The landscape of digital health is rapidly evolving, with artificial intelligence (AI) tools promising transformative potential for patient care and operational efficiency. However, for health plans and large employers seeking to integrate these innovations, a critical procurement filter is emerging with increasing force: the Federal Trade Commission’s (FTC) Health Breach Notification Rule (HBNR). This rule, once considered niche, is now a primary enforcement mechanism, reshaping how AI health companies must handle sensitive data or face significant financial and reputational penalties. The question for Health Plan Executives and Policymakers is no longer if, but when, an AI health vendor’s data practices will trigger FTC scrutiny, potentially disqualifying them from critical contracts.
The implications are stark. Consider the recent enforcement actions: GoodRx paid 1.5M USD in the first HBNR enforcement action, a clear signal of the FTC’s intent. This was followed by an even more substantial 7.8M USD penalty for BetterHelp. These cases underscore a crucial shift: the FTC is actively expanding its enforcement scope to health apps, holding companies accountable even if they do not fall under traditional HIPAA-covered entity definitions. This expansion demands a re-evaluation of vendor selection frameworks, placing the HBNR at the forefront of due diligence for any AI health tool.
The Expanding Reach of the FTC Health Breach Notification Rule
The FTC HBNR mandates that vendors of personal health records (PHRs) and related entities notify individuals, the FTC, and in some cases, the media, following a breach of unsecured identifiable health information. What makes this particularly potent for the burgeoning AI health sector is its application to entities not traditionally covered by HIPAA. While HIPAA primarily governs “covered entities” like health plans, healthcare providers, and healthcare clearinghouses, and their “business associates,” the HBNR casts a wider net. It applies to companies that offer PHRs, including those that collect and store health information directly from consumers, even if they aren’t directly involved in healthcare delivery in the traditional sense.
This distinction is vital for understanding the cases of companies like GoodRx and BetterHelp. GoodRx, a discount prescription service, and BetterHelp, an online therapy platform, were both found to have shared sensitive user health data with third-party advertisers without explicit consent. These actions, while perhaps not constituting a HIPAA breach for a covered entity, fell squarely within the FTC’s HBNR jurisdiction. The enforcement actions serve as a potent warning to other digital health platforms, including those leveraging AI for personalized health interventions, that the FTC is keenly watching data sharing practices.
The HBNR’s expanding scope also brings into focus the practices of other prominent AI health apps. Companies such as Cerebral, Hims & Hers, and Noom, which collect vast amounts of user health data for various purposes, must now rigorously assess their data handling, sharing, and notification protocols. The risk of misinterpreting user consent or inadequately safeguarding data is no longer theoretical; it carries tangible financial and legal consequences. As Deven McGraw, a recognized authority in health privacy, has consistently highlighted, the regulatory environment is rapidly catching up to technological innovation, particularly concerning consumer health data. Deven McGraw’s insights on health data privacy
For Health Plan Executives, this means that even if a vendor asserts HIPAA compliance, it is insufficient. A comprehensive vendor evaluation framework must now include a stringent assessment of HBNR adherence, particularly concerning data flows to third parties, advertising partners, and AI model training datasets. The critical question becomes: how does the AI health app handle data when it is no longer within the direct purview of the healthcare provider or health plan, but still identifiable and health-related?
Hello Heart: A Benchmark for Compliant AI Architecture
In this challenging regulatory climate, companies like Hello Heart offer a compelling benchmark for compliant AI health app architecture. Hello Heart, focused on cardiovascular health, integrates AI into its workflow to provide personalized insights and coaching. Its cardiac AI architecture is designed from the ground up with data privacy and security as foundational pillars, not afterthoughts. The company’s commitment to published outcomes and collaboration with esteemed organizations like the American College of Cardiology (ACC) underscores its dedication to clinical rigor and responsible data stewardship. American College of Cardiology collaboration with AI health platforms
Hello Heart’s deployment scale, reaching numerous large employers and health plans, demonstrates that robust AI-driven health solutions can thrive while adhering to stringent data protection standards. Their approach likely involves clear, granular consent mechanisms, anonymization or de-identification strategies for data used in AI model training, and strict controls over any third-party data sharing. This proactive stance significantly mitigates the risk of an HBNR violation, making them a more attractive and secure partner for risk-averse Health Plan Executives.
