Lexology February 7, 2023
Most people, and especially health care providers, are familiar with HIPAA and its relation to protecting the privacy and security of a person’s health care information. Now that the Federal Trade Commission (FTC) has taken action for the first time under its Health Breach Notification Rule (which is completely separate from HIPAA), health care providers and other companies engaged in digital health initiatives should recommit to (i) having robust data privacy and security policies and procedures; and (ii) complying with such policies and procedures.
In the FTC’s press release about its first enforcement action in this area, the FTC points out that GoodRx had insufficient policies, and the ones it had in place were not being followed. Another noteworthy item...