Paymentsmd, LLC
Volume 159 · 159 F.T.C. 241
deceptive advertisingprivacy data securityonline internet
Cite this decision
Paymentsmd, LLC, 159 F.T.C. 241 (2015). Consumer Law Library, https://consumerlawlibrary.org/decisions/v159-0006
Report an error in this record (decision id v159-0006)
Cited by 0 later FTC decisions
Cites
Text (OCR of the scan at left; may contain errors)
IN THE MATTER OF PAYMENTSMD, LLC CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATION OF SEC. 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4505; File No. 132 3088 Complaint, January 27, 2015 – Decision, January 27, 2015 This consent order addresses deceptive acts and practices regarding the collection of consumers’ sensitive health information from third parties. The respondent, Paymentsmd, operated a website where consumers could pay their medical bills. They used this sign-up process for a “patient portal” as a pathway to deceptively seek consumer consent to obtain detailed medical information about the consumers. The complaint alleges PaymentMD misled thousands of consumers who signed up for the online billing portal by failing to adequately inform them that the company would seek highly detailed medical information from pharmacies, medical labs, and insurance companies. The consent order requires Paymentsmd to destroy any information collected related to the patient health report service. In addition, the respondent is banned from deceiving consumers about the way it collects and uses information, including how collected information might be shared with or collected from a third party. The respondent must also obtain consumers’ affirmative express consent before collecting health information about a consumer from a third party. The Commission entered a similar order against PaymentsMD’s CEO, Michael C. Hughes. See 159 F.T.C. 60.
Participants For the Commission: Jacquelie Connor, David Lincicum, and Kevin Moriarty.
For the Respondent: Kristy Brown and Kimberly Peretti, Alston & Bird LLP.
COMPLAINT The Federal Trade Commission, having reason to believe that Paymentsmd, LLC (“Respondent”) has violated the provisions of the Federal Trade Commission Act, and it appearing to the Commission that this proceeding is in the public interest, alleges: 1. Respondent Paymentsmd, LLC (“Paymentsmd”) is a Georgia limited liability company with its principal office or place PAYMENTSMD, LLC 242 Complaint of business at 5665 New Northside Dr., Suite 320, Atlanta, GA 30328. Paymentsmd is a wholly owned subsidiary of ApolloMD Business Services, LLC.
2. The acts and practices of respondent as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the Federal Trade Commission Act. RESPONDENT’S BUSINESS PRACTICES 3. Since 2008, Paymentsmd has provided billing services to medical providers. Medical providers that have contracted with Paymentsmd direct their patients to the Paymentsmd website, where consumers are able to enter their invoice number and credit card information to pay their medical bills. 4. In December 2011, Paymentsmd launched a free “Patient Portal” product that provided consumers with a place to view their billing history. Unlike the bill-payment service, which enables consumers only to make a one-time payment, the billing history service of the Patient Portal enables consumers to access and view records of the consumers’ past and upcoming payment obligations for any medical providers that use PaymentsMD’s billing services. The Patient Portal service enabled consumers to pay their bills and to view their balance, payments made, adjustments taken, and information for other service dates. 5. In June 2012, Paymentsmd entered into an agreement with Metis Health LLC (“Metis Health”) to develop an entirely new service called Patient Health Report, a fee-based service that would enable consumers to access, review, and manage their consolidated health records through a Patient Portal account. Paymentsmd and Metis Health agreed to split the profits. Both companies participated in developing the disclosures and authorizations for the service, and how and when this information would be presented to consumers during the Patient Portal registration process.
6. As described further below, in order to populate the Patient Health Report, respondent tried to obtain the sensitive health information of consumers registering for the Patient Portal from health insurance plans, pharmacies, and a medical testing PAYMENTSMD, LLC 243 Complaint lab, without appropriate authorization from those consumers. Indeed, many consumers registering for the Patient Portal had no idea that respondent would seek to collect their sensitive health information from third parties for use in the Patient Health Report service.
THE PATIENT PORTAL INTERFACE FAILED TO DISCLOSE THAT RESPONDENT WOULD COLLECT CONSUMERS’ SENSITIVE HEALTH INFORMATION FOR THE PATIENT HEALTH REPORT 7. PaymentsMD’s home page described the Patient Portal as a medical billing related service. It stated that “At Paymentsmd, we can help you navigate through the maze of medical billing, reimbursement and payment processes. We also make it easy for you to maintain current information about your insurance coverage and to make payments over the Internet, at your convenience.” In order to register for the Patient Portal, a consumer could click on a button labeled “Patient Portal Login.” (Exhibit A).
