Anda di halaman 1dari 1

31836 Federal Register / Vol. 72, No.

110 / Friday, June 8, 2007 / Notices

disclosures, consistent with the Privacy guidance, agencies must consider Time and Date: June 20, 2007: 9 a.m.–3:15
Act’s requirement that individuals be various factors in determining whether p.m.; June 21, 2007: 9 a.m.–3 p.m.
made aware of how their records may be notice is appropriate in a given case. Place: Natcher Center, Building 45,
National Institutes of Health, Bethesda
disclosed, even if the FTC anticipates The routine use published by the FTC Campus, Bethesda, MD.
that there may often be very limited or neither addresses nor is it intended to Status: Open.
no disclosure of an individual’s records supersede or supplant such guidance, or Purpose: At this meeting the Committee
to third parties as part of the agency’s any other applicable guidance that may will hear presentations and hold discussions
investigatory or remedial efforts. later arise in applicable statute, rule or on several health data policy topics. On the
Developing fixed categories of access policy regarding when notice to morning and afternoon of the first day the
for certain entities or individuals, as individuals must or should be given. Committee will hear updates and status
EPIC suggests, would not appear to Accordingly, after consideration of reports from its subcommittees as well as a
confer significantly greater protection, if briefing on the 5010 transaction data set.
the above, the FTC has determined to On the morning of the second day the
any, for an individual’s records than adopt the routine use for data breach as Committee will first hear updates from the
limiting disclosures to those that are originally published, and hereby Department on activities of the Data Council
‘‘reasonably necessary.’’ The amends Appendix 1 of its Privacy Act and the Office of the National Coordinator for
determination of when disclosure is system notices, as published at 57 FR Health Information Technology (ONCHIT)
‘‘reasonably necessary’’ will logically 45678, by adding the following new followed by Committee actions on selected
depend on a case-by-case evaluation of routine use at the end of the existing topics from the subcommittees. The next
the specific circumstances of the breach, item will be a briefing on the International
routine uses set forth in that Appendix:
including how much of an individual’s Health Terminology Standards Development
*** Organization (IHTSDO.) This briefly will be
information, if any, it is reasonably To appropriate agencies, entities, and followed by a discussion of secondary uses
necessary to disclose, and the specific persons when (1) the FTC suspects or of electronic medical record information
nature of the entities to whom such has confirmed that the security or which will continue after the noon break.
information needs to be disclosed, in confidentiality of information in the There will be a short discussion of future
order to investigate or respond to a system of records has been agendas before the meeting adjourns.
breach.5 Amending a routine use to compromised; (2) the FTC has The times shown above are for the full
accommodate disclosures in response to determined that as a result of the Committee meeting. Subcommittee breakout
a breach is not a viable option when sessions are scheduled for late in the
suspected or confirmed compromise afternoon of the first day and in the morning
there is a clear need to respond rapidly there is a risk of harm to economic or prior to the full Committee meeting on the
and effectively in investigating and property interests, identity theft or second day. Agendas for these breakout
mitigating the breach, in light of the fraud, or harm to the security or sessions will be posted on the NCVHS Web
prior notice and comment requirements integrity of this system or other systems site (URL below) when available.
of the Privacy Act for routine use or programs (whether maintained by the Contact Person for More Information:
amendments. FTC or another agency or entity) that Substantive program information as well as
Second, EPIC’s comment advocates rely upon the compromised summaries of meetings and a roster of
that consumers be notified as soon as committee members may be obtained from
information; and (3) the disclosure
possible after a security breach results Marjorie S. Greenberg, Executive Secretary,
made to such agencies, entities, and NCVHS, National Center for Health Statistics,
in their personal information being persons is reasonably necessary to assist Centers for Disease Control and Prevention,
accessed by an unauthorized person, in connection with the FTC’s efforts to 3311 Toledo Road, Room 2402, Hyattsville,
and before notifying any other agency, respond to the suspected or confirmed Maryland 20782, telephone (301) 458–4245.
entity or individual. That issue, compromise and prevent, minimize, or Information also is available on the NCVHS
however, is outside the scope of a remedy such harm. home page of the HHS Web site: http://
routine use notice under the Privacy By direction of the Commission. www.ncvhs.hhs.gov/, where further
Act. The Act requires that agencies Donald S. Clark information including an agenda will be
notify individuals about the Secretary posted when available.
establishment of a Privacy Act system of Should you require reasonable
[FR Doc. E7–11122 Filed 6–7–07: 8:45 am] accommodation, please contact the CDC
records, the routine uses of such [BILLING CODE 6750–01–S] Office of Equal Employment Opportunity on
systems of records, and additional (301) 458–4EEO (4336) as soon as possible.
notice at the time that information in
such a system is collected from Dated: May 31, 2007.
DEPARTMENT OF HEALTH AND James Scanlon,
individuals. HUMAN SERVICES
Nothing in the Act, however, governs Deputy Assistant Secretary for Planning and
or provides criteria for determining Evaluation (SDP), Office of the Assistant
National Committee on Vital and Health Secretary for Planning and Evaluation.
when notice of a data breach to affected Statistics: Meeting
individuals would be appropriate or [FR Doc. 07–2861 Filed 6–7–07; 8:45 am]
not. Guidance on that issue has been Pursuant to the Federal Advisory BILLING CODE 4151–05–M
issued to all Federal agencies by the Committee Act, the Department of
Office of Management & Budget (OMB), Health and Human Services (HHS)
in conjunction with the President’s announces the following advisory DEPARTMENT OF HEALTH AND
Identity Theft Task Force, chaired by committee meeting. HUMAN SERVICES
the Attorney General and co-chaired by Name: National Committee on Vital and Administration on Aging
the FTC Chairman.6 As stated in that Health Statistics (NCVHS).
Agency Information Collection
5 For example, under FTC rules, disclosures to
pwalker on PROD1PC71 with NOTICES

Identity Theft Related Data Breach Notification’’ Activities; Proposed Collection;


other law enforcement agencies may be made on a (Sept. 20, 2006) (attaching Memorandum from the
confidential basis for law enforcement purposes. Identity Theft Task Force, ‘‘Identity Theft Related Comment Request; Fourth National
See Commission Rule 4.11(c), 16 CFR 4.11(c). Data Security Breach Notification Guidance’’ (Sept. Study of Older Americans Act
6 See Memorandum for the Heads of Department 19, 2006), also reproduced in The President’s Recipients
and Agencies, from Clay Johnson, Deputy Director Identity Theft Task Force, Combating Identity Theft:
for Management, OMB, ‘‘Recommendations for A Strategic Plan (Apr. 2007) at 73-82 (App. A)). AGENCY: Administration on Aging, HHS.

VerDate Aug<31>2005 19:26 Jun 07, 2007 Jkt 211001 PO 00000 Frm 00042 Fmt 4703 Sfmt 4703 E:\FR\FM\08JNN1.SGM 08JNN1

Anda mungkin juga menyukai