Prepared or not, Roe v. Wade leak or not, well being app builders are on discover. Those who accumulate delicate private info, similar to reproductive knowledge, should fastidiously navigate each federal and state legal guidelines. These legal guidelines are frequently in flux and warrant ongoing monitoring.
Final September, I wrote concerning the FTC’s Coverage Assertion on implementing the Well being Breach Notification Rule. This adopted a weblog I posted about Flo Well being’s breach and failure to promptly notify its tens of millions of feminine customers that it allowed their private and uniquely delicate well being info for use by third events, together with Google and Fb, for their very own functions, together with promoting.
Yesterday, the California Legal professional Common Rob Bonta issued a press launch stating:
“The Confidentiality of Medical Info Act (CMIA) applies to cellular apps that are designed to retailer medical info, together with some fertility trackers, and establishes privateness protections that transcend federal legislation. In in the present day’s alert, Legal professional Common Bonta urges well being apps to undertake sturdy safety and privateness measures to defend reproductive well being info. At a minimal, these apps ought to assess the dangers related to gathering and sustaining abortion-related info that could possibly be leveraged in opposition to individuals looking for to train their healthcare rights.”
Client-facing well being apps that aren’t topic to HIPAA as enterprise associates should adjust to CMIA in the event that they accumulate info of California customers, and apps which are topic to HIPAA should adjust to any opposite and extra stringent CMIA privateness and safety necessities.
Lastly, Legal professional Common Bonta identified that even when CMIA doesn’t apply to sure apps, different California legal guidelines (such because the California Client Privateness Act) might apply and supply knowledge rights and protections.
Well being app builders should perceive not solely which knowledge privateness and safety legal guidelines apply, however how the character and sensitivity of the information should dictate privateness and safety design. If they don’t, they threat scrutiny in what doubtless will probably be a intently watched space of information privateness for years to return.
In case you have any questions on how greatest to deal with the reproductive knowledge you obtain and/or create as a vendor, or the applicability of HIPAA or state knowledge and privateness legal guidelines to your organization, please contact me at firstname.lastname@example.org.