Skip to main content
Leech Tishman: Legal Services
  • Why LT
    • About Us
    • Leadership
    • Life at LT
    • Careers
  • People
  • Capabilities
    • Practice Groups
      • Business Restructuring & Insolvency
        • Business Restructuring & Insolvency Overview
        • Bankruptcy Chapters 7 and 13 Debtor
        • Bankruptcy Chapter 11 Debtor
        • Bankruptcy Chapter 11 Subchapter V Debtor
        • Business Wind Down and Liquidation
        • Court Appointed Trustees and Receivers
        • Creditors’ Rights
        • Official Committee of Unsecured Creditors in Chapter 11 Bankruptcy Proceedings
        • Prosecution and Defense of Avoidance Actions in Bankruptcy
        • Real Estate-Related Insolvency
      • Construction
      • Corporate
        • Corporate Overview
        • Asset Protection
        • Business Succession
        • Capital Markets
        • Commercial Contracts
        • Construction
        • Corporate Compliance & Ethics Program
        • Corporate Governance
        • Data Privacy & Cybersecurity
        • General Counsel
        • Government Relations
        • Investment Advisory
        • Lending
        • Mergers & Acquisitions
        • Nonprofits & Tax-Exempt Organizations
        • Secured Transactions
        • Securities
        • Software Development and Licensing
        • Start-Up Services
        • Tax
        • Women/Minority-Owned Businesses
      • Healthcare
        • Healthcare Overview
        • Healthcare Litigation
        • Healthcare Regulatory Compliance
        • Healthcare Corporate Transactions
        • Healthcare Government Investigations
      • Intellectual Property
        • Intellectual Property Overview
        • Copyright Protection
        • Litigation – Copyright
        • Litigation – Patent
        • Litigation – Trademark
        • Patent Preparation and Prosecution
        • Patent Validity, Infringement and Freedom to Operate Opinions
        • Trade Secret
        • Technology Agreements and Transactions
        • Trademark Clearance, Preparation, Prosecution and Maintenance
      • Labor & Employment
        • Labor & Employment Overview
        • Discrimination, Sexual Harassment and Employment Litigation
        • Employment Policies & Prevention
        • ERISA, Employee Benefits & Executive Compensation
        • Immigration
        • Public Sector Employment
        • Restrictive Covenants / Non-Competes
        • Traditional Labor Law
        • Wage and Hour
        • Workplace Investigations
        • Workplace Privacy
        • Workplace Safety/OSHA
      • Litigation
        • Litigation Overview
        • ADA Title III Defense Litigation
        • Alternative Dispute Resolution
        • Appellate
        • Commercial Litigation
        • Construction Litigation
        • Defamation: Libel, Slander, and Commercial Disparagement
        • E-Discovery
        • Election Law
        • Family Law and Matrimonial Law
        • Government & Internal Investigations
        • Insurance Coverage
        • Trusts & Estates Litigation
        • Product Liability Defense
        • Real Estate Litigation
        • Restrictive Covenants / Non-Competes
        • Shareholder / Equity Disputes
        • White Collar Defense
      • Real Estate
        • Real Estate Overview
        • Assessments and Appeals
        • Development
        • Environmental
        • Franchise Development & Leasing
        • Landlord/Tenant Law
        • Leasing
        • New York Co-Ops and Condominiums (Closing Capabilities)
        • Oil & Gas
        • Permitting and Zoning
        • Real Estate Litigation
        • Real Estate-Related Insolvency
        • Transactional Commercial
        • Transactional Residential
        • Leech Tishman Closings
      • Tax
      • Trusts & Estates
        • Trusts & Estates Overview
        • Asset Protection
        • Basic & Complex Estate Planning
        • Charitable Planning & Giving
        • Federal Estate, Gift, and Fiduciary Taxation and Compliance
        • Florida Homestead Exemption
        • Guardianships
        • Marital Agreements
        • Private Foundations
        • Probate and Orphans’ Court Practice
        • Special Needs Planning
        • State Estate, Inheritance, and Fiduciary Taxation and Compliance
        • Tax
        • Trust & Estate Administration
        • Trusts & Estates Litigation
        • Trust Creation, Modification, and Termination
    • Industries
      • Aviation & Aerospace
      • Beauty & Wellness
      • Cannabis
      • Data Privacy & Cybersecurity
      • Energy & Natural Resources
      • Entertainment & Sports
      • Healthcare
      • Life Sciences
    • International
      • International Overview
      • Asia Practice
      • Europe Practice
      • Latin America Practice
      • Middle East Practice
  • Insights
    • Client Alerts
    • Tariff Tracker
    • Firm News
    • Press
    • Events
    • Success Stories
    • Podcasts
    • Resources
    • Videos
  • Offices
  • Careers
  • Payments
  • Contact
Leech Tishman: Legal Services
  • Careers
  • Payments
  • Contact
  • Why LT
    • About Us
    • Leadership
    • Life at LT
    • Careers
  • People
  • Capabilities
    • Practice Groups
      • Business Restructuring & Insolvency
        • Business Restructuring & Insolvency Overview
        • Bankruptcy Chapters 7 and 13 Debtor
        • Bankruptcy Chapter 11 Debtor
        • Bankruptcy Chapter 11 Subchapter V Debtor
        • Business Wind Down and Liquidation
        • Court Appointed Trustees and Receivers
        • Creditors’ Rights
        • Official Committee of Unsecured Creditors in Chapter 11 Bankruptcy Proceedings
        • Prosecution and Defense of Avoidance Actions in Bankruptcy
        • Real Estate-Related Insolvency
      • Construction
      • Corporate
        • Corporate Overview
        • Asset Protection
        • Business Succession
        • Capital Markets
        • Commercial Contracts
        • Construction
        • Corporate Compliance & Ethics Program
        • Corporate Governance
        • Data Privacy & Cybersecurity
        • General Counsel
        • Government Relations
        • Investment Advisory
        • Lending
        • Mergers & Acquisitions
        • Nonprofits & Tax-Exempt Organizations
        • Secured Transactions
        • Securities
        • Software Development and Licensing
        • Start-Up Services
        • Tax
        • Women/Minority-Owned Businesses
      • Healthcare
        • Healthcare Overview
        • Healthcare Litigation
        • Healthcare Regulatory Compliance
        • Healthcare Corporate Transactions
        • Healthcare Government Investigations
      • Intellectual Property
        • Intellectual Property Overview
        • Copyright Protection
        • Litigation – Copyright
        • Litigation – Patent
        • Litigation – Trademark
        • Patent Preparation and Prosecution
        • Patent Validity, Infringement and Freedom to Operate Opinions
        • Trade Secret
        • Technology Agreements and Transactions
        • Trademark Clearance, Preparation, Prosecution and Maintenance
      • Labor & Employment
        • Labor & Employment Overview
        • Discrimination, Sexual Harassment and Employment Litigation
        • Employment Policies & Prevention
        • ERISA, Employee Benefits & Executive Compensation
        • Immigration
        • Public Sector Employment
        • Restrictive Covenants / Non-Competes
        • Traditional Labor Law
        • Wage and Hour
        • Workplace Investigations
        • Workplace Privacy
        • Workplace Safety/OSHA
      • Litigation
        • Litigation Overview
        • ADA Title III Defense Litigation
        • Alternative Dispute Resolution
        • Appellate
        • Commercial Litigation
        • Construction Litigation
        • Defamation: Libel, Slander, and Commercial Disparagement
        • E-Discovery
        • Election Law
        • Family Law and Matrimonial Law
        • Government & Internal Investigations
        • Insurance Coverage
        • Trusts & Estates Litigation
        • Product Liability Defense
        • Real Estate Litigation
        • Restrictive Covenants / Non-Competes
        • Shareholder / Equity Disputes
        • White Collar Defense
      • Real Estate
        • Real Estate Overview
        • Assessments and Appeals
        • Development
        • Environmental
        • Franchise Development & Leasing
        • Landlord/Tenant Law
        • Leasing
        • New York Co-Ops and Condominiums (Closing Capabilities)
        • Oil & Gas
        • Permitting and Zoning
        • Real Estate Litigation
        • Real Estate-Related Insolvency
        • Transactional Commercial
        • Transactional Residential
        • Leech Tishman Closings
      • Tax
      • Trusts & Estates
        • Trusts & Estates Overview
        • Asset Protection
        • Basic & Complex Estate Planning
        • Charitable Planning & Giving
        • Federal Estate, Gift, and Fiduciary Taxation and Compliance
        • Florida Homestead Exemption
        • Guardianships
        • Marital Agreements
        • Private Foundations
        • Probate and Orphans’ Court Practice
        • Special Needs Planning
        • State Estate, Inheritance, and Fiduciary Taxation and Compliance
        • Tax
        • Trust & Estate Administration
        • Trusts & Estates Litigation
        • Trust Creation, Modification, and Termination
    • Industries
      • Aviation & Aerospace
      • Beauty & Wellness
      • Cannabis
      • Data Privacy & Cybersecurity
      • Energy & Natural Resources
      • Entertainment & Sports
      • Healthcare
      • Life Sciences
    • International
      • International Overview
      • Asia Practice
      • Europe Practice
      • Latin America Practice
      • Middle East Practice
  • Insights
    • Client Alerts
    • Tariff Tracker
    • Firm News
    • Press
    • Events
    • Success Stories
    • Podcasts
    • Resources
    • Videos
  • Offices
    • How can we help you?

Insights

News Types

  • All
  • Client Alerts
  • Tariff Tracker
  • Firm News
  • Press
  • Events
  • Success Stories
  • Executive Orders
  • Resources
  • Videos
  • 30 Years, 30 Stories

Archives

FTC Rescinds 2021 Policy Statement Interpreting Health Breach Notification Rule

September 23, 2026

By: Tara A. Davidoff, Esq. and Charles P. Kramer

Summary:

  • Development: The FTC rescinded its 2021 Policy Statement that interpreted the Health Breach Notification Rule (“HBNR” or “the Rule”) as applying to health applications and connected technologies operating outside the Health Insurance Portability and Accountability Act (“HIPAA”). The HBNR remains in effect, but the FTC no longer endorses the interpretation articulated in 2021.
  • Why it matters: The rescission signals a change in the FTC’s approach to interpreting the HBNR, particularly with respect to consumer health apps and connected technologies that fall outside of HIPAA. Organizations operating in the digital health ecosystem should continue to evaluate compliance obligations under the Rule, applicable State privacy laws, and contractual requirements.
  • Key takeaways:
    1. Federal Enforcement May Become Less Expansive. By withdrawing the 2021 Policy Statement, the FTC has stepped back from its prior position that certain advertising and analytics-related disclosures could constitute reportable breaches under the HBNR. Organizations should not assume, however, that regulatory risk has disappeared.
    2. The HBNR Remains in Effect. The FTC rescinded only the 2021 Policy Statement interpreting the Rule, not the Rule itself, expressly noting that the 2021 Policy Statement had been superseded by the FTC’s 2024 rulemaking. The HBNR continues to apply to entities within its scope.
    3. HIPAA Obligations are Unchanged. Covered entities and business associates remain subject to the HIPAA Breach Notification Rule, and the FTC’s action does not affect existing HIPAA compliance requirements.
    4. Consumer Trust Remains a Critical Issue. As CMS and other federal agencies continue to promote patient-directed access to health information through third-party applications, the rescission raises important questions about whether consumers can continue to rely on the same regulatory expectations regarding how their health information may be disclosed, shared, or monetized once it leaves the HIPAA-regulated healthcare environment.

Background

On September 9, 2026, the Federal Trade Commission (“FTC”) rescinded its 2021 Policy Statement (the “Policy Statement”) that had interpreted the scope of the FTC’s Health Breach Notification Rule, 16 C.F.R. Part 318, as applying to developers of health and wellness applications, fitness trackers, and connected devices that track vital signs, sleep, mental health, diet, exercise, and other health-related data. These were entities that were  not covered under the Health Insurance Portability and Accountability Act.

