Summary:
- Development: The FTC rescinded its 2021 Policy Statement that interpreted the Health Breach Notification Rule (“HBNR” or “the Rule”) as applying to health applications and connected technologies operating outside the Health Insurance Portability and Accountability Act (“HIPAA”). The HBNR remains in effect, but the FTC no longer endorses the interpretation articulated in 2021.
- Why it matters: The rescission signals a change in the FTC’s approach to interpreting the HBNR, particularly with respect to consumer health apps and connected technologies that fall outside of HIPAA. Organizations operating in the digital health ecosystem should continue to evaluate compliance obligations under the Rule, applicable State privacy laws, and contractual requirements.
- Key takeaways:
- Federal Enforcement May Become Less Expansive. By withdrawing the 2021 Policy Statement, the FTC has stepped back from its prior position that certain advertising and analytics-related disclosures could constitute reportable breaches under the HBNR. Organizations should not assume, however, that regulatory risk has disappeared.
- The HBNR Remains in Effect. The FTC rescinded only the 2021 Policy Statement interpreting the Rule, not the Rule itself, expressly noting that the 2021 Policy Statement had been superseded by the FTC’s 2024 rulemaking. The HBNR continues to apply to entities within its scope.
- HIPAA Obligations are Unchanged. Covered entities and business associates remain subject to the HIPAA Breach Notification Rule, and the FTC’s action does not affect existing HIPAA compliance requirements.
- Consumer Trust Remains a Critical Issue. As CMS and other federal agencies continue to promote patient-directed access to health information through third-party applications, the rescission raises important questions about whether consumers can continue to rely on the same regulatory expectations regarding how their health information may be disclosed, shared, or monetized once it leaves the HIPAA-regulated healthcare environment.
Background
On September 9, 2026, the Federal Trade Commission (“FTC”) rescinded its 2021 Policy Statement (the “Policy Statement”) that had interpreted the scope of the FTC’s Health Breach Notification Rule, 16 C.F.R. Part 318, as applying to developers of health and wellness applications, fitness trackers, and connected devices that track vital signs, sleep, mental health, diet, exercise, and other health-related data. These were entities that were not covered under the Health Insurance Portability and Accountability Act.
The HBNR was adopted under the 2009 Federal HITECH Act to address gaps in the federal health privacy framework by requiring certain vendors of personal health records and related entities not subject to the HIPAA breach-notification regime to notify individuals, the FTC, and in some cases, the media following specified security breaches. The Policy Statement aimed to “clarify the scope” of the HBNR for health apps and connected devices. The Policy Statement took an expansive view of which companies were covered by the HBNR. The FTC interpreted the Rule as extending beyond traditional personal health record vendors to encompass many consumer-facing health applications and connected devices that collected health information directly from users or drew information from multiple sources through Application Programming Interfaces. As a result, fitness, fertility, mental health, glucose-monitoring, and similar applications could fall within the HBNR.
The Policy Statement expressly stated that a “breach of security” was not limited to malicious cyberattacks. The FTC took the position that a breach could include the disclosure of covered health information without the individual’s authorization, even where there was no external intrusion or hacking. As a result, disclosures of covered information to analytics, advertising, or other third-party platforms without the user’s authorization could trigger breach notification obligations under the FTC’s interpretation of the Rule.
The Policy Statement, therefore, introduced a significant federal compliance risk for app developers and other non-HIPAA entities operating within the digital-health ecosystem.
What Changed and Why Does it Matter?
The rescission does not change HIPAA obligations. HIPAA-covered entities and business associates remain subject to the breach-notification requirements administered by the Department of Health and Human Services. Nor does it repeal the HBNR. However, the significance of the FTC’s action extends beyond breach notification.
The Policy Statement formed part of the regulatory backdrop against which federal interoperability and patient-access initiatives have developed. Those initiatives increasingly encourage patients to use third-party applications and digital platforms to access, aggregate, manage, and share their health information outside traditional HIPAA-regulated environments.
CMS’s Medicare App Library illustrates the point. CMS launched its Medicare App Library in April 2026, and describes it as a “trusted, centralized directory” with “vetted digital health care options.” The Library includes mobile and web-based applications, digital health platforms, and other digital tools that allow beneficiaries to access records, manage chronic conditions, coordinate care, and share health information electronically.
For many Medicare beneficiaries, particularly older adults who may have limited visibility into the complex privacy and data-sharing practices underlying digital health technologies, inclusion in a CMS-sponsored library may reasonably create an expectation that participating applications satisfy meaningful privacy and security standards. The FTC’s 2021 interpretation reinforced that expectation by signaling that consumer health applications could face regulatory consequences not only for cybersecurity failures, but also for unauthorized disclosures of health information to third parties.
For Medicare beneficiaries who are encouraged by CMS to use third-party health applications, the practical significance of the rescission is not whether a breach notice is ultimately required. Rather, it is whether consumers can continue to rely on the same regulatory expectations regarding how their health information may be disclosed, shared, or monetized once it leaves the HIPAA-regulated healthcare environment and enters the consumer-app ecosystem.
At the same time, reports have alleged that certain applications in the CMS library shared consumer data with technology companies for advertising or analytics purposes, which is precisely the type of disclosures the FTC highlighted in its Policy Statement. The rescission therefore, has implications beyond breach notification obligations, potentially reshaping how developers, regulators, healthcare providers, and consumers evaluate privacy expectations and data-sharing practices in the expanding market for consumer-directed health applications.
As CMS and other federal agencies continue to promote interoperability and patient-directed access to health information, the FTC’s future enforcement posture towards consumer health applications, digital platforms, and other non-HIPAA actors will remain an important area to watch.
Looking Ahead
The FTC’s rescission is significant not because it eliminates the HBNR, but because it withdraws an expansive Policy Statement that helped shape privacy expectations for consumer-health applications outside the scope of HIPAA. The HBNR remains in effect, and HIPAA-covered entities and business associates remain subject to their existing breach-notification obligations. What has changed is the regulatory context surrounding consumer-directed health applications and digital platforms that increasingly serve as gateways to personal health information.
As federal agencies continue to promote interoperability, patient-directed exchange, and the use of third-party digital health tools, the question is no longer simply when a breach notice must be provided. Rather, it is whether consumers can continue to rely on the same regulatory expectations regarding how their health information may be collected, disclosed, shared, or monetized once it leaves the traditional HIPAA-regulated healthcare environment.
For healthcare providers, digital-health companies, and organizations participating in patient-access initiatives, privacy, security, consent, and downstream data-sharing practices should remain core compliance priorities. The FTC’s future enforcement posture toward consumer health applications and other non-HIPAA actors may play an important role in defining the boundaries of consumer trust in the next phase of healthcare interoperability.
Leech Tishman has extensive experience advising healthcare and digital health clients on data privacy, security, and regulatory compliance. Our team is prepared to help clients evaluate how the Health Breach Notification Rule, state privacy laws, and related requirements may apply to consumer health apps, patient-access tools, and downstream data-sharing practices outside the traditional HIPAA framework. For assistance or additional information, please contact Tara A. Davidoff at tdavidoff@leechtishman.com, Partner in Leech Tishman’s Healthcare Practice Group.