Skip to main content
ComplianceData Protection

FTC Reverses Health App Breach Notification Policy

Federal Trade Commission office interior with a table and papers in the foreground.

"The Commission has determined that the statement – contentious at the time of issuance – provided minimal benefit and has been superseded by rulemaking," the Federal Trade Commission said in a half‑page statement posted Wednesday.

FTC rescission statement and stated rationale

The commission announced it had withdrawn a Biden administration‑era policy that had folded health and fitness apps into federal breach‑notification regulations. The FTC said the policy provided "minimal benefit" and has been superseded by ongoing rulemaking. The commission also tied the withdrawal to White House guidance urging a deregulatory approach and cautioning against "unnecessary use of subregulatory guidance." The FTC added that "Parties understand that guidance generally creates neither substantive rights nor binding obligations."

What the Sept. 2021 policy added

The policy the FTC rescinded had been issued in Sept. 2021 in a divided 3–2 vote during the Biden administration under then‑FTC chair Lina Khan. It explicitly extended an existing rule requiring companies to disclose health‑related data breaches to users so as to cover health apps, fitness trackers and other connected devices. The changes were written to apply to any "vendor of personal health records that contain individually identifiable health information created or received by health care providers." The FTC justified the expansion by citing digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act and by identifying gaps in major health privacy laws such as HIPAA that allow some apps to handle sensitive personal health records without the same breach notification obligations as other health care organizations.

Enforcement mechanics and penalties the rule would have triggered

The Sept. 2021 statement said the FTC intended to subject violators to daily fines of $43,792 per violation and to enforce the rule against firms that failed to secure consumer data. The rule triggered automatic notification obligations when a covered entity suffered a breach of security, defined broadly to include standard breaches and data losses as well as the disclosure of sensitive health information to third parties without users' authorization. The FTC warned at the time: "As many Americans turn to apps and other technologies to track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, diet, and other vital areas, this Rule is more important than ever." That language framed the rule as a response to the volume and sensitivity of health data collected by consumer apps.

Political changes that altered the commission’s makeup

This week’s unanimous vote to rescind the policy came after a series of personnel changes at the FTC. The source reports that President Trump fired Democratic FTC commissioners who had supported the original 2021 changes and advanced party allies as their replacements. Andrew Ferguson — described in the source as a Republican commissioner who was nominated by former Democratic President Joe Biden — is now chair of an FTC "filled entirely with Republican appointees" and has defended President Trump's authority to fire and hire commissioners at will. Those shifts in personnel shaped the commission majority that voted to withdraw the guidance.

What this means for technologists, policymakers, and consumers

  • Technologists and security teams: Without the guidance, teams running health and fitness apps will not face the automatic breach‑notification framework the Sept. 2021 statement sought to impose; they may instead await outcomes of the rulemaking the FTC cited as superseding the guidance.
  • Policymakers and regulators: The rescission signals a preference for formal rulemaking over subregulatory guidance, reflecting the White House direction the FTC cited. Regulators that want to extend breach obligations to apps will need to press that rulemaking or pursue alternative statutory or regulatory routes.
  • End users and patients: Because many health and fitness apps prompt users to upload medical records and other health data, the withdrawal removes an explicit, commission‑backed path that would have required prompt notification when sensitive health information was exposed or improperly disclosed — including disclosures to third‑party data brokers that the 2021 rule would have treated as reportable events.

The FTC’s statement frames the action as administrative housekeeping — removing a contentious subregulatory posture now overtaken by rulemaking — but it leaves the practical question intact: whether and how formal rulemaking will close the notification gap the commission identified in Sept. 2021. The stakes remain concrete for apps that collect medical records and for users whose most intimate data can flow through consumer devices and services.

Source: CyberScoop