PrivacySignal
Breach

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

HIPAA Journal · · US Federal · Data Breaches

The Federal Trade Commission has rescinded a 2021 policy statement that had extended the Health Breach Notification Rule to cover health apps and connected devices. The original statement had broadened consumer protections by requiring health technology companies outside traditional HIPAA coverage to notify users of data breaches.

Why this matters: Millions of people use apps to track their periods, blood pressure, mental health, sleep, and fitness. Most of those apps are not covered by HIPAA. The 2021 policy statement was one of the few tools that forced those companies to tell users when their health data was exposed. Pulling it back shrinks accountability in a space where the data is deeply personal and the companies collecting it face almost no other federal check. If your health app gets breached, you may now have less right to know about it.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected?

Silent Ransom Group added Greenberg Traurig to its list of prominent law firms it attacked and leaked. DataBreaches.net has exclusive details on the incident. On August 21, when DataBreaches reported on a data breach affecting Troutman Pepper Locke, the firm was one of 64 law firm listings on Silent Ransom Group’s (SRG’s) leak site. As... Source

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Conti Ransomware Member Sentenced to 4 Years in Jail

A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and […] The post Conti Ransomware Member Sentenced to 4 Years in Jail appeared first on The HIPAA Journal.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

Delaware Consumer Privacy and Data-Breach Law Updates

Delaware's governor signed two bills in September 2026 that update the state's existing privacy and data-breach framework. One bill amends the Delaware Personal Data Privacy Act, which took effect in January 2025, while the other updates the state's breach notification law.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

Not just Korea: Google leaked identifying info for sex crime victims across the world

Google's process for handling removal requests related to non-consensual sexual images exposed victims' identifying information online, not only in South Korea but in multiple countries, according to reporting by the Hankyoreh. People who sought help removing intimate images — including images of minors — had their private details inadvertently published as part of that process.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →