Pull to refresh
Logo
FTC rescinds health app breach notification policy

FTC rescinds health app breach notification policy

Rule Changes

2021 policy statement withdrawn as obsolete; Health Breach Notification Rule still covers health apps

3 days ago: FTC rescinds health app policy

Overview

Updated 2 days ago

The Federal Trade Commission rescinded its 2021 policy statement that required health apps and connected devices to notify users when their health data is breached. The agency said the guidance was obsolete, superseded by a 2024 rulemaking that already extended the underlying Health Breach Notification Rule to those products.

The withdrawal advances President Trump's executive order directing agencies to eliminate unnecessary guidance documents. The 2024 rule remains in force, so the practical effect depends on whether health app companies keep notifying users of breaches without the policy statement's explicit language.

Why it matters

The rescission could leave millions of health app users without breach notifications if companies stop complying.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

$43,792
Maximum daily fine per violation
Penalty for failing to notify users under the Health Breach Notification Rule.
5 years
Policy was in effect
From the September 2021 policy statement to the September 2026 rescission.
2
Enforcement actions before 2024 rule
FTC settled HBNR cases against GoodRx and Easy Healthcare in 2023.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

September 2021 September 2026

5 events Latest: 3 days ago
Tap a bar to jump to that date
  1. FTC rescinds health app policy

    Latest Statement

    Unanimous vote withdraws the 2021 statement as obsolete; the 2024 rule remains in effect.

  2. FTC finalizes HBNR rule changes

    Rule Change

    Rule updated to explicitly cover health apps and connected devices not covered by HIPAA; passed 3-2.

  3. FTC issues health app breach policy

    Statement

    3-2 vote extends Health Breach Notification Rule to apps and connected devices, with fines up to $43,792 per violation per day.

Scenarios

1

FTC keeps enforcing health breach rule without the policy

Likely Resolves by Q2 2027

Discussed by: FTC officials and consumer advocates

The 2024 rule codified the health app coverage, so the rescission removes only the interpretive gloss. The FTC continues its enforcement pipeline, announcing new settlements against health app companies that fail to notify users of breaches.

2

Health apps cut breach notifications, states step in

Possible Resolves by Q3 2027

Discussed by: Privacy researchers and state attorneys general

Some companies treat the rescission as weakening their obligations and stop notifying users of breaches. Privacy groups document the gaps, and one or more state attorneys general open investigations or file suits under state breach notification laws, filling the federal enforcement void.

3

FTC proposes narrowing the 2024 health breach rule

Unlikely Resolves by End of 2027

Discussed by: Regulatory analysts and industry observers

The deregulatory push extends beyond guidance rescission to the rule itself. The FTC publishes a notice of proposed rulemaking to narrow the HBNR's scope or reduce notification requirements, targeting the 2024 amendments that expanded coverage to health apps.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

March 2017

Broadband privacy rules repeal (2017)

Congress voted to repeal Federal Communications Commission rules that would have required internet providers to get opt-in consent before sharing customers' browsing history and app usage data. The rules never took effect.

Then

Internet providers were not required to get opt-in consent, and privacy advocates warned consumers would see more targeted advertising and data sharing.

Now

The repeal became a template for rolling back consumer data protections through the Congressional Review Act after a presidential transition.

Why this matters now

Shows how a consumer data privacy protection can be undone when political control shifts, though the FTC rescission is narrower than a congressional repeal.

January-May 2017

Congressional Review Act rollbacks (2017)

Using the Congressional Review Act, the Republican Congress rolled back 14 Obama-era regulations, including the broadband privacy rules and a rule limiting coal mining impacts. Each repeal required only a simple majority.

Then

Obama-era rules were voided, and agencies could not issue substantially similar rules without new legislation.

Now

Established the CRA as a standard tool for reversing regulations after a presidential transition.

Why this matters now

Illustrates the broader deregulatory mechanism at work in the FTC's rescission, though the FTC used its own authority rather than waiting for Congress.

February-May 2023

GoodRx and Easy Healthcare HBNR settlements (2023)

The FTC brought its first enforcement actions under the Health Breach Notification Rule, fining telehealth company GoodRx and fertility app publisher Easy Healthcare for sharing user health data without consent. Both cases relied on the 2021 policy statement's interpretation of the rule.

Then

The settlements put health app companies on notice that the FTC would enforce breach notification requirements and third-party data-sharing prohibitions.

Now

The enforcement push led to the 2024 rulemaking that codified the policy statement's interpretations into the rule itself.

Why this matters now

Shows the policy statement was not just guidance on paper — it drove real enforcement actions, which the 2024 rule now sustains on its own.

Sources

(8)