FTC Rescinds 2021 Health App Breach Policy Statement

Independently fact-checkedBy Recording Law Editorial Team10 min read

Independently fact-checked against primary sources (last audited September 18, 2026). · 9 primary sources cited on this page. How we verify our legal content

FTC Rescinds 2021 Health App Breach Policy Statement

Frequently Asked Questions

Did the FTC eliminate the Health Breach Notification Rule?

No. The FTC rescinded only a 2021 policy statement, which was non-binding interpretive guidance. The Health Breach Notification Rule itself, 16 C.F.R. Part 318 as amended in 2024, remains in effect and continues to require notice after a breach.

Do health and fitness apps still have to notify me after a data breach?

Apps and connected devices that meet the Rule's current definitions, generally those not covered by HIPAA that maintain a personal health record capable of drawing information from multiple sources, must still notify affected users, the FTC, and in some cases the media following a breach of security, under the Rule as amended effective July 29, 2024.

Why did the FTC withdraw the 2021 statement?

The Commission's rescission document gives several reasons it calls independently sufficient: the statement was contentious when issued, provided minimal benefit, and was superseded by the Commission's 2024 rulemaking. The document also cites the current administration's deregulatory policy and a general preference for avoiding non-binding guidance.

Is my doctor's office or health plan covered by this FTC rule?

No. The Health Breach Notification Rule applies to vendors of personal health records and related entities that are not covered by HIPAA. Hospitals, doctors' offices, and health plans covered by HIPAA are instead governed by the HHS HIPAA Breach Notification Rule; see our guide on reporting HIPAA breaches for that separate process.

Has the FTC ever actually enforced the Health Breach Notification Rule?

Yes. The FTC brought its first two enforcement actions under the Rule in 2023, against GoodRx Holdings (a $1.5 million penalty) and against Easy Healthcare Corporation, developer of the Premom fertility app (a $100,000 penalty), both for sharing users' health data with third parties without authorization.

Does this rescission affect state health-privacy laws?

No. The rescission is a federal FTC action affecting only a federal guidance document. State laws that separately regulate health or consumer data, such as Washington's My Health My Data Act, are unaffected and may impose their own, often broader, requirements.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. FTC, Rescission of Policy Statement (Sept. 9, 2026)(ftc.gov).gov
  2. FTC press release, "FTC Withdraws Obsolete Policy Statement" (Sept. 9, 2026)(ftc.gov).gov
  3. Health Breach Notification Rule, 89 Fed. Reg. 47028 (May 30, 2024), effective July 29, 2024(federalregister.gov).gov
  4. 16 C.F.R. Part 318, Health Breach Notification Rule, current text (eCFR)(ecfr.gov).gov
  5. FTC Legal Library, Health Breach Notification Rule(ftc.gov).gov
  6. FTC, Statement of the Commission On Breaches by Health Apps and Other Connected Devices (Sept. 15, 2021)(ftc.gov).gov
  7. FTC case page, GoodRx Holdings, Inc.(ftc.gov).gov
  8. FTC case page, Easy Healthcare Corporation, U.S. v. (Premom)(ftc.gov).gov
  9. FTC press release, "FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices" (July 29, 2026)(ftc.gov).gov
Share: