Skip to main content
Guide

The FTC Health Breach Notification Rule 2026 Expansion: Who's Now Covered Beyond HIPAA

When the Federal Trade Commission extracted a $1.5 million civil penalty from GoodRx in 2023 for sharing prescription data with Facebook and Google, it was the agency's first-ever enforcement of a...

11 min read

When the Federal Trade Commission extracted a $1.5 million civil penalty from GoodRx in 2023 for sharing prescription data with Facebook and Google, it was the agency's first-ever enforcement of a rule that had sat dormant since 2009.[1] Two years later, that same rule covers a vastly broader universe of companies. The FTC Health Breach Notification Rule 2026 landscape now sweeps in health apps, fitness trackers, connected devices, fertility platforms, mental health services, and direct-to-consumer wellness technologies that previously fell outside HIPAA entirely. If your organization collects health-related data and isn't a HIPAA covered entity, you are very likely subject to the FTC HBNR expansion, and the penalties for non-compliance now include both federal fines and class-action exposure. This article explains who is covered, what triggers liability, and how to reduce risk before enforcement reaches your door.

The Current Enforcement Landscape

OCR Enforcement Trends

HHS Office for Civil Rights (OCR) closed 22 HIPAA enforcement actions in 2024, recovering over $9 million in settlements and civil monetary penalties.[2] The largest single resolution was Montefiore Medical Center's $4.75 million settlement to resolve potential HIPAA Security Rule violations after an employee stole electronic protected health information of 12,517 patients and sold it to an identity theft ring.[3]

In late 2024, OCR launched a Risk Analysis Initiative explicitly designed to increase enforcement against entities that fail to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI.[4] Inadequate risk analysis has been the most frequently cited Security Rule violation in recent OCR enforcement matters, appearing in the majority of announced settlements.[2]

FTC Involvement and the FTC Health Breach Notification Rule 2026 Expansion

The amended Health Breach Notification Rule took effect on July 29, 2024.[5] The Final Rule modernizes the original 2009 regulation by clarifying its applicability to health apps and similar technologies, expanding the definition of breach, and broadening notification content requirements.[6]

Two changes matter most. First, the Rule's revised definitions of "PHR" and "PHR identifiable health information" now cover websites, mobile apps, and internet-connected devices that track health-related data such as vital signs, symptoms, fitness, fertility, sexual health, sleep, mental health, genetic information, or diet.[6] Second, a "breach of security" is no longer limited to cyberattacks. The FTC has clarified that a breach includes intentional unauthorized disclosures, such as sharing identifiable health information with advertising vendors without consumer authorization.[5]

That clarification has teeth. Under the FTC Health Breach Notification Rule 2026 framework, an entity's intentional sharing of identifiable health information with third parties (for example, through Meta Pixel or Google Analytics tags) can itself constitute a reportable breach. For breaches of 500 or more individuals, covered entities must notify the FTC simultaneously with affected individuals, without unreasonable delay and no later than 60 calendar days after discovery.[6]

The GoodRx and Premom Precedents

The FTC's first HBNR enforcement action targeted GoodRx in February 2023, resulting in a $1.5 million civil penalty and a first-of-its-kind permanent ban on sharing user health data with third parties for advertising.[1] The FTC alleged that GoodRx had integrated tracking tools from Facebook, Google, Criteo, Branch, and Twilio into its websites and mobile app, transmitting events data that reflected consumers' health concerns and prescription medications.[1]

Three months later, the FTC settled with Easy Healthcare, operator of the Premom fertility tracking app. Easy Healthcare agreed to a $100,000 civil penalty for HBNR violations plus an additional $100,000 to attorneys general in Connecticut, Oregon, and the District of Columbia.[7] The complaint alleged that Premom shared identifiable health and location information through software development kits (SDKs), including data sent to two China-based analytics firms.[7]

State-Level Actions

State attorneys general have ramped up parallel enforcement. A multistate investigation by the attorneys general of New York, New Jersey, and Connecticut against Enzo Biochem produced a $4.5 million settlement in 2024 over a ransomware attack that compromised the data of approximately 2.4 million individuals.[8] State health privacy laws, including Washington's My Health My Data Act, layer additional obligations on top of HIPAA and the HBNR. Practices marketing across state lines should also review our analysis of Washington My Health My Data Act compliance requirements.

Specific Risks and Consequences

Financial Penalties Under the FTC Health Breach Notification Rule 2026

The penalty stack now spans multiple agencies and private plaintiffs:

  • OCR civil penalties: Tiered by culpability, with statutory maximums adjusted annually for inflation.[2]
  • FTC HBNR civil penalties: GoodRx paid $1.5 million; Easy Healthcare paid $100,000 to the FTC alone.[1]
  • State AG penalties: The Enzo Biochem multistate action produced a $4.5 million penalty in 2024.[8]
  • Single HIPAA settlements: Montefiore's $4.75 million settlement demonstrated how a single insider breach can drive seven-figure penalties.[3]
  • Class-action exposure: Hundreds of pixel-related class actions have been filed against hospitals and digital health companies since 2022, with settlements ranging from the high six figures into the tens of millions.

