The Department of Health and Human Services’ Office for Civil Rights and Federal Trade Commission yesterday sent a letter to about 130 hospital systems and telehealth providers reminding them to comply with HIPAA Privacy, Security and Breach Notification Rules, the FTC Act and FTC Health Breach Notification Rule when using technologies that can track a user’s online activities, such as Meta/Facebook Pixel and Google Analytics.  
 
“Both agencies are closely watching developments in this area,” the letter states. “To the extent you are using the tracking technologies described in this letter on your website or app, we strongly encourage you to review the laws cited in this letter and take actions to protect the privacy and security of individuals’ health information.”
 
For more information, see the HHS press release.

Related News Articles

Chairperson's File
Trust — in one another, in our field, and in our communities — is so important to what we do. Everyone should know that our hospitals and health systems are a…
Headline
A joint advisory released Feb. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Multi-State Information Sharing and Analysis…
Headline
Rural hospitals’ limited access to technology, staff and financial resources constrains their ability to defend against the malicious actors behind today’s…
Headline
Nearly one year after the cyberattack on Change Healthcare, the AHA released a report highlighting the continued need for health care organizations to…
Headline
The Department of Justice Feb. 10 announced charges for Roman Berezhnoy and Egor Nikolaevich Glebov, Russian nationals alleged to be leaders of a ransomware…
Headline
The AHA participated Feb. 18 at ViVE, a health care conference in Nashville focusing on digital health technology. Chris DeRienzo, M.D., AHA senior vice…