PAYMENTSMD, LLC 244 Complaint 8. Consumers could then either enter their login credentials or click on a link that stated “Don’t have an account? Create one now.” (See Exhibit B).
Consumers that followed the link would then be taken to the Payment Portal registration page, which appeared as follows. (Exhibit C).
PAYMENTSMD, LLC 245 Complaint The registration page stated that registering for the Payment Portal service would “allow you to: View your original balance; View any payments made; View any adjustments taken; View your current balance; View information for other service dates.” At no point in this process was it stated that respondent would be seeking consumers’ sensitive health information from third parties for use in a Patient Health Report service. 9. Consumers who clicked the “Submit” button were taken to a “Patient Portal Account Authorization” page, which required four authorizations. The page presented the authorizations in four boxes that showed only six lines of text at a time. (Exhibit D). PAYMENTSMD, LLC 246 Complaint Under each text box was a check box that consumers could select in order to proceed with the registration process. Alternatively, consumers could select a single box at the top of the page, which would populate all four boxes to indicate that each of the four was authorized. Although consumers who scrolled through the second and fourth boxes would have seen a statement that “[H]health records related to your treatment . . . may be used or disclosed pursuant to this Authorization,” the site design simultaneously made it hard to read the authorizations in their entirety, and easy PAYMENTSMD, LLC 247 Complaint to skip over them by clicking a single check box that preceded all of the authorizations.
10. Consumers would reasonably believe that all four authorizations were to be used to provide the Patient Portal billing services for which they were registering. In fact, respondent used two of the four purported authorizations to allow it to collect sensitive health information from third parties for use with the Patient Health Report service.
11. Although PaymentsMD’s home page and login page included links that allowed consumers to “click here to learn more” about the Patient Health Report service (see Exhibit A), these links conveyed that the Patient Health Report was a separate service from the Patient Portal. At no point in registering for the Patient Portal would it have been clear to the consumer that they were purportedly giving respondent permission to obtain their sensitive health information from third parties for use in the Patient Health Report service.
RESPONDENT SOUGHT CONSUMERS’ SENSITIVE HEALTH INFORMATION WITHOUT THEIR KNOWLEDGE OR CONSENT 12. Respondent requested sensitive health information from a large number of health plans, pharmacies, and a medical lab about everyone who registered for the Patient Portal. These requests used consumers’ name, birth date, address, and sex. The information requested was as follows:
a. Pharmacies: Medication dispensed, dispense date, instructions, prescription number, prescribing physician, quantity dispensed, refill ability, co-pay amount, amount payable as co-insurance or deductible, and amount paid by health plan.
b. Health plans: Medical information (procedures, diagnoses, dates of service, medical providers, co-pay amount, amount payable for co-insurance or deductible, and the amount paid by health plan); prescription information (medications dispensed, dispense dates, prescription number, prescribing PAYMENTSMD, LLC 248 Complaint physician, quantity dispensed, refill ability, co-pay amount, amount payable as coinsurance or deductible, and the amount paid by health plan); and lab information (test performed, date, laboratory, physician, co-pay, amount payable as co-insurance or deductible, and amount paid by health plan). c. Laboratory: Lab test performed, date, laboratory, test results, normal range for test values, ordering physician, co-pay, amount payable as co-insurance or deductible, and the amount paid by health plan. 13. Metis Health sent requests to health plans that were identified using PaymentsMD’s billing records. For the pharmacies, Metis Health sent requests to all major commercial pharmacies with locations near the consumers’ home address, notwithstanding that neither Paymentsmd nor Metis Health had any reason to believe that the consumer had used any of those pharmacies.
14. Metis Health sent approximately 5,500 requests for consumers’ health information to 31 different companies. One company fulfilled the requests. The others, concerned about the validity of the requests – which in some cases related to minors or consumers who were not in fact a customer of the company receiving the request – refused to fulfill the requests. RESPONDENT’S SUBSEQUENT COMMUNICATIONS TO CONSUMERS GENERATED NUMEROUS COMPLAINTS 15. Initially, respondent did not inform consumers that Metis Health was attempting to collect their sensitive health information. When Paymentsmd began informing consumers, via an email sent a day after users registered for Patient Portal, numerous consumers filed complaints with Paymentsmd regarding the collection of their sensitive health information. The common themes of the complaints were that consumers did not want their information collected, and that they had only registered for the Patient Portal to track their bills. Paymentsmd ultimately did not sell any Patient Health Reports. PAYMENTSMD, LLC 249 Complaint DECEPTIVE OMISSION (Count 1) 16. As described in Paragraphs 3-15, respondent represented, directly or indirectly, expressly or by implication, that consumers registering for its free Patient Portal billing service could access and review their medical payment history. 17. Respondent failed to disclose adequately that, if consumers registered for its free Patient Portal billing service, respondent would also engage in a comprehensive collection from third parties of consumers’ sensitive health information for the Patient Health Report service.
