The Federal Trade Commission (FTC) updated its health breach notification rule (HBNR) on April 26, 2024. The final rule expanded the scope of the HBNR to cover health applications and similar technologies, to limit sharing of sensitive health data, and to update reporting obligations for data breaches. The updated rule took effect on July 29, 2024.

The HBNR was originally adopted in 2009 to provide protection for consumer health information that fell outside the scope of the Health Insurance Portability and Accountability Act (HIPAA). However, enforcement under the HBNR and reporting to the FTC of breaches was minimal until recently.