Compare with different regulatory event:

Description

Adopted FTC Health Breach Notification Rule

On 17 August 2009, the Federal Trade Commission (FTC) adopted the Health Breach Notification Rule outlining notification requirements for vendors of personal health records, such as platforms allowing consumers to access health data and third-party applications for personal health records. In particular, the Rule requires entities to notify the consumers and the FTC of data breaches without unreasonable delay and no later than 60 days after the discovery of unauthorised data access and within 10 days if more than 500 consumers will be affected. The Rule came into force on 24 September 2009, and the FTC stated that it would enforce it starting on 22 February 2010 to enable entities to implement the new security procedures.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
platform intermediary: other
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2009-08-17
adopted

On 17 August 2009, the Federal Trade Commission (FTC) adopted the Health Breach Notification Rule o…

2009-09-24
in force

On 24 September 2009, the Federal Trade Commission (FTC) Health Breach Notification Rule entered in…

2010-02-22
in force

On 22 February 2010, the Federal Trade Commission (FTC) started enforcing the Health Breach Notific…