The HBNR spent a dozen years as a footnote, enacted in 2009, enforced never, until the FTC noticed that the entire consumer health-app economy had grown up outside HIPAA’s fence. GoodRx changed the rule’s meaning in practice: a ‘breach’ is not just an intruder in the database but your own marketing stack shipping prescription histories to ad platforms without permission. The 2024 amendments made that reading text rather than theory. For the fertility trackers, mental-health apps, and wearable platforms holding the most intimate data Americans generate, the compliance question inverted: not ‘could we be hacked?’ but ‘what did we already send, and who said we could?‘
| Rule | 16 CFR Part 318 (HITECH) |
|---|---|
| Covers | PHR vendors, related entities, their service providers (non-HIPAA) |
| “Breach” | Includes unauthorized disclosures (ad pixels, SDKs), per 2024 amendments |
| Clocks | Individuals + FTC ≤60 days (500+ contemporaneous; media 500+/state) |
| First case | GoodRx, $1.5M + ad-sharing ban (2023) |
| Safe harbor | Encryption per HHS guidance |
Getting ahead of the rule
Audit the SDK and pixel layer first. Unauthorized health-data flows to ad platforms are breaches under current text, not just enforcement theory; Section 5 supplies the companion counts.
Make authorization real. Specific, affirmative consent for sharing, designed without dark patterns, is the line between marketing and notification events.
Encrypt to exit. The rule reaches unsecured data only; HHS-standard encryption is the same safe harbor the HIPAA breach rule offers.
Route incidents correctly. PHI goes to OCR’s rule, PHR data here, one playbook, one routing decision; OCR enforcement trends cover the other track.
Health apps start leaking on their marketing pages: see exactly what your site sends to third parties with a free scan.