NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA). On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having been superseded by rulemaking.

The Health Breach Notification Rule was issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act and applies to vendors of personal health records (PHRs) and related entities that are not subject to HIPAA. In 2021, the FTC determined that because health apps were mainstream and increasingly collected consumers’ sensitive health and personal information, the developers of the apps should have a responsibility to ensure that the data they collect is secured, protected against unauthorized access, and that consumer notifications are required when there is a breach of that information or an unauthorized disclosure.

Per the 2021 policy statement, the FTC viewed the developers of health apps and other connected devices to be vendors of personal health records, if an app or device had the capability to draw data from multiple sources and was not covered by a similar rule issued by the Department of Health and Human Services. The change in position was contentious at the time, and while the policy statement received majority FTC backing, it was only approved with a 3-2 vote. Commissioners Noah Joshua Philips and Christin S. Wilson voted against the policy statement, with both believing that the FTC’s interpretation of applicability for the Health Breach Notification Rule stretched the statutory text beyond its terms.

In 2024, the FTC updated its Health Breach Notification Rule, significantly expanding its scope. The definition of health information was broadened to make it clear that the rule applies to data collected via health apps, connected devices, and any other technology that draws health inferences from user data. The update also clarified that breaches that trigger the notification requirements include cybersecurity incidents and unauthorized disclosures to third parties.

In its September 9, 2026, statement, the FTC said the 2024 update the Health Breach Notification Rule rendered the policy statement unnecessary and that pursuant to an Executive Order by President Trump, agencies have been directed to eliminate obsolete guidance documents, policy statements, and unnecessary rules that provide no benefit to Americans, hence the decision to withdraw the policy statement.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist