Prepared or not, Roe v. Wade leak or not, well being app builders are on discover. Those who gather delicate private info, comparable to reproductive knowledge, should rigorously navigate each federal and state legal guidelines. These legal guidelines are regularly in flux and warrant ongoing monitoring.
Final September, I wrote in regards to the FTC’s Coverage Assertion on implementing the Well being Breach Notification Rule. This adopted a weblog I posted about Flo Well being’s breach and failure to promptly notify its tens of millions of feminine customers that it allowed their private and uniquely delicate well being info for use by third events, together with Google and Fb, for their very own functions, together with promoting.
Yesterday, the California Legal professional Normal Rob Bonta issued a press launch stating:
“The Confidentiality of Medical Data Act (CMIA) applies to cell apps that are designed to retailer medical info, together with some fertility trackers, and establishes privateness protections that transcend federal legislation. In in the present day’s alert, Legal professional Normal Bonta urges well being apps to undertake strong safety and privateness measures to shield reproductive well being info. At a minimal, these apps ought to assess the dangers related to gathering and sustaining abortion-related info that could possibly be leveraged in opposition to individuals looking for to train their healthcare rights.”
Client-facing well being apps that aren’t topic to HIPAA as enterprise associates should adjust to CMIA in the event that they gather info of California customers, and apps which might be topic to HIPAA should adjust to any opposite and extra stringent CMIA privateness and safety necessities.
Lastly, Legal professional Normal Bonta identified that even when CMIA doesn’t apply to sure apps, different California legal guidelines (such because the California Client Privateness Act) could apply and supply knowledge rights and protections.
Well being app builders should perceive not solely which knowledge privateness and safety legal guidelines apply, however how the character and sensitivity of the information should dictate privateness and safety design. If they don’t, they danger scrutiny in what possible will probably be a carefully watched space of information privateness for years to come back.
When you’ve got any questions on how greatest to deal with the reproductive knowledge you obtain and/or create as a vendor, or the applicability of HIPAA or state knowledge and privateness legal guidelines to your organization, please contact me at firstname.lastname@example.org.