Skip to Main Content

This year has seen the Federal Trade Commission crack down on digital health companies’ irresponsible data use. Since February, it has charged four companies with improperly handling sensitive health information — starting with the first-ever enforcement of its long-stagnant Health Breach Notification Rule, against GoodRx.

Now, the FTC is arming itself for even more aggressive enforcement. In June, it proposed changes to the Health Breach Notification Rule that would clarify its ability to regulate digital health companies and their use of health data — filling in some of the gaps left by the patient privacy law HIPAA, which in many cases doesn’t cover the fast-growing world of online and app-based health and wellness services.

advertisement

“The FTC is seeking to put developers of these kind of apps on notice that they, too, have responsibilities to protect health data,” said Angie Matney, counsel focused on data privacy at the law firm Reed Smith.

Get unlimited access to award-winning journalism and exclusive events.

Subscribe

Exciting news! STAT has moved its comment section to our subscriber-only app, STAT+ Connect. Subscribe to STAT+ today to join the conversation or join us on Twitter, Facebook, LinkedIn, and Threads. Let's stay connected!

To submit a correction request, please visit our Contact Us page.