Consumer Law Library

Henry Schein Practice Solutions, Inc.

Volume 161 · 161 F.T.C. 705

Citation
161 F.T.C. 705
Docket
C-4575
Complaint
2016-05-20
Decision
2016-05-20
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
dental practice management software
Outcome
consent order entered
Relief
notice_to_customers; redress; recordkeeping; compliance_reporting
Money (USD)
250000
Order term (years)
20
Commission counsel
The Respondent, its attorney, and counsel
Source
Original volume PDF
Original PDF
This decision as a PDF

deceptive advertisingprivacy data security

Cite this decision

Henry Schein Practice Solutions, Inc., 161 F.T.C. 705 (2016). Consumer Law Library, https://consumerlawlibrary.org/decisions/v161-0014

Report an error in this record (decision id v161-0014)

Order status: active_until:2036-05-20. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF HENRY SCHEIN PRACTICE SOLUTIONS, INC.

CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4575; File No. 142 3161 Complaint, May 20, 2016 – Decision, May 20, 2016 This consent order addresses Henry Schein Practice Solutions, Inc.’s data security claims for its Dentrix G5 software. The complaint alleges that Henry Schein violated Section 5 of the Federal Trade Commission Act by making falsely representing that Dentrix G5 provides industry-standard encryption of patient data and helps dentists meet the security requirements of the Health Insurance Portability and Accountability Act. The consent order requires Henry Schein to notify affected customers that Dentrix G5 uses a less complex encryption algorithm to protect patient data than Advanced Encryption Standard, which is recommended as an industry standard by the National Institute of Standards and Technology. The Order also requires Henry Schein to pay $250,000 into a fund to be administered by the Commission for such other relief (including consumer information remedies) as it determines is reasonably related to Henry Schein’s practices. Participants For the Commission: Jessica Lyon and Kristin Madigan. For the Respondent: Stephen Chuk and Christopher Ondeck, Proskauer Rose, LLP.

COMPLAINT The Federal Trade Commission, having reason to believe that Henry Schein Practice Solutions, Inc., a corporation, has violated the provisions of the Federal Trade Commission Act, and it appearing to the Commission that this proceeding is in the public interest, alleges:

1. Respondent Henry Schein Practice Solutions, Inc. (“Henry Schein”) is a Utah corporation with its principal office or place of business at 1220 South 630 East, American Fork, Utah 84003. VOLUME 161 Complaint 2. Respondent manufactures, advertises, offers for sale, sells, and distributes office management software for dental practices, including but not limited to the Dentrix software described below. 3. The acts or practices of Respondent alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the Federal Trade Commission Act. Respondent’s Business Practices 4. Dentrix software enables dentists to perform common office tasks such as entering patient data, sending appointment reminders, processing patient payments, submitting patient insurance claims, documenting treatment planning, entering progress notes, and recording diagnostic information. 5. In the spring of 2012, Respondent introduced the Dentrix G5 software (“Dentrix G5”). Dentrix G5 incorporated a new “database engine” provided by a third-party vendor, which included new capabilities, including a form of data protection that Respondent advertised as “encryption.”

6. Dentists use Dentrix G5 to collect and store patients’ personal information. The personal information can consist of sensitive information about patients, including, in some instances: name, address, telephone number, Social Security number, date of birth, driver’s license number, email address, web user ID and password, picture, name of insurance providers, clinical notes, prescriptions, and diagnoses. 7. As early as November 2010, the database engine vendor informed Respondent that the form of data protection used in Dentrix G5 was a proprietary algorithm that had not been tested publicly, and was less secure and more vulnerable than widelyused, industry-standard encryption algorithms, such as Advanced Encryption Standard (“AES”) encryption. 8. Prior to releasing Dentrix G5, Respondent was aware that the Department of Health and Human Services (“HHS”) directs healthcare providers, including most dentists, to guidance HENRY SCHEIN PRACTICE SOLUTIONS, INC. 707 Complaint promulgated by the National Institute of Standards and Technology (“NIST”) to help them meet their regulatory obligations to protect patient data. The NIST guidance recommends AES encryption. Respondent was also aware that HHS’ Breach Notification Rule, 45 C.F.R. §§ 164.400-414, requires dentists to notify patients of certain breaches, but includes a “safe harbor” so that dentists would not have to notify patients about breached data that was encrypted consistent with NIST Special Publication 800-111.

9. Nevertheless, for a period of two years Respondent has disseminated or caused to be disseminated promotional materials and statements for the Dentrix G5 software that emphasize the product’s ability to encrypt patient data and help dentists meet regulatory obligations related to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), including but not limited to the following statements:

a. “The database also provides new encryption capabilities that can help keep patient records safe and secure. And of course, encryption plays a key role in your efforts to stay compliant with HIPAA security standards.” (Dentrix G5 brochure).

b. “Henry Schein is pleased to announce the release of Dentrix G5. G5 stores information in an SQL database, which . . . offers improved protection by storing your patient data in an encrypted format.” (eNewsletter Article).

c. “The SQL database also offers improved protection by storing customer data in an encrypted format. With ever-increasing data protection regulations, Dentrix G5 provides an important line of defense for both patient and practitioner.” (eNewsletter Article). d. “With the release of Dentrix G5, Dentrix now stores information in an SQL database, which delivers several distinct benefits for your practice, including improved data access speed and improved data protection by storing customer data in an encrypted VOLUME 161 Complaint format. With medical professionals under strict regulatory obligations to protect their patients’ personal health information, the new Dentrix G5 database provides an important line of defense for both patient and practitioner.” (Dentrix Magazine). e. “Dentrix versions prior to G5 relied on the underlying Microsoft operating system and file system safeguard to protect user data. Unfortunately, these were rarely activated by default, and if practices failed to turn them on, their data were at risk to hackers. With Dentrix G5’s embedded SQL database, users have the advanced protection they need without burdening them with another system to manage.”

(Interview in DentalTown Magazine).

10. On June 10, 2013, the United States Computer Emergency Readiness Team (“US-CERT”) issued Vulnerability Note VU#900031, describing the form of data protection used in Dentrix G5 software as a “weak obfuscation algorithm.” On June 16, 2013, NIST published a corresponding vulnerability alert. 11. The US-CERT Vulnerability Note stated that the database engine vendor had agreed to re-brand the data protection as “Data Camouflage” so it would not be confused with standard encryption algorithms, such as AES encryption. 12. Despite receiving notice of the US-CERT Vulnerability Note and the database vendor’s decision to re-brand in June 2013, for an additional seven months, Respondent continued to disseminate marketing materials stating that Dentrix G5 “encrypts” patient data and offers “encryption.” 13. The facts set forth in Paragraphs 7 and 10 would be material to dentists’ purchase of Dentrix G5. An attacker who unmasks patients’ sensitive personal information could subject patients to the unanticipated disclosure of personal information or use that information to commit identity theft, medical identity theft, or other harms. If dentists were aware that Dentrix G5 used a form of data protection that was more vulnerable than widely- HENRY SCHEIN PRACTICE SOLUTIONS, INC. 709 Complaint used, industry standard encryption algorithms, they may have chosen to purchase another product.

14. The facts set forth in Paragraphs 7, 8, and 10 would also be material to dentists’ use of Dentrix G5. For instance, without knowing that Dentrix G5 provided only minimal protection for their patients’ sensitive personal information, dentists may not take other reasonable and commercially available steps to protect patients’ sensitive personal information. 15. Moreover, the facts set forth in Paragraphs 7, 8, and 10 would be material to dentists responding to a data breach. For example, in the event of a breach, dentists may mistakenly believe they qualify for the encryption safe harbor under the Breach Notification Rule, and are not required to notify patients in the event of a breach. Even if a dentist does notify patients, the dentist may misinform patients about their risk of identity theft by telling them that the lost data was “encrypted.” 16. Finally, in January 2014, following a series of online media reports criticizing the company’s failure to amend its encryption claims, Respondent published the following statement in the Spring 2014 issue of Dentrix Magazine: “Available only in Dentrix G5, we previously referred to this data protection as encryption. Based on further review, we believe that referring to it as a data masking technique using cryptographic technology would be more appropriate.”

17. Respondent concurrently revised an array of its marketing materials replacing references to “encryption” or “encryption capabilities” with references to “a data masking technique using cryptographic technologies.” Respondent also added language to many of its marketing materials warning users that this data masking technique “helps to supplement, not replace” a dentist’s own security measures.

