FTC Announces Fourth Extension of Red Flags Rule Enforcement
Client Alert | 1 min read | 11.06.09
The Federal Trade Commission (the "FTC") has announced that it will postpone enforcement of the Red Flags Rule1 until June 1, 2010 for financial institutions and creditors that are subject to FTC oversight. This is the fourth time that the FTC has extended the enforcement timeline. While the Red Flags Rule became effective on January 1, 2008, and the mandatory enforcement date was originally November 1, 2008, the FTC subsequently suspended enforcement of the Rule until May 1, 2009 and then again until August 1, 2009.2
The Red Flags Rule requires financial institutions and creditors to look for "red flags" that signal possible identity theft. In its last extension, the FTC announced that it intended to provide assistance to small businesses and entities with a low risk of identity theft. The FTC has continued to provide guidance, including through materials posted on its Red Flags Rule website3 and in other media. The FTC has also established a template that enables low-risk entities to create identity theft programs within a prescribed format.
This most recent extension came after the House of Representatives passed a bill that would exempt certain facilities and other entities from the Rule, including healthcare, legal, and accounting practices that employ fewer than 20 individuals. Since the Senate has yet to act on the measure, House members were prompted to request this fourth extension in order to avoid imposing the Rule on entities that may, following legislation, be exempt from compliance.
Please let us know if you have any questions or if we can help you in crafting a compliant program.
1 72 Fed. Reg. 63717, 63771-63775 (Nov. 9, 2007) (codified at 16 C.F.R. Part 681).
2 The enforcement delay does not apply to the address discrepancy and credit card issuer rules. These rules are not addressed in this Health Law Alert.
3 www.ftc.gov/redflagsrule
Insights
Client Alert | 2 min read | 02.03.26
CMS Doubles Down on RADV Audit Changes
On January 27, 2026, the Centers for Medicare and Medicaid Services (CMS) released a Health Plan Management System (HPMS) memo that provided a long-awaited update on how the agency plans to approach previously announced Risk Adjustment Data Validation (RADV) audits for Payment Years (PY) 2020-2024. The memo is the agency’s most comprehensive statement on the subject since September 25, 2025, when the Northern District of Texas vacated the 2023 RADV Final Rule. The memo makes clear that, while CMS has made certain operational adjustments in response to concerns expressed by Medicare Advantage Organizations (MAOs), the agency is largely pressing forward with the accelerated audit strategy announced in May 2025.
Client Alert | 2 min read | 02.03.26
Sedona Model Jury Instructions for DTSA: A Step Forward—But Questions Remain
Client Alert | 7 min read | 01.30.26
CMS Proposes CY 2027 Growth Rate and Changes to Risk Adjustment for Medicare Parts C and D
Client Alert | 4 min read | 01.30.26
Optimum’s Shot Across the Bow: An Antitrust Challenge to Cooperation Agreements
