FEDERAL · 42 U.S.C. · Chapter 156

Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities

Current through Pub. L. 119-102
Title 42The Public Health and Welfare·Ch. 156 — HEALTH INFORMATION TECHNOLOGY·Subch. III·Pt. A
(a)In general In accordance with subsection (c), each vendor of personal health records, following the discovery of a breach of security of unsecured PHR identifiable health information that is in a personal health record maintained or offered by such vendor, and each entity described in clause (ii), (iii), or (iv) of section 17953(b)(1)(A) of this title, following the discovery of a breach of security of such information that is obtained through a product or service provided by such entity, shall—
(1)notify each individual who is a citizen or resident of the United States whose unsecured PHR identifiable health information was acquired by an unauthorized person as a result of such a breach of security; and
(2)notify the Federal Trade Commission.
(b)Notification by third party service

Free access — add to your briefcase to read the full text and ask questions with AI

42 U.S.C. § 17937 (Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

§ 17953
42 U.S.C. § 17953
§ 17932
42 U.S.C. § 17932
§ 57a
42 U.S.C. § 57a
§ 1320d
42 U.S.C. § 1320d

Source Credit

History

(Pub. L. 111–5, div. A, title XIII, §13407, Feb. 17, 2009, 123 Stat. 269.)

Editorial Notes

Statutory Notes and Related Subsidiaries

Effective Date
Section effective 12 months after Feb. 17, 2009, except as otherwise specifically provided, see section 13423 of Pub. L. 111–5, set out as a note under section 17931 of this title.