FTC Rescinds 2021 Health App Breach Policy Statement
Independently fact-checked against primary sources (last audited September 18, 2026). · 9 primary sources cited on this page. How we verify our legal content

The Federal Trade Commission rescinded a 2021 policy statement that told health and fitness apps they could face breach-notification duties. The move, announced September 9, 2026, does not touch the actual Health Breach Notification Rule, which a 2024 amendment already rewrote to cover health apps directly.
Information last verified on September 18, 2026.
Status: The FTC rescinded the 2021 policy statement on September 9, 2026. The Health Breach Notification Rule itself, 16 C.F.R. Part 318 as amended effective July 29, 2024, remains in force and continues to require notification after a breach.
Jurisdiction scope: This is a federal FTC rule. It applies to vendors of personal health records, PHR-related entities, and their service providers that are not covered by HIPAA. Hospitals, doctors' offices, health plans, and other HIPAA-covered entities are instead governed by the U.S. Department of Health and Human Services' HIPAA Breach Notification Rule. Some states also layer their own health- or consumer-data breach notification duties on top of federal law.
What Happened
On September 9, 2026, the FTC published a short document titled "Rescission of Policy Statement," formally withdrawing the "Statement of the Commission On Breaches by Health Apps and Other Connected Devices," which the Commission had issued on September 15, 2021.
The rescission document is brief, about 130 words of text plus four footnotes citing supporting authority, and it gives the Commission's reasoning directly. The 2021 statement, it says, was "contentious at the time of issuance," "provided minimal benefit," and "has been superseded by rulemaking." Withdrawing it, the document adds, "will also advance President Trump's deregulatory agenda" and the Commission's "policy of avoiding unnecessary use of subregulatory guidance." The Commission characterizes each of those reasons as "independently sufficient to support the Commission's decision to rescind this policy statement."
The document closes with a line worth reading carefully: "Parties understand that guidance generally creates neither substantive rights nor binding obligations. Thus, the aforementioned reasons, alone and together, outweigh any reliance interests parties may have." In other words, the FTC's own position is that the 2021 statement was never binding law in the first place, only interpretive guidance about how it read its existing Rule.
The document's footnotes cite the 2021 statement's two original dissents, from then-Commissioners Noah Joshua Phillips and Christine S. Wilson, and a separate, unrelated July 29, 2026 enforcement action the FTC and the states of Utah and California brought against telehealth provider Hims & Hers over alleged unlawful sharing of consumers' sensitive information, offered as evidence that health-privacy enforcement generally "remains a top priority of the Commission." That case does not involve the Health Breach Notification Rule. The FTC's accompanying press release adds that the 2024 amendments rendered the 2021 statement unnecessary, because the Commission's own 2024 rule amendments already accomplished what the statement was trying to do through non-binding guidance. Neither the rescission document nor the press release states how individual commissioners voted or whether any commissioner issued a separate statement on this rescission.
What the Law Actually Says
What the 2021 policy statement said. The 2021 statement did not change the Rule's text. It offered the Commission's interpretation of how far the existing Health Breach Notification Rule, 16 C.F.R. Part 318, already reached. Its central argument was that a health app or connected device maintains a covered "personal health record," and therefore counts as a vendor of one, if it has the technical capacity to draw information from more than one source, even if the health-specific data comes from only one of those sources. The statement's own example: a blood-sugar monitoring app that draws health information only from the user's manual entries, but also pulls unrelated data such as calendar dates from another source, is still covered. It also stated that a "breach" under the Rule "is not limited to cybersecurity intrusions or nefarious behavior" and that unauthorized sharing of health data can itself be a reportable breach. Two commissioners, Noah Joshua Phillips and Christine S. Wilson, dissented from the 2021 statement. Their primary objection was procedural, that the statement bypassed an FTC rulemaking already under way on the same question, and secondarily that its reading of who counts as a health care provider and what counts as a breach went beyond what the statute and rule text supported.
What actually changed in 2024. The Commission did not leave that dispute unresolved. It ran a formal rulemaking, and on May 30, 2024 published amendments to the Health Breach Notification Rule in the Federal Register, effective July 29, 2024. Those amendments rewrote the Rule's definitions in ways that track much of what the 2021 statement had argued, but as binding regulatory text rather than guidance. As currently codified in 16 C.F.R. § 318.2:
- A "personal health record" is "an electronic record of PHR identifiable health information on an individual that has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual." The 2024 amendment specifically changed "can be drawn from" to "has the technical capacity to draw," so an app with an unused sync feature, such as a fitness-tracker API a particular user never connects, still counts.
