NY AG Announces Settlements with Three Mobile-Health App Developers Over Privacy, Marketing Concerns

Robinson+Cole Data Privacy + Security Insider
Contact

On March 23, 2017, New York State Attorney General Eric T. Schneiderman announced settlements with three mobile health application (app) development companies aimed at curbing deceptive marketing practices and inadequate privacy disclosures to consumers. The settlements – reached with Cardiio, Inc., Matis Ltd., and Runtastic GmbH, respectively – target health measurement apps that “purport to measure vital signs or other indicators of health using only a smartphone’s camera and sensors, without any need for an external device.”

The Office of Attorney General (OAG) expressed concern that growing consumer reliance on health-related apps “can be harmful” if the apps provide inaccurate or misleading results because they could cause consumers to potentially forgo necessary medical treatment, or conversely incur unnecessary treatment, in reliance on false assurances of health provided by such apps. In the settlements the OAG highlighted apparent issues it had identified with each of the developers’ apps, including:

  • That both Cardiio and Runtastic created a “net impression” via claims made on their websites and in app store listings that their respective heart rate monitor apps would accurately measure and monitor a consumer’s heart rate “without providing sufficient evidence substantiating” their claims regarding the app’s accuracy; and
  • That Matis made unsubstantiated claims regarding its fetal heartbeat app’s ability to monitor and play the sound of a fetal heartbeat by placing a smartphone on a woman’s stomach.

The OAG also cited deficiencies in each developer’s privacy practices as grounds for its enforcement actions. For example, the OAG each of the developers for relying on a “default consent” by users to be bound by their respective privacy policies as a condition of submitting data related to their conditions, and faulted each entity for not informing users that their personal information may not be protected under HIPAA. The OAG also found that the developers failed to fully disclose the types of information collected and stored by their apps.

To resolve the OAG’s investigations, the developers agreed to pay monetary penalties, document substantiation of claims concerning app-functionality, and also to update their disclosures to consumers. Among other obligations, the developers were required to more clearly notify consumers that the apps are not for medical use, and to agree to not make false or misleading marketing claims. Cardiio and Runtastic also agreed to require users to affirmatively consent to be bound by their respective app’s privacy policy. As health-related mobile apps proliferate to increase patient engagement and wellness, this enforcement action serves as a reminder to developers in the highly-regulated health care market of the need to implement accurate marketing materials and comprehensive privacy policies.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Robinson+Cole Data Privacy + Security Insider

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide