FTC rescinds policy requiring health apps to notify customers after a breach
The FTC has rescinded a Biden-era policy that required health apps to notify users when their personal health data was exposed in a breach or shared without authorization. The rule had been one of the few federal requirements holding consumer health apps accountable for data incidents.
Why this matters: Health apps sit outside HIPAA. A fitness tracker, period tracker, or mental health app can collect deeply personal data and face far weaker rules than a hospital does. That breach notification requirement was one of the few tools forcing these companies to tell you when something went wrong with your data. Without it, a company can quietly mishandle your health information and you may never find out. Removing the rule does not make breaches less likely. It just means you are less likely to hear about them.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.