ARTICLE
27 April 2023

Attorneys Examine Impact Of FTC's Settlements Involving Health Breach Notification Rule

BB
Bass, Berry & Sims

Contributor

Bass, Berry & Sims is a national law firm with nearly 350 attorneys dedicated to delivering exceptional service to numerous publicly traded companies and Fortune 500 businesses in significant litigation and investigations, complex business transactions, and international regulatory matters. For more than 100 years, our people have served as true partners to clients, working seamlessly across substantive practice disciplines, industries and geographies to deliver highly-effective legal advice and innovative, business-focused solutions. For more information, visit www.bassberry.com.
Bass, Berry & Sims attorneys Wes McCulloch, Nesrin Tift, Shannon Wiley and Roy Wyman authored an article for Fierce Healthcare outlining recent settlements between the Federal Trade Commission...
United States Food, Drugs, Healthcare, Life Sciences
To print this article, all you need is to be registered or login on Mondaq.com.

Bass, Berry & Sims attorneys Wes McCulloch, Nesrin Tift, Shannon Wiley and Roy Wyman authored an article for Fierce Healthcare outlining recent settlements between the Federal Trade Commission (FTC) and healthcare companies involving the Health Breach Notification Rule. These settlements mark the first time the FTC has enforced rules around breaches of healthcare data that aren't subject to HIPAA. In the first case, GoodRx Holdings agreed to pay $1.5 million to settle allegations it did not adequately disclose the collection and use of health information to users; in the second case, BetterHelp agreed to pay $7.8 million for sharing consumers' health data with social media companies for advertising purposes.

As the authors point out, "The settlements, along with FTC's allegations regarding the underlying conduct, signal increased enforcement around the use of monitoring technologies by digital health companies and can provide guidance regarding the terms of consent forms and privacy policies." With this in mind, the attorneys outline four things companies should be mindful of:

  1. Usage data can constitute identifiable health information.
  2. Inaccurate public statements can lead to "breaches" of personal health information.
  3. Be wary of statements regarding compliance with HIPAA.
  4. Implement privacy and data-sharing governance.

Details about these four issues can be found in the article, "Industry Voices-FTC Health Breach Notification Rule Finally Gets a Target," that was published by Fierce Healthcare on April 18 and is available online.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More