18. This fact would be material to consumers in deciding whether to register for the Patient Portal. Respondent’s failure to disclose adequately this fact, in light of the representations made, is a deceptive act or practice.
DECEPTIVE REPRESENTATION (Count 2) 19. As described in Paragraphs 3-15, respondent represented, directly or indirectly, expressly or by implication, that the authorizations were to be used exclusively to provide the free Patient Portal billing history service for which consumers were registering.
20. In fact, the authorizations were not used exclusively to provide the free Patient Portal billing history service for which consumers were registering. Instead, all of the authorizations were also used by respondent to attempt to collect sensitive health information for use with the Patient Health report service, and two were only used for this purpose. Therefore, this representation is false or misleading.
VIOLATIONS OF SECTION 5 21. The acts and practices of respondent as alleged in this complaint constitute deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act, 15 U.S.C. § 45(a).
PAYMENTSMD, LLC 250 Complaint THEREFORE, the Federal Trade Commission this twenty-seventh day of January, 2015, has issued this complaint against respondent.
By the Commission.
DECISION AND ORDER The Federal Trade Commission (“Commission” or “FTC”), having initiated an investigation of certain acts and practices of the respondent named in the caption hereof, and the respondent having been furnished thereafter with a copy of a draft complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge respondent with violations of the Federal Trade Commission Act (“FTC Act”), 15 U.S.C. § 45 et seq.;
The respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), which includes: a statement by respondent that it neither admits nor denies any of the allegations in the draft complaint, except as specifically stated in the Consent Agreement, and, only for purposes of this action, admits the facts necessary to establish jurisdiction; and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the respondent has violated the FTC Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed consent agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, now in further conformity with the procedure prescribed in Commission Rule 2.34, 16 C.F.R. § 2.34, the Commission hereby issues its PAYMENTSMD, LLC 251 Decision and Order complaint, makes the following jurisdictional findings, and enters the following Order:
1. Respondent Paymentsmd, LLC (“Paymentsmd”) is a Georgia limited liability company with its principal office or place of business at 5665 New Northside Dr., Suite 320, Atlanta, GA 30328.
2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the respondent, and the proceeding is in the public interest. ORDER DEFINITIONS For purposes of this Order, the following definitions shall apply:
1. “Covered information” shall mean information from or about an individual consumer, including but not limited to (a) a first and last name; (b) a home or other physical address, including street name and name of city or town; (c) an email address or other online contact information, such as an instant messaging user identifier or a screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license or other state-issued identification number; (g) a financial institution account number; (h) an insurance account number or other insurance information; (i) credit or debit card information; (j) credit report information; (k) a persistent identifier, such as a customer number held in a “cookie,” a static Internet Protocol (“IP”) address, a mobile device ID, or processor serial number; and (l) health information, as defined below. 2. “Health information” shall mean information about an individual consumer’s health or medical care, including but not limited to (a) an insurance account number or other insurance information; (b) prescription information; (c) medical records; (d) PAYMENTSMD, LLC 252 Decision and Order information concerning the consumer’s diagnoses or treatments; and (e) medical or health related purchases. 3. Unless otherwise specified, “respondent” shall mean Paymentsmd, LLC and its successors and assigns. 4. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. 5. “Clear(ly) and prominent(ly)” shall mean: a. In textual communications (e.g., printed publications or words displayed on the screen of a computer or mobile device), the required disclosures are of a type, size, and location sufficiently noticeable for an ordinary consumer to read and comprehend them, in print that contrasts highly with the background on which they appear; b. In communications disseminated orally or through audible means (e.g., radio or streaming audio), the required disclosures are delivered in a volume and cadence sufficient for an ordinary consumer to hear and comprehend them;
c. In communications disseminated through video means (e.g., television or streaming video), the required disclosures are in writing in a form consistent with subparagraph (a) of this definition and shall appear on the screen for a duration sufficient for an ordinary consumer to read and comprehend them, and in the same language as the predominant language that is used in the communication;
d. In communications made through interactive media, such as the Internet, online services, and software, the required disclosures are unavoidable and presented in a form consistent with subparagraph (a) of this definition, in addition to any audio or video presentation of them; and PAYMENTSMD, LLC 253 Decision and Order e. In all instances, the required disclosures: (1) are presented in an understandable language and syntax, and (2) include nothing contrary to, inconsistent with, or in mitigation of any statement contained within the disclosure or within any document linked to or referenced therein. I.
