FTC Rescinds 2021 Policy Statement on Health App Data Breaches
The Federal Trade Commission has rescinded a 2021 policy statement that had extended the Health Breach Notification Rule to cover health apps and connected devices. The original statement had broadened consumer protections by requiring health technology companies outside traditional HIPAA coverage to notify users of data breaches.
Why this matters: Millions of people use apps to track their periods, blood pressure, mental health, sleep, and fitness. Most of those apps are not covered by HIPAA. The 2021 policy statement was one of the few tools that forced those companies to tell users when their health data was exposed. Pulling it back shrinks accountability in a space where the data is deeply personal and the companies collecting it face almost no other federal check. If your health app gets breached, you may now have less right to know about it.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.