2.7 Stakeholder Notices Beyond the NPP: Payment Card Data, FTC Authority and Consumer-Facing Disclosures

Key Takeaways

  • Cardholder data collected at registration and billing is governed by the PCI DSS contract regime, not by HIPAA, and a card breach triggers card-brand and state obligations that the HIPAA breach analysis will not surface.
  • The FTC Health Breach Notification Rule at 16 CFR Part 318 reaches vendors of personal health records and health apps that are not HIPAA covered entities or business associates.
  • FTC Act Section 5 reaches deceptive or unfair privacy statements by any commercial actor, including a HIPAA covered entity whose website privacy policy or tracking practices contradict its actual conduct.
  • Online tracking technologies on patient-facing pages can disclose PHI to third parties; after the 2024 vacatur of part of OCR's tracking guidance the exposure shifted toward FTC and state enforcement rather than disappearing.
  • A stakeholder notice inventory should map every external privacy statement — NPP, website policy, app disclosure, research consent, patient portal terms — to a named owner and a review date.
Last updated: August 2026

Stakeholder Notices Beyond the NPP: Payment Card Data, FTC Authority and Consumer-Facing Disclosures

Task 1.F of the Detailed Content Outline reads: develop, review, or update communications and notices for stakeholders (e.g., privacy notices, PCI, FTC). Two of the three named items are not HIPAA at all. That is deliberate. A hospital privacy officer whose field of view ends at the Notice of Privacy Practices will miss the payment-card obligations sitting in the registration desk and the consumer-protection obligations sitting on the marketing website.


1. Payment Card Data: A Contractual Regime, Not a Federal Rule

Every provider that takes a credit card at registration, in the gift shop, on the patient portal, or over the phone handles cardholder data. The governing framework is the Payment Card Industry Data Security Standard (PCI DSS), maintained by the PCI Security Standards Council and imposed through the merchant agreement with the acquiring bank and the card brands. It is contract law backed by fines and by the loss of card-processing privileges — not a statute enforced by OCR.

DimensionPHI under HIPAACardholder Data under PCI DSS
Source of obligationFederal regulation (45 CFR Parts 160, 164)Contract with acquiring bank and card brands
EnforcerHHS OCR, state attorneys general, DOJCard brands and acquirers, via fines and merchant-status action
Core protected elementIndividually identifiable health informationPrimary account number, cardholder name, expiration, service code; and sensitive authentication data
ValidationRisk analysis, policies, OCR investigationAnnual self-assessment questionnaire or a Report on Compliance by a qualified security assessor, plus quarterly scans, scaled by merchant level
Storage ruleRetain per policy and lawSensitive authentication data — full magnetic stripe, CVV/CVC, PIN block — may never be stored after authorization
Breach consequenceSubpart D notification analysisCard-brand forensic investigation, fines, reissuance costs, plus state data breach statutes

The practical intersections a privacy officer must own:

  1. Scope reduction is the primary control. Point-to-point encryption and tokenization at the payment terminal keep cardholder data out of the hospital's systems entirely, shrinking the PCI environment. This is the single highest-value recommendation the privacy officer can carry to revenue cycle.
  2. Do not let card data land in the chart. Registration staff who write a card number on a face sheet, or who paste it into a free-text EHR comment field, have simultaneously created a PCI violation and put unnecessary financial data into a clinical record.
  3. Call recordings. Patient financial services lines that record calls capture spoken card numbers and security codes. Storage of the security code is prohibited outright; the recording system must pause-and-resume or redact.
  4. Notice content. Billing and payment communications, the patient portal payment page, and financial assistance materials are stakeholder notices; they must describe payment data handling accurately and must not promise protections the organization does not deliver.

2. The FTC's Two Distinct Levers

The Federal Trade Commission reaches health data through two different mechanisms, and candidates confuse them constantly.

A. The Health Breach Notification Rule (16 CFR Part 318)

This rule applies to vendors of personal health records, PHR-related entities, and their service providers that are not HIPAA covered entities or business associates. Its jurisdictional trigger is precisely the gap HIPAA leaves: the consumer health app, the fitness and fertility tracker, the direct-to-consumer testing service, the standalone personal health record.

Key operating features:

  • A breach of security includes unauthorized acquisition, and the FTC has applied it to voluntary disclosures the consumer did not authorize — for example, transmission of health data to advertising platforms through embedded trackers.
  • Notification runs to affected individuals, the FTC, and, for larger incidents, the media.
  • The rule was amended in 2024 to modernize definitions for health apps and to clarify electronic notice methods.