IT IS ORDERED that respondent and its officers, agents, representatives, and employees, directly or through any corporation, subsidiary, division, website, or other device or affiliate owned or controlled by respondent, in or affecting commerce, shall not misrepresent, in any manner, expressly or by implication, the extent to which respondent uses, maintains, and protects the privacy, confidentiality, security, or integrity of covered information collected from or about consumers, including but not limited to:
A. Services for which consumers are being enrolled as part of any sign-up process;
B. The extent to which respondent will share covered information with, or seek covered information from, third parties; and C. The purpose(s) for which covered information collected from third parties will be used. II.
IT IS FURTHER ORDERED that respondent and its officers, agents, representatives, and employees, directly or through any corporation, subsidiary, division, website, or other device or affiliate owned or controlled by respondent, in or affecting commerce, in connection with the online advertising, marketing, promotion, offering for sale, sale, or dissemination of any service, shall:
A. Separate and apart from any final “end user license agreement,” “privacy policy,” “terms of use” page, or similar document, clearly and prominently disclose to PAYMENTSMD, LLC 254 Decision and Order consumers respondent’s practices regarding the collection, use, storage, disclosure or sharing of health information prior to seeking authorization to collect health information from a third party; and B. Obtain affirmative express consent from consumers prior to collecting health information from a third party.
III.
IT IS FURTHER ORDERED that respondent and its officers, agents, representatives, and employees, directly or through any corporation, subsidiary, division, website, or other device or affiliate owned or controlled by respondent, in or affecting commerce, shall not use, collect or permit any third party to use or collect any covered information pursuant to any authorization obtained prior to the date of service of this order from consumers registering for the Patient Portal, except for the sole purpose of offering any health-related bill-payment or bill history services. Within sixty (60) days after the date of service of the order, respondent shall permanently delete or destroy all covered information in respondent’s possession or control that was collected pursuant to such authorization by or on behalf of respondent from any third party for any purpose except for the offering of any health-related bill-payment or bill history services and shall provide a written statement to the Commission, sworn under penalty of perjury, confirming that all such information has been deleted or destroyed. Provided that, if respondent is prohibited from deleting or destroying such information by law, regulation, or court order, respondent shall provide a written statement to the Commission, sworn under penalty of perjury, identifying any information that has not been deleted or destroyed and the specific law, regulation, or court order that prohibits respondent from deleting or destroying such information. Unless otherwise directed by a representative of the Commission, all statements required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580, with the subject line In the Matter of Paymentsmd, LLC, FTC File No. 1323088. Provided, however, that, in lieu of PAYMENTSMD, LLC 255 Decision and Order overnight courier, notices may be sent by first-class mail, but only if an electronic version of such notices is contemporaneously sent to the Commission at [email protected].
IV.
IT IS FURTHER ORDERED that respondent shall maintain and upon request make available to the Federal Trade Commission for inspection and copying, for a period of five (5) years from the date of preparation or dissemination, whichever is later, a print or electronic copy of all documents relating to compliance with this order, including but not limited to: A. statements disseminated to consumers that describe the extent to which respondent maintains and protects the privacy, security and confidentiality of any covered information, including, but not limited to, any statement related to a change in any website or service controlled by respondent that relates to the privacy, security, and confidentiality of covered information, with all materials relied upon in making or disseminating such statements;
B. all consumer complaints directed at respondent, or forwarded to respondent by a third party, that relate to the conduct prohibited by this order, and any responses to such complaints; and C. all forms, websites, and other methods used to obtain affirmative express consent to collect health information from third parties; and any documents, whether prepared by or on behalf of respondent, that contradict, qualify, or call into question compliance with this order.
V.
IT IS FURTHER ORDERED that respondent shall deliver a copy of this order to all current and future subsidiaries, current and future principals, officers, directors, and managers, and to all current and future employees, agents, and representatives having responsibilities relating to the subject PAYMENTSMD, LLC 256 Decision and Order matter of this order. Respondent shall deliver this order to such current subsidiaries and personnel within thirty (30) days after service of this order, and to such future subsidiaries and personnel within thirty (30) days after the person or subsidiary assumes such position or responsibilities. For any business entity resulting from any change in structure set forth in Part VI, delivery shall be at least ten (10) days prior to the change in structure. Respondent must secure a signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons or subsidiaries receiving a copy of the order pursuant to this Part. VI.
