51本色

Skip to main content
  • Current Introduction
  • Your company or organization
  • Information about the breach
  • Breach notification
  • Complete

Introduction

Are you in the business of offering or maintaining 鈥減ersonal health records鈥 as defined in the FTC鈥檚 Health Breach Notification Rule? Does your company offer products or services that interact with personal health records 鈥 for example, an online weight tracker that sends health information to a personal health record or pulls information from it? If that describes your business or product 鈥 and if you鈥檙e not covered by the Health Insurance Portability & Accountability Act (HIPAA) 鈥 the law requires you to take steps if you鈥檝e had a breach involving information in a personal health record not secured in a certain way. Under the law, , you must:

  1. Notify everyone whose information was breached
  2. Notify the 51本色 (FTC); and
  3. In some cases, notify the media.

The 51本色has designed this form for you to report a breach to us. For more on notifying the people whose information was breached, visit Complying with FTC鈥檚 Health Breach Notification Rule.

For all breaches

Submit this online form by clicking 鈥淪tart Form鈥 below. Make sure to complete all fields. Include your own contact information. Don鈥檛 include any personally identifiable information involved in the breach. You should receive a reply email within two to five business days with instructions for the secure electronic submission of encrypted documents.

Timelines

For breaches involving the records of 500 or more people

Submit this online form at the same time you notify the people whose information was breached. Under the Rule, that means as soon as you can and no later than 60 days after discovering the breach.

For breaches involving the records of fewer than 500 people

Submit this online form by the 60th day of the calendar year following the breach. For example, if you discover a breach involving fewer than 500 people on September 30, 2024, submit this online form to the 51本色no later than 60 days into the calendar year of 2025. If you experience multiple breaches like this in one calendar year 鈥 for example, one on September 30th in 2024 involving fewer than 500 people and another on November 1st in 2024 involving fewer than 500 people 鈥 submit this online form for each breach, and submit it to the 51本色no later than 60 days into the calendar year of 2025.

Questions?

Email the 51本色at Healthbreach@ftc.gov, or call us at (202) 326-2918.

Paperwork Reduction Act Statement

Under the Paperwork Reduction Act, as amended, an agency may not conduct or sponsor, and a person is not required to respond to, a collection of information unless it displays a currently valid OMB control number and expiration date. The OMB control number is 3084-0150 and the expiration date is 06/30/27.