CIPP/US FTC health breach notification rule guide
The FTC Health Breach Notification Rule addresses certain breaches of identifiable health information held by covered vendors and related entities outside HIPAA.
Practical example
For a health application incident, identify the entity, information, breach facts and whether the rule's notice framework applies before choosing a response.
Common mistake
Assuming that HIPAA and the FTC health breach notification rule cover the same entities or information.
The FTC maintains the Health Breach Notification Rule and related compliance material. Coverage and notification duties depend on the defined entity, information and event.
For CIPP/US study, compare the health-record business model with HIPAA coverage before turning to the notice rule.
How this supports CIPP/US study
Use this lesson to separate sectoral scope, data type and regulated entity before testing an exception. Continue with the CIPP/US practice exam.
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.