Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2782+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FTC Rescinds Policy Requiring Health Apps to Notify Users After a Breach
FTC Rescinds Policy Requiring Health Apps to Notify Users After a Breach
NEWS

FTC Rescinds Policy Requiring Health Apps to Notify Users After a Breach

The FTC has withdrawn its 2021 policy applying breach notification rules to health apps and connected devices, narrowing compliance obligations.

Dylan H.

News Desk

September 12, 2026
3 min read

FTC Withdraws 2021 Health App Breach Policy

The Federal Trade Commission has rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, a Biden-era statement that had extended the FTC's Health Breach Notification Rule (HBNR) to cover health apps, fitness trackers, and other connected devices collecting consumer health information.

What Changed

According to the FTC's rescission statement, the Commission determined the 2021 policy statement — "contentious at the time of issuance" — provided minimal benefit and has since been superseded by formal rulemaking:

  • In 2024, the Commission updated the Health Breach Notification Rule itself to explicitly cover health apps and connected devices, making the 2021 interpretive statement redundant
  • The withdrawal aligns with a Trump administration executive order directing agencies to eliminate "obsolete" guidance documents and policy statements deemed part of an "ever-expanding morass of complicated Federal regulation"
  • The Commission voted unanimously to rescind the statement

Background

The original 2021 policy passed on a divided 3-2 vote under then-FTC Chair Lina Khan, adding health apps and connected devices to the scope of an existing rule that had historically applied to more traditional health record services. The two dissenting votes at the time came from Republican-appointed commissioners.

The current unanimous vote to rescind reflects a changed commission: President Trump removed the Democratic commissioners who backed the original policy and replaced them with allies aligned with the deregulatory push.

Practical Impact for Health App Developers

Legal analysts note the rescission narrows compliance obligations in several concrete ways:

  • Health app developers outside HIPAA's reach are no longer treated as "health care providers" for breach-notification purposes under the withdrawn interpretation
  • The "aggregation theory" that pulled ordinary wellness and fitness apps into HBNR scope through their combination of health-adjacent data points is gone
  • Unauthorized data-sharing alone no longer automatically triggers HBNR notice obligations

The FTC's core Section 5 authority over "unfair or deceptive" practices remains untouched — the agency can still act against health apps that mishandle data in ways that violate their own privacy promises to users, just not under the specific breach-notification theory the 2021 statement had articulated.

Why the Timing Matters

Some observers have flagged the timing as notable: the rescission lands as the Centers for Medicare and Medicaid Services actively steers seniors toward health apps that collect and process identifiable consumer health data outside HIPAA's reach — precisely the population and use case the 2021 policy had been designed to cover.

What This Means for Users and Organizations

  • Consumers relying on non-HIPAA health and wellness apps should not assume a breach will trigger the same notification obligations it may have previously
  • App developers and vendors should re-review their compliance posture against the FTC's 2024 HBNR update directly, rather than the now-withdrawn 2021 interpretive statement
  • Security and privacy teams at health-adjacent companies should continue treating breach disclosure as a Section 5 fair-practices question even where HBNR's specific triggers no longer clearly apply

References

  • Federal Trade Commission — FTC Withdraws Obsolete Policy Statement
  • CyberScoop — FTC Rescinds Policy Requiring Health Apps to Notify Customers After a Breach
  • DataBreaches.Net — FTC Withdraws Obsolete Policy Statement
  • National Law Review — FTC Rescinds 2021 Health App Breach Rule, Narrowing HBNR Scope
#FTC#Health Data#Privacy#Regulation#Data Breach

Related Articles

FTC Rescinds 2021 Policy on Health App Breach Notifications

The FTC withdrew its 2021 policy statement on health app breaches, saying a 2024 rule update already covers the ground it addressed.

3 min read

Here's How the FTC Plans to Enforce the Take It Down Act

The FTC will levy hefty fines and pursue investigations against platforms that fail to remove non-consensual intimate imagery, including AI-generated...

3 min read

Amazon Fined $2.25M by FTC for Blocking Identity Theft Victims' Evidence

The FTC fined Amazon $2.25 million for systematically obstructing identity theft victims' legally-mandated access to their transaction records, violating...

4 min read
Back to all News