{"id":430,"date":"2021-09-22T11:28:57","date_gmt":"2021-09-22T15:28:57","guid":{"rendered":"https:\/\/pbacyber.com\/?p=430"},"modified":"2021-09-22T11:28:57","modified_gmt":"2021-09-22T15:28:57","slug":"ftc-issues-policy-statement-clarifying-data-privacy-obligations-for-digital-health","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2021\/09\/22\/ftc-issues-policy-statement-clarifying-data-privacy-obligations-for-digital-health\/","title":{"rendered":"FTC Issues Policy Statement Clarifying Data Privacy Obligations for Digital Health \u00a0"},"content":{"rendered":"<p>By Jennifer K. Wagner<\/p>\n<p>&nbsp;<\/p>\n<p>On September 15, the Federal Trade Commission (FTC) <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596364\/statement_of_the_commission_on_breaches_by_health_apps_and_other_connected_devices.pdf\">issued a Policy Statement<\/a> \u201cOn Breaches by Health Apps and Other Connected Devices,\u201d the most recent step taken by the FTC to signal its interest in preventing abusive data practices and ensuring relevant consumer protections for digital health. This step came about through a 3-2 vote by the commissioners during an <a href=\"https:\/\/www.ftc.gov\/news-events\/audio-video\/video\/open-commission-meeting-september-15-2021\">open commission meeting<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>The focus of the statement is the Health Breach Notification Rule (HBN Rule), which we <a href=\"https:\/\/pbacyber.com\/index.php\/2020\/05\/19\/ftc-undertakes-10-year-review-of-health-breach-notification-rule-seeks-public-comments\/\">reported<\/a> last year in May 2020 was <a href=\"https:\/\/www.federalregister.gov\/documents\/2020\/05\/22\/2020-10263\/health-breach-notification\">undergoing<\/a> a 10-year review by the FTC. During the 90-day public comment period, only 26 comments were submitted. Among them, for example, the American Medical Informatics Association (AMIA) <a href=\"https:\/\/downloads.regulations.gov\/FTC-2020-0045-0009\/attachment_1.pdf\">criticized<\/a> the HBN rule as \u201cstructurally flawed\u201d and recommended that the FTC take the opportunity to develop guidance to clarify the scope of identifiable health information in a personal health record (PHR) and ultimately \u201creorient\u201d the HBN rule so that it is more suitable for the ever-changing digital health industry. The Healthcare Information and Management Systems (HIMSS) and Personal Connected Health Alliance (PCHAlliance) <a href=\"https:\/\/downloads.regulations.gov\/FTC-2020-0045-0023\/attachment_1.pdf\">submitted joint comments<\/a>, describing the HBN Rule as \u201ca critical piece in a broader, overarching health data privacy regulatory system\u201d but also calling for the FTC to modernize its terminology to suit today\u2019s digital health environment. The CARIN Alliance <a href=\"https:\/\/downloads.regulations.gov\/FTC-2020-0045-0016\/attachment_1.pdf\">expressed<\/a> its ongoing support for the HBN Rule, while the Connected Health Initiative <a href=\"https:\/\/downloads.regulations.gov\/FTC-2020-0045-0027\/attachment_1.pdf\">suggested<\/a> broader legislative reform for data privacy was needed. It appears that only <a href=\"https:\/\/downloads.regulations.gov\/FTC-2020-0045-0024\/attachment_1.pdf\">one Attorney General submitted public comments<\/a>: then California Attorney General Xavier Becerra\u2014notably now serving <a href=\"https:\/\/www.hhs.gov\/about\/leadership\/xavier-becerra.html\">as Secretary<\/a> of the Department of Health and Human Services. In those comments, Becerra called upon the FTC to \u201calign\u201d the HBN Rule with the HIPAA rule on breach notifications, underscoring that such a tighter alignment \u201cbenefits consumers and serves Congress\u2019s intent.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>The <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596364\/statement_of_the_commission_on_breaches_by_health_apps_and_other_connected_devices.pdf\">FTC policy statement issued<\/a> this month was accompanied by comments or remarks by each of the commissioners. Commissioners <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596356\/wilson_health_apps_policy_statement_dissent_combined_final.pdf\">Wilson<\/a> and <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596328\/hbnr_dissent_final_formatted.pdf\">Phillips<\/a> each filed dissenting statements criticizing the approach taken, with Wilson framing the statement not as a clarification but as an expansion of the HBN Rule and Phillips claiming the majority is \u201creimagining\u201d the scope and, in effect, circumventing \u201ctwo ongoing rulemaking processes.