Research

The breach rule for health apps HIPAA does not cover

A separate federal rule requires notice when health information leaks from an app or online service outside the medical privacy law. It defines a breach to include an unauthorized disclosure, not just a hack.

By Nora Castellan, Standards Editor

The rule exists because of a gap, and it says so

The medical privacy law most people have heard of covers health providers, plans and their business associates. A wellness app, a symptom tracker or a direct-to-consumer health service often sits outside it.

A separate rule fills that space. Its first section states the boundary directly: "This part does not apply to HIPAA-covered entities", or to any entity to the extent it is acting as a business associate of one.

What it does apply to is vendors of personal health records, related entities and their service providers, where they hold information of United States citizens or residents. It reaches them "irrespective of any jurisdictional tests" in the commission's own governing statute.

Foreign and domestic companies are both named.

So the two regimes are complementary rather than overlapping. If one applies, the other does not, and the interesting question for a consumer service is which side of the line it sits on.

The definition that catches almost every health app

The scope turns on defined terms, and one of them is written broadly enough to be worth reading in full.

Health care services or supplies means "any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases". The list continues through health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs and symptoms. It ends with bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information and diet.

The list ends with a catch-all for other health-related services or tools.

A personal health record is an electronic record of identifiable health information with the technical capacity to draw information from multiple sources, managed, shared and controlled by or primarily for the individual.

A related entity is one that offers products or services through such a vendor's website or online service. It also covers one offering them through the websites of covered entities that offer personal health records, or one that accesses or sends this information to a personal health record.

A third party service provider is one that provides services in connection with those products and that accesses, maintains, retains, modifies, records, stores, destroys, holds, uses or discloses the information.

A breach here is broader than a break-in

The most consequential definition is the one for a breach, and it is not limited to attackers.

A breach of security means "acquisition of such information without the authorization of the individual".

It then adds a presumption that shifts the work of proving things. "Unauthorized acquisition will be presumed to include unauthorized access" unless the entity has reliable evidence showing there has not been, and could not reasonably have been, unauthorized acquisition.

And it states the two routes expressly. A breach includes unauthorized acquisition that occurs "as a result of a data breach or an unauthorized disclosure".

That second route is the one that surprises people. A company sharing health information with a third party in a way the individual did not authorize falls inside the definition, without anyone breaking in.

The information covered is unsecured, meaning not protected by a technology or methodology specified in the relevant federal guidance.

Three notifications, and the one that goes to the newspapers

After discovering a breach, a vendor or related entity has three duties.

Notify each affected individual who is a citizen or resident of the United States whose unsecured identifiable health information was acquired by an unauthorized person.

Notify the commission.

And, where five hundred or more residents of a state or jurisdiction are affected or reasonably believed to be, "Notify prominent media outlets serving a State or jurisdiction".

A service provider has a different duty. It notifies an official designated in a written contract, or a senior official at the vendor or related entity it serves, must obtain acknowledgment that the notice was received, and must identify each affected customer.

For that chain to work, vendors and related entities have to tell their service providers what their status is under the rule.

Sixty days, and who has to prove it happened

The deadline is stated twice over, as a standard and as an outer limit.

Notifications must be sent "without unreasonable delay and in no case later than 60 calendar days after the discovery of a breach of security".

Notice to the commission tracks that for larger breaches. Where five hundred or more individuals are involved, it goes at the same time as the individual notice. Smaller breaches may be logged and reported annually, no later than sixty calendar days after the end of the calendar year.

The burden of proof sits with the company. The vendor, related entity or service provider "shall have the burden of demonstrating that all notifications were made" as required, including evidence showing why any delay was necessary.

One exception can stop the clock. Where a law enforcement official determines that a notification would impede a criminal investigation or cause damage to national security, it is delayed.

How the notice reaches you, including when it cannot

Individual notice is written, sent to the last known address.

Electronic mail may be used where the individual specified it as the primary method of communication, and such a notice must be clear and conspicuous, a term the rule defines in its own definitions section.

Where an individual has died, notice goes to the next of kin if the individual had provided their contact information along with authorization to contact them.

When the addresses do not work, a substitute route opens. If contact information for ten or more individuals is insufficient or out of date after reasonable efforts, the company must give substitute notice reasonably calculated to reach those affected.

That means either "Through a conspicuous posting for a period of 90 days on the home page of its website", or notice in major print or broadcast media. The media route includes areas where affected individuals likely live.

A media or web posting of that kind must carry a toll-free number that stays active for at least ninety days.

What the notice has to tell you

The contents are prescribed, and the requirement opens with a plain-language instruction. Notice "shall be in plain language".

It must give a brief description of what happened, including the date of the breach and the date of discovery where known.

It must name the third parties that acquired the information, if known, though a description may replace the name where naming would pose a risk to individuals or to the entity giving notice.

It must describe the types of information involved, and the illustrative list is worth reading because of one entry. Alongside name, social security number, date of birth, address, account number, diagnosis, lab results, medications and other treatment information sits "the individual's use of a health-related mobile application".

The fact that you used a particular health app is itself treated as health information here.

