Skip to content

Regulatory Pulse

FTC withdraws 2021 health-app breach policy—but the notification rule remains

The FTC has rescinded its 2021 health-app breach policy statement, but the binding Health Breach Notification Rule remains in force. Teams should update source registers without dismantling scope, incident-response or notice controls.

United States
Health privacy, breach notification and digital health
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Final FTC rescission of nonbinding guidance · Reviewed 11 September 2026 · 7 min read

The 60-second summary

On 9 September 2026, the FTC rescinded its 2021 policy statement on breaches by health apps and connected devices. The agency said the statement had been superseded by its 2024 rulemaking. This does not repeal or suspend the Health Breach Notification Rule in 16 CFR Part 318. The current rule expressly addresses qualifying health apps, connected devices and related service providers outside HIPAA coverage. It can require notice to affected individuals, the FTC and, for certain breaches affecting 500 or more residents of a jurisdiction, the media. Applicability remains fact-specific and should be assessed against the binding rule rather than the withdrawn statement.

Timeline that matters

  1. 15 September 2021

    Policy statement issued

    The FTC issued interpretive guidance on breaches by health apps and connected devices.

  2. 30 May 2024

    Final rule published

    The FTC published amendments clarifying scope, breach definitions, notice methods, content and timing.

  3. 29 July 2024

    Amendments effective

    The 2024 amendments to the Health Breach Notification Rule took effect.

  4. 9 September 2026

    Policy statement rescinded

    The FTC withdrew the 2021 statement, saying the later rulemaking had superseded it.

  5. 11 September 2026

    Editorial review

    PrivacyBuilt verified the rescission, current rule text and final-rule dates against official sources.

  6. 9 October 2026

    Next review

    Check for further FTC guidance, rule amendments or enforcement developments.

What changed

The source hierarchy changed. Teams should stop treating the 2021 policy statement as operative FTC guidance and anchor current scope, incident classification, notice timing and evidence decisions in the amended rule, its definitions and the 2024 final-rule materials. The withdrawal creates no new reporting deadline and does not erase existing notification duties.

Who should pay attention?

Digital health and wellness product teams

Determine whether product architecture and data sources create a personal health record within the rule’s definitions.

Privacy and legal teams

Replace superseded guidance references with a current, documented applicability analysis grounded in binding text.

Security and incident response

Treat unauthorized acquisition, access and disclosure as potential triggers and preserve discovery-time evidence.

Marketing, analytics and advertising teams

Assess whether disclosures through SDKs, pixels, APIs or other integrations can trigger health-data breach analysis.

Vendors and service providers

Confirm contractual notice contacts, customer status notifications, escalation paths and acknowledgement evidence.

What the guidance clarifies

The rule remains in force
The FTC withdrew a 2021 policy statement, not 16 CFR Part 318. The agency expressly said the statement had been superseded by its 2024 rulemaking.
Coverage is not automatic for every health product
Applicability depends on the rule’s definitions, including vendor of personal health records, PHR related entity, third-party service provider and personal health record.
Unauthorized disclosure can be a breach
The amended rule states that a breach can result from a data-security incident or an unauthorized disclosure of unsecured PHR identifiable health information.
Service providers have direct operational duties
A covered third-party service provider must notify the designated or senior official of the relevant covered customer and obtain acknowledgement.
The notification clock did not change
Required individual, media and service-provider notices generally must be sent without unreasonable delay and no later than 60 calendar days after discovery, subject to the rule’s law-enforcement exception.
Cross-border providers can be in scope
The rule states that it applies to foreign and domestic covered entities maintaining information of U.S. citizens or residents, while excluding HIPAA-covered activities as specified.

Removing an interpretive document does not remove operational duties

Why this matters for global organisations

Governance teams need a reliable hierarchy of legal sources and version-controlled control mappings. When guidance is withdrawn or superseded, policies, incident playbooks, vendor terms and training should point to the current binding requirements without assuming that the underlying duties disappeared.

  • Maintain a source register that distinguishes binding rules from guidance and commentary.
  • Map product scope to definitions and data flows rather than broad product labels.
  • Use one incident workflow for security events and potentially unauthorized disclosures.
  • Preserve decision records, notice evidence and accountable approvals.

13 actions to start now

  1. Remove the withdrawn 2021 policy statement from legal inventories as an operative source while retaining it in the change-history record.
  2. Map each product and business activity to the current definitions in 16 CFR Part 318.
  3. Document whether the organisation acts as a vendor of personal health records, PHR related entity, third-party service provider, HIPAA-covered entity or business associate for each activity.
  4. Test whether relevant electronic records can draw identifiable health information from multiple sources and are managed, shared or controlled by or primarily for the individual.
  5. Inventory health and wellness information collected, inferred, received or disclosed through apps, websites, devices, SDKs, pixels, APIs and vendors.
  6. Update incident criteria to capture unauthorized acquisition, access and disclosure—not only malicious intrusions.
  7. Record the first date on which a breach was known or reasonably should have been known.
  8. Configure notice workflows for affected individuals, the FTC and any required media notices, including the rule’s population thresholds.
  9. Retain the annual log and submission process for breaches involving fewer than 500 individuals.
  10. Name contractual notice recipients for covered service providers and require acknowledgement of receipt.
  11. Refresh plain-language notice templates to cover the information required by the current rule.
  12. Test delivery channels, substitute-notice procedures and law-enforcement delay controls.
  13. Run a tabletop using a health-data disclosure to an analytics or advertising recipient and record remediation.

Suggested next steps

  • Replace withdrawn-guidance citations in policies and playbooks, then conduct a documented scope and incident-response review against the current rule. Prioritise products using analytics, advertising, wearable or connected-device integrations and obtain qualified advice for borderline roles or breach determinations.

Evidence worth retaining

  • Version-controlled legal-source register showing the 2021 statement’s withdrawal.
  • Product-by-product applicability and role assessments.
  • System architecture, data-flow maps and multiple-source analysis.
  • Inventory of health information, identifiers, SDKs, APIs and recipients.
  • HIPAA-covered-activity and business-associate boundary analysis.
  • Incident intake records and breach-discovery timestamps.
  • Reliable evidence supporting any conclusion that unauthorized acquisition did not occur.
  • Affected-person counts and jurisdiction-level calculations.
  • Copies of individual, FTC, media and service-provider notices.
  • Submission receipts, delivery evidence and acknowledgement records.
  • Annual breach logs for incidents involving fewer than 500 individuals.
  • Delay decisions, law-enforcement communications and approval records.
  • Tabletop results, control defects and remediation tickets.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which products meet each element of the current personal-health-record definition?
  • Does the service have the technical capacity to draw information from multiple sources?
  • Which activities fall outside the rule because they are performed as a HIPAA-covered entity or business associate?
  • Could disclosures through advertising, analytics, cloud or support providers amount to unauthorized acquisition?
  • What reliable evidence would rebut the rule’s presumption following unauthorized access?
  • Which vendors qualify as third-party service providers, and have they been told of the customer’s covered status?
  • Who receives provider notices, and how is acknowledgement captured?
  • When does the organisation treat a breach as discovered, including knowledge held by employees or agents?
  • How are individuals, FTC and media thresholds, timing and notice content validated?
  • Which additional laws, contractual duties and specialist advice apply to the same incident?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.