FTC: Organizations not bound by HIPAA must report breaches – Security

In a 4-0 ruling Monday, the FTC approved a rule that will require Web based businesses that deal with personal health information, even if they are not bound by HIPAA laws, to report security breaches. The Health Breach Notification Rule was created and put in place because Congress directed the FTC to issue the rule as part of the American Recovery and Reinvestment Act of 2009.

via FTC: Organizations not bound by HIPAA must report breaches – Security.