Skip to main content
Framework library
Framework module · ftc-health-breach-notification-rule

FTC Health Breach Notification Rule

The federal breach-notification rule for vendors of personal health records and related entities that are not covered by HIPAA, including applicable health apps and connected services.

16 CFR Part 318 (2024 amended rule) · Federal Trade Commission · published 2024-05-30

Standing today
Directory entry

00Answer

from the registry record
What is FTC Health Breach Notification Rule?
The federal breach-notification rule for vendors of personal health records and related entities that are not covered by HIPAA, including applicable health apps and connected services.
Who does FTC Health Breach Notification Rule apply to?
FTC Health Breach Notification Rule applies to consumer health, technology, US, per Federal Trade Commission.
What is the current version of FTC Health Breach Notification Rule?
The current edition is 16 CFR Part 318 (2024 amended rule), issued by Federal Trade Commission and published 2024-05-30. Source: https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule.
What does an assessment under FTC Health Breach Notification Rule require?
No control catalog has been ingested for FTC Health Breach Notification Rule yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

FTC Health Breach Notification Rule is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; applicability logic and notification obligations have not been modelled as a requirement catalog.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Applicability · Consumer notice · FTC notice · Media notice · Service-provider notice
Applies to
consumer health · technology · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

1 edition
16 CFR Part 318 (2024 amended rule)Current edition2024-05-30

06Related frameworks

scored from registry facts
  1. Also applies to consumer health · The first US law protecting consumer health data that falls outside HIPAA, with a private right of action — an increasingly distinct healthcare-SaaS ask, separate from HIPAA itself.

  2. CCPA/CPRA + US state privacyCCPA/CPRA with 2026 CPPA regulations

    Same framework family · California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.

  3. Also applies to technology · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.

  4. Also applies to technology · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

FTC Health Breach Notification Rule | ControlFrame