16 C.F.R. · Commercial Practices
16 C.F.R. § 318.3

Breach notification requirement.

Title 16 C.F.R. ● ACTIVE Primary Source
Regulatory Text

16 C.F.R. § 318.3 — Breach notification requirement.

§ 318.3 Breach notification requirement. (a) In general. In accordance with §§ 318.4, 318.5, and 318.6, each vendor of personal health records, following the discovery of a breach of security of unsecured PHR identifiable health information that is in a personal health record maintained or offered by such vendor, and each PHR related entity, following the discovery of a breach of security of such information that is obtained through a product or service provided by such entity, shall: (1) Notify each individual who is a citizen or resident of the United States whose unsecured PHR identifiable health information was acquired by an unauthorized person as a result of such breach of security; and (2) Notify the Federal Trade Commission. (b) Third party service providers. A third party service provider shall, following the discovery of a breach of security, provide notice of the breach to an official designated in a written contract by the vendor of personal health records or the PHR related entity to receive such notices or, if such a designation is not made, to a senior official at the vendor of personal health records or PHR related entity to which it provides services, and obtain acknowledgment from such official that such notice was received. Such notification shall include the identification of each customer of the vendor of personal health records or PHR related entity whose unsecured PHR identifiable health information has been, or is reasonably believed to have been, acquired during such breach. For purposes of ensuring implementation of this requirement, vendors of personal health records and PHR related entities shall notify third party service providers of their status as vendors of personal health records or PHR related entities subject to this Part. (c) Breaches treated as discovered. A breach of security shall be treated as discovered as of the first day on which such breach is known or reasonably should have been known to the vendor of personal health records, PHR related entity, or third party service provider, respectively. Such vendor, entity, or third party service provider shall be deemed to have knowledge of a breach if such breach is known, or reasonably should have been known, to any person, other than the person committing the breach, who is an employee, officer, or other agent of such vendor of personal health records, PHR related entity, or third party service provider.

Source: ecfr.gov · govinfo.gov — public domain Official Source ↗
Root-LD Entity Data
◈ Machine-Readable Provenance Record Root-LD v1.0 · boisestandard.org
Federation ID
BS-CFR16-SEC-D00CC7
Entity Class
REGULATION / FEDERAL-CFR-SECTION
Domain Signature
boisestandard.org
Citation
16 C.F.R. § 318.3
Corpus
CFR — Code of Federal Regulations
Status
✓ ACTIVE
Source
PRIMARY-SOURCE
Source Verified
✓ TRUE
Content Hash
56cad258dd764cf7...
Semantic Edges
Pending — corpus passes queued
The regulatory text of 16 C.F.R. § 318.3 is reproduced from the official Code of Federal Regulations as published by the Office of the Federal Register and the National Archives and Records Administration.
Navigate Corpus — Title 16 C.F.R.
◈ Provenance
boisestandard.org United States Law CFR Title 16 16 C.F.R. § 318.3