❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

FTC rescinds policy statement requiring health apps to notify customers after a breachΒ 

By: djohnson
9 September 2026 at 15:18

The Federal Trade Commission has rescinded a Biden administration-era policy statement that asserted coverage over health and fitness apps under federal data breach notification regulations.

In a half-page statement posted Wednesday, the FTC said it β€œhas determined that the statement – contentious at the time of issuance – provided minimal benefit and has been superseded by rulemaking.” The commission said the statement’s withdrawal also aligns with guidance from the White House to pursue a deregulatory agenda and avoid β€œunnecessary use of subregulatory guidance.”

Unlike a formal regulation, which carries the legally binding force of law created through a public rulemaking process, an agency policy statement is non-binding guidance that merely outlines how officials intend to interpret and enforce existing statutes. An FTC spokesperson told CyberScoop that the underlying policy including health apps remains codified through a regulatory update in 2024.

β€œEach of these reasons is independently sufficient to support the Commission’s decision to rescind this policy statement,” the FTC continued. β€œParties understand that guidance generally creates neither substantive rights nor binding obligations.”

The initial policy statement, passed in a divided 3-2 vote during the Biden administration under then-FTC chair Lina Khan, asserted that health apps, fitness trackers and other connected devices were covered under an existing regulation requiring companies to disclose health-related data breaches to customers.

The interpretation targeted any β€œvendor of personal health records that contain individually identifiable health information created or received by health care providers.” Many health and fitness apps ask users to upload medical records and other health-related data in order to function effectively.

More recently, health and cybersecurity experts have pointed to similar regulatory gaps that exist for AI companies that make healthcare specific models that can answer questions, examine patient records and dispense medical advice to users.

The underlying Health Breach Notification Rule also triggers automatic notification when a covered entity suffers a breach of security, which can include both standard breaches and data losses as well as the disclosure of sensitive health information to third parties without users’ authorization. That would potentially put health apps on the hook for selling customer data to third-party data brokers and other entities-a standard formally codified in a binding 2024 FTC rule update.

A Sept. 2021 statement by the FTC justifies its interpretation by citing digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act as well as gaps in major health privacy laws like the Health Insurance Portability and Accountability Act that allow such apps to handle and store sensitive personal health records or data without being subject to the same breach notification requirements as other health care organizations.

The FTC said it intended to enforce health apps under the law and subject violators to daily fines of $43,792 per violation.

β€œAs many Americans turn to apps and other technologies to track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, diet, and other vital areas, this Rule is more important than ever,” the FTC said in 2021. β€œFirms offering these services should take appropriate care to secure and protect consumer data.”

This week, the FTC voted unanimously to rescind the policy statement. But that unity is in part because President Trump fired Democratic FTC commissioners who voted in favor of the original rules, while advancing party allies as their replacements.

The two dissenting votes against the policy statement in 2021 were from Republican-appointed commissioners casting their dissents under a Democratic executive. Andrew Ferguson, a Republican commissioner nominated by former Democratic President Joe Biden, is now chair of an FTC filled entirely with Republican appointees, and has defended President Trump’s authority to fire and hire new commissioners at-will.

Update, 9/11/26, 4:15 p.m.: This story has been updated to clarify the impact of the FTC’s policy statement revision.

The post FTC rescinds policy statement requiring health apps to notify customers after a breachΒ  appeared first on CyberScoop.

❌
❌