US Federal Law United States

FTC Health Breach Notification Rule: Apps On the Clock

The HBNR after the 2024 amendments: which health apps are covered, why sharing data with advertisers is a 'breach', notification clocks, and the GoodRx and Premom precedents.

Regulation

Health Breach Notification Rule, 16 CFR Part 318, under the HITECH Act; amended final rule effective July 29, 2024

Max Penalty

Civil penalties per violation, inflation-adjusted above $50,000, with each day of continued violation countable; GoodRx paid $1.5 million on the rule's first enforcement

Enforcing Authority

Federal Trade Commission (FTC)

Official Source

www.ftc.gov

Executive Summary

  • The HBNR (16 CFR Part 318) requires vendors of personal health records and related entities NOT covered by HIPAA, health apps, fitness trackers, fertility and mental-health apps, connected devices, to notify individuals, the FTC, and sometimes media after a breach of unsecured identifiable health information.
  • The FTC reads 'breach' to include unauthorized disclosures, not just hacking: sharing health data with advertising platforms without authorization triggered the rule's first enforcement (GoodRx, $1.5 million, 2023) and the Premom action.
  • The 2024 amendments, effective July 29, 2024, codified that reading: 'breach of security' expressly covers unauthorized acquisition resulting from unauthorized disclosure, and definitions now clearly reach health apps and emergent technologies.
  • Clocks: individuals and the FTC within 60 calendar days (FTC contemporaneously for 500+ individuals; annually for smaller breaches), media for 500+ residents of a jurisdiction; electronic notice methods were expanded in 2024.
  • The rule fills HIPAA's consumer gap: the same fertility app that HIPAA cannot reach answers to the FTC, with per-day penalties available from the first violation.

The HBNR spent a dozen years as a footnote, enacted in 2009, enforced never, until the FTC noticed that the entire consumer health-app economy had grown up outside HIPAA’s fence. GoodRx changed the rule’s meaning in practice: a ‘breach’ is not just an intruder in the database but your own marketing stack shipping prescription histories to ad platforms without permission. The 2024 amendments made that reading text rather than theory. For the fertility trackers, mental-health apps, and wearable platforms holding the most intimate data Americans generate, the compliance question inverted: not ‘could we be hacked?’ but ‘what did we already send, and who said we could?‘

Rule16 CFR Part 318 (HITECH)
CoversPHR vendors, related entities, their service providers (non-HIPAA)
“Breach”Includes unauthorized disclosures (ad pixels, SDKs), per 2024 amendments
ClocksIndividuals + FTC ≤60 days (500+ contemporaneous; media 500+/state)
First caseGoodRx, $1.5M + ad-sharing ban (2023)
Safe harborEncryption per HHS guidance

Getting ahead of the rule

Audit the SDK and pixel layer first. Unauthorized health-data flows to ad platforms are breaches under current text, not just enforcement theory; Section 5 supplies the companion counts.

Make authorization real. Specific, affirmative consent for sharing, designed without dark patterns, is the line between marketing and notification events.

Encrypt to exit. The rule reaches unsecured data only; HHS-standard encryption is the same safe harbor the HIPAA breach rule offers.

Route incidents correctly. PHI goes to OCR’s rule, PHR data here, one playbook, one routing decision; OCR enforcement trends cover the other track.

Health apps start leaking on their marketing pages: see exactly what your site sends to third parties with a free scan.

Frequently Asked Questions

Who is covered by the HBNR?

Three categories, none HIPAA-covered: (1) vendors of personal health records, businesses offering or maintaining records of identifiable health information drawn from multiple sources that individuals manage (the 2024 amendments confirm a health app qualifies when it draws information from multiple sources, including a device sensor plus user input, or health and non-health inputs combined); (2) PHR-related entities, those offering products or services through a PHR vendor's site or app, or accessing/sending information to a PHR; (3) third-party service providers to either. Practical translation: fitness and sleep trackers, fertility and period apps, mental-health and telecoverage apps outside HIPAA, glucose and blood-pressure apps, and wellness platforms. If your health product's data layer would be a business associate's problem inside HIPAA, outside HIPAA it is probably your HBNR problem.

How can sharing with advertisers be a 'breach'?

Because the rule defines breach of security as acquisition of unsecured PHR identifiable health information without the authorization of the individual, and the FTC reads intentional, unauthorized disclosures as squarely within it. GoodRx (February 2023) established the position: the company shared users' prescription and health-condition data with Facebook, Google, and other platforms for advertising, contrary to its promises and without authorization, the FTC charged an HBNR violation (plus Section 5), and GoodRx paid $1.5 million with a permanent ban on sharing health data for ads. Premom (May 2023) followed the same theory for a fertility app's SDK data flows. The 2024 amendments wrote the interpretation into the rule text, closing the 'it was a disclosure, not a hack' argument for good. A misconfigured ad pixel on a covered app is a notifiable breach, full stop.

What are the notification requirements and clocks?

Individuals: without unreasonable delay, no later than 60 calendar days after discovery, by written notice, or, since the 2024 amendments, email paired with in-app or portal messaging, containing what happened, the data involved, what recipients should do, contact information, and (new in 2024) the identity or description of third parties that acquired the data. FTC: through its portal, contemporaneously with individual notice for breaches involving 500 or more individuals, or within 60 days after calendar year-end for smaller ones. Media: prominent outlets in a state or jurisdiction where 500+ residents are affected. Third-party service providers notify the vendor/entity they serve, which then owns the outward notifications. Discovery is the first day the breach is known or reasonably should have been known to any employee, officer, or agent other than the breaching person.

How does the HBNR interact with HIPAA?

They are mutually exclusive by design: HIPAA-covered entities and business associates handling PHI follow OCR's Breach Notification Rule, not the HBNR; the HBNR covers the consumer-health world HIPAA cannot reach. Dual-track companies exist, a firm can run a HIPAA-covered telehealth service and a direct-to-consumer wellness app, and each product line follows its own rule. The rules rhyme deliberately (60-day clocks, 500-person media and regulator triggers, 'unsecured' meaning unencrypted per HHS guidance), so a unified incident-response playbook with a routing decision, PHI or PHR?, at the top handles both. What differs is the enforcement flavor: the FTC brings penalty authority from the first violation plus Section 5 companions, and its orders ban business practices (ad-sharing bans) rather than imposing OCR-style corrective action plans.

What should covered apps do before any incident?

Five moves. Map data flows, especially SDKs, pixels, and analytics: every third party receiving identifiable health information without user authorization is a breach already in progress under the FTC's reading. Fix authorization: affirmative, specific consent for any health-data sharing, buried policy language is not authorization, and dark-pattern consent invites a Section 5 count. Encrypt: the rule reaches only unsecured data, so encryption to HHS standards is the same safe harbor HIPAA offers. Pre-build notification: templates, the FTC portal path, and the 60-day clock in the IR plan, with the 2024 electronic-notice options wired in. Contract the chain: third-party service providers owe you breach notice; make the timing contractual and short. The GoodRx order's practical lesson is that the cheapest time to discover your ad stack shares health data is before the FTC does.

Regulatory Crosswalk

HIPAA Breach Notification RuleState breach lawsFTC Act Section 5

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.