Health Breach Notification Rule
The Federal Trade Commission ("FTC" or "Commission") proposes to amend the Commission's Health Breach Notification Rule (the "HBN Rule" or the "Rule") and requests public comment on the proposed changes. The HBN Rule requires vendors of personal health records ("PHRs") and related entities that are not covered by the Health Insurance Portability and Accountability Act ("HIPAA") to notify individuals, the FTC, and, in some cases, the media of a breach of unsecured personally identifiable health data.
What this rule actually says
The FTC wants to make sure that if someone's health data gets breached, individuals get notified quickly—and so does the FTC. This applies to AI companies and vendors who store or handle personal health records but aren't already covered by HIPAA (the old healthcare privacy law). So if a medical scribe AI gets hacked and patient notes leak, notification obligations kick in.
Who it applies to
- If you collect or store health data (medical notes, symptom histories, medication lists, diagnoses, etc.) and your users aren't already protected by HIPAA, this likely applies to you.
- If you're in the US: This is a federal FTC rule, so it applies nationwide. No state-specific carveouts change the baseline.
- AI use cases that trigger it: Medical scribes, symptom checkers, health coaching chatbots, hiring assistants that process health accommodations, support chatbots that users mention medical conditions to.
- What counts as "health data": Anything reasonably identifiable as relating to someone's physical or mental health—including sensitive inferences (e.g., "user searches suggest pregnancy").
- What doesn't count: Truly anonymized, non-identifiable data; general wellness tips; aggregate statistics.
- The HIPAA loophole: If your users are covered by HIPAA already (e.g., they're using your tool through a hospital), HIPAA applies instead and this rule doesn't. But if you're selling directly to consumers, assume this applies.
What founders need to do
- Audit what data you're actually storing (2-3 days). Walk through your app: what health-related information are users inputting, uploading, or generating? Be honest about inferences too.
- If you collect health data, implement breach notification policies (1-2 weeks). Document: how fast you'll detect a breach, how you'll notify users, what you'll tell the FTC, and timelines (proposed rule suggests 60 days). This is a policy document, not code.
- Secure that data appropriately (ongoing, but start now). Encryption at rest and in transit, access controls, regular security audits. Regulatory bodies care less about perfection and more about evidence you *tried*.
- Set up a breach response plan (3-5 days). Who's the point person? What's the notification template? Who contacts legal? Practice this before you need it.
- Monitor for final rule finalization (5 minutes/month). This is still proposed as of June 2023. Once it's final, requirements might shift slightly. Join FTC mailing lists or check back annually.
Bottom line
If you're handling health data, act now on breach notification and security—the rule is coming, compliance is cheaper than a breach, and you'll sleep better.