FTC Withdraws Biden-Era Health App Guidance
The Federal Trade Commission has rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, a Biden-administration-era guidance document that applied the FTC's Health Breach Notification Rule to health and fitness apps collecting consumer health information.
Why the FTC Pulled the Policy
In a brief statement, the FTC said the 2021 policy — passed on a divided 3-2 vote under then-Chair Lina Khan — "provided minimal benefit and has been superseded by rulemaking." The commission pointed to its 2024 update to the Health Breach Notification Rule, which formally and explicitly extended coverage to health apps, fitness trackers, and similar connected devices, making the older policy statement redundant.
The withdrawal also aligns with a broader deregulatory push: an executive order from President Trump directed federal agencies to eliminate not just unnecessary rules but also obsolete guidance documents and policy statements, which the administration says contribute to regulatory complexity without added consumer benefit. The FTC noted that "guidance generally creates neither substantive rights nor binding obligations" — underscoring that policy statements were never legally binding to begin with.
What Actually Changes
This is a narrower move than the headline suggests:
- The underlying Health Breach Notification Rule — the actual binding regulation — is unaffected and still explicitly covers health apps and connected devices per the 2024 Final Rule
- Only the 2021 policy statement, an interpretive document layered on top of the older rule, has been withdrawn
- Companies still face notification obligations, and violators can still face civil penalties, under the rule itself
Background
The original 2021 policy statement justified extending breach-notification coverage to health apps by citing digital security provisions in the 2009 American Recovery and Reinvestment Act, along with gaps in HIPAA that let many consumer health apps handle sensitive data without HIPAA-equivalent breach-notification duties. At the time, the FTC signaled it intended to actively enforce against health apps and was prepared to pursue penalties as high as $43,792 per violation, per day.
Why This Matters for Compliance Teams
Because the substantive rule remains in force, health app operators should not read this as a relaxation of their breach-notification duties. The practical effect is mostly interpretive: the FTC is cleaning up superseded guidance rather than narrowing what's covered. Compliance teams should continue treating the 2024 Final Rule — not the withdrawn 2021 statement — as the authoritative source for notification obligations.
Recommendations
- Health app and connected-device vendors should review breach-notification obligations against the 2024 Final Rule, not the withdrawn 2021 statement
- Do not treat this rescission as reduced regulatory exposure — enforcement authority under the binding rule is unchanged
- Legal and compliance teams should monitor for further deregulatory guidance withdrawals stemming from the same executive order
- Continue maintaining breach-notification playbooks that meet the Health Breach Notification Rule's timing and content requirements