies regardless of where your company is incorporated.
  • Data scope: The rule covers any personally identifiable information or sensitive data (health records, financial info, employment history). Generic usage analytics are lower-risk but still subject to truthfulness requirements.

What founders need to do

  1. Audit your marketing claims (1-2 days). Go through your website, demo videos, pitch deck, and landing page. Flag anything that says your AI is "accurate," "secure," "private," "compliant," or "guaranteed." If you can't back it up with testing data or third-party validation, remove it or qualify it.
  1. Document what you actually do with data (2-3 days). Write a clear privacy policy explaining what data you collect, who can access it, how long you keep it, and whether you share it. Make sure your actual engineering practices match this document.
  1. Implement promised security features (ongoing). If you say data is encrypted, encrypted it. If you claim you don't log conversations, don't log them. The gap between promise and practice is where the FTC looks.
  1. Get security basics in place (1-2 weeks depending on your tech stack). At minimum: encrypted data in transit and at rest, access controls, basic incident response plan. Document it.
  1. Monitor FTC guidance (ongoing, low effort). The FTC publishes AI-specific guidance regularly. Skim it quarterly to stay ahead of enforcement trends.

Bottom line

Act now if you've made unsubstantiated claims about accuracy, security, or compliance; monitor if you collect sensitive user data; ignore if you're building a simple public chatbot with no data collection and modest feature claims.