Health Breach Notification Rule
The Federal Trade Commission ("FTC" or "Commission") is amending the Commission's Health Breach Notification Rule (the "HBN Rule" or the "Rule"). The HBN Rule requires vendors of personal health records ("PHRs") and related entities that are not covered by the Health Insurance Portability and Accountability Act ("HIPAA") to notify individuals, the FTC, and, in some cases, the media of a breach of unsecured personally identifiable health data.
What this rule actually says
If someone's health data gets stolen from a product, the FTC wants to know about it—and so do the people affected. This rule requires certain AI products that handle health information to send breach notifications to users, the FTC, and sometimes the media. It's the FTC's version of "you got hacked, you have to tell people."
Who it applies to
- If building a medical scribe, health coaching app, symptom checker, or any product that stores patient health records or medical history — this likely applies to you.
- If you're NOT HIPAA-covered — meaning you're not working with a healthcare provider or health plan that's already regulated. Most indie founders fall here.
- If your users are in the US — this is FTC jurisdiction only; international rules vary.
- If you collect "personally identifiable health data" — names + any health info (symptoms, diagnoses, medications, test results, genetic info). Even de-identified data plus a name counts.
- If you don't collect health data at all — a hiring assistant using generic resume data, or a support chatbot for non-health companies, you're probably fine.
What founders need to do
- Audit what data you actually store (1-2 days). List every health detail your product collects. If it's zero health info, stop here.
- Confirm you're not HIPAA-covered (a few hours). Ask: Am I a business associate to a hospital or health plan? If no, the Health Breach Notification Rule applies to you instead.
- Write a breach response plan (3-5 days). Document: how you'll detect a breach, who notifies users (you), timeline (generally "without unreasonable delay"), and what you'll tell them (what data, what happened, what they should do).
- Set up secure data practices now (ongoing). Encrypt health data at rest and in transit. Limit who can access it. Run regular security audits. A breach you prevent is a notification you don't send.
- Create a notification template (1 day). Draft what you'll actually say to users if breached. The FTC will expect this.
Bottom line
If you're building any health-related AI product and not HIPAA-covered, treat this as a requirement to secure health data and notify users if breached—act now on the audit and security foundation.