Back to Intelligence

FTC Rescinds 2021 Health App Breach Notification Policy Statement — What Health App Vendors and Healthcare Security Teams Must Do Now

SA
Security Arsenal Team
September 14, 2026
7 min read

The Federal Trade Commission has formally rescinded its September 2021 policy statement that had extended the Health Breach Notification Rule (HBNR) to mobile health applications and connected health device vendors not covered by HIPAA. For organizations operating in the digital health space — and for the security teams supporting them — this is a significant regulatory shift that demands an immediate review of breach notification obligations, incident response playbooks, and contractual language.

Make no mistake: the rescission does not eliminate breach notification obligations for health apps, and it absolutely does not reduce your exposure to FTC enforcement, state-level notification statutes, or civil litigation. If anything, the rollback introduces ambiguity — and ambiguity in regulatory compliance is where organizations get burned.

Background: The 2021 Policy Statement and the HBNR

The FTC Health Breach Notification Rule, originally issued in 2009 under the authority of the HITECH Act, applies to vendors of personal health records (PHRs) and related entities that are not covered entities or business associates under HIPAA. The rule requires these entities to notify affected individuals, the FTC, and in some cases the media following a breach of unsecured identifiable health information.

In September 2021, the FTC issued a policy statement clarifying — aggressively, in the view of many industry observers — that the rule's scope extended to health apps and connected devices. Under that interpretation:

  • A breach was not limited to malicious intrusion. It included any unauthorized acquisition of health data — including sharing data with advertising or analytics platforms without meaningful consent.
  • Apps that collect health data directly from consumers, or pull data from APIs (fitness trackers, glucose monitors, fertility apps, mental health platforms), were considered vendors of personal health records.
  • A security incident involving an app's health data could trigger notification obligations even if the disclosure was intentional business practice rather than an intrusion.

This policy statement was the legal foundation for several high-profile FTC enforcement actions against digital health companies that shared sensitive health data with third parties for advertising purposes. It effectively created a parallel breach notification regime for the consumer health app market, which sits outside HIPAA's perimeter.

What the Rescission Changes

With the 2021 policy statement withdrawn, the FTC has stepped back from its expansive interpretation of what constitutes a PHR vendor and what constitutes a breach under the HBNR. Key implications:

  1. The HBNR itself remains in force. This is a rescission of interpretive guidance, not repeal of the rule. The FTC retained — and in 2024 finalized — amendments to the HBNR that modernized its definitions and notification mechanics. The underlying regulation still applies to entities within its statutory scope.
  2. Enforcement posture is softening at the federal level. The aggressive reading that treated ad-tech data sharing as a reportable breach is no longer standing FTC policy. Organizations should not, however, read this as a green light — state regulators and private litigants have taken up the mantle.
  3. HIPAA coverage is unchanged. Covered entities and business associates remain fully subject to the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). If your organization touches PHI on behalf of a covered entity, nothing about this action reduces your obligations.
  4. State law fills the vacuum. Washington's My Health My Data Act, along with comprehensive privacy statutes in states like California, Virginia, Colorado, and Connecticut, impose their own health-data breach and consent requirements — many broader than the rescinded FTC interpretation.

Why This Matters to Defenders

In my IR practice, the single most common post-breach failure I see at health-tech companies isn't the intrusion itself — it's the notification misstep. Organizations either notify when they shouldn't (triggering unnecessary panic and regulatory scrutiny) or fail to notify when they must (converting a containable incident into an existential legal liability).

The rescission creates a gray zone precisely where that failure mode lives. Your legal team may now tell you the FTC rule doesn't apply to your app. That may be technically accurate under the narrowed interpretation — while your obligations under state law, your BAAs, your cyber insurance policy, and your own privacy notice remain fully intact. Breach response decisions made on incomplete regulatory analysis are how companies end up in front of a judge.

Executive Takeaways

Because this is a regulatory and compliance development rather than a technical threat, the appropriate response is governance action, not detection engineering. Here is what I am advising our healthcare and health-tech clients to do this quarter:

  1. Re-map your breach notification obligations. Build a jurisdiction-by-jurisdiction matrix covering the FTC HBNR (as it stands post-rescission), HIPAA (if you're a covered entity or business associate), all applicable state breach notification statutes, and state health-data-specific laws such as Washington's My Health My Data Act. Do not assume the federal rollback reduces your total obligation set — in most states, it doesn't.

  2. Update your incident response playbooks. Your IR runbooks should reference the current regulatory landscape, not the 2021 policy statement. Ensure escalation criteria, notification decision trees, and outside counsel contacts reflect the rescission. Playbooks citing rescinded guidance create confusion during active incidents — the worst possible time for a compliance debate.

  3. Audit your health data flows regardless of notification obligations. The 2021 policy statement may be gone, but the practices it targeted — undisclosed sharing of health data with advertising SDKs, analytics platforms, and data brokers — remain enforcement targets under Section 5 of the FTC Act (unfair or deceptive practices) and state consumer protection laws. Inventory every third party receiving health-adjacent data from your apps. If you can't enumerate them, that's your first finding.

  4. Review your privacy notices and consent mechanisms. Enforcement risk now centers on the gap between what you tell users and what you actually do. Any disclosure of health data to third parties that isn't accurately described in your privacy policy is a deception claim waiting to happen. Alignment between policy language and technical reality is a security control, not a legal nicety.

  5. Re-examine contracts with covered entities. If your health app integrates with HIPAA-covered providers or payers, your business associate agreements and data use agreements impose breach notification duties contractually — independent of any FTC rule. Those obligations survive the rescission untouched. Confirm your IR timelines meet the strictest contractual notification window (often 24–72 hours, far tighter than statutory deadlines).

  6. Brief your board and adjust cyber insurance posture. Regulators and insurers both track regulatory volatility. Document that your organization has assessed the rescission and adjusted its compliance program accordingly. Several cyber insurance carriers have begun asking specifically about health-data regulatory exposure during renewals — a documented, current analysis is now table stakes.

Remediation Actions for Security and Compliance Teams

There is no patch for a policy change — but there is concrete work to do:

  • Within 30 days: Complete the notification-obligation mapping exercise described above. Engage outside privacy counsel for jurisdictions where your exposure is unclear, particularly if you operate a consumer-facing health app in Washington, California, or Nevada.
  • Within 60 days: Update IR playbooks, tabletop exercise scenarios, and breach response templates. Run a tabletop specifically exercising a scenario where FTC HBNR applicability is ambiguous and state obligations are not — this is now the most likely real-world situation.
  • Within 90 days: Complete the third-party data flow audit. Remove or contractually constrain any advertising or analytics SDK receiving identifiable health data without a documented legal basis and accurate privacy-notice coverage.
  • Ongoing: Monitor FTC rulemaking activity. The HBNR's amended form remains in effect, and further interpretive shifts are possible as the regulatory environment evolves. Assign ownership for tracking this to your GRC function, with quarterly reporting to security leadership.

The Bottom Line

The FTC's rescission of its 2021 policy statement narrows the federal regulatory perimeter around health app data breaches — but it does not create safe harbor. State legislatures, state attorneys general, HIPAA's unchanged breach notification regime, contractual obligations, and plaintiff's attorneys collectively ensure that mishandled health data remains one of the highest-liability categories in incident response. Treat this development as a trigger to tighten your compliance architecture, not loosen it.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.