FTC Retains Authority to Regulate Data Security at HIPAA Covered Entities - For Now
The FTC originally issued an administrative complaint against LabMD for failing to provide adequate protection for patient information stored on its internal network. After the FTC denied LabMD’s motion to dismiss the administrative complaint, LabMD filed suit in the district court challenging the FTC’s authority under Section 5 of the FTC Act to address alleged security breaches of protected health information regulated by HIPAA (see our coverage here). The federal court dismissed the case for lack of jurisdiction, holding that the order to deny the motion to dismiss did not constitute a final agency action.
Although the federal court stated in a footnote that the “likelihood of a favorable jurisdictional or merits outcome for LabMD is slight,” it left the door open for a later resolution in the court system, noting that LabMD has some rights of appeal after the administrative process is complete.
Footnotes: For additional information about the LabMD case or regulatory issues involving the security of health information, please contact: Ron Breaux 214.651.5688 Bill Morrison 214.651.5018 Kenya Woodruff 214.651.5446 Emily Westridge Black 512.867.8422 Jennifer Kreick 214.651.5492 Timothy Newman 214.651.5029
|