Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
The United States does not have a single comprehensive federal data protection law equivalent to the GDPR. Instead, the US employs a sectoral approach, with federal laws addressing privacy in specific contexts: health care (HIPAA), financial services (GLBA), children's online data (COPPA), education (FERPA), consumer reporting (FCRA), electronic communications (ECPA), and video rental records (VPPA). The Federal Trade Commission (FTC) exercises broad privacy enforcement authority under Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices. This patchwork creates a complex compliance landscape that requires mapping federal obligations alongside the growing number of state comprehensive privacy laws.
Federal Sectoral Privacy Laws
Health Insurance Portability and Accountability Act (HIPAA)
Statute: Pub. L. 104-191 (1996); HITECH Act, Pub. L. 111-5 (2009)
Regulations: 45 CFR Parts 160, 162, 164
Scope: Covered entities (health plans, health care clearinghouses, health care providers who transmit health information electronically) and their business associates
Key Requirements:
Privacy Rule (45 CFR 164 Subpart E): use and disclosure limitations for Protected Health Information (PHI)
Security Rule (45 CFR 164 Subpart C): administrative, physical, and technical safeguards for ePHI
Breach Notification Rule (45 CFR 164 Subpart D): notification to individuals, HHS, and media for breaches of unsecured PHI
Individual rights: access, amendment, accounting of disclosures, restriction requests
Enforcement: HHS Office for Civil Rights (OCR); state attorneys general
Penalties: Up to USD 2,067,813 per violation per calendar year (2024 adjusted); criminal penalties up to USD 250,000 and 10 years imprisonment
Scope: Financial institutions — broadly defined to include entities significantly engaged in financial activities (banks, insurance companies, securities firms, but also tax preparers, auto dealers offering financing, etc.)
Key Requirements:
Financial Privacy Rule: notice of privacy practices and opt-out for sharing with non-affiliated third parties
Safeguards Rule: comprehensive information security programme with risk assessment, access controls, encryption, multi-factor authentication, incident response
Pretexting protections: prohibition on obtaining customer information through false pretences
Scope: Educational agencies and institutions receiving federal funding
Key Requirements:
Parents (or eligible students over 18) have the right to access education records and request amendments
Written consent required before disclosure of personally identifiable information from education records, with exceptions (directory information, legitimate educational interest, health/safety emergency, judicial order)
Annual notification of rights
Enforcement: US Department of Education, Family Policy Compliance Office
Penalties: Withdrawal of federal funding (in practice, compliance agreements and corrective action)
Children's Online Privacy Protection Act (COPPA)
Statute: 15 U.S.C. 6501-6506 (1998)
Regulations: 16 CFR Part 312 (COPPA Rule)
Scope: Operators of commercial websites and online services directed to children under 13, or that have actual knowledge of collecting personal information from children under 13
Key Requirements:
Verifiable parental consent before collecting personal information from children
Clear privacy notice describing information practices
Parents' rights: review, delete, refuse further collection
Reasonable security measures
Data retention limitations
Enforcement: FTC; state attorneys general
Penalties: Up to USD 50,120 per violation (2024 adjusted)
Fair Credit Reporting Act (FCRA)
Statute: 15 U.S.C. 1681 et seq. (1970, amended by FACTA 2003)
Scope: Consumer reporting agencies, users of consumer reports, furnishers of information
Key Requirements:
Permissible purpose required to obtain consumer reports (credit, employment, insurance, government benefit, legitimate business need)