Understanding the Regulatory Gap: HIPAA's Limitations and the FTC Rule
The healthcare cybersecurity landscape has fundamentally shifted as digital health innovation outpaced regulatory architecture. While HIPAA remains the dominant framework for entities handling protected health information (PHI), its scope excludes a rapidly expanding ecosystem of non-HIPAA entities: fitness tracking platforms, mental health applications, fertility apps, and direct-to-consumer wearables that collect, process, and store sensitive health data. This regulatory gap has created a critical vulnerability—one that the Federal Trade Commission has begun to address through aggressive enforcement of its Health Breach Notification Rule (16 CFR Part 318).
The FTC Health Breach Notification Rule applies to vendors of personal health records and PHR related entities that are not covered under HIPAA. This distinction is crucial for healthcare CISOs and compliance officers: your organization may fall outside HIPAA's protective umbrella yet remain subject to FTC enforcement authority. Understanding this overlapping jurisdiction prevents the catastrophic compliance failures that have resulted in multi-million-dollar FTC penalties against prominent health tech companies over the past three years.
Scope and Applicability: Who Must Comply?
The FTC's authority extends to three primary categories of non-HIPAA entities. First, vendors of personal health records (PHR vendors) who maintain electronic systems of health information that individuals can access, download, and control. Second, PHR related entities—such as employers, health insurers, or pharmacies that offer PHR functionality to consumers as a standalone service (not as part of HIPAA-covered clinical operations). Third, college health centers and other entities maintaining health information outside traditional HIPAA coverage.
The operational definition hinges on whether your platform collects, maintains, or transmits "individually identifiable health information." This includes any information that identifies an individual or reasonably can identify an individual, combined with health information such as diagnoses, medication records, treatment plans, or genetic data. A fitness app that correlates step counts with historical heart disease suggests clinical insight; a mental health chatbot collecting mood data paired with demographic identifiers; a period-tracking application storing intimate reproductive health patterns—all fall within FTC jurisdiction if they lack HIPAA-covered status.
CISOs managing portfolio risk across multiple platforms must perform entity mapping and categorization. A health system launching a direct-to-consumer telehealth app may face dual compliance obligations (HIPAA for institutional operations, FTC for the standalone consumer app). Conversely, a health tech startup remains solely subject to FTC oversight. This distinction determines which frameworks apply and how breach response procedures are triggered.
Core Security and Breach Notification Obligations
The FTC Rule establishes three foundational requirements aligned with NIST Cybersecurity Framework principles and CIS Controls. First, entities must implement administrative, technical, and physical safeguards consistent with the Health Insurance Portability and Accountability Act Security Rule standards—despite not being HIPAA-covered. This creates a curious regulatory mandate: non-HIPAA entities must effectively mirror HIPAA's security requirements without the compliance infrastructure that covered entities have built.
Second, breach notification is mandatory. When unsecured individually identifiable health information is acquired without authorization, affected individuals must be notified without unreasonable delay and in no case later than 60 calendar days after discovery of a breach. Notification must include (1) a description of the breach, (2) the types of information involved, (3) steps individuals should take, (4) what the entity is doing to investigate and mitigate harm, and (5) contact information for questions. Unlike HIPAA's stricter timeline, the FTC Rule permits a 60-day window—a window that must be actively managed through mature breach detection and incident response protocols aligned with NIST's incident response function.
Third, media notification is required when breaches affect more than 500 residents of a state or U.S. territory. Prominent media outlets in affected jurisdictions, plus the major media outlets serving the nation, must be notified simultaneously. This public disclosure carries reputational and business continuity risk that extends beyond compliance penalties.
Practical Implementation Guidance for Healthcare Technology Leaders
Organizations subject to the FTC Health Breach Notification Rule should implement a tiered approach to compliance. Begin with a detailed HIPAA/FTC regulatory mapping exercise using HITRUST as a common control framework. HITRUST certification provides evidence of rigorous control implementation that satisfies both HIPAA's Security Rule and FTC expectations, regardless of whether your organization is technically covered by HIPAA. This unified framework reduces compliance duplication and strengthens your defense-in-depth posture.
Operationalize breach detection and response aligned with NIST CSF's Detect and Respond functions. Implement continuous monitoring systems, anomaly detection, and security information and event management (SIEM) infrastructure capable of identifying unauthorized access or data exfiltration. Define incident response roles and escalation procedures; establish a 60-day breach notification calendar to ensure timely disclosure. Conduct tabletop exercises with legal, communications, and security teams to simulate breach scenarios involving 500+ affected individuals, ensuring media notification workflows are tested before a real incident.
Document all safeguards and risk assessments. The FTC has demonstrated that enforcement actions focus heavily on adequacy of security measures given the sensitivity of health information and known vulnerabilities. Using FAIR (Factor Analysis of Information Risk) methodology, quantify the gap between your current control environment and regulatory expectations. This documentation becomes your defense if enforcement action occurs.
Finally, establish vendor management protocols. If your platform relies on third-party cloud providers, analytics vendors, or service integrators, include contractual language requiring compliance with FTC standards and immediate breach notification. The FTC will hold you accountable for vendors' failures, so due diligence and ongoing monitoring are non-negotiable.
Conclusion: Proactive Risk Management in an Evolving Regulatory Environment
The FTC Health Breach Notification Rule reflects regulators' recognition that health data breaches occur outside traditional HIPAA boundaries—and consumer harm is identical regardless of entity type. For healthcare technology leaders, compliance is not an optional expense but a strategic imperative that protects consumer trust, prevents multi-million-dollar penalties, and demonstrates responsible stewardship of sensitive information. Begin your assessment today by identifying which of your platforms fall within FTC scope, then systematically close compliance gaps using proven frameworks. The cost of proactive compliance is substantially lower than reactive enforcement.