What laws protect PHRs?
No laws protect your right to control health information in PHRs. PHRs are required to comply with posted corporate privacy policies. The FTC is charged with monitoring and enforcement of PHR privacy policies. If the FTC determines what the PHR does with information is inconsistent with what they say they do in their policies, the FTC could determine that the PHR is “unfair and deceptive” and require fines, changes in what they do, etc. The American Recovery and Reinvestment Act (ARRA) requires PHRs to notify victims if there is a breach of privacy. The FTC and HHS are required to study PHRs and make recommendations for how PHRs should be regulated. This report is due to Congress on 2/17/10.