- A "vendor of personal health records" is an entity, other than a HIPAA-covered entity or its business associate, "that offers or maintains a personal health record."
- A "PHR related entity" is a non-HIPAA-covered entity that offers products or services through a personal health record vendor's website, offers products or services through a HIPAA-covered entity's own personal-health-record website, or accesses or sends unsecured PHR identifiable health information to a personal health record.
- A "breach of security" is "acquisition of such information without the authorization of the individual," and unauthorized access is presumed to be an unauthorized acquisition unless the entity has reliable evidence otherwise. The 2024 amendment clarifies this expressly covers both traditional data breaches and unauthorized disclosures, such as sharing health data with an advertiser without permission, not only hacking incidents.
- The amended rule also added a "Covered health care provider" definition reaching any entity "furnishing health care services or supplies," and defined "health care services or supplies" to include online services, apps, or connected devices that track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, or diet. That is the specific change the FTC's 2026 press release points to when it says the 2024 rulemaking already "updated the Health Breach Notification Rule to cover health apps and connected devices like fitness trackers."
So the 2024 rulemaking is the reason the FTC now describes the 2021 statement as superseded: the interpretation the statement urged is now written directly into the Rule the FTC actually enforces, rather than living only in a separate guidance document. Full current text is available at 16 C.F.R. Part 318 on eCFR and at the FTC's own Health Breach Notification Rule page.
Enforcement record. The FTC has brought two actions under the Rule since it was issued in 2009. In February 2023, it charged GoodRx Holdings with violating the Rule by sharing users' prescription and health information with Facebook, Google, Criteo and other advertising companies without authorization and failing to notify affected consumers, the FTC, or the media as required; GoodRx paid a $1.5 million civil penalty. In May 2023, the Commission brought a similar action against Easy Healthcare Corporation, developer of the ovulation and fertility-tracking app Premom, for sharing users' health data with third parties including Google, AppsFlyer, and China-based companies; Easy Healthcare paid a $100,000 civil penalty. Both settlements were entered before the 2024 rule amendments took effect.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The most important fact in this story is what the FTC itself says about the document it just withdrew: guidance "generally creates neither substantive rights nor binding obligations." That is not spin from a critic of the rescission, it is the Commission's own stated legal position, in the rescission document itself. If a policy statement never bound anyone in the first place, withdrawing it does not, by definition, remove a legal duty that existed under it.
The real question a reader should ask is whether that framing holds up, and on the record here, it largely does. The 2021 statement's central interpretive claim, that a health app is covered if it has the technical capacity to draw data from multiple sources even when the health data itself comes from one source, is no longer just an interpretation sitting in a guidance memo. It is now the actual regulatory text of 16 C.F.R. § 318.2, adopted through notice-and-comment rulemaking in 2024. Rulemaking carries more legal weight than a policy statement, and it is also harder to undo quickly: reversing a codified rule requires another rulemaking, not a one-page rescission.
That said, "superseded" is not the same as "identical." A rulemaking preamble and a Rule's operative text are not always as detailed or as example-rich as a standalone policy statement. The 2021 statement's specific blood-sugar-and-calendar illustration, for instance, is a helpful interpretive example that will not automatically reappear verbatim anywhere in the Rule's text now that the statement is gone, even though the amended definitions were built to reach the same result. Businesses and their counsel who relied on that statement's worked examples for compliance guidance will need to work from the Rule's text and the 2024 rulemaking's preamble instead, which is a real, if narrow, practical adjustment even where the underlying legal outcome does not change.
The rescission document also names an explicit second purpose beyond the legal argument: advancing "President Trump's deregulatory agenda" and a general policy against "subregulatory guidance." That is a stated policy goal, not a legal finding, and it does not by itself change what any business or consumer is required to do under the Rule.
How This Affects You
If you use a health, fitness, fertility, or mental-health app, or a connected device like a wearable that is not offered by a HIPAA-covered provider such as your doctor's office or insurer, this rescission does not remove your right to be notified if that app or device suffers a data breach or improperly discloses your health information. That obligation comes from the Health Breach Notification Rule itself, which was not withdrawn and remains in force under its 2024 amendments.
