AUG 26, 2009 4:38am ET

Related Links

Cloud-Based Solutions Represent “True Breakthrough” in Collaboration
May 22, 2013
An Agile Approach to Databases
May 22, 2013
Five Secrets to Kick Off an Analytic Project
May 22, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

FTC Breach Rule Now Official

Print
Reprints
Email

The Federal Trade Commission on Aug. 25 published in the Federal Register its final rule governing the reporting of data breaches by vendors of personal health records and online applications that interact with PHRs.

The rule has been available for more than a week but publication starts the clock on compliance (see healthdatamanagement.com/news/PHR-38824-1.html). The rule is effective Sept. 24, 2009, with full compliance required by Feb. 22, 2010. The rule explains the selected dates as follows:

"Two commenters expressed concern that the effective compliance date of 30 calendar days from the date of publication of this final rule would not allow covered entities sufficient time to come into compliance. In response, the Commission notes that the effective compliance date is mandated by the Recovery Act. Moreover, as discussed above, the Commission believes that in many instances the rule will apply to entities that already have obligations to provide notification of data breaches under certain state laws covering medical breaches. As a result, these entities can build upon their existing programs in order to come into compliance with this final rule. Nevertheless, the Commission has determined that it will use its enforcement discretion to refrain from imposing sanctions for failure to provide the required notifications for breaches that are discovered before February 22, 2010."

The Department of Health and Human Services recently published a separate rule that governs notification of data breaches by HIPAA-covered entities (see healthdatamanagement.com/news/stimulus-38838-1.html).

The official final FTC rule is available at gpoaccess.gov/fr/index.html.

This article can also be found at HealthDataManagement.com.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.