18. Aside from revising its marketing materials as described, Respondent did not take any additional steps to alert dentists who purchased Dentrix G5 prior to January 2014, that the software VOLUME 161 Complaint used a less complex algorithm to protect patient data than a standard encryption algorithm such as AES encryption. Violations of Section 5 Count I Deceptive Claims of Encryption – Industry-Standard 19. Through the means described in Paragraphs 5, 9, and 12 Respondent has represented, directly or indirectly, expressly or by implication, that Dentrix G5 provides industry-standard encryption.

20. In truth and in fact, as described in Paragraphs 7, 10, and 11, Dentrix G5 used technology that was less secure than industry-standard encryption. Therefore, the representation set forth in Paragraph 19 was false or misleading. Count II Deceptive Claims of Encryption – Regulatory Obligations 21. Through the means described in Paragraphs 5, 9, and 12 Respondent has represented, directly or indirectly, expressly or by implication, that Dentrix G5 helps dentists protect patient data, as required by HIPAA.

22. In truth and in fact, as described in Paragraphs 7, 8, 10, and 11, Dentrix G5 used technology that was not capable of helping dentists protect patient data, as required by HIPAA. Therefore, the representation set forth in Paragraph 21 was false or misleading.

23. The acts and practices of Respondent as alleged in this complaint constitute unfair or deceptive acts or practices, in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission this twentieth day of May, 2016, has issued this complaint against Respondent. By the Commission.

HENRY SCHEIN PRACTICE SOLUTIONS, INC. 711 Decision and Order DECISION AND ORDER The Federal Trade Commission (“Commission” or “FTC”), having initiated an investigation of certain acts and practices of the Respondent named in the caption hereof, and the Respondent having been furnished thereafter with a copy of a draft of complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge Respondent with violations of the Federal Trade Commission Act (“FTC Act”), 15 U.S.C. § 45 et seq.;

The Respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), which includes: a statement by Respondent that it neither admits nor denies any of the allegations in the draft complaint, except as specifically stated in the Consent Agreement, and, only for purposes of this action, admits the facts necessary to establish jurisdiction; and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the Respondent has violated the FTC Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, and having duly considered the comments filed by interested persons, now in further conformity with the procedure prescribed in Commission Rule 2.34, 16 C.F.R. § 2.34, the Commission hereby issues its Complaint, makes the following jurisdictional findings, and enters the following Order:

1. Respondent Henry Schein Practice Solutions, Inc. (“Henry Schein”) is a Utah corporation with its principal office or place of business at 1220 South 630 East, American Fork, Utah 84003.

2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the VOLUME 161 Decision and Order Respondent, and the proceeding is in the public interest.

ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:

A. “Affected Customer(s)” means any consumer, including any dental practice, that purchased the Dentrix G5 dental office practice management software.

B. “Commerce” means as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. C. “Clear(ly) and Conspicuous(ly)” means that a required disclosure is difficult to miss (i.e., easily noticeable) and easily understandable by ordinary consumers, including in all of the following ways: A. In any communication that is solely visual or solely audible, the disclosure must be made through the same means through which the communication is presented. In any communication made through both visual and audible means, such as a television advertisement, the disclosure must be presented simultaneously in both the visual and audible portions of the communication, even if the representation requiring the disclosure is made in only one means. B. A visual disclosure, by its size, contrast, location, the length of time it appears, and other characteristics, must stand out from any accompanying text or other visual elements so that it is easily noticed, read, and understood. C. An audible disclosure, including by telephone or streaming video, must be delivered in a volume, HENRY SCHEIN PRACTICE SOLUTIONS, INC. 713 Decision and Order speed, and cadence sufficient for ordinary consumers to easily hear and understand it. D. In any communication using an interactive electronic medium, such as the Internet or software, the disclosure must be unavoidable. E. On a product label, the disclosure must be presented on the principal display panel. F. The disclosure must use diction and syntax understandable to ordinary consumers and must appear in each language in which the representation that requires the disclosure appears. D. “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, Pub.L. 104-191, 110 Stat. 1936.

E. “Personal Information” shall mean individually identifiable information from or about an individual consumer including, but not limited to: (a) a first and last name; (b) a home or other physical address, including street name; (c) online contact information, such as an email address, instant messaging user identifier, or screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license number or other government-issued identification number; (g) a bank account, debit card, or credit card account number; (h) a photograph; and (i) medical information about a consumer including, but not limited to, prescription information, clinical laboratory testing information, health insurance information, physician examination notes, and medical history. F. “Respondent” shall mean Henry Schein Practice Solutions, Inc. and its successors and assigns. VOLUME 161 Decision and Order I.

