---
kind: "section"
citation: "42 U.S.C. § 17937"
title: "42"
title_heading: "The Public Health and Welfare"
number: "17937"
heading: "Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/42/17937"
units:
  - "Chapter 156 — Health Information Technology"
  - "Subchapter III — Privacy"
  - "Part A — Improved Privacy Provisions and Security Provisions"
---

# §17937. Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities

- (a) **In general—** In accordance with [subsection (c)](#c), each [vendor of personal health records](/usc/42/17921.md?p=18), following the discovery of a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) of unsecured PHR identifiable health information that is in a [personal health record](/usc/42/17921.md?p=11) maintained or offered by such vendor, and each entity described in clause (ii), (iii), or (iv) of [section 17953(b)(1)(A) of this title](/usc/42/17953.md?p=b-1-A), following the discovery of a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) of such information that is obtained through a product or service provided by such entity, shall—
  - (1) notify each individual who is a citizen or resident of the United States whose unsecured PHR identifiable health information was acquired by an unauthorized person as a result of such a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14); and
  - (2) notify the Federal Trade Commission.
- (b) **Notification by third party service providers—** A third party service provider that provides services to a [vendor of personal health records](/usc/42/17921.md?p=18) or to an entity described in clause (ii), (iii).[^1] or (iv) of [section 17953(b)(1)(A) of this title](/usc/42/17953.md?p=b-1-A) in connection with the offering or maintenance of a [personal health record](/usc/42/17921.md?p=11) or a related product or service and that accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or [discloses](/usc/42/17921.md?p=4) unsecured PHR identifiable health information in such a record as a result of such services shall, following the discovery of a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) of such information, notify such vendor or entity, respectively, of such [breach](/usc/42/17921.md?p=1-A). Such notice shall include the identification of each individual whose unsecured PHR identifiable health information has been, or is reasonably believed to have been, accessed, acquired, or disclosed during such [breach](/usc/42/17921.md?p=1-A).
- (c) **Application of requirements for timeliness, method, and content of notifications—** Subsections (c), (d), (e), and (f) of [section 17932 of this title](/usc/42/17932.md) shall apply to a notification required under [subsection (a)](#a) and a [vendor of personal health records](/usc/42/17921.md?p=18), an entity described in [subsection (a)](#a) and a third party service provider described in [subsection (b)](#b), with respect to a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) under [subsection (a)](#a) of unsecured PHR identifiable health information in such records maintained or offered by such vendor, in a manner specified by the Federal Trade Commission.
- (d) **Notification of the Secretary—** Upon receipt of a notification of a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) under [subsection (a)(2)](#a-2), the Federal Trade Commission shall notify the [Secretary](/usc/42/17921.md?p=13) of such [breach](/usc/42/17921.md?p=1-A).
- (e) **Enforcement—** A [violation](/usc/42/2000e–16a.md?p=c) of subsection [(a)](#a) or [(b)](#b) shall be treated as an unfair and deceptive act or practice in [violation](/usc/42/2000e–16a.md?p=c) of a regulation under [section 57a(a)(1)(B) of title 15](/usc/15/57a.md?p=a-1-B) regarding unfair or deceptive acts or [practices](/usc/42/17061.md?p=19).
- (f) **Definitions—** For purposes of this section:
  - (1) **Breach of security—** The term “[breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14)” means, with respect to unsecured PHR identifiable health information of an individual in a [personal health record](/usc/42/17921.md?p=11), acquisition of such information without the authorization of the individual.
  - (2) **PHR identifiable health information—** The term “PHR identifiable health information” means individually identifiable health information, as defined in [section 1320d(6) of this title](/usc/42/1320d.md?p=6), and includes, with respect to an individual, information—
    - (A) that is provided by or on behalf of the individual; and
    - (B) that identifies the individual or with respect to which there is a reasonable basis to believe that the information can be used to identify the individual.
  - (3) **Unsecured PHR identifiable health information—**
    - (A) **In general—** Subject to [subparagraph (B)](#f-3-B), the term “unsecured PHR identifiable health information” means PHR identifiable health information that is not protected through the use of a technology or methodology specified by the [Secretary](/usc/42/17921.md?p=13) in the guidance issued under [section 17932(h)(2) of this title](/usc/42/17932.md?p=h-2).
    - (B) **Exception in case timely guidance not issued—** In the case that the [Secretary](/usc/42/17921.md?p=13) does not issue guidance under [section 17932(h)(2) of this title](/usc/42/17932.md?p=h-2) by the date specified in such section, for purposes of this section, the term “unsecured PHR identifiable health information” shall mean PHR identifiable health information that is not secured by a technology standard that renders [protected health information](/usc/42/17921.md?p=12) unusable, unreadable, or indecipherable to unauthorized individuals and that is developed or endorsed by a standards developing organization that is accredited by the American National Standards Institute.
- (g) **Regulations; effective date; sunset—**
  - (1) **Regulations; effective date—** To carry out this section, the Federal Trade Commission shall promulgate interim final regulations by not later than the date that is 180 days after February 17, 2009. The provisions of this section shall apply to [breaches](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) that are discovered on or after the date that is 30 days after the date of publication of such interim final regulations.
  - (2) **Sunset—** If Congress enacts new legislation establishing requirements for notification in the case of a [breach](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14), that apply to entities that are not [covered entities](/usc/42/17921.md?p=3) or [business associates](/usc/42/17921.md?p=2), the provisions of this section shall not apply to [breaches](/usc/42/17921.md?p=1-A) of [security](/usc/42/17921.md?p=14) discovered on or after the effective date of regulations implementing such legislation.

## Footnotes

[^1]: So in original. The period probably should be a comma.

## Source credit

(Pub. L. 111–5, div. A, title XIII, § 13407, Feb. 17, 2009, 123 Stat. 269.)

## Notes

### Statutory Notes and Related Subsidiaries

### Effective Date

Section effective 12 months after Feb. 17, 2009, except as otherwise specifically provided, see section 13423 of Pub. L. 111–5, set out as a note under section 17931 of this title.
