The American Recovery and Reinvestment
Act of 2009 ("Recovery Act") requires the Department of Health and
Human Services to study, in consultation with the FTC, potential
privacy, security, and breach notification requirements and submit
a report to Congress containing recommendations within one year of
enactment of the Recovery Act. Until Congress enacts new
legislation implementing any recommendations contained in the
HHS/FTC report, the Recovery Act contains temporary requirements,
to be enforced by the FTC, that such entities notify customers in
the event of a security breach. The proposed rule implements these
requirements.
PL:
Pub.L. 111 - 5 13407 Name of Law: American Recovery and
Reinvestment Act of 2009
PL: Pub.L. 111 - 5 13407 Name of Law:
American Recovery and Reinvestment Act of 2009
This is a new rule having
provisions requiring notification to consumers and to the
Commission; thus, there are "collection(s) of information" subject
to the PRA.
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.