If a company tells you it no longer has to notify you because the FTC "withdrew its health app guidance," that claim conflates the 2021 policy statement with the Rule. The statement is gone; the Rule, and the definitions that reach most consumer health apps, is not.
If you run a business that collects health-adjacent data through an app or connected device, your compliance obligations continue to come from 16 C.F.R. Part 318 as currently written, not from the withdrawn 2021 statement. If your product was only borderline covered under the older statement's reasoning, it is worth rechecking the current regulatory definitions directly rather than relying on secondhand summaries of what changed.
If your health data was involved in a breach at a company covered by this Rule, see our guide on what to do after a data breach for practical next steps.
This article is for general information only and is not legal advice. Laws, regulations, and agency enforcement priorities change. Consult a licensed attorney for guidance about your specific situation.
Related articles
Consumers navigating a health-adjacent data breach at a HIPAA-covered provider should see our guide on filing a HIPAA breach report. Readers in Washington state should note the additional protections created by the My Health My Data Act, which covers health data beyond what federal law reaches. For a broader look at how state privacy rules differ, see our comparison of state privacy laws. If you have already been notified of a breach involving your data, our practical after-a-data-breach checklist walks through next steps.
Last updated: 2026-09-18. This is a developing story; details verified as of 2026-09-18.
Frequently Asked Questions
Did the FTC eliminate the Health Breach Notification Rule?
No. The FTC rescinded only a 2021 policy statement, which was non-binding interpretive guidance. The Health Breach Notification Rule itself, 16 C.F.R. Part 318 as amended in 2024, remains in effect and continues to require notice after a breach.
Do health and fitness apps still have to notify me after a data breach?
Apps and connected devices that meet the Rule's current definitions, generally those not covered by HIPAA that maintain a personal health record capable of drawing information from multiple sources, must still notify affected users, the FTC, and in some cases the media following a breach of security, under the Rule as amended effective July 29, 2024.
Why did the FTC withdraw the 2021 statement?
The Commission's rescission document gives several reasons it calls independently sufficient: the statement was contentious when issued, provided minimal benefit, and was superseded by the Commission's 2024 rulemaking. The document also cites the current administration's deregulatory policy and a general preference for avoiding non-binding guidance.
Is my doctor's office or health plan covered by this FTC rule?
No. The Health Breach Notification Rule applies to vendors of personal health records and related entities that are not covered by HIPAA. Hospitals, doctors' offices, and health plans covered by HIPAA are instead governed by the HHS HIPAA Breach Notification Rule; see our guide on reporting HIPAA breaches for that separate process.
Has the FTC ever actually enforced the Health Breach Notification Rule?
Yes. The FTC brought its first two enforcement actions under the Rule in 2023, against GoodRx Holdings (a $1.5 million penalty) and against Easy Healthcare Corporation, developer of the Premom fertility app (a $100,000 penalty), both for sharing users' health data with third parties without authorization.
Does this rescission affect state health-privacy laws?
No. The rescission is a federal FTC action affecting only a federal guidance document. State laws that separately regulate health or consumer data, such as Washington's My Health My Data Act, are unaffected and may impose their own, often broader, requirements.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- FTC, Rescission of Policy Statement (Sept. 9, 2026)(ftc.gov).gov
- FTC press release, "FTC Withdraws Obsolete Policy Statement" (Sept. 9, 2026)(ftc.gov).gov
- Health Breach Notification Rule, 89 Fed. Reg. 47028 (May 30, 2024), effective July 29, 2024(federalregister.gov).gov
- 16 C.F.R. Part 318, Health Breach Notification Rule, current text (eCFR)(ecfr.gov).gov
- FTC Legal Library, Health Breach Notification Rule(ftc.gov).gov
- FTC, Statement of the Commission On Breaches by Health Apps and Other Connected Devices (Sept. 15, 2021)(ftc.gov).gov
- FTC case page, GoodRx Holdings, Inc.(ftc.gov).gov
- FTC case page, Easy Healthcare Corporation, U.S. v. (Premom)(ftc.gov).gov
- FTC press release, "FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices" (July 29, 2026)(ftc.gov).gov