It must set out "Steps individuals should take to protect themselves from potential harm" resulting from the breach.

It must describe what the company is doing to investigate, mitigate harm, prevent further breaches and protect affected individuals, such as offering credit monitoring.

And it must give contact procedures using at least two of a toll-free number, an email address, a website, an in-application route, or a postal address.

Teeth, and a built-in expiry

Enforcement runs through the commission's ordinary machinery. A violation is treated as a violation of a rule about unfair or deceptive acts or practices, and is subject to civil penalties adjusted for inflation.

The rule also carries an unusual clause about its own future. If new legislation is enacted establishing breach notification requirements for the entities it covers, this part stops applying to breaches discovered on or after the effective date of regulations implementing that legislation.

It preempts state law only as set out in the statute it implements.

For a reader, the practical value is knowing that a health service outside the medical privacy law is not therefore outside all notification duties. It also helps to know that a disclosure you did not authorize can count as a breach.

Two limits on this article. Only part 318 was read, in full. No company was assessed against it and no breach notice was retrieved. Whether any particular seller is a vendor of personal health records, a related entity, or a covered entity under the other law was not determined.

Key takeaways

Frequently asked questions

What does this rule cover that the medical privacy law does not?

Vendors of personal health records, related entities and their third party service providers, where they hold information of United States citizens or residents. The rule states in its first section that it does not apply to entities covered by the medical privacy law, or to any entity to the extent it acts as a business associate of one. It applies to foreign and domestic companies alike, irrespective of the commission's usual jurisdictional tests.

Would a health app be covered?

It depends on the definitions, and one of them is broad. Health care services or supplies means any online service such as a website, mobile application or internet-connected device that provides tracking mechanisms. The list of what may be tracked runs from diseases, health conditions, diagnoses and diagnostic testing through treatment, medications, vital signs and symptoms. It continues through bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information and diet, and ends with other health-related services or tools. Whether a specific company falls inside was not assessed here.

Does a breach have to be a hack?

No. A breach of security means acquisition of unsecured identifiable health information without the individual's authorization. The rule states that it includes unauthorized acquisition occurring as a result of a data breach or an unauthorized disclosure. It also presumes that unauthorized access amounts to unauthorized acquisition unless the entity has reliable evidence that acquisition did not and could not reasonably have happened.

How quickly must I be told?

Notifications must be sent without unreasonable delay and in no case later than sixty calendar days after discovery of the breach. Notice to the commission goes at the same time where five hundred or more individuals are affected; smaller breaches may be logged and reported annually within sixty days of the year end. The company carries the burden of demonstrating that all notifications were made, including evidence justifying any delay.

What if the company does not have my current address?

Substitute notice applies. If contact information for ten or more individuals is insufficient or out of date after reasonable efforts, the company must give notice reasonably calculated to reach those affected. That is either a conspicuous posting for ninety days on its website home page, or notice in major print or broadcast media, including where affected people likely live. Such a notice must include a toll-free number active for at least ninety days.

What must the notice say?

It must be in plain language. It includes a brief description of what happened, with the breach and discovery dates where known, and the identity or a description of any third parties that acquired the information. It also covers the types of information involved, steps individuals should take to protect themselves, what the company is doing to investigate and mitigate, and contact procedures using at least two channels. The list of information types expressly includes the individual's use of a health-related mobile application.

Is there a penalty?

A violation is treated as a violation of a rule concerning unfair or deceptive acts or practices, and is subject to civil penalties adjusted for inflation, enforced with the commission's ordinary powers. The rule also contains a clause ending its own application if new legislation establishes breach notification requirements for the same entities, from the effective date of regulations implementing it.

Sources

Each document below is named as it names itself, with the date printed on that document rather than the day it was read.

  1. Title 16 Code of Federal Regulations section 318.1, Purpose and scope, read in fullElectronic Code of Federal Regulations, Office of the Federal Register, May 2024
  2. Title 16 Code of Federal Regulations section 318.2, Definitions, read for breach of security, health care services or supplies, personal health record, PHR related entity and third party service providerElectronic Code of Federal Regulations, Office of the Federal Register, May 2024
  3. Title 16 Code of Federal Regulations section 318.3, Breach notification requirement, read in fullElectronic Code of Federal Regulations, Office of the Federal Register, May 2024
  4. Title 16 Code of Federal Regulations section 318.4, Timeliness of notification, read in full for the sixty-day limit, the burden of proof and the law enforcement exceptionElectronic Code of Federal Regulations, Office of the Federal Register, May 2024
  5. Title 16 Code of Federal Regulations section 318.5, Methods of notice, read in full including the substitute notice provisionsElectronic Code of Federal Regulations, Office of the Federal Register, May 2024
  6. Title 16 Code of Federal Regulations section 318.6, Content of notice, read in fullElectronic Code of Federal Regulations, Office of the Federal Register, May 2024
  7. Title 16 Code of Federal Regulations section 318.7, Enforcement, and section 318.9, Sunset, read in fullElectronic Code of Federal Regulations, Office of the Federal Register, May 2024