OMB control number

Health Breach Notification Rule

OMB 3084-0150 · FTC.

OMB 3084-0150

The Health Breach Notification Rule ("Rule"), 16 C.F.R. Part 318, requires vendors of personal health records ("PHR") and PHR related entities to provide: (1) notice to consumers whose unsecured personally identifiable health information has been breached; and (2) notice to the Commission. The Rule only applies to electronic health records and does not include recordkeeping requirements. The Rule requires third party service providers (i.e., those companies that provide services such as billing or data storage) to notify vendors of personal health records (PHR) and PHR related entities following the discovery of a breach; those entities in turn must provide notification to consumers and the Commission. To notify the FTC of a breach, the Commission developed a form for entities subject to the Rule to complete and return to the agency. The proposed amendments pertain to, among others: (1) the coverage of the rule—specifically, the rule’s coverage of developers of many health applications (“apps”) and PHR identifiable health information that is drawn from multiple sources; (2) methods of notice; and (3) the content of notice.

The latest form for Health Breach Notification Rule expires 2027-06-30 and can be found here.

OMB Details

Single-person Breaches

Federal Enterprise Architecture: Economic Development - Business and Industry Development

Form Not ApplicableNotice of Breach of Health InformationFillable FileableForm and instruction

Review document collections for all forms, instructions, and supporting documents - including paper/printable forms.