IT IS ORDERED that Respondent, directly or through any corporation, subsidiary, division, or other device, in connection with the labeling, advertising, promotion, offering for sale, sale, or distribution of any product or service designed to collect or store Personal Information, in or affecting commerce, shall not misrepresent, in any matter, expressly or by implication: A. whether or to what extent the product or service offers industry-standard encryption;

B. the ability of the product or service to help customers meet regulatory obligations related to privacy or security; or C. the extent to which a product or service maintains the privacy, security, confidentiality, and integrity of Personal Information.

II.

IT IS FURTHER ORDERED that Respondent must notify Affected Customers, Clearly and Conspicuously, that Dentrix G5 uses a less complex encryption algorithm to protect patient data than Advanced Encryption Standard (“AES”), which is recommended as an industry standard by the National Institute of Standards and Technology (“NIST”). Notification must include the following:

A. Respondent must identify all Affected Customers who purchased Dentrix G5 prior to January 2014 (“eligible customers”).

1. Such eligible customers, and their contact information, must be identified to the extent such information is in Respondent’s possession, custody, or control.

HENRY SCHEIN PRACTICE SOLUTIONS, INC. 715 Decision and Order 2. Eligible customers include those identified at any time through the eligibility period, which runs for one (1) year after the date of service of this order. B. Respondent must notify all identified eligible customers by mailing each a notice:

1. The letter must be in the form shown in Attachment A.

2. The envelope containing the letter must be in the form shown in Attachment B.

3. The mailing of the notification letter must not include any other enclosures.

4. The mailing must be sent by first-class mail, postage prepaid, address correction service requested with forwarding and return postage guaranteed. For any mailings returned as undeliverable, Respondent must use standard search methodologies such as re-checking Respondent’s records and the Postal Service’s National Change of Address database and remailing to the corrected address within eight days. C. Respondent must notify all eligible customers within sixty (60) days after service of this order and any eligible customers identified thereafter within thirty (30) days of their identification.

D. Respondent must establish a toll-free telephone number and an email address dedicated to responding to inquiries about the order and must respond promptly and accurately to such inquiries.

E. Respondent must submit reports on its notification program under penalty of perjury:

1. Respondent must submit a report, within one hundred and twenty (120) days after the date of VOLUME 161 Decision and Order service of this order, annually thereafter, and at the conclusion of the program summarizing its compliance to date, including: the total number of eligible customers identified, notices mailed, and notices re-mailed, the number of mailings returned as undeliverable, and efforts taken to locate the customers for whom mailings were returned and deliver them the notice, as well as the number of calls and emails received and their disposition. For customers for whom mailings were returned as undeliverable, Respondent shall make reasonable efforts to locate and notify those customers. 2. If a representative of the Commission requests any information regarding the notice program, including any of the underlying customer data, Respondent must submit it within ten (10) days of the request.

III.

IT IS FURTHER ORDERED that:

A. Respondent must pay to the Commission $250,000, which Respondent stipulates its undersigned counsel holds in escrow for no purpose other than payment to the Commission.

B. Such payment must be made within eight (8) days of the effective date of this order by electronic fund transfer in accordance with instructions provided by a representative of the Commission.

IV.

IT IS FURTHER ORDERED that:

A. All money paid to the Commission pursuant to this order may be deposited into a fund administered by the Commission or its designee to be used for relief, including consumer redress and any attendant expenses HENRY SCHEIN PRACTICE SOLUTIONS, INC. 717 Decision and Order for the administration of any redress fund. If a representative of the Commission decides that direct redress to Affected Customers is wholly or partially impracticable or money remains after redress is completed, the Commission may apply any remaining money for such other relief (including consumer information remedies) as it determines to be reasonably related to Respondent’s practices alleged in the complaint. Any money not used is to be deposited to the U.S. Treasury. Respondent may, upon request, be notified whether the money has been deposited to the U.S. Treasury, but has no right to challenge any activities pursuant to this provision. No portion of any payment under this Part shall be deemed a payment of any fine, penalty, or punitive assessment. B. In the event of default on any obligation to make payment under this order, interest, computed as if pursuant to 28 U.S.C. § 1961(a), shall accrue from the date of default to the date of payment. In the event such default continues for ten (10) days beyond the date that payment is due, the entire amount will immediately become due and payable.

