Court Rules
All enforcement actions
SettlementLow Risk

FTC Settles with SkyMed Over Unsecured Health Data and HIPAA Misrepresentation

SkyMed International, Inc.February 5, 2021Federal Trade Commission

Consumers Affected

130,000

Summary

The FTC finalized a settlement with SkyMed International, Inc., an emergency travel services provider, for failing to secure sensitive consumer data and deceiving consumers about HIPAA compliance. The company left a cloud database with 130,000 membership records unsecured, containing personal and health information. Under the settlement, SkyMed must notify affected consumers, implement a security program, undergo biennial assessments, and is prohibited from misrepresenting its data practices.

Remedy

SkyMed must send a notice to affected consumers, implement a comprehensive information security program, obtain biennial third-party assessments of its security program, and is prohibited from misrepresenting how it secures personal data, the circumstances of and response to a data breach, and whether it has been endorsed by or participates in any government-sponsored privacy or security program.

Corrective NoticeCompliance ProgramAudit RequirementInjunction

Contract Impact

In-house legal teams should review all vendor agreements, customer contracts, and data processing addendums where SkyMed International, Inc. is a service provider handling personal or health information. Specific clauses to scrutinize include data security obligations, representations regarding regulatory compliance (especially HIPAA), breach notification requirements, audit and assessment rights, and restrictions on misleading marketing claims. Given the unsecured cloud database and false HIPAA seal, contracts may need amendments to mandate specific security frameworks (e.g., NIST, ISO 27001), require removal of unauthorized compliance seals, and incorporate mandatory biennial security assessments by a qualified third party. Additionally, ensure contracts clearly define data handling procedures for sensitive health information and establish robust consumer notification protocols for any security incident.

Contract Search Terms

data security requirementsHIPAA compliance representationcloud database securitybreach notification clausedata processing standardsaudit rightssecurity assessmentsconsumer notification proceduresdata retention policymisrepresentation prohibition

Laws Cited

Health Insurance Portability and Accountability Act

Violation Types

Entity Details

Entity

SkyMed International, Inc.

Also known as: SkyMed

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"SkyMed International, Inc."
Laws Cited
"Health Insurance Portability and Accountability Act (HIPAA)"
Violation Types
"failed to employ reasonable measures to secure the personal information"
Violation Types
"deceived consumers by displaying a 'HIPAA Compliance' seal"

Related Enforcement Actions

FTC

SkyMed International, Inc.

SkyMed International, Inc. settled FTC allegations that it failed to secure sensitive consumer data, including health information, leaving a cloud database with 130,000 records exposed to the public. The FTC also alleged that SkyMed misrepresented HIPAA compliance on its website. As part of the settlement, SkyMed must implement a comprehensive security program, undergo biennial third-party assessments, and send notices to affected consumers.

FTC

Federal Trade Commission

The FTC rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had purported to apply the Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The rescission follows the Commission's 2024 update to the Health Breach Notification Rule, which already covers health apps and connected devices like fitness trackers, and implements an executive order directing agencies to eliminate obsolete guidance documents. No company was charged or penalized; this is a deregulatory action.

FTC

Humboldt Merchant Services

$12.0M

The FTC alleged that payment processor Humboldt Merchant Services knowingly processed payments for more than 1,000 shell merchant entities serving as fronts for fraudulent companies engaged in unauthorized billing scams, despite red flags including chargeback rates nearly 10 times higher than card-brand thresholds. Under the proposed stipulated order filed in the U.S. District Court for the Eastern District of Michigan, Humboldt will pay $12 million for consumer redress and is permanently banned from processing payments for merchants with a heightened risk of potential fraud.

FTC

Nuvei Corporation

$4.8M

The FTC charged Canada-based payment processor Nuvei Corporation and its subsidiaries with knowingly processing payments for fraudulent merchants, including more than $30 million in payments for the Reimage tech support scam from 2017 to 2023, as well as merchants making false earnings claims and impersonating government tax authorities. Under the stipulated order filed in the U.S. District Court for the District of Arizona, Nuvei will pay $4.85 million for consumer redress, is banned from serving tech support telemarketers, and must implement robust merchant screening and chargeback monitoring practices. Note: this is a payments-fraud facilitation action under the FTC Act and Telemarketing Sales Rule, not a data privacy violation.

FTC

N/A (no entity named - agency policy announcement)

The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.

FTC

Amazon.com, Inc.

Colorado Attorney General Phil Weiser joined the FTC and 22 state attorneys general in filing a lawsuit against Amazon for manipulating the auctions used to set advertising prices, replacing actual auction results with higher prices since 2019 and overcharging nearly 1.2 million U.S. advertising customers. The FTC estimates total improper surcharges from 2018 to 2026 exceed $20 billion, with costs ultimately passed to shoppers through higher prices. The states seek a permanent injunction and monetary relief; no penalty has been imposed yet as this is a newly filed complaint.