Chapter 8: Medical Privacy

CIPP/US FTC health breach notification rule guide

The FTC Health Breach Notification Rule addresses certain breaches of identifiable health information held by covered vendors and related entities outside HIPAA.

Practical example

For a health application incident, identify the entity, information, breach facts and whether the rule's notice framework applies before choosing a response.

Common mistake

Assuming that HIPAA and the FTC health breach notification rule cover the same entities or information.

The FTC maintains the Health Breach Notification Rule and related compliance material. Coverage and notification duties depend on the defined entity, information and event.

For CIPP/US study, compare the health-record business model with HIPAA coverage before turning to the notice rule.

How this supports CIPP/US study

Use this lesson to separate sectoral scope, data type and regulated entity before testing an exception. Continue with the CIPP/US practice exam.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.