2.7 Stakeholder Notices Beyond the NPP: Payment Card Data, FTC Authority and Consumer-Facing Disclosures
Key Takeaways
- Cardholder data collected at registration and billing is governed by the PCI DSS contract regime, not by HIPAA, and a card breach triggers card-brand and state obligations that the HIPAA breach analysis will not surface.
- The FTC Health Breach Notification Rule at 16 CFR Part 318 reaches vendors of personal health records and health apps that are not HIPAA covered entities or business associates.
- FTC Act Section 5 reaches deceptive or unfair privacy statements by any commercial actor, including a HIPAA covered entity whose website privacy policy or tracking practices contradict its actual conduct.
- Online tracking technologies on patient-facing pages can disclose PHI to third parties; after the 2024 vacatur of part of OCR's tracking guidance the exposure shifted toward FTC and state enforcement rather than disappearing.
- A stakeholder notice inventory should map every external privacy statement — NPP, website policy, app disclosure, research consent, patient portal terms — to a named owner and a review date.
Stakeholder Notices Beyond the NPP: Payment Card Data, FTC Authority and Consumer-Facing Disclosures
Task 1.F of the Detailed Content Outline reads: develop, review, or update communications and notices for stakeholders (e.g., privacy notices, PCI, FTC). Two of the three named items are not HIPAA at all. That is deliberate. A hospital privacy officer whose field of view ends at the Notice of Privacy Practices will miss the payment-card obligations sitting in the registration desk and the consumer-protection obligations sitting on the marketing website.
1. Payment Card Data: A Contractual Regime, Not a Federal Rule
Every provider that takes a credit card at registration, in the gift shop, on the patient portal, or over the phone handles cardholder data. The governing framework is the Payment Card Industry Data Security Standard (PCI DSS), maintained by the PCI Security Standards Council and imposed through the merchant agreement with the acquiring bank and the card brands. It is contract law backed by fines and by the loss of card-processing privileges — not a statute enforced by OCR.
| Dimension | PHI under HIPAA | Cardholder Data under PCI DSS |
|---|---|---|
| Source of obligation | Federal regulation (45 CFR Parts 160, 164) | Contract with acquiring bank and card brands |
| Enforcer | HHS OCR, state attorneys general, DOJ | Card brands and acquirers, via fines and merchant-status action |
| Core protected element | Individually identifiable health information | Primary account number, cardholder name, expiration, service code; and sensitive authentication data |
| Validation | Risk analysis, policies, OCR investigation | Annual self-assessment questionnaire or a Report on Compliance by a qualified security assessor, plus quarterly scans, scaled by merchant level |
| Storage rule | Retain per policy and law | Sensitive authentication data — full magnetic stripe, CVV/CVC, PIN block — may never be stored after authorization |
| Breach consequence | Subpart D notification analysis | Card-brand forensic investigation, fines, reissuance costs, plus state data breach statutes |
The practical intersections a privacy officer must own:
- Scope reduction is the primary control. Point-to-point encryption and tokenization at the payment terminal keep cardholder data out of the hospital's systems entirely, shrinking the PCI environment. This is the single highest-value recommendation the privacy officer can carry to revenue cycle.
- Do not let card data land in the chart. Registration staff who write a card number on a face sheet, or who paste it into a free-text EHR comment field, have simultaneously created a PCI violation and put unnecessary financial data into a clinical record.
- Call recordings. Patient financial services lines that record calls capture spoken card numbers and security codes. Storage of the security code is prohibited outright; the recording system must pause-and-resume or redact.
- Notice content. Billing and payment communications, the patient portal payment page, and financial assistance materials are stakeholder notices; they must describe payment data handling accurately and must not promise protections the organization does not deliver.
2. The FTC's Two Distinct Levers
The Federal Trade Commission reaches health data through two different mechanisms, and candidates confuse them constantly.
A. The Health Breach Notification Rule (16 CFR Part 318)
This rule applies to vendors of personal health records, PHR-related entities, and their service providers that are not HIPAA covered entities or business associates. Its jurisdictional trigger is precisely the gap HIPAA leaves: the consumer health app, the fitness and fertility tracker, the direct-to-consumer testing service, the standalone personal health record.
Key operating features:
- A breach of security includes unauthorized acquisition, and the FTC has applied it to voluntary disclosures the consumer did not authorize — for example, transmission of health data to advertising platforms through embedded trackers.
