yourstate.us
16 CFR 318.1

§ 318.1 Purpose and scope.

United States · 16 CFR — Commercial Practices · Status: effective

Get this as JSONEmbed this
Cite this
Citation
16 CFR 318.1, § 318.1 Purpose and scope, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/64424
Permanent ID
ys:prov:64424@1
SHA-256
32a11232c8a0d56b1241e029af914f5b3103f336b3464bc0660ea1ffb2485e52

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) This part, which shall be called the “Health Breach Notification Rule,” implements section 13407 of the American Recovery and Reinvestment Act of 2009, 42 U.S.C. 17937. This part applies to foreign and domestic vendors of personal health records, PHR related entities, and third party service providers, irrespective of any jurisdictional tests in the Federal Trade Commission (FTC) Act, that maintain information of U.S. citizens or residents. This part does not apply to HIPAA-covered entities, or to any other entity to the extent that it engages in activities as a business associate of a HIPAA-covered entity. (b) This part preempts State law as set forth in section 13421 of the American Recovery and Reinvestment Act of 2009, 42 U.S.C 17951.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.