Utopia Tech
Healthcare2 min read

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA). On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having

UT

Utopia Tech

September 14, 2026 · 2 min read

Share

In September 2021, the U. S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA).

On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having been superseded by rulemaking. The Health Breach Notification Rule was issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act and applies to vendors of personal health records (PHRs) and related entities that are not subject to HIPAA.

In 2021, the FTC determined that because health apps were mainstream and increasingly collected consumers’ sensitive health and personal information, the developers of the apps should have a responsibility to ensure that the data they collect is secured, protected against unauthorized access, and that consumer notifications are required when there is a breach of that information or an unauthorized disclosure.

Per the 2021 policy statement, the FTC viewed the developers of health apps and other connected devices to be vendors of personal health records, if an app or device had the capability to draw data from multiple sources and was not covered by a similar rule issued by the Department of Health and Human Services. The change in position was contentious at the time, and while the policy statement received majority FTC backing, it was only approved with a 3-2 vote.

Commissioners Noah Joshua Philips and Christin S. Wilson voted against the policy statement, with both believing that the FTC’s interpretation of applicability for the Health Breach Notification Rule stretched the statutory text beyond its terms. In 2024, the FTC updated its Health Breach Notification Rule, significantly expanding its scope.

The definition of health information was broadened to make it clear that the rule applies to data collected via health apps, connected devices, and any other technology that draws health inferences from user data. The update also clarified that breaches that trigger the notification requirements include cybersecurity incidents and unauthorized disclosures to third parties.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy In its September 9, 2026, statement, the FTC said the 2024 update the Health Breach Notification Rule rendered the policy statement unnecessary and that pursuant to an Executive Order by President Trump, agencies have been directed to eliminate obsolete guidance documents, policy statements, and unnecessary rules that provide no benefit to Americans, hence the decision to withdraw the policy statement.

The post FTC Rescinds 2021 Policy Statement on Health App Data Breaches appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content