Digital Health Privacy & Consumer Protection
FTC retires old health-app guidance; the breach rule still covers trackers
The FTC withdrew a 2021 policy statement after its 2024 rule update. The move does not erase breach-notice duties for covered health apps and fitness trackers.
The FTC withdrew a policy statement—not the breach-notification rule
The Federal Trade Commission rescinded its 2021 policy statement on health apps and connected devices Wednesday. The agency said the statement became unnecessary after amendments adopted in 2024 expressly addressed health apps, fitness trackers and similar technology. That distinction is the news: a guidance document is gone, but the underlying Health Breach Notification Rule remains in force. The announcement did not identify a new breach, weaken a specific consumer notice or declare that fitness data is now outside federal protection.
The 2024 amendments have been effective since July 29, 2024
The amended rule, 16 CFR Part 318, applies to covered vendors of personal health records, related entities and service providers that are not governed by the HIPAA breach-notification framework for the same information. FTC guidance says a health app that collects information from a user and can sync with a fitness tracker is probably a vendor of personal health records because its record can draw from more than one source. The Federal Register notice set July 29, 2024 as the effective date. Wednesday's action leaves that text and date unchanged.
Coverage turns on the product and data flow—not the word “wellness”
Not every step counter, workout site or digital service automatically falls within the rule. Coverage depends on definitions in the regulation, including whether the service offers or maintains an electronic personal health record with identifiable health information and the technical capacity to draw from multiple sources. A company's marketing label does not settle the issue. “Wellness,” “fitness” and “lifestyle” products can still handle information about conditions, medications, precise routines or app use, while a particular product may fall outside this rule or inside a different federal or state framework.
A breach can be an unauthorized disclosure, not only a hack
FTC compliance guidance says the trigger is unauthorized acquisition of unsecured, identifiable health information covered by the rule. A stolen database or employee laptop may qualify, but the agency also says a breach is not limited to a cyberattack: sending covered health information to another company without the user's authorization can trigger the notification analysis. That is why a notice should be read for what actually happened, which data moved and who received it—not judged only by whether the company uses the word “hacker.”
Covered companies generally must notify people without unreasonable delay
A covered vendor or related entity must notify each affected U.S. citizen or resident without unreasonable delay and no later than 60 calendar days after discovering the breach. The notice must explain what happened, the dates known, the types of information involved, third parties that acquired the information when disclosure is safe, steps people can take and how to contact the notifying company. The FTC must also receive notice. When at least 500 residents of one state, the District of Columbia or a U.S. territory are affected, the rule also calls for notice to prominent media serving that area. Exact duties can depend on the facts and entity, so this is a reading guide rather than legal advice.
HIPAA does not follow every health data point into every consumer app
HHS says HIPAA generally applies to covered health plans, healthcare clearinghouses, certain healthcare providers and their business associates. When a person directs health information into an independent app that is neither a covered entity nor a business associate, HIPAA protections may no longer govern the app's later use or disclosure. Other law may still apply, including the FTC Act, the Health Breach Notification Rule and state privacy or breach-notice laws. A badge, app-store category or link to a clinic does not by itself answer which framework covers a particular data flow.
California residents have additional places to check and report
The California Attorney General publishes sample breach notices submitted when more than 500 California residents receive notice under state law. The list can help confirm the notifying organization and read the sample, but absence from the list does not prove that no incident occurred or that no other rule applies. California residents can also use rights available under the CCPA for covered businesses, including requests to know, delete or correct information and to limit certain uses of sensitive personal information. The California Privacy Protection Agency accepts complaints about possible CCPA violations; it does not act as an individual's attorney or guarantee an investigation.
Treat a notice as an incident-specific checklist
Open the company's known website or app directly instead of signing in through an unexpected email link. Save the notice, write down the dates and identify whether it names passwords, Social Security numbers, financial accounts, location, diagnoses, medications or app-use history. Change an exposed or reused password from a trusted device and enable multi-factor authentication where available. If Social Security or financial information was involved, review the FTC's IdentityTheft.gov steps and consider a free credit freeze; a freeze does not stop misuse of an existing account, so keep checking statements. Review connected apps and permissions, but preserve records before deleting an account if you may need them for a complaint. The September 9 policy change does not create a reason to panic or ignore a real notice—it is a reason to read the current rule and the incident facts separately.
Sources
- Federal Trade Commission: withdrawal of the 2021 health-app policy statement (September 9, 2026) ↗
- Federal Trade Commission: Health Breach Notification Rule overview and current rule links ↗
- Federal Trade Commission: compliance guide for health apps, connected devices and breach notices ↗
- Federal Register: 2024 final Health Breach Notification Rule and July 29 effective date ↗
- U.S. Department of Health and Human Services: health apps, APIs and the limits of HIPAA coverage ↗
- California Privacy Protection Agency: CCPA rights, request methods and complaint guidance ↗
- California Attorney General: searchable list of submitted data-breach notices ↗
- Federal Trade Commission: identity-theft recovery, credit freezes and account protection ↗
Find men's massage near you
Compare local providers privately and contact the professional you choose directly.
Search NOCTI