Reputational Damage

OCR maintains a public-facing breach portal (the "Wall of Shame") listing breaches affecting 500 or more individuals. The amended HBNR also requires notification to prominent media outlets for breaches affecting 500 or more residents of a state or jurisdiction, and consumer-facing notices must now name the third parties that acquired the data.[6] That recipient-naming requirement can cause specific reputational damage when those third parties are recognizable advertising platforms.

Operational Disruption

OCR investigations are slow. Corrective Action Plans accompanying OCR settlements typically impose multi-year ongoing monitoring requirements, board-level reporting, third-party privacy assessments, and detailed documentation obligations.[3] The GoodRx consent order similarly required designating a privacy lead, conducting annual risk assessments, and submitting to ongoing third-party assessments.[1]

Personal Liability

The HBNR's expanded scope captures officers and executives whose decisions about tracking technology, vendor selection, and privacy disclosures may now constitute "unauthorized disclosures" triggering reporting obligations. Knowing HIPAA violations remain subject to criminal penalties under 42 U.S.C. § 1320d-6. Class-action plaintiffs increasingly name executives and board members in derivative suits following major breaches.

How Violations Happen

Technical Configurations

The GoodRx complaint specified that the company integrated third-party tracking tools from Facebook, Google, Criteo, and others into its websites and mobile app, which collected and transmitted personal data to those third parties for advertising and analytics.[1] Common failure points include:

  • Meta Pixel default settings that transmit URL parameters, button clicks, and form interactions.
  • Google Analytics implementations that capture event data reflecting health concerns.
  • SDKs in mobile apps: The Premom complaint focused on SDKs that shared descriptive Custom App Event titles containing identifiable health information.[7]
  • URL parameter exposure revealing condition names, appointment types, or provider specialties.
  • Third-party widgets (chat, scheduling, reviews) that transmit page context to vendors.

Vendor Relationships and Privacy Notice Mismatches

HHS has separately warned that the use of online tracking technologies on regulated entity websites and mobile apps can result in impermissible disclosures of PHI to tracking technology vendors and other third parties.[9] An individual only authorizes the disclosures specifically described in the company's privacy notice or other public statements; disclosures to third parties not specifically described may be unauthorized acquisitions subject to the HBNR. Vendor BAA gaps, missing data processing agreements, and lack of subcontractor audits compound this exposure.

Staff Actions and Audit Triggers

Marketing teams routinely install pixels and tags without consulting compliance. IT teams deploy heatmaps and session-replay tools to optimize conversions. These deployments often surface during OCR or FTC inquiries triggered by:

  • Patient or consumer complaints to OCR or the FTC.
  • Whistleblower reports from former employees or contractors.
  • Investigative journalism (reports like The Markup's 2022 hospital pixel investigation triggered widespread litigation).
  • Self-reported breaches that lead investigators to discover unrelated tracking violations.

Protection Strategies for FTC Health Breach Notification Rule 2026 Compliance

Immediate Actions (This Week)

  1. Inventory every tracking pixel, tag, SDK, and third-party script on your websites and apps.
  2. Map what data each tool transmits and to which recipients.
  3. Compare those data flows against your published privacy notice and consent language.
  4. Identify any vendor receiving health-adjacent data without a BAA or compliant data processing agreement.

Short-Term Fixes (This Month)

  1. Remove or reconfigure client-side pixels that transmit PHI or health-related events.
  2. Implement server-side tracking with PHI stripping before data leaves your environment.
  3. Update privacy notices to specifically describe all third-party recipients and purposes.
  4. Train marketing and IT staff on the FTC's definition of "breach" under the amended HBNR.

Long-Term Compliance Infrastructure

HHS guidance recommends that regulated entities address the use of tracking technologies through their HIPAA risk analysis and risk management processes, and ensure that all disclosures of PHI to tracking technology vendors are specifically permitted by the Privacy Rule.[9] Build a documented technology review process, regular audit schedules, and vendor management standards into your compliance program. For organizations engaged in direct-to-consumer health marketing, review our guidance on pharmaceutical DTC advertising compliance under FTC and FDA rules.

Vendor Evaluation Criteria

  • BAA availability: Will the vendor sign a HIPAA-compliant Business Associate Agreement?
  • PHI handling: Does the vendor strip identifiers server-side before forwarding events to ad platforms?
  • Certifications: SOC 2 Type II at minimum; HITRUST is preferable for healthcare-specific use.
  • Subcontractor transparency: Does the vendor disclose its own subprocessors?
  • Healthcare experience: Has the vendor handled OCR or FTC inquiries on behalf of clients?

