{"id":2257,"date":"2023-08-11T05:27:41","date_gmt":"2023-08-11T13:27:41","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=2257"},"modified":"2023-08-11T05:27:41","modified_gmt":"2023-08-11T13:27:41","slug":"mozilla-supports-updates-to-the-health-breach-notification-rule","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/","title":{"rendered":"Mozilla Supports Updates to the Health Breach Notification Rule"},"content":{"rendered":"<p style=\"text-align: center;\"><i>[<\/i><a href=\"https:\/\/www.regulations.gov\/comment\/FTC-2023-0037-0072\"><i>Read our full submission here.<\/i><\/a><i>]<\/i><\/p>\n<p>Privacy is in our DNA at Mozilla, from our privacy-enhancing products to our support for laws and regulations that enshrine privacy for all. In line with our <a href=\"https:\/\/www.mozilla.org\/en-US\/about\/manifesto\/\">foundational principle<\/a> that individual privacy and security on the web should never be treated as optional, we have supported a range of <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2022\/08\/29\/save-the-date-the-long-road-to-federal-privacy-protections-are-we-there-yet\/\">US action on privacy<\/a>, including <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2022\/08\/24\/its-time-to-pass-u-s-federal-privacy-legislation\/\">bipartisan Federal privacy legislative proposals<\/a> and the Federal Trade Commission\u2019s (FTC\u2019s) <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2022\/11\/15\/mozilla-comments-on-ftcs-commercial-surveillance-and-data-security-advance-notice-of-proposed-rulemaking\/\">Commercial Surveillance and Data Security ANPR<\/a>.<\/p>\n<p>This week, we submitted a comment supporting the FTC\u2019s <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/05\/ftc-proposes-amendments-strengthen-modernize-health-breach-notification-rule\">Notice of Proposed Rulemaking<\/a> for the Health Breach Notification Rule (HBNR.) The purpose of the HBNR is to protect non-HIPAA health-related data, such as data from running apps and diet-tracking websites. It does so by requiring certain entities that share health-related information without consent, or experience a data breach, to notify individuals, the FTC, and sometimes the media of the breach of privacy.<\/p>\n<p>The rule already applied to many health apps and websites, as demonstrated by a <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/02\/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising\">set<\/a> of <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/05\/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc\">settlements<\/a> from earlier this year, but the new proposed rule even more clearly delineates the responsibilities of companies running health-related apps or websites.<\/p>\n<p>Mozilla has deep insight into the privacy practices of health-related apps, because our <i>*Privacy Not Included<\/i> research team recently did deep dives on the privacy policies and practices of <a href=\"https:\/\/foundation.mozilla.org\/en\/privacynotincluded\/articles\/are-mental-health-apps-better-or-worse-at-privacy-in-2023\/\">mental health<\/a> and <a href=\"https:\/\/foundation.mozilla.org\/en\/privacynotincluded\/articles\/in-post-roe-v-wade-era-mozilla-labels-18-of-25-popular-period-and-pregnancy-tracking-tech-with-privacy-not-included-warning\/\">reproductive health<\/a> apps. They found dismal privacy practices for some of the most sensitive apps they studied. *PNI\u2019s research demonstrates the dire need for this update to the HBNR, and allowed us to suggest two main ways in which the FTC can further strengthen its proposed rule:<\/p>\n<ul>\n<li aria-level=\"1\">The FTC should explicitly define consent (or \u201cauthorization\u201d) in the context of the HBNR. We know that many companies will use deceptive designs to trick people into giving consent, for example, and the FTC should clearly state that deceptive consent flows do not count as consent.<\/li>\n<li aria-level=\"1\">We have been <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2021\/10\/28\/implementing-global-privacy-control\/\">early<\/a> supporters of browser-based privacy signals such as the Global Privacy Control, with proper enforcement; the HBNR should allow users to indicate their lack of consent using these signals. Browser based privacy signals are already recognized in a number of laws and regulations, and make privacy more consumer-friendly.<\/li>\n<\/ul>\n<p>You can read our full comment <a href=\"https:\/\/www.regulations.gov\/comment\/FTC-2023-0037-0072\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Read our full submission here.] Privacy is in our DNA at Mozilla, from our privacy-enhancing products to our support for laws and regulations that enshrine privacy for all. In line &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/\">Read more<\/a><\/p>\n","protected":false},"author":1932,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[847,46877],"tags":[],"coauthors":[453000],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mozilla Supports Updates to the Health Breach Notification Rule - Open Policy &amp; Advocacy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Noam Kantor\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/\",\"name\":\"Mozilla Supports Updates to the Health Breach Notification Rule - Open Policy &amp; Advocacy\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"datePublished\":\"2023-08-11T13:27:41+00:00\",\"dateModified\":\"2023-08-11T13:27:41+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/b56c9f502f5fc637facf905bb5baee73\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mozilla Supports Updates to the Health Breach Notification Rule\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/b56c9f502f5fc637facf905bb5baee73\",\"name\":\"Noam Kantor\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/04947ca0d74f1a7be9c456e99693ec44\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/baf3871c4471a1ea9e9a6ad1c01cdd01?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/baf3871c4471a1ea9e9a6ad1c01cdd01?s=96&d=mm&r=g\",\"caption\":\"Noam Kantor\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mozilla Supports Updates to the Health Breach Notification Rule - Open Policy &amp; Advocacy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/","twitter_misc":{"Written by":"Noam Kantor","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/","name":"Mozilla Supports Updates to the Health Breach Notification Rule - Open Policy &amp; Advocacy","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"datePublished":"2023-08-11T13:27:41+00:00","dateModified":"2023-08-11T13:27:41+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/b56c9f502f5fc637facf905bb5baee73"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2023\/08\/11\/mozilla-supports-updates-to-the-health-breach-notification-rule\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"Mozilla Supports Updates to the Health Breach Notification Rule"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/b56c9f502f5fc637facf905bb5baee73","name":"Noam Kantor","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/04947ca0d74f1a7be9c456e99693ec44","url":"https:\/\/secure.gravatar.com\/avatar\/baf3871c4471a1ea9e9a6ad1c01cdd01?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/baf3871c4471a1ea9e9a6ad1c01cdd01?s=96&d=mm&r=g","caption":"Noam Kantor"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/2257"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/1932"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=2257"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/2257\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=2257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=2257"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=2257"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=2257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}