RoutineMetric

FTC Health Breach Notification Rule (HBNR) Compliance Tool

Fully updated for strict 2026 FTC amendments and pixel tracking enforcement standards.

Digital health apps, websites, and connected devices that are not subject to HIPAA fall under the enforcement of the FTC. Under the latest rules, sharing health-related data or user logs with ad networks via tracking pixels or analytics SDKs without affirmative user consent constitutes a statutory breach of security. Use this tool to verify applicability, evaluate incident risks, compute regulatory deadlines, and generate a compliance record memorandum.

Profile & System Metadata

FTC HBNR Applicability Checklist

Are you a HIPAA Covered Entity (e.g., hospital, physician) or a Business Associate providing services to one?

Includes user-provided data on symptoms, treatments, medical history, reproductive cycles, dietary logs, heart rates, etc.

E.g., pulls user-typed logs and connects with mobile APIs (Apple HealthKit/Google Fit), wearable sensors, or allows third-party data exchange.

Incident Characteristics & Data Exposure

Commercial Pixel Warning

In 2024-2026, the FTC cracked down on several major digital health companies. Voluntary implementation of marketing track-SDKs without affirmative consent is categorized as an unauthorized breach. The FTC does not require a "hack" to trigger the Rule.

Assessment Summary
HBNR ApplicabilitySubject to FTC HBNR
Breach of Security Triggered?YES (Breach Active)
Regulatory Risk RatingCRITICAL

Your organization acts as a PHR vendor, related entity, or third-party service provider handling unsecured health information that is not subject to HIPAA. You must comply with all 16 CFR Part 318 provisions.
Mandatory Deadlines
Consumer Notice DeadlineWednesday, October 14, 2026Strict 60 calendar days from discovery
FTC Filing DeadlineFriday, August 28, 2026Strict 10 business days after discovery
State Media Notice Required?YES (Required)Deadline: Wednesday, October 14, 2026
Caution: Missing FTC or consumer notification deadlines is treated by federal authorities as a separate, compounding violation of the FTC Act.
Advertisement
Bottom Banner Ad (728x90)

Understanding the FTC Health Breach Notification Rule (HBNR) & 2026 Standards

The Health Breach Notification Rule (HBNR), codified at 16 CFR Part 318, is a critical cornerstone of United States digital privacy regulations. While the Health Insurance Portability and Accountability Act (HIPAA) governs traditional health providers, health insurance companies, and their business associates, a massive ecosystem of consumer wellness tech operates entirely outside HIPAA. The FTC enforces the HBNR to protect consumers using wellness trackers, health websites, and period, fertility, or mental health applications.

The "Pixel" Enforcement Paradigm

Recent statutory revisions and FTC regulatory complaints have significantly expanded the legal definition of a "breach of security." Historically, a breach was understood to mean a traditional malicious cyberattack—such as a database intrusion or SQL injection. However, under strict 2026 guidelines, a breach of security encompasses unauthorized commercial transmission of health data.

If a digital health website or application implements marketing software development kits (SDKs), application programming interfaces (APIs), or tracking cookies (such as those operated by Meta, Google, TikTok, or Pinterest) and shares specific user search terms, health actions, or logged symptoms without first receiving affirmative, explicit user consent, it qualifies as a statutory breach. Organizations cannot bury this sharing in generic privacy policies; consent must be proactive, informed, and separate from terms of service.

Determining HBNR Scope

HBNR coverage relies on three central questions:

  • HIPAA Exemption: Is the entity a "covered entity" or "business associate" under HIPAA? If yes, it is regulated by HHS OCR and exempt from the HBNR. If no, the HBNR is highly likely to apply.
  • PHR Identifiable Health Information: Does the product contain individually identifiable health data? This is defined broadly, encompassing health status, medical history, treatments, exercise logs, caloric intake, symptoms, or prescription names.
  • Multi-Source Capacity: Does the application have the capacity to pull data from more than one source? Under revised guidelines, an application does not need to actually pull data from two sources to qualify; it only needs the technical capacity to do so (e.g., matching user-logged fields with a phone's internal calendar or step counter, or featuring an option to sync with Apple Health or Google Fit).

The High Cost of Non-Compliance

Violations of the HBNR carry substantial financial risks under the FTC Act. For 2026, the maximum civil penalty is $51,744 per violation per day. When assessing penalties, the FTC evaluates:

  • Accrual Period: The total number of days the unauthorized sharing or database breach remained active and unremediated.
  • Notice Delays: Additional penalties accumulate if individual notifications are delayed beyond the statutory 60-day limit or if the FTC is not notified within 10 business days for breaches affecting 500 or more people.
  • Remediation speed: Proactive compliance teams can limit statutory damage risks by conducting regular pixel audits, deploying consent management platforms (CMPs), and documenting contemporaneous decisions using structured compliance memorandums.
Advertisement