FTC Withdraws 2021 Health App Breach Policy
The Federal Trade Commission has rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, a Biden-era statement that had extended the FTC's Health Breach Notification Rule (HBNR) to cover health apps, fitness trackers, and other connected devices collecting consumer health information.
What Changed
According to the FTC's rescission statement, the Commission determined the 2021 policy statement — "contentious at the time of issuance" — provided minimal benefit and has since been superseded by formal rulemaking:
- In 2024, the Commission updated the Health Breach Notification Rule itself to explicitly cover health apps and connected devices, making the 2021 interpretive statement redundant
- The withdrawal aligns with a Trump administration executive order directing agencies to eliminate "obsolete" guidance documents and policy statements deemed part of an "ever-expanding morass of complicated Federal regulation"
- The Commission voted unanimously to rescind the statement
Background
The original 2021 policy passed on a divided 3-2 vote under then-FTC Chair Lina Khan, adding health apps and connected devices to the scope of an existing rule that had historically applied to more traditional health record services. The two dissenting votes at the time came from Republican-appointed commissioners.
The current unanimous vote to rescind reflects a changed commission: President Trump removed the Democratic commissioners who backed the original policy and replaced them with allies aligned with the deregulatory push.
Practical Impact for Health App Developers
Legal analysts note the rescission narrows compliance obligations in several concrete ways:
- Health app developers outside HIPAA's reach are no longer treated as "health care providers" for breach-notification purposes under the withdrawn interpretation
- The "aggregation theory" that pulled ordinary wellness and fitness apps into HBNR scope through their combination of health-adjacent data points is gone
- Unauthorized data-sharing alone no longer automatically triggers HBNR notice obligations
The FTC's core Section 5 authority over "unfair or deceptive" practices remains untouched — the agency can still act against health apps that mishandle data in ways that violate their own privacy promises to users, just not under the specific breach-notification theory the 2021 statement had articulated.
Why the Timing Matters
Some observers have flagged the timing as notable: the rescission lands as the Centers for Medicare and Medicaid Services actively steers seniors toward health apps that collect and process identifiable consumer health data outside HIPAA's reach — precisely the population and use case the 2021 policy had been designed to cover.
What This Means for Users and Organizations
- Consumers relying on non-HIPAA health and wellness apps should not assume a breach will trigger the same notification obligations it may have previously
- App developers and vendors should re-review their compliance posture against the FTC's 2024 HBNR update directly, rather than the now-withdrawn 2021 interpretive statement
- Security and privacy teams at health-adjacent companies should continue treating breach disclosure as a Section 5 fair-practices question even where HBNR's specific triggers no longer clearly apply
References
- Federal Trade Commission — FTC Withdraws Obsolete Policy Statement
- CyberScoop — FTC Rescinds Policy Requiring Health Apps to Notify Customers After a Breach
- DataBreaches.Net — FTC Withdraws Obsolete Policy Statement
- National Law Review — FTC Rescinds 2021 Health App Breach Rule, Narrowing HBNR Scope