Legaltechmonitor iconLegaltechmonitorSep 10, 2026 ~2 min source read

FTC Rescinds Expanded Health Breach Guidance for Apps and Connected Devices

The agency withdrew a Biden-era policy that broadened what counts as a reportable health-data breach for certain consumer health apps and connected-device providers, prompting compliance teams to revisit incident-response plans and legal strategies.

FTC Pulls Back Health Breach Notification Policy for Apps and Connected Devices

Share this story

Send the public story page.

Useful takeaways from this story.

The FTC rescinded a policy that had expanded the Health Breach Notification Rule to cover certain disclosures to analytics or advertising platforms.

Companies outside HIPAA still face enforcement risk under the FTC Act, state consumer-protection laws, and state privacy or health-data statutes.

Compliance teams should update breach definitions, notification decision trees, vendor management, and public disclosures that were built around the rescinded interpretation.

The useful part

At issue is the FTC's approach to the Health Breach Notification Rule, which applies to certain vendors of personal health records and related entities not covered by HIPAA. Under the prior policy, the agency took a broader view of what counted as a reportable "breach," including some unauthorized disclosures of health information to third parties such as analytics or advertising platforms. Companies handling sensitive consumer information still face exposure under the FTC Act, state consumer-protection laws, and a growing patchwork of state privacy and health-data statutes.

How it works

  • The rescission matters because policy statements often shape how companies assess risk, structure incident-response plans, and decide whether a particular disclosure event triggers user notification...
  • Businesses in the health-app and smart-device ecosystem should reassess internal definitions of "breach," notification decision trees, vendor-management practices, and disclosures regarding data sharing.
  • This is especially important for companies that sit outside HIPAA but still collect highly sensitive wellness, fertility, biometric, or symptom-related data.
  • For litigators, the development may affect how parties frame unfairness and deception claims in investigations and civil suits involving consumer health data.
  • For legal teams, this is the kind of change that warrants a fresh review of incident-response playbooks, consumer-facing disclosures, and regulator-facing strategy before the next data event puts those...

What to take from it

For in-house counsel and compliance teams, the immediate takeaway is practical: revisit breach-response protocols that were built around the rescinded FTC interpretation. A withdrawn policy can weaken arguments that a company ignored clearly articulated federal expectations, even if it does not eliminate broader statutory or common-law theories.

Details worth keeping

The move is part of a broader agency push toward regulatory streamlining, but it also sends a clear signal to the digital-health market: the FTC may be narrowing how aggressively it interprets and enforces health-data breach obligations outside traditional healthcare settings. That does not mean health-data enforcement is disappearing. Defense counsel will likely point to the rescission in arguing that prior FTC interpretations were too expansive, while plaintiffs and regulators may pivot toward privacy representations, consent practices, or state-law duties instead.

Related coverage

  • Legaltechdaily: Biden-era policy statement that had expanded expectations around breach notifications for certain health apps and connected-device providers.
  • Foxnews: Security numbers, banking information and medical records belonging to more than 3.75 million people.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app