IT IS FURTHER ORDERED that respondent shall notify the Commission at least thirty (30) days prior to any change in the corporation(s) that may affect compliance obligations arising under this order, including, but not limited to: a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Provided, however, that, with respect to any proposed change in the corporation(s) about which respondent learns fewer than thirty (30) days prior to the date such action is to take place, respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a representative of the Commission, all notices required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, D.C. 20580, with the subject line In the Matter of Paymentsmd, LLC, FTC File No. 1323088. Provided, however, that in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of any such notice is contemporaneously sent to the Commission at [email protected].
VII.
IT IS FURTHER ORDERED that respondent within sixty (60) days after the date of service of this order, shall file PAYMENTSMD, LLC 257 Decision and Order with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, it shall submit an additional true and accurate written report.
VIII.
This order will terminate on January 27, 2035, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. any Part in this order that terminates in fewer than twenty (20) years;
B. this order’s application to any respondent that is not named as a defendant in such complaint; and C. this order if such complaint is filed after the order has terminated pursuant to this Part.
Provided, further, that if such complaint is dismissed or a federal court rules that respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order as to such respondent will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.
By the Commission.
PAYMENTSMD, LLC 258 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, a consent order applicable to Paymentsmd, LLC (“Paymentsmd”).
The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. PaymentsMD’s principal line of business is the delivery of electronic billing records and the collection of accounts receivable for medical providers. In December 2011, Paymentsmd launched a free “Patient Portal” product that enabled consumers to pay their bills and to view their balance, payments made, adjustments taken, and information for other service dates. The Commission’s complaint alleges that Paymentsmd deceived consumers regarding the collection of consumers’ sensitive health information from third parties. In June 2012, Paymentsmd entered into an agreement with Metis Health LLC (“Metis Health”) to develop an entirely new service called Patient Health Report, a fee-based service that would enable consumers to access, review, and manage their consolidated health records through a Patient Portal account. In order to populate the Patient Health Report, Paymentsmd obtained consumers’ authorization to collect sensitive health information for one purpose – to track their medical bills – and then used that authority to attempt to collect a massive amount of sensitive health information, including treatment information, from third parties without consumers’ knowledge or consent. Based on such authorization, sensitive health information about everyone who registered for the Patient Portal was then requested from a large number of health plans, pharmacies, and a medical lab.
The first count of the Commission’s complaint alleges that Paymentsmd represented that consumers registering for their free PAYMENTSMD, LLC 259 Analysis to Aid Public Comment Patient Portal billing service could access and review their medical payment history, but failed to disclose adequately that Paymentsmd would also engage in a comprehensive collection of consumers’ sensitive health information for a Patient Health Report. The second count alleges that Paymentsmd deceptively represented that the consumers’ authorizations were to be used exclusively to provide the billing service. The proposed order contains provisions designed to prevent Paymentsmd from engaging in the future in practices similar to those alleged in the complaint. Part I prohibits Paymentsmd from making any future misrepresentation regarding the extent to which it uses, maintains, and protects the privacy, confidentiality, and security of covered information collected from or about consumers, including but not limited to: (1) the services for which consumers are being enrolled as part of any sign-up process; (2) the extent to which Paymentsmd will share covered information with, or seek covered information from, third parties; and (3) the purpose(s) for which covered information collected from third parties will be used. Part II requires Paymentsmd to clearly and prominently disclose its practices regarding the collection, use, storage, disclosure or sharing of health information prior to seeking authorization to collect health information from a third party. Paymentsmd must also obtain affirmative express consent from consumers prior to collecting health information from a third party. Part III prohibits Paymentsmd from using, collecting, or permitting any third party to use or collect any covered information pursuant to any authorization obtained prior to the date of the order from consumers registering for the Patient Portal, except for the purpose of offering health-related bill-payment or bill history services. Paymentsmd also must, within sixty days, delete all covered information that was collected in relation to the Patient Health Report service. (Paymentsmd need not destroy the information related to the bill-payment or bill history services that consumers actually signed up for.) Parts IV through VIII of the proposed order are reporting and compliance provisions. Part IV requires Paymentsmd to retain documents relating to its compliance with the order. The order requires that Paymentsmd retain all of the documents for a PAYMENTSMD, LLC 260 Analysis to Aid Public Comment five-year period. Part V requires dissemination of the order now and in the future to all current and future subsidiaries, principals, officers, directors, and managers, and to persons with responsibilities relating to the subject matter of the order. Part VI ensures notification to the FTC of changes in corporate status. Part VII mandates that Paymentsmd submit a compliance report to the FTC within 60 days, and periodically thereafter as requested. Part VIII is a provision “sunsetting” the order after twenty (20) years, with certain exceptions. The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the order’s terms in any way.
PLASMA, INC. 261 Complaint