By: Alex Rankin


On September 15, the Federal Trade Commission voted 3-2 to issue a policy statement (“Statement”) that health apps are included under the Health Breach Notification Rule (“HBNR”)[1] requirement that vendors of personal health records (“PHR”) and PHR-related entities notify the FTC and any affected U.S. users following a breach of those users’ PHR.  HBNR has gone unenforced since its enactment in 2009,[2] including in any instance of PHR breaches experienced by health apps which could track sensitive information ranging from one’s sleep cycle to one’s menstrual cycle.[3]  According to the FTC, it intends to “bring actions to enforce the Rule” against noncompliant companies, noting the potential for “civil penalties of $43,792 per violation per day.”[4]

The Statement was bolstered by supporting remarks from the three affirming commissioners, Chair Lina Khan, Commissioner Rohit Chopra, and Commissioner Rebecca Kelly Slaughter. [5]  However, Commissioners Christine Wilson and Noah Phillips issued critical responses to the Statement,[6] which have been echoed by outside legal commentators.[7]  Wilson’s and Phillips’ dissents focus on two general points:  first, that the majority’s holding that HBNR applies to health apps expands the Rule’s scope beyond what was originally intended by the Commission and Congress;[8] and second, that the Statement undermines ongoing rulemaking by the FTC and the Department of Health and Human Services (“HHS”) meant to address the same or similar issues.[9]

In the first point, the dissenting commissioners argue that the majority misapplies the meaning of the term “health care providers” as intended under the Social Securities Act when construing HBNR’s use of that phrase to include health apps.[10]  They note that HHS guidance limits that phrase to imply “traditional forms” of health care providers (i.e., doctors, nurses, nursing homes, pharmacies, and the like).[11]  Furthermore, the dissenters dispute the majority’s interpretation of HBNR’s definition of PHRs.  According to HBNR, PHRs contain a user’s data “that can be drawn from multiple sources…”[12]  Specifically, Wilson and Phillips argue that the Statement’s assertion that “an app that draws information from multiple sources is covered [by HBNR], even if the health information comes from only one source” directly conflicts with the Commission’s existing online business guidance defining PHR-related entities.[13]

In the second point, Wilson and Phillips argue that the Statement undermines ongoing rulemaking by the FTC designed to determine whether HBNR applies to health apps, as well as parallel rulemaking HHS has undertaken to address its approach to health apps under the Health Insurance Portability and Accountability Act (“HIPAA”) privacy standards.[14]  By disregarding the public notice and comment process for these ongoing rulemakings, Commissioner Phillips argues that the majority undermined the spirit of the Administrative Procedure Act in issuing the Statement.[15]  Commissioner Wilson likewise notes that the FTC already sought input from the public in its ongoing rulemaking to a number of questions which the Statement’s “clarification” essentially renders null.[16]

Despite the detailed arguments offered by Commissioners Wilson and Phillips, the separate remarks issued in support of the Statement by Chair Khan and Commissioners Chopra and Slaughter offer only cursory defenses in reply.[17]  So, it seems the majority is willing to push past such arguments to advance a shift in the FTC’s approach to protecting digital health data.  After not enforcing HBNR for more than a decade, the Commission’s assertion that it will begin pursuing hefty civil penalties against all HBNR violators, including health apps, should put the consumer data industry on notice that regulators are placing renewed focus on privacy.  While some corporate players have expressed support for the FTC’s move,[18] some legal experts have voiced concern over the scope of the Statement, suggesting that the Commission’s attempt to clarify HBNR as applying to health apps may raise more questions than it answers.[19]

The FTC’s move can be viewed as part of a broader federal (and international) trend toward stricter regulation of tech companies’ use of consumer data, as seen in the heightened scrutiny recently faced by major players like Facebook and Google.[20]  Although one may sympathize with the majority’s aim of curbing lax data controls and illegal consumer data sharing by health apps, affected companies have cause to criticize the Statement for those reasons expressed by Commissioners Wilson and Phillips.  Although the Statement sought to clarify the meaning of HBNR as applied to health apps, its arguably over-broad interpretation of HBNR could open ground for affected companies to challenge the Commission’s interpretation.  Furthermore, by disregarding ongoing FTC and HHS rulemaking addressing the same or similar issues, the Statement undermines regulatory predictability needed by industry for effective business planning.  Thus, though privacy and consumer advocates may applaud the FTC’s recent move, many large and small health tech businesses may find cause for concern in the Commission’s aggressive new HBNR enforcement approach.

