Security & Compliance
Transaction Privacy Exposure

Your business may be one transaction away from a serious privacy problem.

State and federal privacy rules have changed. A payment can clear successfully, the card can be protected — and your business can still have a consumer-data exposure. When penalties are assessed per violation, one overlooked data flow can become a significant financial risk.

See What Your State Can Fine
The risk has changed

Your processor can protect the card and still leave you asking: what happened to the rest of the data?

PCI DSS, encryption and tokenization protect critical payment credentials. But a modern transaction can involve information surrounding the payment — information that can identify, describe or be linked to a consumer.

IdentityLocationMerchantPurchaseDate & TimeDeviceTransaction InformationBehavioral InformationPhoneEmail
State enforcement

One data problem can multiply into many violations.

State laws differ, but the research supplied to Fluid Financial identifies civil penalty structures reaching thousands — and in some circumstances tens of thousands — of dollars per violation. If conduct affects many consumers or transactions, potential exposure can escalate rapidly where the applicable statute treats them as separate violations. Some states provide cure opportunities; others have eliminated mandatory cure periods or leave them to regulator discretion.

$7,500per violation under certain state laws
$10,000per violation under certain state laws
$20,000per violation under certain state laws
$50,000+possible under certain laws and circumstances
The uncomfortable questions

If an Attorney General asked today, could you answer these?

01What consumer information leaves with each transaction?
02Which processors, platforms, vendors and analytics systems receive it?
03Can that information identify, describe or be linked to a consumer?
04Which state and federal requirements govern how you handle it?

“We are PCI compliant” may not answer those questions. Payment-card security and consumer-data privacy are related, but they are not the same problem.

State privacy assessment

Find Your State Privacy Exposure

Before the regulator asks the questions, know the answers. Enter your information and select a state to see the fines and enforcement provisions currently identified in Fluid Financial's working state-law research.

Federal privacy rules to review in every state

Federal obligations can apply whether or not your state has a comprehensive consumer privacy law. Coverage depends on your business, the information involved and how it is used. State requirements may apply alongside federal rules; this is not a complete list of laws.

HIPAA Privacy Rule: healthcare payment information

For covered entities and business associates, HIPAA governs protected health information (PHI). Under 45 CFR 164.506, covered entities may generally use or disclose PHI for treatment, payment and healthcare operations without individual authorization, subject to limits. Payment activities include billing, claims and collections. Payment disclosures and requests generally must be limited to the minimum necessary, subject to the Rule’s exceptions.

HHS payment guidance · Read the supplied HHS payment guidance (PDF, revised April 2003)
HIPAA Security and Breach Notification Rules

Covered entities and business associates must protect electronic PHI with administrative, physical and technical safeguards, including risk analysis and appropriate access controls. Breaches of unsecured PHI can trigger notification to affected individuals, HHS and, in some cases, the media, subject to the Rule’s exceptions and assessment requirements.

HHS Security Rule · HHS breach notification
FTC Act and health breach notification

For businesses within FTC jurisdiction, deceptive privacy promises or unfair data practices can lead to enforcement under Section 5 of the FTC Act. Certain personal health record vendors, related entities and service providers outside HIPAA also have obligations under the FTC Health Breach Notification Rule. It does not cover every business holding health information.

FTC health privacy guidance · FTC breach rule coverage
GLBA: consumer financial information

Covered financial institutions have duties concerning the privacy and security of customers’ nonpublic personal information. The FTC Safeguards Rule requires covered institutions under its jurisdiction to maintain an information security program. Coverage depends on the financial activities performed and the responsible regulator; accepting card payments alone does not establish coverage.

FTC financial privacy guidance · Safeguards Rule coverage

What this means for payment data

The supplied PDF explains permitted healthcare payment disclosures under the Privacy Rule; it is not the Security Rule and does not make every payment record PHI. HHS distinguishes financial institutions carrying out ordinary consumer payment transfers from vendors providing services involving PHI on behalf of a covered entity. Routine funds-transfer activities alone do not require a business associate agreement; additional services involving PHI can change that analysis.

Review what billing details, patient identifiers and transaction metadata each vendor receives, why it receives them, and whether it reuses or discloses them. A permitted payment disclosure does not provide unlimited permission for unrelated uses.

HHS business associate and financial-institution guidance
Request a Transaction Privacy Assessment

A successful payment does not mean your privacy risk ended.

MEDToken™ is designed for healthcare transaction protection. ICX™ is designed to reduce unnecessary exposure and movement of sensitive consumer information associated with commercial and payment transactions.