Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2728+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FTC Rescinds 2021 Policy on Health App Breach Notifications
FTC Rescinds 2021 Policy on Health App Breach Notifications
NEWS

FTC Rescinds 2021 Policy on Health App Breach Notifications

The FTC withdrew its 2021 policy statement on health app breaches, saying a 2024 rule update already covers the ground it addressed.

Dylan H.

News Desk

September 10, 2026
3 min read

FTC Withdraws Biden-Era Health App Guidance

The Federal Trade Commission has rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, a Biden-administration-era guidance document that applied the FTC's Health Breach Notification Rule to health and fitness apps collecting consumer health information.

Why the FTC Pulled the Policy

In a brief statement, the FTC said the 2021 policy — passed on a divided 3-2 vote under then-Chair Lina Khan — "provided minimal benefit and has been superseded by rulemaking." The commission pointed to its 2024 update to the Health Breach Notification Rule, which formally and explicitly extended coverage to health apps, fitness trackers, and similar connected devices, making the older policy statement redundant.

The withdrawal also aligns with a broader deregulatory push: an executive order from President Trump directed federal agencies to eliminate not just unnecessary rules but also obsolete guidance documents and policy statements, which the administration says contribute to regulatory complexity without added consumer benefit. The FTC noted that "guidance generally creates neither substantive rights nor binding obligations" — underscoring that policy statements were never legally binding to begin with.

What Actually Changes

This is a narrower move than the headline suggests:

  • The underlying Health Breach Notification Rule — the actual binding regulation — is unaffected and still explicitly covers health apps and connected devices per the 2024 Final Rule
  • Only the 2021 policy statement, an interpretive document layered on top of the older rule, has been withdrawn
  • Companies still face notification obligations, and violators can still face civil penalties, under the rule itself

Background

The original 2021 policy statement justified extending breach-notification coverage to health apps by citing digital security provisions in the 2009 American Recovery and Reinvestment Act, along with gaps in HIPAA that let many consumer health apps handle sensitive data without HIPAA-equivalent breach-notification duties. At the time, the FTC signaled it intended to actively enforce against health apps and was prepared to pursue penalties as high as $43,792 per violation, per day.

Why This Matters for Compliance Teams

Because the substantive rule remains in force, health app operators should not read this as a relaxation of their breach-notification duties. The practical effect is mostly interpretive: the FTC is cleaning up superseded guidance rather than narrowing what's covered. Compliance teams should continue treating the 2024 Final Rule — not the withdrawn 2021 statement — as the authoritative source for notification obligations.

Recommendations

  • Health app and connected-device vendors should review breach-notification obligations against the 2024 Final Rule, not the withdrawn 2021 statement
  • Do not treat this rescission as reduced regulatory exposure — enforcement authority under the binding rule is unchanged
  • Legal and compliance teams should monitor for further deregulatory guidance withdrawals stemming from the same executive order
  • Continue maintaining breach-notification playbooks that meet the Health Breach Notification Rule's timing and content requirements

Sources

  • CyberScoop — FTC rescinds policy requiring health apps to notify customers after a breach
  • FTC — FTC Withdraws Obsolete Policy Statement
#FTC#Regulation#Health Breach Notification Rule#Healthcare#Privacy

Related Articles

Here's How the FTC Plans to Enforce the Take It Down Act

The FTC will levy hefty fines and pursue investigations against platforms that fail to remove non-consensual intimate imagery, including AI-generated...

3 min read

Sensitive Information Exposed in Nutex Health Data Breach

Nasdaq-listed ER operator Nutex Health disclosed a cyberattack in an SEC 8-K, saying data was exfiltrated from its network by an unauthorized party.

4 min read

Amazon Fined $2.25M by FTC for Blocking Identity Theft Victims' Evidence

The FTC fined Amazon $2.25 million for systematically obstructing identity theft victims' legally-mandated access to their transaction records, violating...

4 min read
Back to all News