C. Each day of nonpayment is a violation through continuing failure to obey or neglect to obey a final order of the Commission and thus will be deemed a separate offense and violation for which a civil penalty shall accrue.

D. Respondent acknowledges that its Taxpayer Identification Number, which Respondent has previously provided to the Commission, may be used for collecting and reporting on any delinquent amount arising out of this order, in accordance with 31 U.S.C. § 7701.

V.

IT IS FURTHER ORDERED that Respondent must directly or indirectly provide sufficient customer information to enable the VOLUME 161 Decision and Order Commission to efficiently administer consumer redress to all Affected Customers. Respondent represents that it has provided this redress information to the Commission. If a representative of the Commission requests in writing any information related to redress, Respondent must provide it, in the form prescribed by the Commission representative, within fourteen (14) days. VI.

IT IS FURTHER ORDERED that Respondent shall, for five (5) years after the last date of dissemination of any representation covered by this order, maintain and upon request make available to the Commission for inspection and copying: A. All advertisements and promotional materials containing the representation;

B. All materials that were relied upon in disseminating the representation; and C. All tests, reports, studies, surveys, demonstrations, or other evidence in its possession or control that contradict, qualify, or call into question the representation, or the basis relied upon for the representation, including complaints and other communications with consumers or with governmental or consumer protection organizations.

VII.

IT IS FURTHER ORDERED that Respondent shall deliver a copy of this order to all current and for the next five (5) years future principals, officers, directors, and managers, and to all current and future employees having managerial responsibilities with respect to the subject matter of this order. Respondent shall deliver this order to such current personnel within thirty days after service of this order, and to such future personnel within thirty (30) days after the person assumes such position or responsibilities. For any business entity resulting from any change in structure set forth in Part VIII, delivery shall be at least ten (10) days prior to the change in structure. Respondent must secure a HENRY SCHEIN PRACTICE SOLUTIONS, INC. 719 Decision and Order signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons receiving a copy of the order pursuant to this section. VIII.

IT IS FURTHER ORDERED that Respondent shall notify the Commission at least thirty (30) days prior to any change in the corporation(s) that may affect compliance obligations arising under this order, including but not limited to a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Provided, however, that with respect to any proposed change in the corporation about which Respondent learns less than thirty (30) days prior to the date such action is to take place, Respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a representative of the Commission in writing, all notices required by this Part shall be emailed to [email protected] or sent by overnight courier (not the U.S. Postal Service) to: Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580. The subject line must be: In re Henry Schein Practice Solutions, Inc..

IX.

IT IS FURTHER ORDERED that Respondent, within sixty (60) days after the date of service of this order, shall file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, Respondent shall submit additional true and accurate written reports. VOLUME 161 Decision and Order X.

This order will terminate on May 20, 2036, or twenty (20) years from the most recent date that the United States or the Federal Trade Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part in this order that terminates in less than twenty (20) years;

B. This order’s application to any Respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.

Provided further, that if such complaint is dismissed or a federal court rules that the Respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as thought the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal. By the Commission.

HENRY SCHEIN PRACTICE SOLUTIONS, INC. 721 Decision and Order Attachment A [To appear on Henry Schein Practice Solutions, Inc. letterhead] [Date] [Name of customer] [Mailing address of customer Including zip code] SUBJECT: Important Information Regarding the Security of Patient Records Stored in Dentrix G5 Dear Valued Customer:

Our records show you purchased Dentrix G5, which is sold by our company, Henry Schein Practice Solutions, Inc. (“HSPS”), prior to January 2014. From early 2012 to January 2014, we advertised that Dentrix G5 “encrypts” patient data and helps dentists meet the security requirements of HIPAA, the Health Insurance Portability and Accountability Act. But according to the Federal Trade Commussion, the nation’s consumer protection agency, our claims were deceptive. To resolve the case, we have agreed to not make those claims in the future and to contact our customers so they can take appropriate steps to protect patient records, if necessary.

We understand that the security of your patients’ records is important to you. So here’s what you need to know if you use our software.

The Department of Health and Human Services (“HHS”) looks to the National Institute of Standards and Technology for guidance on how healthcare providers should encrypt sensitive information. NIST recommends a method called Advanced Encryption Standard (AES) and says, “Whenever possible, AES should be used for the encryption algorithm because of its strength and speed.”