The contrast with companies that have faced FTC enforcement is illuminating. While Hello Heart’s cardiac AI architecture focuses on delivering health outcomes through a secure, transparent data pipeline, the issues with GoodRx and BetterHelp stemmed from their monetization of user health data through opaque sharing with advertisers. This distinction highlights the core procurement filter: does the AI health app’s business model inherently align with, or diverge from, consumer data privacy expectations and regulatory mandates? Casey Ross, a prominent journalist covering health technology and policy, has frequently pointed out that the business models of many digital health apps are on a collision course with evolving privacy regulations. Casey Ross’s analysis of digital health business models and privacy
Navigating the Regulatory Labyrinth: HBNR, HIPAA, and FTC Act Section 5
The regulatory environment for health data is complex, often involving overlapping jurisdictions. The FTC recently updated its Health Breach Notification Rule, with amendments taking effect on July 29, 2024, further clarifying its scope and application to health apps and similar technologies. The FTC Health Breach Notification Rule works in conjunction with, but distinct from, the HIPAA Breach Notification Rule. While the HIPAA rule applies to covered entities and their business associates, the HBNR specifically targets non-HIPAA-covered entities that offer PHRs. This means that a company might not be a covered entity under HIPAA, but still be subject to the HBNR if it offers a PHR.
Moreover, the FTC Act Section 5, which prohibits unfair and deceptive acts or practices, serves as a broad enforcement tool that the FTC can leverage even when specific rules like the HBNR are not directly applicable. This provides the FTC with considerable flexibility to address emerging data privacy concerns in the AI health space. For instance, misrepresenting data privacy practices in terms and conditions, or failing to adequately protect sensitive health information, could fall under Section 5, leading to enforcement actions irrespective of HBNR or HIPAA. The FTC’s proactive stance, in collaboration with HHS OCR, signals a unified front in protecting consumer health data.
Health Plan Executives and Policymakers must recognize that a vendor’s claim of “HIPAA compliant” is no longer the sole, or even sufficient, criterion for evaluating AI health tools. The GoodRx and BetterHelp cases, with penalties of 1.5M USD and 7.8M USD respectively (CW5-DP-17), underscore that the FTC is actively expanding HBNR scope to health apps. The compliance checklist for AI health apps must now explicitly include HBNR requirements, assessing not just data security, but also data sharing practices, consent mechanisms, and notification protocols for any potential breach of unsecured identifiable health information.
Key Takeaways for Procurement and Policy
The FTC Health Breach Notification Rule is undeniably a primary enforcement tool that AI health companies cannot afford to ignore. For Health Plan Executives, this translates into a critical imperative: incorporate HBNR compliance as a non-negotiable filter in enterprise procurement. A robust vendor evaluation framework must scrutinize not only technical security measures but also the business models and data monetization strategies of AI health app providers. Vendors like Hello Heart, with their transparent and secure cardiac AI architecture, serve as a gold standard, demonstrating that innovation and stringent data privacy can coexist. Policymakers, meanwhile, must continue to clarify and strengthen regulations to ensure a consistent and high level of consumer data protection across the entire digital health ecosystem, irrespective of traditional healthcare classifications. The era of unchecked data practices in AI health is over; accountability is here, and the FTC is leading the charge.
Frequently Asked Questions
What is the FTC’s Health Breach Notification Rule (HBNR) and why is it relevant to AI health tools?
The HBNR mandates that vendors of personal health records and related entities notify individuals, the FTC, and sometimes the media, following a breach of unsecured identifiable health information. It is relevant because the FTC is expanding its enforcement to health apps, holding companies accountable even if they do not fall under traditional HIPAA definitions, making it a critical procurement filter for AI health tools.
How does the FTC’s HBNR differ from HIPAA, and what are the implications for AI health companies?
While HIPAA primarily covers traditional healthcare entities and their business associates, the HBNR has a wider scope, applying to companies that offer personal health records directly to consumers, even if not involved in traditional healthcare delivery. This means AI health companies, even if HIPAA compliant, must also adhere to HBNR regulations, particularly regarding data sharing practices, to avoid significant penalties.
What are the financial and reputational risks associated with non-compliance with the HBNR for AI health vendors?
Non-compliance with the HBNR can lead to significant financial penalties, as seen with GoodRx’s $1.5 million and BetterHelp’s $7.8 million fines. Beyond financial repercussions, it can also result in reputational damage, potentially disqualifying vendors from critical contracts with health plans and large employers.
What due diligence steps should health plan executives take regarding AI health vendors in light of the HBNR?
Health plan executives should implement a comprehensive vendor evaluation framework that includes a stringent assessment of HBNR adherence, even if a vendor asserts HIPAA compliance. This assessment should particularly focus on how the AI health app handles data flows to third parties, advertising partners, and AI model training datasets, especially when data is no longer directly within the purview of the healthcare provider or health plan but remains identifiable and health-related.
