in

FTC and OCR Subject Joint Web site Monitoring Warning Letter

FTC and OCR Subject Joint Web site Monitoring Warning Letter


If you’re concerned with any well being info, even in case you are not coated by HIPAA, you have to be conscious of the federal government’s current place that there could also be severe privateness and severe dangers with use of on-line monitoring applied sciences that could be current on a web site or cellular app that tracks client delicate private well being info.  Final week, the Federal Commerce Fee (“FTC”) and the U.S. Division of Well being and Human Companies’ Workplace for Civil Rights (“OCR”) issued a joint letter (“Joint Letter”) (https://www.ftc.gov/system/information/ftc_gov/pdf/FTC-OCR-Letter-Third-Occasion-Trackers-07-20-2023.pdf) to roughly 130 hospitals and telehealth suppliers, warning that on-line monitoring applied sciences built-in into their web sites and/or cellular apps could also be improperly disclosing private well being knowledge to 3rd events.

Know-how corresponding to Google Analytics and Meta/Fb Pixel can observe a person’s on-line actions which, unbeknownst to the person, could collect personally identifiable info. If you’re a coated entity or enterprise affiliate (a “regulated entity”) beneath HIPAA, you will need to adjust to the HIPAA Privateness, Safety, and Breach Notification Guidelines, with regard to protected well being info (“PHI”) that’s transmitted or maintained in digital or another type or medium.  Below HIPAA, impermissible makes use of/disclosures are presumed to be a reportable breach except it may be demonstrated that there’s a low chance of compromise when thought of beneath the 4 elements set forth at 45 C.F.R. 164.402

Impermissibly disclosed info could vary from a client’s looking historical past on a regulated entity’s webpage, which might not be a reportable breach if a willpower is made that there’s a low chance that the buyer’s PHI was compromised, to one thing extra delicate such because the disclosure of a affected person’s well being circumstances, diagnoses, drugs, medical therapies, frequency of visits to well being care professionals, and the place a person seeks medical remedy. Such disclosures may end up in monetary loss, stigma, discrimination, psychological anguish, or id theft, amongst many different potential repercussions. It needs to be famous that in December 2022, OCR issued a bulletin which, amongst different issues, cautioned that regulated entities are usually not permitted to make use of monitoring applied sciences in a way that might lead to impermissible disclosures of PHI to monitoring know-how distributors. The Joint Letter serves as a reinforcement of the warnings made final 12 months. The American Hospital Affiliation (“AHA”) submitted feedback to OCR lately asking that they rethink the place taken within the December 1, 2022 Bulletin. Particularly, the AHA believes that the steerage is just too broad and can lead to important antagonistic penalties for hospitals, sufferers and the general public at giant, and that by treating an IP tackle as PHI beneath HIPAA, public entry to credible well being info will probably be decreased.

See also  Consumer Protections Meet Political Pushback: Lessons from States Studying Facility Fees

The federal government letter warned that even when an entity just isn’t coated by HIPAA, it nonetheless has an obligation to guard in opposition to impermissible disclosures of non-public well being info beneath the FTC Act. That is true even when a 3rd get together developed the web site or cellular app and even when the data obtained by way of use of a monitoring know-how just isn’t used for any advertising and marketing functions. The FTC and OCR strongly urged monitoring of information flows to 3rd events by way of applied sciences built-in into web sites, and warned that disclosure of such info and not using a client’s authorization can, in some circumstances, violate the FTC Act in addition to represent a breach of safety beneath the FTC’s Well being Breach Notification Rule.

You possibly can see Fox Rothschild attorneys’ associated posts right here:

Odia Kagan’s Submit on Third-Occasion Trackers’ Dangers (July 2022): Watch out for Third-Occasion Trackers Like Meta Pixel. Ignoring Them Might Be Pricey. | HIPAA & Well being Data Know-how (foxrothschild.com)

Elizabeth Litten’s Submit on OCR’s December 2022 Bulletin (December 2022): OCR Warns Suppliers About Affected person Information Trackers | HIPAA & Well being Data Know-how (foxrothschild.com)

Elizabeth Litten’s Submit on the FTC’s Criticism Alleging that BetterHelp Engaged in Unfair and Unreasonable Privateness Practices (March 2023): Higher Hold Well being Information Personal, FTC Indicators to On-Line Well being Care Suppliers | HIPAA & Well being Data Know-how (foxrothschild.com)


#FTC #OCR #Subject #Joint #Web site #Monitoring #Warning #Letter

Supply hyperlink

What do you think?

Written by HealthMatters

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

WW (Weight Watchers) Weekly Meal Plan #243

WW (Weight Watchers) Weekly Meal Plan #243

Navigator Information FAQs of the Week: Monetary Help Out there By the Market

Navigator Information FAQs of the Week: Monetary Help Out there By the Market