The commission voted unanimously on September 9 to rescind guidance that had passed 3-2 five years earlier.

 

What happened

The Federal Trade Commission rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices on September 9, 2026, in a half-page statement describing the guidance as contentious at the time of issuance, of minimal benefit, and superseded by rulemaking. The commission gave three separate grounds, adding that each was independently sufficient. Withdrawal also advances the current administration's deregulatory agenda and the commission's policy of avoiding unnecessary subregulatory guidance. The original statement extended the Health Breach Notification Rule to health apps and connected devices falling outside HIPAA, and passed 3-2 under then-chair Lina Khan, CyberScoop reported. This week's vote was unanimous, in part because Democratic commissioners who backed the original statement were removed and replaced.

 

Going deeper

The Health Breach Notification Rule itself remains in force. Issued in 2009 under the HITECH Act, it applies to vendors of personal health records and related entities not subject to HIPAA, and the commission expanded it substantially through 2024 rulemaking to cover health apps, connected devices, and other technology that draws health inferences from user data. That 2024 revision is what the FTC now cites as making the policy statement redundant, according to its announcement, which states that protecting the privacy of Americans' sensitive health information remains a commission priority. Section 5 authority over unfair or deceptive practices is untouched. What disappears is the interpretive guidance rather than the rule, and the commission notes that guidance of this kind generally creates neither substantive rights nor binding obligations.

 

What was said

The statement "provided minimal benefit and has been superseded by rulemaking," the commission wrote in its rescission. Its 2021 position had read differently: "As many Americans turn to apps and other technologies to track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, diet, and other vital areas, this Rule is more important than ever," the FTC said at the time, adding that firms offering those services should take appropriate care to secure and protect consumer data.

 

In the know

Medicare beneficiaries gained access to third-party apps through the Medicare App Library in April 2026, a CMS directory listing tools that have passed independent review against requirements covering privacy and security, according to KFF. Five apps were listed as of June, with eight more expected. Vetting is not performed by CMS itself. Developers complete an assessment through one of two industry bodies, then sign a code of conduct and meet identity verification standards before submission, under the agency's published requirements. Uptake among the relevant population is already high, with 78% of Medicare beneficiaries aged 65 and over having used a health care app or website to manage their care during 2025.

 

The big picture

Covered entities transmitting records to a patient-selected app are not liable under HIPAA for what the app does afterward, provided the app developer is not their business associate, according to OCR guidance on the access right, health apps, and APIs. That guidance also states a covered entity cannot refuse a request because it has concerns about how the app will use the information or because the app does not encrypt data at rest. Liability changes where the relationship changes, since an app a provider uses to deliver services, or one an EHR developer builds on the provider's behalf, creates a business associate relationship that brings the arrangement back inside HIPAA. Organizations whose portals integrate with consumer applications should establish which of those arrangements they are in before a patient asks, and document the determination rather than assuming either way.

 

FAQs

Does the rescission remove breach notification duties for health apps?

The 2024 Health Breach Notification Rule remains in effect and explicitly covers health apps and connected devices, so the underlying obligation stands. What has been withdrawn is the 2021 guidance interpreting how the earlier version of the rule applied to those products.

 

What is a policy statement and how does it differ from a rule?

A rule goes through formal rulemaking with public comment and carries binding legal force. A policy statement explains how an agency intends to interpret or enforce existing law, and the FTC notes that such guidance generally creates neither substantive rights nor binding obligations.

 

Which companies fall under the Health Breach Notification Rule?

Vendors of personal health records and related entities that are not covered by HIPAA, a category the 2024 revision extended to health apps, fitness trackers, and technology drawing health inferences from user data. Organizations already covered by HIPAA answer to the Breach Notification Rule instead.

 

Can a health app become a business associate?

Yes, where it creates, receives, maintains, or transmits protected health information on behalf of a covered entity. An app a patient chooses independently generally does not, while one a provider contracts with, recommends, or integrates into its own services may, which makes the arrangement worth reviewing.

 

What happens when a patient moves records into an app?

HIPAA protection does not travel with the data. Once records reach an app the patient selected, the app's own terms and whatever consumer protection law applies govern what happens next, which is why patient-facing guidance on app selection has practical value.