CyberSECURITY August, 18th 2009 by admin

FTC extends breach notification to Web-based health repositories

The Federal Trade Commission has issued a rule that broadens the reach of data breach notification rules covered by the Health Insurance Portability and Accountability Act (HIPAA). The new FTC rule applies to companies that provide an online repository of health information, such as vendors that provide Web-based tools that track and maintain blood pressure readings and other health related data.

Typically, web-based companies that collect health information are not covered under HIPAA. The new FTC rule applies only to these companies and requires vendors of personal health records and their service providers to notify consumers following a data security breach. If the breach involves more than 500 people, the company must give notice to the media, the FTC said. (Search Security)

0 Comments

Socialize

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>