How Curve Addresses Each Risk

Curve was built specifically for the post-HBNR-expansion environment where intentional sharing of identifiable health information with advertising vendors can itself constitute a reportable breach. The platform addresses the precise failure modes that produced the GoodRx and Premom enforcement actions:

  • Automated PHI stripping: Curve removes protected health information from event payloads before data reaches Meta, Google, or other advertising endpoints, eliminating the unauthorized disclosure that triggers HBNR notification obligations.
  • Server-side tracking: By moving data collection server-side and filtering at the source, Curve prevents the client-side pixel transmissions that produced the FTC complaints against GoodRx.
  • Signed BAAs: Curve executes Business Associate Agreements with covered entities, closing the vendor-relationship gap that OCR routinely cites in enforcement actions.
  • Audit trails: Every event, transformation, and destination is logged with documentation suitable for OCR investigations, FTC inquiries, and state AG subpoenas.
  • Healthcare-specific design: Unlike general-purpose tag managers and analytics products, Curve's filtering logic is calibrated to the categories of health information that the amended HBNR sweeps in: fertility, mental health, prescription, condition, and treatment data.

For a deeper look at the FTC-specific protection layer, see how Curve protects healthcare organizations from FTC penalties and our analysis of the FTC health claims crackdown and how to avoid six-figure penalties.

Don't Wait for Enforcement

Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve.

Compliance Self-Assessment Checklist

  • Scope assessment: Have you determined whether your organization is a vendor of PHRs, a PHR-related entity, or a third-party service provider under the amended HBNR?
  • Tracking inventory: Do you have a current list of every pixel, tag, SDK, and third-party script in production?
  • Data flow mapping: Do you know exactly what data each tracking tool sends, to whom, and for what purpose?
  • Privacy notice alignment: Does your privacy notice specifically name every third-party advertising recipient and describe the categories of data shared?
  • Consent mechanism: Have you implemented opt-in consent that meets the FTC's "meaningful choice" standard, not buried policy language?
  • Vendor BAAs: Is there a signed BAA with every vendor that may receive health-identifiable information?
  • Server-side filtering: Have you implemented server-side tracking with PHI stripping?
  • Risk analysis: Have you completed a current Security Rule risk analysis covering tracking technologies (the most-cited OCR violation)?
  • Incident response: Does your breach response plan account for the 60-day FTC notification requirement and the requirement to identify third-party recipients in consumer notices?
  • Documentation: Can you produce audit trails showing what data was transmitted, when, and to whom?

Frequently Asked Questions

What are the penalties for HIPAA marketing violations?

Penalties span multiple regimes. OCR HIPAA penalties are tiered by culpability and adjusted annually for inflation.[2] Single OCR settlements in 2024 reached $4.75 million in Montefiore's malicious-insider matter.[3] Under the FTC HBNR, GoodRx paid a $1.5 million civil penalty[1] and Easy Healthcare paid $200,000 across FTC and state AG settlements.[7]

Can healthcare practices be sued for using Meta Pixel?

Yes. The FTC's enforcement theory in GoodRx and Premom directly applies to tracking technologies like Meta Pixel when those tools transmit identifiable health information to advertising platforms without proper authorization.[1] HHS has also warned HIPAA-regulated entities that disclosures of PHI to tracking technology vendors without authorization or a BAA can violate the HIPAA Rules.[9] Class-action plaintiffs have filed hundreds of pixel-related lawsuits against hospitals and digital health companies since 2022.

How do I know if my healthcare marketing is compliant?

Start with three tests. First, identify every third-party recipient of any data from your patient-facing properties. Second, compare those recipients against the specific disclosures in your privacy notice. Third, confirm whether the data transmitted includes any information that could reasonably be linked to an identifiable individual and a health condition, treatment, or service. If any third party receives identifiable health information that is not specifically described to consumers, you likely have an HBNR or HIPAA exposure under current federal interpretation.[6]

What should I do if I discover a compliance violation?

Involve legal counsel immediately. The amended HBNR requires FTC notification within 60 calendar days of discovery for breaches affecting 500 or more individuals, simultaneous with notice to affected individuals.[6] HIPAA-covered entities face a parallel 60-day notification obligation to HHS and affected individuals. Stop the offending data flow, preserve forensic evidence, retain outside counsel experienced in OCR and FTC matters, and prepare notices that meet the amended Rule's content requirements, including the identity of any third parties that acquired data.

Who is covered by the FTC HBNR expansion that isn't covered by HIPAA?

The amended Rule applies to vendors of personal health records, PHR-related entities, and third-party service providers that are not covered by HIPAA, including websites, mobile apps, and internet-connected devices that collect health-related information.[5] Health apps, fitness trackers, fertility and period trackers, mental health platforms, sleep trackers, genetic testing companies, diet apps, and direct-to-consumer wellness technologies are now explicitly within scope.[6]

Sources

  1. FTC Press Release: FTC Enforcement Action to Bar GoodRx (Feb. 2023)
  2. HIPAA Journal: Penalties for HIPAA Violations
  3. HHS Press Release: Montefiore Medical Center $4.75 Million Settlement
  4. HHS Press Release: OCR Ransomware Settlement and Risk Analysis Initiative
  5. Federal Register: Health Breach Notification Rule Final Amendments
  6. FTC Press Release: FTC Finalizes Changes to the Health Breach Notification Rule
  7. FTC Press Release: Premom Will Be Barred from Sharing Health Data (May 2023)
  8. HIPAA Journal: HIPAA Enforcement by State Attorneys General
  9. HHS OCR: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit