Court Rules
All enforcement actions
SettlementLow Risk

FTC Settles with SkyMed Over Unsecured Health Data and HIPAA Misrepresentation

SkyMed International, Inc.February 5, 2021Federal Trade Commission

Consumers Affected

130,000

Summary

The FTC finalized a settlement with SkyMed International, Inc., an emergency travel services provider, for failing to secure sensitive consumer data and deceiving consumers about HIPAA compliance. The company left a cloud database with 130,000 membership records unsecured, containing personal and health information. Under the settlement, SkyMed must notify affected consumers, implement a security program, undergo biennial assessments, and is prohibited from misrepresenting its data practices.

Remedy

SkyMed must send a notice to affected consumers, implement a comprehensive information security program, obtain biennial third-party assessments of its security program, and is prohibited from misrepresenting how it secures personal data, the circumstances of and response to a data breach, and whether it has been endorsed by or participates in any government-sponsored privacy or security program.

Corrective NoticeCompliance ProgramAudit RequirementInjunction

Contract Impact

In-house legal teams should review all vendor agreements, customer contracts, and data processing addendums where SkyMed International, Inc. is a service provider handling personal or health information. Specific clauses to scrutinize include data security obligations, representations regarding regulatory compliance (especially HIPAA), breach notification requirements, audit and assessment rights, and restrictions on misleading marketing claims. Given the unsecured cloud database and false HIPAA seal, contracts may need amendments to mandate specific security frameworks (e.g., NIST, ISO 27001), require removal of unauthorized compliance seals, and incorporate mandatory biennial security assessments by a qualified third party. Additionally, ensure contracts clearly define data handling procedures for sensitive health information and establish robust consumer notification protocols for any security incident.

Contract Search Terms

data security requirementsHIPAA compliance representationcloud database securitybreach notification clausedata processing standardsaudit rightssecurity assessmentsconsumer notification proceduresdata retention policymisrepresentation prohibition

Laws Cited

Health Insurance Portability and Accountability Act

Violation Types

Entity Details

Entity

SkyMed International, Inc.

Also known as: SkyMed

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"SkyMed International, Inc."
Laws Cited
"Health Insurance Portability and Accountability Act (HIPAA)"
Violation Types
"failed to employ reasonable measures to secure the personal information"
Violation Types
"deceived consumers by displaying a 'HIPAA Compliance' seal"

Related Enforcement Actions

FTC

SkyMed International, Inc.

SkyMed International, Inc. settled FTC allegations that it failed to secure sensitive consumer data, including health information, leaving a cloud database with 130,000 records exposed to the public. The FTC also alleged that SkyMed misrepresented HIPAA compliance on its website. As part of the settlement, SkyMed must implement a comprehensive security program, undergo biennial third-party assessments, and send notices to affected consumers.

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.