\u201d FTC Chair <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596360\/remarks_of_chair_lina_m_khan_regarding_health_breach_notification_rule_policy_statement.pdf\">Khan\u2019s remarks<\/a> responded to the dissents and indicated the policy statement is \u201cconsistent with\u2014and, in fact, serves to clarify\u2014the FTC\u2019s earlier guidance\u201d on the HBN Rule. Commissioner <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596352\/20210915_final_chopra_oral_remarks_health_breach_notification_rule.pdf\">Chopra\u2019s statement<\/a> called attention to the failures of predecessors on the Commission to enforce the HBN Rule and confirmed that the FTC has \u201cnot collected a single penny in penalties\u201d for consumer data breaches. In Commissioner <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596320\/rks_remarks_on_health_breach_policy_statement_09152021.pdf\">Slaughter\u2019s prepared remarks<\/a>, she reminded everyone that the policy statement does not change the underlying law for the HBN Rule and made a bold closing, calling for the FTC to \u201clead a market shift towards data minimalism.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>The substance of the <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596364\/statement_of_the_commission_on_breaches_by_health_apps_and_other_connected_devices.pdf\">FTC Policy Statement<\/a> is straightforward. Apps that collect data from multiple sources through APIs (application programming interfaces) are covered by this rule. Breaches triggering the required notifications are any form of unauthorized access to individual\u2019s information, not merely malicious activity. Violations of the HBN Rule are punishable by civil penalties of up to $43,792 per violation per day. The FTC Policy Statement references the FTC <a href=\"https:\/\/www.ftc.gov\/tips-advice\/business-center\/guidance\/mobile-health-app-developers-ftc-best-practices\">Best Practices for Mobile Health App Developers<\/a> as well as the <a href=\"https:\/\/www.ftc.gov\/tips-advice\/business-center\/guidance\/mobile-health-apps-interactive-tool#which\">interactive tool<\/a> to help mobile health app developers understand which laws apply to their products issued five years ago in 2016.<\/p>\n<p>&nbsp;<\/p>\n<p>In the months and years ahead, we expect increasing attention by the FTC to digital health technologies. While the June 25, 2021 Supreme Court decision in <a href=\"https:\/\/www.supremecourt.gov\/opinions\/20pdf\/20-297_4g25.pdf\">Transunion LLC v. Ramirez<\/a> might have made it a bit trickier for the FTC to fulfill its consumer protection role, the digital health sector is an obvious target for more stringent enforcement of cybersecurity and privacy measures for the apps and platforms as well as closer scrutiny of mergers and acquisitions, data engineering practices, and health claims through the doctrinal lenses of anti-competition, fairness, and deception. Additionally, with President Biden\u2019s <a href=\"https:\/\/www.law.georgetown.edu\/news\/georgetown-laws-alvaro-bedoya-nominated-as-ftc-commissioner\/\">nomination of Alvaro Bedoya<\/a> to replace Commissioner Chopra at the FTC and <a href=\"https:\/\/www.blumenthal.senate.gov\/imo\/media\/doc\/2021.09.20%20-%20FTC%20-%20Privacy%20Rulemaking.pdf\">increasing pressure from senators<\/a> for new consumer data privacy rulemaking, all signs point toward the FTC taking a more aggressive approach to ensure fairness in digital health.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>Jennifer K. Wagner, J.D., Ph.D., is a solo practicing attorney and an assistant professor of law, policy &amp; engineering at Pennsylvania State University. She is a former contributing editor of the Genomics Law Report and has published scholarly articles in prominent legal and scientific journals, including the Journal of Law &amp; Biosciences; Journal of Law, Medicine, &amp; Ethics; Albany Law Journal of Science &amp; Technology; Virginia Sports and Entertainment Law Journal; North Carolina Journal of Law and Technology; Nature Communications; Nature Medicine; American Journal of Human Genetics; Genetics in Medicine; and PLOS Genetics. She served as a AAAS Congressional Fellow in a U.S. Senator\u2019s office in 2014-2015, and her work has been cited by the Supreme Court of the United States. You may follow her on <a href=\"https:\/\/twitter.com\/\">Twitter<\/a> as @DNAlawyer. Views expressed are her own. Dr. Wagner discloses she has related research on Consumer Protections for Genomics &amp; Precision Health funded by NHGRI Grant No. R01HG0011051.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Jennifer K. Wagner &nbsp; On September 15, the Federal Trade Commission (FTC) issued a Policy Statement \u201cOn Breaches by Health Apps and Other Connected Devices,\u201d the most recent step taken by the FTC to signal its interest in preventing abusive data practices and ensuring relevant consumer protections for digital health. This step came about <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2021\/09\/22\/ftc-issues-policy-statement-clarifying-data-privacy-obligations-for-digital-health\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[36,43,32],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/430"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=430"}],"version-history":[{"count":2,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/430\/revisions"}],"predecessor-version":[{"id":432,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/430\/revisions\/432"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}