PrivacySignal
Breach

FTC rescinds policy requiring health apps to notify customers after a breach

CyberScoop · · US Federal · Data Breaches

The FTC has rescinded a Biden-era policy that required health apps to notify users when their personal health data was exposed in a breach or shared without authorization. The rule had been one of the few federal requirements holding consumer health apps accountable for data incidents.

Why this matters: Health apps sit outside HIPAA. A fitness tracker, period tracker, or mental health app can collect deeply personal data and face far weaker rules than a hospital does. That breach notification requirement was one of the few tools forcing these companies to tell you when something went wrong with your data. Without it, a company can quietly mishandle your health information and you may never find out. Removing the rule does not make breaches less likely. It just means you are less likely to hear about them.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
WIRED — AI · · International

I Let an AI Agent Hack All My Gadgets—and I’d Do It Again

After I removed the safety guardrails from a powerful open-source model, it found vulnerabilities in my household devices and hacked into a PC. But it also told me how to make everything a lot more secure.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
Microsoft Threat Intelligence · · International

Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation#security Read original →
Breach
The Record · · International

Electronic health record company says customer data stolen in breach

Veradigm, an electronic health record company, disclosed that customer data was stolen in a breach affecting a specific interface. The company stated the incident did not spread to its broader infrastructure and caused no operational disruptions.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Veradigm warns of patient data breach after ransomware gang claims attack

Veradigm, a healthcare technology company, has disclosed a data breach affecting patient personal data following a cyberattack on one of its third-party vendors. A ransomware group has claimed responsibility for the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy#security Read original →
Breach
WIRED — AI · · International

A Stealth Startup Thinks It Just Hacked the Memory Shortage

Kepler Computing, a stealth-stage chip startup, says it has developed a new design approach and a proprietary material that could ease the memory supply shortages driving up prices across the semiconductor industry.

Who should care: Cybersecurity · Privacy officers · Administrators