Summary

Contact us
The Federal Trade Commission announced it has finalized changes to the Health Breach Notification Rule (HBNR) that will strengthen and modernize the rule by clarifying its applicability to health apps and other similar technologies and expanding the information that covered entities must provide to consumers when notifying them of a breach of their health data.

Modifications to the regulation

  1. Updating Definitions: The Commission has updated several definitions to emphasize the applicability of the final rule to health apps and similar technologies not governed by HIPAA. This includes altering the definition of “PHR identifiable health information” and introducing new definitions for “covered health care provider” and “health care services or supplies.”
  2. Specifying Security Breaches: The rule now specifies that a "breach of security" encompasses unauthorized access to identifiable health information, whether through a data security incident or unauthorized disclosure.
  3. Amending the Definition of PHR Related Entity: The definition of “PHR related entity” has been refined in two significant ways relevant to the rule’s scope. It now specifies that the rule applies to entities that provide products and services via the online services of personal health record vendors, including mobile apps. It also restricts the definition to entities that access or transmit unsecured PHR identifiable health information to a personal health record.
  4. Clarifying Information from Multiple Sources: The rule clarifies the criteria for a personal health record to incorporate PHR identifiable health information from various sources.
  5. Enhancing Electronic Notifications: The final rule permits broader use of email and other electronic methods for sending clear and effective breach notifications to consumers.
  6. Broadening Notice Requirements: The content required in consumer notifications has been expanded. Notices must now include either the name or a description of any third parties who obtained unsecured PHR identifiable health information due to a security breach, especially when revealing the full name poses a risk.
  7. Adjusting Notification Timelines: The final rule changes the timing for notifying the FTC about breaches impacting 500 or more individuals. Covered entities must now notify the FTC concurrently with affected individuals, doing so promptly and no later than 60 calendar days after identifying a breach.
  8. Improving Clarity and Compliance: The final rule also includes modifications to enhance clarity and facilitate compliance.

The rule takes effect 60 days after its announcement in the Federal Register.

Click to read more

Contact us

FAQs

Our frequently questions

No items found.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Abstract graphic showing a digital EU flag alongside a US state outline representing new AI regulation milestones in Europe and Rhode Island in July 2026
July 29, 2026
Healthtech
Regulations & Guidelines
DPIA
Biotech & Healthtech
Health Data Warehouse

EU Digital Omnibus Simplifies AI Act Obligations; Rhode Island Enacts AI Healthcare Laws

Regulation (EU) 2026/1744 streamlines EU AI Act compliance, while Rhode Island enacts three AI healthcare laws. Key updates for biotech and healthtech teams.

Diagram illustrating the EDPB three-criteria anonymisation test applied to clinical trial datasets under GDPR, with icons for record isolation, linkage and inference
July 13, 2026
DPIA
AI
Testimonial
EU Privacy Law
Regulations & Guidelines

EDPB Anonymisation Guidelines 2026 and Clinical Trial Data: What Life Sciences Organisations Must Know

EDPB Guidelines 02/2026 on anonymisation set new standards for clinical trial data. Learn the three-criteria test, enforcement lessons and compliance steps. iliomad.

Abstract digital network connecting a hospital, a regulatory building and a courtroom, representing AI governance, health data privacy and transatlantic data transfer risks in 2026
July 8, 2026
Healthtech
Regulations & Guidelines
DPIA
Regulation
LLMS

AI Triage, Biopharma Workbenches and Crumbling Data Bridges: iliomad Weekly Digest

NHS AI triage, Anthropic Claude Science, medical AI privacy risks, MHRA GxP guidance, EDPS ADM checklist and the EU-US data transfer threat explained.