State and federal privacy rules have changed. A payment can clear successfully, the card can be protected — and your business can still have a consumer-data exposure. When penalties are assessed per violation, one overlooked data flow can become a significant financial risk.
See What Your State Can FinePCI DSS, encryption and tokenization protect critical payment credentials. But a modern transaction can involve information surrounding the payment — information that can identify, describe or be linked to a consumer.
State laws differ, but the research supplied to Fluid Financial identifies civil penalty structures reaching thousands — and in some circumstances tens of thousands — of dollars per violation. If conduct affects many consumers or transactions, potential exposure can escalate rapidly where the applicable statute treats them as separate violations. Some states provide cure opportunities; others have eliminated mandatory cure periods or leave them to regulator discretion.
“We are PCI compliant” may not answer those questions. Payment-card security and consumer-data privacy are related, but they are not the same problem.
Before the regulator asks the questions, know the answers. Enter your information and select a state to see the fines and enforcement provisions currently identified in Fluid Financial's working state-law research.
Submit your details to receive your state results and request follow-up from Fluid Financial. We will record your contact information and selected state and notify our team. See our Privacy Policy.
Federal obligations can apply whether or not your state has a comprehensive consumer privacy law. Coverage depends on your business, the information involved and how it is used. State requirements may apply alongside federal rules; this is not a complete list of laws.
For covered entities and business associates, HIPAA governs protected health information (PHI). Under 45 CFR 164.506, covered entities may generally use or disclose PHI for treatment, payment and healthcare operations without individual authorization, subject to limits. Payment activities include billing, claims and collections. Payment disclosures and requests generally must be limited to the minimum necessary, subject to the Rule’s exceptions.
HHS payment guidance · Read the supplied HHS payment guidance (PDF, revised April 2003)Covered entities and business associates must protect electronic PHI with administrative, physical and technical safeguards, including risk analysis and appropriate access controls. Breaches of unsecured PHI can trigger notification to affected individuals, HHS and, in some cases, the media, subject to the Rule’s exceptions and assessment requirements.
HHS Security Rule · HHS breach notificationFor businesses within FTC jurisdiction, deceptive privacy promises or unfair data practices can lead to enforcement under Section 5 of the FTC Act. Certain personal health record vendors, related entities and service providers outside HIPAA also have obligations under the FTC Health Breach Notification Rule. It does not cover every business holding health information.
FTC health privacy guidance · FTC breach rule coverageCovered financial institutions have duties concerning the privacy and security of customers’ nonpublic personal information. The FTC Safeguards Rule requires covered institutions under its jurisdiction to maintain an information security program. Coverage depends on the financial activities performed and the responsible regulator; accepting card payments alone does not establish coverage.
FTC financial privacy guidance · Safeguards Rule coverageThe supplied PDF explains permitted healthcare payment disclosures under the Privacy Rule; it is not the Security Rule and does not make every payment record PHI. HHS distinguishes financial institutions carrying out ordinary consumer payment transfers from vendors providing services involving PHI on behalf of a covered entity. Routine funds-transfer activities alone do not require a business associate agreement; additional services involving PHI can change that analysis.
Review what billing details, patient identifiers and transaction metadata each vendor receives, why it receives them, and whether it reuses or discloses them. A permitted payment disclosure does not provide unlimited permission for unrelated uses.
HHS business associate and financial-institution guidanceFederal enforcement and penalties depend on the applicable law, violation and circumstances. These rules are not an automatic fine schedule for every merchant, and federal and state maximums should not simply be added together. The supplied PDF is historical HHS guidance; use the linked agency sources and qualified counsel to confirm current requirements.
Source: Fluid Financial state-law working research. This working research has not been independently legally verified. Confirm current law and applicability with qualified counsel.
This tool provides general educational information and is not legal advice. Whether a law applies, whether a violation has occurred, and the amount of any penalty depend on the particular statute, business, data, conduct and circumstances.
MEDToken™ is designed for healthcare transaction protection. ICX™ is designed to reduce unnecessary exposure and movement of sensitive consumer information associated with commercial and payment transactions.