B. FTC Act Section 5 — Deception and Unfairness

Section 5 reaches any commercial actor, including a HIPAA covered entity, whose privacy representations are deceptive or whose data practices are unfair. HIPAA compliance is not a defense to a Section 5 claim. The exposure is generated by the organization's own words:

  • A website privacy policy stating that the organization "never shares your information with third parties" while advertising pixels transmit page views on a condition-specific page.
  • A patient portal enrollment screen promising encryption the system does not use.
  • A marketing email describing a data practice more narrowly than reality.

[!IMPORTANT] The rule to teach the marketing department: every public privacy claim is a legally enforceable promise. The safest posture is that no privacy statement goes live without privacy office review, and that the statement describes what the systems actually do rather than what the organization aspires to.


3. Website and Application Tracking Technologies

Pixels, tag managers, session replay tools, and analytics SDKs embedded on patient-facing pages transmit data to third parties by design. When the page is authenticated, or when an unauthenticated page addresses a specific condition or provider, the transmitted combination of IP address, device identifier, and page context can constitute PHI.

The regulatory history matters for a 2026 candidate. OCR issued guidance in December 2022 and revised it in March 2024, asserting that certain unauthenticated-page tracking involved PHI. On June 20, 2024, the U.S. District Court for the Northern District of Texas vacated the portion of that bulletin treating metadata such as an IP address collected from an unauthenticated page as individually identifiable health information (American Hospital Association v. Becerra); OCR noticed an appeal in August 2024 and then voluntarily withdrew it. The consequence is not that tracking became safe. It is that the risk redistributed: OCR retains authority over authenticated portal tracking and over any transmission that meets the PHI definition, while FTC Section 5, the Health Breach Notification Rule, state consumer health data statutes such as Washington's My Health My Data Act, and a very active plaintiffs' bar all remain fully available.

The defensible operating posture:

  1. Inventory every tag on every patient-facing property, including those injected by tag managers and by marketing agencies.
  2. Remove trackers from authenticated pages and from any page whose URL or content reveals a condition, provider specialty, or appointment intent.
  3. Execute BAAs with analytics vendors only where the vendor will genuinely act as a business associate and can contractually forgo its own use of the data — many advertising platforms will not.
  4. Re-scan on a schedule. Tags reappear after every website release; a one-time cleanup is not a control.

4. Building a Stakeholder Notice Inventory

Task 1.F is satisfied by a maintained inventory, not by a single document. The privacy officer should be able to produce, on request, a table like this:

Notice or CommunicationAudienceOwnerGoverning FrameworkLast Reviewed
Notice of Privacy PracticesPatientsPrivacy officer45 CFR 164.520
Website privacy policyPublicPrivacy officer with marketingFTC Act Section 5, state law
Patient portal terms and privacy statementEnrolled patientsPrivacy officer with ITHIPAA, FTC Section 5
Mobile app disclosures and store listingApp usersPrivacy officer with digitalFTC HBNR if outside HIPAA
Billing and payment communicationsPatients and guarantorsRevenue cyclePCI DSS, state law
Research authorizations and consent languageStudy participantsResearch compliance45 CFR 164.508, 164.512(i), Common Rule
Breach notification letters and substitute notice templatesAffected individualsPrivacy officer45 CFR 164.404, 164.406
Employee and workforce privacy noticesWorkforceHuman resourcesState law, GINA, ADA

Each row needs an owner, a review date, and a documented sign-off. Notices drift, and drift is what turns a communication problem into an FTC deception case.

Test Your Knowledge

A hospital's patient financial services department records all inbound calls for quality purposes. Patients routinely read their credit card number and three-digit security code aloud during those calls, and the recordings are archived for two years. What is the primary compliance defect?

A
B
C
D
Test Your Knowledge

A direct-to-consumer fertility tracking app, operated by a technology company that is neither a covered entity nor a business associate, transmits users' cycle data to an advertising network through an embedded software development kit without user authorization. Which framework most directly governs the incident?

A
B
C
D
Test Your Knowledge

A health system's public website states that it 'never shares any information about your visit with outside companies.' A tag audit reveals that an advertising pixel on the oncology service line pages transmits page URLs and device identifiers to a social media platform. Beyond any HIPAA analysis, what additional exposure does the statement itself create?

A
B
C
D