Prepared or not, Roe v. Wade leak or not, well being app builders are on discover. Those who acquire delicate private data, akin to reproductive information, should rigorously navigate each federal and state legal guidelines. These legal guidelines are frequently in flux and warrant ongoing monitoring.
Final September, I wrote concerning the FTC’s Coverage Assertion on imposing the Well being Breach Notification Rule. This adopted a weblog I posted about Flo Well being’s breach and failure to promptly notify its thousands and thousands of feminine customers that it allowed their private and uniquely delicate well being data for use by third events, together with Google and Fb, for their very own functions, together with promoting.
Yesterday, the California Lawyer Common Rob Bonta issued a press launch stating:
“The Confidentiality of Medical Info Act (CMIA) applies to cellular apps that are designed to retailer medical data, together with some fertility trackers, and establishes privateness protections that transcend federal regulation. In immediately’s alert, Lawyer Common Bonta urges well being apps to undertake strong safety and privateness measures to defend reproductive well being data. At a minimal, these apps ought to assess the dangers related to accumulating and sustaining abortion-related data that could possibly be leveraged in opposition to individuals in search of to train their healthcare rights.”
Shopper-facing well being apps that aren’t topic to HIPAA as enterprise associates should adjust to CMIA in the event that they acquire data of California customers, and apps which might be topic to HIPAA should adjust to any opposite and extra stringent CMIA privateness and safety necessities.
Lastly, Lawyer Common Bonta identified that even when CMIA doesn’t apply to sure apps, different California legal guidelines (such because the California Shopper Privateness Act) could apply and supply information rights and protections.
Well being app builders should perceive not solely which information privateness and safety legal guidelines apply, however how the character and sensitivity of the information should dictate privateness and safety design. If they don’t, they danger scrutiny in what seemingly shall be a carefully watched space of knowledge privateness for years to come back.
In case you have any questions on how greatest to deal with the reproductive information you obtain and/or create as a vendor, or the applicability of HIPAA or state information and privateness legal guidelines to your organization, please contact me at firstname.lastname@example.org.