- Notification runs to affected individuals, the FTC, and, for larger incidents, the media.
- The rule was amended in 2024 to modernize definitions for health apps and to clarify electronic notice methods.
B. FTC Act Section 5 — Deception and Unfairness
Section 5 reaches any commercial actor, including a HIPAA covered entity, whose privacy representations are deceptive or whose data practices are unfair. HIPAA compliance is not a defense to a Section 5 claim. The exposure is generated by the organization's own words:
- A website privacy policy stating that the organization "never shares your information with third parties" while advertising pixels transmit page views on a condition-specific page.
- A patient portal enrollment screen promising encryption the system does not use.
- A marketing email describing a data practice more narrowly than reality.
[!IMPORTANT] The rule to teach the marketing department: every public privacy claim is a legally enforceable promise. The safest posture is that no privacy statement goes live without privacy office review, and that the statement describes what the systems actually do rather than what the organization aspires to.
3. Website and Application Tracking Technologies
Pixels, tag managers, session replay tools, and analytics SDKs embedded on patient-facing pages transmit data to third parties by design. When the page is authenticated, or when an unauthenticated page addresses a specific condition or provider, the transmitted combination of IP address, device identifier, and page context can constitute PHI.
The regulatory history matters for a 2026 candidate. OCR issued guidance in December 2022 and revised it in March 2024, asserting that certain unauthenticated-page tracking involved PHI. On June 20, 2024, the U.S. District Court for the Northern District of Texas vacated the portion of that bulletin treating metadata such as an IP address collected from an unauthenticated page as individually identifiable health information (American Hospital Association v. Becerra); OCR noticed an appeal in August 2024 and then voluntarily withdrew it. The consequence is not that tracking became safe. It is that the risk redistributed: OCR retains authority over authenticated portal tracking and over any transmission that meets the PHI definition, while FTC Section 5, the Health Breach Notification Rule, state consumer health data statutes such as Washington's My Health My Data Act, and a very active plaintiffs' bar all remain fully available.
The defensible operating posture:
- Inventory every tag on every patient-facing property, including those injected by tag managers and by marketing agencies.
- Remove trackers from authenticated pages and from any page whose URL or content reveals a condition, provider specialty, or appointment intent.
- Execute BAAs with analytics vendors only where the vendor will genuinely act as a business associate and can contractually forgo its own use of the data — many advertising platforms will not.
- Re-scan on a schedule. Tags reappear after every website release; a one-time cleanup is not a control.
4. Building a Stakeholder Notice Inventory
Task 1.F is satisfied by a maintained inventory, not by a single document. The privacy officer should be able to produce, on request, a table like this:
| Notice or Communication | Audience | Owner | Governing Framework | Last Reviewed |
|---|---|---|---|---|
| Notice of Privacy Practices | Patients | Privacy officer | 45 CFR 164.520 | |
| Website privacy policy | Public | Privacy officer with marketing | FTC Act Section 5, state law | |
| Patient portal terms and privacy statement | Enrolled patients | Privacy officer with IT | HIPAA, FTC Section 5 | |
| Mobile app disclosures and store listing | App users | Privacy officer with digital | FTC HBNR if outside HIPAA | |
| Billing and payment communications | Patients and guarantors | Revenue cycle | PCI DSS, state law | |
| Research authorizations and consent language | Study participants | Research compliance | 45 CFR 164.508, 164.512(i), Common Rule | |
| Breach notification letters and substitute notice templates | Affected individuals | Privacy officer | 45 CFR 164.404, 164.406 | |
| Employee and workforce privacy notices | Workforce | Human resources | State law, GINA, ADA |
Each row needs an owner, a review date, and a documented sign-off. Notices drift, and drift is what turns a communication problem into an FTC deception case.
A hospital's patient financial services department records all inbound calls for quality purposes. Patients routinely read their credit card number and three-digit security code aloud during those calls, and the recordings are archived for two years. What is the primary compliance defect?
A direct-to-consumer fertility tracking app, operated by a technology company that is neither a covered entity nor a business associate, transmits users' cycle data to an advertising network through an embedded software development kit without user authorization. Which framework most directly governs the incident?
A health system's public website states that it 'never shares any information about your visit with outside companies.' A tag audit reveals that an advertising pixel on the oncology service line pages transmits page URLs and device identifiers to a social media platform. Beyond any HIPAA analysis, what additional exposure does the statement itself create?