TPO

Digital Health Information: Applicable to HIPAA Breach Notification? Policy Statement Clarifies

02/08/2022

-

Recently, many guidance documents and draft guidance documents regarding digital health information have been released. This is in response to the increase in numbers of devices used in the course of a clinical trial, including wearable devices, ePRO, eCOA, software such as apps, home monitors, etc. These devices collect health information and store or transmit it outside of the collection site. Such vendors need to be aware of how they are classified to ensure compliance with applicable regulations. If they are not directly considered a medical device, the device manufacturers and app developers may be considered vendors of personal health records (PHR) and would then need to comply with the Federal Trade Commission’s (FTC) Breach Notification Rule. The FTC released a Policy Statement to clarify the scope of this Rule.