$ techbeacon▋
Breaches

FTC Rolls Back Health‑App Breach‑Notice Rule, Leaving Data Notification to State Laws

FTC Rolls Back Health‑App Breach‑Notice Rule, Leaving Data Notification to State Laws

The Federal Trade Commission announced Wednesday that it is withdrawing a policy statement issued during the Biden administration that extended federal data‑breach notification requirements to health and fitness mobile applications. The reversal means that, for the time being, those apps are no longer obligated under the FTC's guidance to inform users when personal health information is exposed in a cyber incident.

The rescinded guidance, released last year, interpreted the FTC's existing authority over consumer data to cover a rapidly expanding market of wellness apps that collect sensitive health metrics, location data, and biometric information. By treating these services as “covered entities” under the broader federal breach‑notification framework, the agency had sought to close a regulatory gap that many privacy advocates said left consumers vulnerable.

With the policy now withdrawn, the responsibility for notifying users of a breach will revert primarily to state‑level statutes and any sector‑specific rules that may apply, such as the Health Insurance Portability and Accountability Act (HIPAA) for covered medical entities. Most consumer‑focused health apps, however, fall outside HIPAA’s scope, and many states lack robust breach‑notification provisions for digital health data, potentially creating a patchwork of protections.

The FTC explained in a brief half‑page statement that it “has determined that the statement … is no longer the appropriate mechanism for addressing data‑security concerns in the health‑app ecosystem.” While the agency did not elaborate on the legal reasoning, officials cited ongoing discussions about the proper balance between federal oversight and industry self‑regulation, as well as the need to avoid duplicative or conflicting requirements.

Privacy groups welcomed the original policy but expressed disappointment at its reversal, warning that consumers could face longer exposure periods before learning that their health information was compromised. Industry representatives, on the other hand, praised the move as a clarification that the FTC’s mandate does not extend to every app that handles health‑related data, arguing that overly broad rules could stifle innovation in the fast‑growing digital wellness sector.

Legal scholars note that the decision may prompt Congress or state legislatures to revisit the issue, potentially crafting more targeted legislation that addresses the unique risks of health‑app data without imposing a one‑size‑fits‑all federal standard. In the interim, experts advise users to monitor app privacy policies, enable two‑factor authentication where available, and stay alert for any communications from app providers regarding security incidents.

Source: CyberScoop
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related