Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
The United States does not have a single comprehensive federal data protection law equivalent to the GDPR. Instead, the US employs a sectoral approach, with federal laws addressing privacy in specific contexts: health care (HIPAA), financial services (GLBA), children's online data (COPPA), education (FERPA), consumer reporting (FCRA), electronic communications (ECPA), and video rental records (VPPA). The Federal Trade Commission (FTC) exercises broad privacy enforcement authority under Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices. This patchwork creates a complex compliance landscape that requires mapping federal obligations alongside the growing number of state comprehensive privacy laws.
Federal Sectoral Privacy Laws
Health Insurance Portability and Accountability Act (HIPAA)
Statute: Pub. L. 104-191 (1996); HITECH Act, Pub. L. 111-5 (2009)
Regulations: 45 CFR Parts 160, 162, 164
Scope: Covered entities (health plans, health care clearinghouses, health care providers who transmit health information electronically) and their business associates
Key Requirements:
Privacy Rule (45 CFR 164 Subpart E): use and disclosure limitations for Protected Health Information (PHI)
Security Rule (45 CFR 164 Subpart C): administrative, physical, and technical safeguards for ePHI
Breach Notification Rule (45 CFR 164 Subpart D): notification to individuals, HHS, and media for breaches of unsecured PHI
Individual rights: access, amendment, accounting of disclosures, restriction requests
Enforcement: HHS Office for Civil Rights (OCR); state attorneys general
Penalties: Up to USD 2,067,813 per violation per calendar year (2024 adjusted); criminal penalties up to USD 250,000 and 10 years imprisonment
Scope: Financial institutions — broadly defined to include entities significantly engaged in financial activities (banks, insurance companies, securities firms, but also tax preparers, auto dealers offering financing, etc.)
Key Requirements:
Financial Privacy Rule: notice of privacy practices and opt-out for sharing with non-affiliated third parties
Safeguards Rule: comprehensive information security programme with risk assessment, access controls, encryption, multi-factor authentication, incident response
Pretexting protections: prohibition on obtaining customer information through false pretences
Scope: Educational agencies and institutions receiving federal funding
Key Requirements:
Parents (or eligible students over 18) have the right to access education records and request amendments
Written consent required before disclosure of personally identifiable information from education records, with exceptions (directory information, legitimate educational interest, health/safety emergency, judicial order)
Annual notification of rights
Enforcement: US Department of Education, Family Policy Compliance Office
Penalties: Withdrawal of federal funding (in practice, compliance agreements and corrective action)
Children's Online Privacy Protection Act (COPPA)
Statute: 15 U.S.C. 6501-6506 (1998)
Regulations: 16 CFR Part 312 (COPPA Rule)
Scope: Operators of commercial websites and online services directed to children under 13, or that have actual knowledge of collecting personal information from children under 13
Key Requirements:
Verifiable parental consent before collecting personal information from children
Clear privacy notice describing information practices
Parents' rights: review, delete, refuse further collection
Reasonable security measures
Data retention limitations
Enforcement: FTC; state attorneys general
Penalties: Up to USD 50,120 per violation (2024 adjusted)
Fair Credit Reporting Act (FCRA)
Statute: 15 U.S.C. 1681 et seq. (1970, amended by FACTA 2003)
Scope: Consumer reporting agencies, users of consumer reports, furnishers of information
Key Requirements:
Permissible purpose required to obtain consumer reports (credit, employment, insurance, government benefit, legitimate business need)