FTC drops its health app breach notice policy

The commission withdrew a Biden-era statement that treated health and fitness apps as covered by federal breach notification rules.

CSBadmin
2 Min Read

Health and fitness apps just lost a stated layer of federal scrutiny. The Federal Trade Commission pulled back a policy statement that had claimed breach notification coverage over them.

The withdrawal ran half a page. In it the commission argued the statement, contentious from the start, offered minimal benefit and later rulemaking had superseded it. The move also matches White House guidance urging agencies toward deregulation and away from unnecessary subregulatory guidance.

That original statement passed on a 3-2 vote under then-chair Lina Khan. Its argument: health apps, fitness trackers, and similar connected devices sat under an existing rule requiring firms to tell customers when health data is breached. Coverage reached any vendor of personal health records holding identifiable health information created or received by providers. Plenty of wellness apps ask users to upload medical records simply to work.

How much has changed is narrower than it looks. A policy statement is guidance, not law: it describes how officials intend to enforce existing statutes. An FTC spokesperson told CyberScoop the underlying policy remains codified through a 2024 regulatory update.

The signal still matters. Pulling the statement narrows the commission’s declared stance on a category of apps that gathers sensitive health data outside HIPAA’s reach.

Teams at health technology firms should not read this as permission. State privacy laws, the 2024 rulemaking, and the FTC’s authority over deceptive practices all remain in force. Keep disclosure documentation and breach notification playbooks current regardless.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.