← All guides

Digital Health Privacy & Consumer Protection

FTC retires old health-app guidance; the breach rule still covers trackers

The FTC withdrew a 2021 policy statement after its 2024 rule update. The move does not erase breach-notice duties for covered health apps and fitness trackers.

Man reviewing privacy settings on his phone while wearing a generic fitness tracker at a Southern California cafe patio

The FTC withdrew a policy statement—not the breach-notification rule

The Federal Trade Commission rescinded its 2021 policy statement on health apps and connected devices Wednesday. The agency said the statement became unnecessary after amendments adopted in 2024 expressly addressed health apps, fitness trackers and similar technology. That distinction is the news: a guidance document is gone, but the underlying Health Breach Notification Rule remains in force. The announcement did not identify a new breach, weaken a specific consumer notice or declare that fitness data is now outside federal protection.

The 2024 amendments have been effective since July 29, 2024

The amended rule, 16 CFR Part 318, applies to covered vendors of personal health records, related entities and service providers that are not governed by the HIPAA breach-notification framework for the same information. FTC guidance says a health app that collects information from a user and can sync with a fitness tracker is probably a vendor of personal health records because its record can draw from more than one source. The Federal Register notice set July 29, 2024 as the effective date. Wednesday's action leaves that text and date unchanged.

Coverage turns on the product and data flow—not the word “wellness”

Not every step counter, workout site or digital service automatically falls within the rule. Coverage depends on definitions in the regulation, including whether the service offers or maintains an electronic personal health record with identifiable health information and the technical capacity to draw from multiple sources. A company's marketing label does not settle the issue. “Wellness,” “fitness” and “lifestyle” products can still handle information about conditions, medications, precise routines or app use, while a particular product may fall outside this rule or inside a different federal or state framework.

A breach can be an unauthorized disclosure, not only a hack

FTC compliance guidance says the trigger is unauthorized acquisition of unsecured, identifiable health information covered by the rule. A stolen database or employee laptop may qualify, but the agency also says a breach is not limited to a cyberattack: sending covered health information to another company without the user's authorization can trigger the notification analysis. That is why a notice should be read for what actually happened, which data moved and who received it—not judged only by whether the company uses the word “hacker.”

Covered companies generally must notify people without unreasonable delay

A covered vendor or related entity must notify each affected U.S. citizen or resident without unreasonable delay and no later than 60 calendar days after discovering the breach. The notice must explain what happened, the dates known, the types of information involved, third parties that acquired the information when disclosure is safe, steps people can take and how to contact the notifying company. The FTC must also receive notice. When at least 500 residents of one state, the District of Columbia or a U.S. territory are affected, the rule also calls for notice to prominent media serving that area. Exact duties can depend on the facts and entity, so this is a reading guide rather than legal advice.

HIPAA does not follow every health data point into every consumer app

HHS says HIPAA generally applies to covered health plans, healthcare clearinghouses, certain healthcare providers and their business associates. When a person directs health information into an independent app that is neither a covered entity nor a business associate, HIPAA protections may no longer govern the app's later use or disclosure. Other law may still apply, including the FTC Act, the Health Breach Notification Rule and state privacy or breach-notice laws. A badge, app-store category or link to a clinic does not by itself answer which framework covers a particular data flow.

California residents have additional places to check and report

The California Attorney General publishes sample breach notices submitted when more than 500 California residents receive notice under state law. The list can help confirm the notifying organization and read the sample, but absence from the list does not prove that no incident occurred or that no other rule applies. California residents can also use rights available under the CCPA for covered businesses, including requests to know, delete or correct information and to limit certain uses of sensitive personal information. The California Privacy Protection Agency accepts complaints about possible CCPA violations; it does not act as an individual's attorney or guarantee an investigation.

Treat a notice as an incident-specific checklist

Open the company's known website or app directly instead of signing in through an unexpected email link. Save the notice, write down the dates and identify whether it names passwords, Social Security numbers, financial accounts, location, diagnoses, medications or app-use history. Change an exposed or reused password from a trusted device and enable multi-factor authentication where available. If Social Security or financial information was involved, review the FTC's IdentityTheft.gov steps and consider a free credit freeze; a freeze does not stop misuse of an existing account, so keep checking statements. Review connected apps and permissions, but preserve records before deleting an account if you may need them for a complaint. The September 9 policy change does not create a reason to panic or ignore a real notice—it is a reason to read the current rule and the incident facts separately.

Sources

Find men's massage near you

Compare local providers privately and contact the professional you choose directly.

Search NOCTI