This 1s important because if a dental practice using AES encryption experiences a data breach, it may not have to contact patients under HHS’ Breach Notification Rule. Our software uses a less complex method that doesn’t meet the AES encryption standard recommended by HHS and NIST. Therefore, practices relying on Dentrix G5 software alone would not qualify for the safe harbor under the Breach Notification Rule. If you experience a data breach, you may have to contact each affected patient personally — and depending on the size of the breach, you may have to notify HHS and others, too. Of course, you should obtain your own legal advice in the event of a data breach.

As of January 2014, our marketing materials state that our software “masks” data, but doesn’t encrypt it. That description is more accurate and will help dentists make informed decisions about protecting thew patients’ data. We also strongly recommend that dentists consider multiple safeguards to secure access to patient data and work with both IT and security policy experts to create and implement a comprehensive security plan for thew practice. VOLUME 161 Decision and Order Attachment B HENRY SCHEIN PRACTICE SOLUTIONS, INC. 723 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission (“Commission”) has accepted, subject to final approval, an agreement containing a consent order from Henry Schein Practice Solutions, Inc. (“Henry Schein”).

The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement or make final the agreement’s proposed order.

Henry Schein develops and sells dental practice management software, including the Dentrix G5 office management software for dental practices. The Commission’s proposed complaint alleges that Henry Schein violated Section 5 of the Federal Trade Commission Act by making false representations to consumers from January 2012 through January 2014 about the security of its Dentrix G5 software. Specifically, the Commission’s proposed complaint alleges that Henry Schein falsely represented that Dentrix G5 provides industry-standard encryption of patient data and helps dentists meet the security requirements of the Health Insurance Portability and Accountability Act (“HIPAA”). The Commission’s proposed complaint alleges that, in truth and in fact, Dentrix G5 used technology that was less secure than industry-standard encryption, and was not capable of helping dentists protect patient data as required by HIPAA. The proposed order contains provisions designed to prevent Henry Schein from engaging in the same or similar acts or practices in the future.

Part I of the proposed order prohibits Henry Schein from misrepresenting: (A) whether or to what extent any product or service designed to collect or store personal information offers industry-standard encryption; (B) the ability of the product or service to help customers meet regulatory obligations related to VOLUME 161 Analysis to Aid Public Comment privacy or security; or (C) the extent to which a product or service maintains the privacy, security, confidentiality, and integrity of personal information.

Part II of the proposed order requires Henry Schein to notify affected customers that Dentrix G5 uses a less complex encryption algorithm to protect patient data than Advanced Encryption Standard, which is recommended as an industry standard by the National Institute of Standards and Technology. Part II provides for individual notice letters to affected customers and the creation of a toll-free telephone number and email address dedicated to responding to inquiries about the order. Parts III through V of the proposed order require Henry Schein to pay $250,000 into a fund to be administered by the Commission. If the Commission decides that direct redress to affected customers is impracticable or money remains after redress is completed, the Commission may apply any remaining money for such other relief (including consumer information remedies) as it determines is reasonably related to Henry Schein’s practices alleged in the proposed complaint. Any money not used is to be deposited to the U.S. Treasury. Parts VI, VII, and IX of the proposed order are reporting and compliance provisions. Part VI requires that for five (5) years after the last date of dissemination of any representation covered by the proposed order, Henry Schein will maintain and upon request make available certain materials, including: (A) all advertisements and promotional materials containing the representation; (B) all materials that were relied upon in disseminating the representation; and (C) all tests, reports, studies, surveys, demonstrations, or other evidence in its possession or control that contradict, qualify, or call into question the representation, or the basis relied upon for the representation. Part VII is an order distribution provision that requires Henry Schein to provide the order to current and future principals, officers, directors, and managers, as well as current and future employees having managerial responsibilities with respect to the subject matter of the order. Part IX requires Henry Schein to submit a compliance report within sixty (60) days after service of the order, and additional compliance reports within ten (10) days HENRY SCHEIN PRACTICE SOLUTIONS, INC. 725 Analysis to Aid Public Comment of written notice from the Commission. Part VIII of the proposed order requires Henry Schein to notify the Commission at least thirty (30) days prior to any corporate changes that may affect compliance obligations. Part X is a provision “sunsetting” the order after 20 years, with certain exceptions. The purpose of this analysis is to aid public comment on the proposed order. It is not intended to constitute an official interpretation of the complaint or proposed order, or to modify in any way the proposed order’s terms.

VOLUME 161 Complaint

← 161 F.T.C. 683 · 161 F.T.C. 726 →