16 CFR 318.6
§ 318.6 Content of notice.
United States · 16 CFR — Commercial Practices · Status: effective
Cite this
- Citation
- 16 CFR 318.6, § 318.6 Content of notice, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/64429
- Permanent ID
ys:prov:64429@1- SHA-256
7ba6c8e33f21bc68baac6364fcb744d275603ca9482a9bb619138872c221c5eb
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
Regardless of the method by which notice is provided to individuals under § 318.5 (regarding methods of notice), notice of a breach of security shall be in plain language and include, to the extent possible, the following:
(a) A brief description of what happened, including: the date of the breach and the date of the discovery of the breach, if known; and the full name or identity (or, where providing the full name or identity would pose a risk to individuals or the entity providing notice, a description) of any third parties that acquired unsecured PHR identifiable health information as a result of a breach of security, if this information is known to the vendor of personal health records or PHR related entity;
(b) A description of the types of unsecured PHR identifiable health information that were involved in the breach (such as but not limited to full name, Social Security number, date of birth, home address, account number, health diagnosis or condition, lab results, medications, other treatment information, the individual's use of a health-related mobile application, or device identifier (in combination with another data element));
(c) Steps individuals should take to protect themselves from potential harm resulting from the breach;
(d) A brief description of what the entity that experienced the breach is doing to investigate the breach, to mitigate harm, to protect against any further breaches, and to protect affected individuals, such as offering credit monitoring or other services; and
(e) Contact procedures for individuals to ask questions or learn additional information, which must include two or more of the following: toll-free telephone number; email address; website; within-application; or postal address.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.