The 60-second summary
On 9 September 2026, the FTC rescinded its 2021 policy statement on breaches by health apps and connected devices. The agency said the statement had been superseded by its 2024 rulemaking. This does not repeal or suspend the Health Breach Notification Rule in 16 CFR Part 318. The current rule expressly addresses qualifying health apps, connected devices and related service providers outside HIPAA coverage. It can require notice to affected individuals, the FTC and, for certain breaches affecting 500 or more residents of a jurisdiction, the media. Applicability remains fact-specific and should be assessed against the binding rule rather than the withdrawn statement.
Timeline that matters
15 September 2021
Policy statement issued
The FTC issued interpretive guidance on breaches by health apps and connected devices.
30 May 2024
Final rule published
The FTC published amendments clarifying scope, breach definitions, notice methods, content and timing.
29 July 2024
Amendments effective
The 2024 amendments to the Health Breach Notification Rule took effect.
9 September 2026
Policy statement rescinded
The FTC withdrew the 2021 statement, saying the later rulemaking had superseded it.
11 September 2026
Editorial review
PrivacyBuilt verified the rescission, current rule text and final-rule dates against official sources.
9 October 2026
Next review
Check for further FTC guidance, rule amendments or enforcement developments.
What changed
The source hierarchy changed. Teams should stop treating the 2021 policy statement as operative FTC guidance and anchor current scope, incident classification, notice timing and evidence decisions in the amended rule, its definitions and the 2024 final-rule materials. The withdrawal creates no new reporting deadline and does not erase existing notification duties.
Who should pay attention?
Digital health and wellness product teams
Determine whether product architecture and data sources create a personal health record within the rule’s definitions.
Privacy and legal teams
Replace superseded guidance references with a current, documented applicability analysis grounded in binding text.
Security and incident response
Treat unauthorized acquisition, access and disclosure as potential triggers and preserve discovery-time evidence.
Marketing, analytics and advertising teams
Assess whether disclosures through SDKs, pixels, APIs or other integrations can trigger health-data breach analysis.
Vendors and service providers
Confirm contractual notice contacts, customer status notifications, escalation paths and acknowledgement evidence.
What the guidance clarifies
- The rule remains in force
- The FTC withdrew a 2021 policy statement, not 16 CFR Part 318. The agency expressly said the statement had been superseded by its 2024 rulemaking.
- Coverage is not automatic for every health product
- Applicability depends on the rule’s definitions, including vendor of personal health records, PHR related entity, third-party service provider and personal health record.
- Unauthorized disclosure can be a breach
- The amended rule states that a breach can result from a data-security incident or an unauthorized disclosure of unsecured PHR identifiable health information.
- Service providers have direct operational duties
- A covered third-party service provider must notify the designated or senior official of the relevant covered customer and obtain acknowledgement.
- The notification clock did not change
- Required individual, media and service-provider notices generally must be sent without unreasonable delay and no later than 60 calendar days after discovery, subject to the rule’s law-enforcement exception.
- Cross-border providers can be in scope
- The rule states that it applies to foreign and domestic covered entities maintaining information of U.S. citizens or residents, while excluding HIPAA-covered activities as specified.
Removing an interpretive document does not remove operational duties
Why this matters for global organisations
Governance teams need a reliable hierarchy of legal sources and version-controlled control mappings. When guidance is withdrawn or superseded, policies, incident playbooks, vendor terms and training should point to the current binding requirements without assuming that the underlying duties disappeared.
- Maintain a source register that distinguishes binding rules from guidance and commentary.
- Map product scope to definitions and data flows rather than broad product labels.
- Use one incident workflow for security events and potentially unauthorized disclosures.
- Preserve decision records, notice evidence and accountable approvals.
13 actions to start now
- Remove the withdrawn 2021 policy statement from legal inventories as an operative source while retaining it in the change-history record.
- Map each product and business activity to the current definitions in 16 CFR Part 318.
- Document whether the organisation acts as a vendor of personal health records, PHR related entity, third-party service provider, HIPAA-covered entity or business associate for each activity.
- Test whether relevant electronic records can draw identifiable health information from multiple sources and are managed, shared or controlled by or primarily for the individual.
- Inventory health and wellness information collected, inferred, received or disclosed through apps, websites, devices, SDKs, pixels, APIs and vendors.
- Update incident criteria to capture unauthorized acquisition, access and disclosure—not only malicious intrusions.
- Record the first date on which a breach was known or reasonably should have been known.
- Configure notice workflows for affected individuals, the FTC and any required media notices, including the rule’s population thresholds.
- Retain the annual log and submission process for breaches involving fewer than 500 individuals.
- Name contractual notice recipients for covered service providers and require acknowledgement of receipt.
- Refresh plain-language notice templates to cover the information required by the current rule.
- Test delivery channels, substitute-notice procedures and law-enforcement delay controls.
- Run a tabletop using a health-data disclosure to an analytics or advertising recipient and record remediation.
Suggested next steps
- Replace withdrawn-guidance citations in policies and playbooks, then conduct a documented scope and incident-response review against the current rule. Prioritise products using analytics, advertising, wearable or connected-device integrations and obtain qualified advice for borderline roles or breach determinations.
Evidence worth retaining
- Version-controlled legal-source register showing the 2021 statement’s withdrawal.
- Product-by-product applicability and role assessments.
- System architecture, data-flow maps and multiple-source analysis.
- Inventory of health information, identifiers, SDKs, APIs and recipients.
- HIPAA-covered-activity and business-associate boundary analysis.
- Incident intake records and breach-discovery timestamps.
- Reliable evidence supporting any conclusion that unauthorized acquisition did not occur.
- Affected-person counts and jurisdiction-level calculations.
- Copies of individual, FTC, media and service-provider notices.
- Submission receipts, delivery evidence and acknowledgement records.
- Annual breach logs for incidents involving fewer than 500 individuals.
- Delay decisions, law-enforcement communications and approval records.
- Tabletop results, control defects and remediation tickets.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which products meet each element of the current personal-health-record definition?
- Does the service have the technical capacity to draw information from multiple sources?
- Which activities fall outside the rule because they are performed as a HIPAA-covered entity or business associate?
- Could disclosures through advertising, analytics, cloud or support providers amount to unauthorized acquisition?
- What reliable evidence would rebut the rule’s presumption following unauthorized access?
- Which vendors qualify as third-party service providers, and have they been told of the customer’s covered status?
- Who receives provider notices, and how is acknowledgement captured?
- When does the organisation treat a breach as discovered, including knowledge held by employees or agents?
- How are individuals, FTC and media thresholds, timing and notice content validated?
- Which additional laws, contractual duties and specialist advice apply to the same incident?
Official sources
- FTC — FTC Withdraws Obsolete Policy Statement, 9 September 2026
- FTC — Rescission of Policy Statement
- eCFR — 16 CFR Part 318, Health Breach Notification Rule
- Federal Register — Health Breach Notification Rule, 89 FR 47028, 30 May 2024
- FTC — Health Breach Notification Rule docket page
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.