Hennessy Quoted in Law360 About COVID Health Apps and Privacy Laws
September 18, 2020
Law360
Senior Counsel Jennifer Hennessy was quoted in the Law360 article, “Amid Pandemic, Health Apps Face Privacy Law Patchwork,” which discussed how in a surging market thanks to the coronavirus pandemic, developers of mobile health apps are facing challenges on how to comply with a patchwork of state data security laws.
Much of the traditional health care space is covered by the rigorous data security requirements outlined by federal regulators in the Health Insurance Portability and Accountability Act, or HIPAA. But other companies, like private businesses building apps to screen employees for symptoms of COVID-19, may not be subject to HIPAA’s requirements despite handling sensitive health data.
Separately, the current FTC in May solicited input about whether it should change a decade-old, little-used rule requiring companies that are not covered by HIPAA but still handle health information to publicly report data breaches. The commission asked for advice on whether it should change its Health Breach Notification Rule in light of “legal, economic, and technological changes,” including “developments in health care products or services related to COVID-19.”
The FTC noted at the time that more companies may soon be covered by its rule as patients increasingly turn to technologies such as virtual assistants and mobile health apps that might not be subject to HIPAA. Those companies are instead struggling to navigate a slew of differing state laws addressing how health data should be protected and how to handle a potential data breach. “We think health care and HIPAA go together in this country, and that’s true most of the time, but not always,” Hennessy said.
Much of the traditional health care space is covered by the rigorous data security requirements outlined by federal regulators in the Health Insurance Portability and Accountability Act, or HIPAA. But other companies, like private businesses building apps to screen employees for symptoms of COVID-19, may not be subject to HIPAA’s requirements despite handling sensitive health data.
Separately, the current FTC in May solicited input about whether it should change a decade-old, little-used rule requiring companies that are not covered by HIPAA but still handle health information to publicly report data breaches. The commission asked for advice on whether it should change its Health Breach Notification Rule in light of “legal, economic, and technological changes,” including “developments in health care products or services related to COVID-19.”
The FTC noted at the time that more companies may soon be covered by its rule as patients increasingly turn to technologies such as virtual assistants and mobile health apps that might not be subject to HIPAA. Those companies are instead struggling to navigate a slew of differing state laws addressing how health data should be protected and how to handle a potential data breach. “We think health care and HIPAA go together in this country, and that’s true most of the time, but not always,” Hennessy said.
People
Related News
March 13, 2026
In the News
Chris Babcock and Chris Converse on Wave of Companies Moving to Texas
Foley & Lardner LLP partners Chrisopher Babcock and Chris Converse commented on the widening trend of companies reincorporating to Texas in the Houston Business Journal article, “Texas law changes could spark wave of corporate redomestication proposals."
March 12, 2026
In the News
Louis Lehot Explores M&A's Growing Blitzhire Phenomenon
Foley & Lardner LLP partner Louis Lehot authors article on the emergence of blitzhires in the Mergers & Acquisitions article, “Blitzhires: The New Fast-Moving M&A Deal.”
March 10, 2026
In the News
Aaron Maguregui Shares Insights on Shadow AI Risks in Health Care
Foley & Lardner LLP partner Aaron Maguregui was quoted in the Part B News article, “Do you need AI policy? Experts suggest guardrails as 'shadow AI' spreads,” discussing the emerging risks of unsanctioned 'shadow AI' use by clinicians and the need to establish robust AI governance.