FTC Rescinds 2021 Health App Breach Policy: How the 2024 Rule Update Made It Obsolete
The Federal Trade Commission has withdrawn a 2021 policy statement that extended breach notification requirements to health apps. The agency deemed the guidance obsolete after formally codifying those same protections into the Health Breach Notification Rule in 2024.
- Regulatory Streamliners
- Argue that obsolete subregulatory guidance clutters the legal landscape and should be removed when formal rulemaking supersedes it.
- Health Tech Compliance Experts
- Emphasize that the underlying legal obligations for health apps remain unchanged despite the policy withdrawal.
Perspectives this story doesn't cover
- Consumer Privacy Advocates
- Health App Developers
Why it matters
While the withdrawal removes a contentious piece of subregulatory guidance, the underlying requirement for health and fitness apps to report data breaches remains fully enforceable under the updated 2024 federal rule. Consumers will still be notified if their sensitive health data is exposed or shared without authorization.
Privacy advocates argue that the Federal Trade Commission’s decision to rescind its 2021 health app breach policy signals a dangerous retreat on consumer data protection, leaving sensitive medical information vulnerable to exposure. Conversely, the FTC and compliance experts maintain that the withdrawal simply cleans up the regulatory books, arguing that the 2021 guidance was rendered entirely redundant when the agency formally codified those exact protections into federal law in 2024.[1][2][5]
The policy in question, passed in a divided 3-2 vote during the Biden administration, extended the federal Health Breach Notification Rule (HBNR) to cover health and fitness apps. It mandated that developers of fertility trackers, diet apps, and connected devices notify users if their personal health records were exposed in a breach or shared without authorization. At the time, the FTC warned that violators would face daily fines of $43,792 per violation.[2][3]
However, the landscape shifted in April 2024 when the FTC finalized comprehensive amendments to the HBNR itself. The updated rule explicitly broadened the definition of "health information" to include data collected through apps and connected devices, and clarified that unauthorized sharing with third parties constitutes a "breach of security." Because the 2024 rulemaking formally integrated these requirements into the binding federal code, the 2021 subregulatory guidance was left obsolete.[3][4]
In a statement posted on September 1, 2026, the FTC announced the unanimous withdrawal of the 2021 policy. The commission stated it "has determined that the statement – contentious at the time of issuance – provided minimal benefit and has been superseded by rulemaking." The agency further noted that "parties understand that guidance generally creates neither substantive rights nor binding obligations."[1][2]
In a statement posted on September 1, 2026, the FTC announced the unanimous withdrawal of the 2021 policy.
The rescission also aligns with a broader deregulatory directive from the White House. President Donald J. Trump recently issued an executive order directing federal agencies to eliminate obsolete guidance documents and policy statements, arguing they contribute to an "ever-expanding morass of complicated Federal regulation" without providing tangible benefits to consumers.[1][2]
Despite the withdrawal of the 2021 guidance, legal experts emphasize that health tech startups are not operating in a regulatory vacuum. The assumption that non-HIPAA entities are exempt from federal health data privacy laws "is wrong—and it's getting expensive," according to Promise Legal Insights. The 2024 HBNR remains fully in effect and carries strict compliance mandates for any technology that draws health inferences from user data.[3][4]
Under the updated 2024 framework, the notification timeline is rigid. If a health app experiences a breach involving 500 or more individuals, the company must notify the FTC and the affected users "without unreasonable delay" and no later than 60 calendar days after discovering the exposure. The notice must clearly identify any third parties that acquired the unsecured health information and describe the potential harm that may result.[3][4]
Recent enforcement history underscores the financial stakes for developers who mishandle user data. Prior to the 2024 rule update, the FTC leveraged the HBNR to secure major settlements, including a $7.8 million penalty against BetterHelp and a $1.5 million fine against GoodRx in 2023 for unauthorized data sharing. The underlying legal framework that enabled those penalties remains intact, meaning consumers will continue to receive notifications if their digital health records are compromised.[3][4]
The removal of the 2021 policy statement shifts the enforcement mechanism from a temporary memo to a permanent federal rule, but the compliance burden on developers remains identical. Moving forward, the FTC's focus will center entirely on enforcing the 2024 HBNR parameters, testing whether health app operators can meet the 60-day reporting window when their internal data-sharing practices are exposed.[1][3][4]
What to know
- The FTC unanimously rescinded its 2021 policy statement on health app data breaches.
- The 2021 guidance was deemed obsolete because the 2024 Health Breach Notification Rule formally codified the same protections.
- Health apps and connected devices must still notify users and the FTC within 60 days of a data breach.
- The withdrawal aligns with a White House directive to eliminate unnecessary subregulatory guidance.
Where opinion splits
Regulatory Streamliners
Argue that obsolete subregulatory guidance clutters the legal landscape and should be removed.
Proponents of the rescission, including the current FTC administration and White House officials, view the 2021 policy statement as an unnecessary layer of bureaucracy. Because the 2024 Health Breach Notification Rule update formally integrated health apps into the binding federal code, maintaining a separate, non-binding policy memo provided no additional consumer protection. They argue that eliminating redundant guidance simplifies compliance for businesses and adheres to executive directives aimed at reducing federal regulatory bloat.
Health Tech Compliance Experts
Emphasize that the underlying legal obligations for health apps remain unchanged despite the policy withdrawal.
Legal analysts and privacy compliance professionals stress that the rescission is purely administrative and does not give health tech startups a free pass to mishandle data. They point out that the 2024 HBNR explicitly covers non-HIPAA entities, meaning developers of diet, fertility, and fitness apps still face strict 60-day reporting windows and severe financial penalties for unauthorized data sharing. For these experts, the focus remains on ensuring companies build robust data security architectures rather than reacting to the withdrawal of an obsolete memo.
Sources
[1]Federal Trade CommissionRegulatory StreamlinersFTC Withdraws Obsolete Policy Statement
Read on Federal Trade Commission →
[2]CyberScoopHealth Tech Compliance ExpertsFTC rescinds policy requiring health apps to notify customers after a breach
Read on CyberScoop →
[3]Promise Legal InsightsHealth Tech Compliance ExpertsFTC Health Breach Rule: Health App Compliance Guide
Read on Promise Legal Insights →
[4]Federal Trade CommissionRegulatory StreamlinersFTC Finalizes Changes to the Health Breach Notification Rule
Read on Federal Trade Commission →
[5]Factlen Editorial TeamSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Shopping & Reviews
See all →Window Efficiency
Decoding the NFRC Window Label: Why U-Factor and SHGC Matter More Than a Basic Energy Star Sticker
9 sources
Harness Biomechanics
Front-Clip vs. Back-Clip Dog Harnesses: How Attachment Points Alter Canine Biomechanics and Pulling Force
6 sources
5G Hardware
Sub-6 GHz vs. mmWave 5G: How Frequency Band Dictates Range, Penetration, and Peak Speed
7 sources
Smartphone Architecture
Comparing the iPhone Duo and iPhone 18 Pro: Screen Real Estate, Thermal Constraints, and the $3,000 Price Tag
7 sources
Every angle. Every day.
Get Shopping & Reviews stories with full source coverage and perspective breakdowns delivered to your inbox.




