Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Settles SkyMed International for Health Data Security Failures

SkyMed International, Inc.December 16, 2020Federal Trade Commission

Consumers Affected

130,000

Summary

SkyMed International, Inc. settled FTC allegations that it failed to secure sensitive consumer data, including health information, leaving a cloud database with 130,000 records exposed to the public. The FTC also alleged that SkyMed misrepresented HIPAA compliance on its website. As part of the settlement, SkyMed must implement a comprehensive security program, undergo biennial third-party assessments, and send notices to affected consumers.

Remedy

SkyMed is required to establish and maintain a comprehensive information security program, obtain regular third-party audits, notify affected consumers about the data breach, and cease making false claims about its data security and HIPAA compliance.

InjunctionCompliance ProgramAudit RequirementCorrective Notice

Contract Impact

In-house legal teams should review all agreements involving the processing of consumer health data, including vendor contracts, customer membership agreements, and data processing addendums. Specific clauses to examine are data security provisions, HIPAA compliance representations, breach notification obligations, and audit rights. Changes may be needed to mandate robust security measures like encryption and access controls, require regular third-party assessments, ensure accurate compliance certifications, and establish clear, timely breach notification procedures to protect sensitive health information.

Contract Search Terms

comprehensive information security programHIPAA compliance representationrisk assessment requirementpenetration testing provisionnetwork monitoring obligationthird-party security assessment clausebreach notification timelineconsumer notice requirementdata encryption standardaccess control measures

Laws Cited

HIPAA

Violation Types

Entity Details

Entity

SkyMed International, Inc.

Also known as: SkyMed International

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"SkyMed International, Inc."
Laws Cited
"HIPAA"
Violation Types
"failed to take reasonable steps to secure sensitive consumer information"

Related Enforcement Actions

FTC

SkyMed International, Inc.

The FTC finalized a settlement with SkyMed International, Inc., an emergency travel services provider, for failing to secure sensitive consumer data and deceiving consumers about HIPAA compliance. The company left a cloud database with 130,000 membership records unsecured, containing personal and health information. Under the settlement, SkyMed must notify affected consumers, implement a security program, undergo biennial assessments, and is prohibited from misrepresenting its data practices.

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.