The HBNR was adopted under the 2009 Federal HITECH Act to address gaps in the federal health privacy framework by requiring certain vendors of personal health records and related entities not subject to the HIPAA breach-notification regime to notify individuals, the FTC, and in some cases, the media following specified security breaches. The Policy Statement aimed to “clarify the scope” of the HBNR for health apps and connected devices. The Policy Statement took an expansive view of which companies were covered by the HBNR. The FTC interpreted the Rule as extending beyond traditional personal health record vendors to encompass many consumer-facing health applications and connected devices that collected health information directly from users or drew information from multiple sources through Application Programming Interfaces. As a result, fitness, fertility, mental health, glucose-monitoring, and similar applications could fall within the HBNR.

The Policy Statement expressly stated that a “breach of security” was not limited to malicious cyberattacks. The FTC took the position that a breach could include the disclosure of covered health information without the individual’s authorization, even where there was no external intrusion or hacking. As a result, disclosures of covered information to analytics, advertising, or other third-party platforms without the user’s authorization could trigger breach notification obligations under the FTC’s interpretation of the Rule.

The Policy Statement, therefore, introduced a significant federal compliance risk for app developers and other non-HIPAA entities operating within the digital-health ecosystem.

What Changed and Why Does it Matter?

The rescission does not change HIPAA obligations. HIPAA-covered entities and business associates remain subject to the breach-notification requirements administered by the Department of Health and Human Services. Nor does it repeal the HBNR. However, the significance of the FTC’s action extends beyond breach notification.

The Policy Statement formed part of the regulatory backdrop against which federal interoperability and patient-access initiatives have developed. Those initiatives increasingly encourage patients to use third-party applications and digital platforms to access, aggregate,  manage, and share their health information outside traditional HIPAA-regulated environments.

CMS’s Medicare App Library illustrates the point. CMS launched its Medicare App Library in April 2026, and describes it as a “trusted, centralized directory” with “vetted digital health care options.” The Library includes mobile and web-based applications, digital health platforms, and other digital tools that allow beneficiaries to access records, manage chronic conditions, coordinate care, and share health information electronically.

For many Medicare beneficiaries, particularly older adults who may have limited visibility into the complex privacy and data-sharing practices underlying digital health technologies, inclusion in a CMS-sponsored library may reasonably create an expectation that participating applications satisfy meaningful privacy and security standards. The FTC’s 2021 interpretation reinforced that expectation by signaling that consumer health applications could face regulatory consequences not only for cybersecurity failures, but also for unauthorized disclosures of health information to third parties.

For Medicare beneficiaries who are encouraged by CMS to use third-party health applications, the practical significance of the rescission is not whether a breach notice is ultimately required. Rather, it is whether consumers can continue to rely on the same regulatory expectations regarding how their health information may be disclosed, shared, or monetized once it leaves the HIPAA-regulated healthcare environment and enters the consumer-app ecosystem.

At the same time, reports have alleged that certain applications in the CMS library shared consumer data with technology companies for advertising or analytics purposes, which is precisely the type of disclosures the FTC highlighted in its Policy Statement. The rescission therefore, has implications beyond breach notification obligations, potentially reshaping how developers, regulators, healthcare providers, and consumers evaluate privacy expectations and data-sharing practices in the expanding market for consumer-directed health applications.

As CMS and other federal agencies continue to promote interoperability and patient-directed access to health information, the FTC’s future enforcement posture towards consumer health applications, digital platforms, and other non-HIPAA actors will remain an important area to watch.

Looking Ahead

The FTC’s rescission is significant not because it eliminates the HBNR, but because it withdraws an expansive Policy Statement that helped shape privacy expectations for consumer-health applications outside the scope of HIPAA. The HBNR remains in effect, and HIPAA-covered entities and business associates remain subject to their existing breach-notification obligations. What has changed is the regulatory context surrounding consumer-directed health applications and digital platforms that increasingly serve as gateways to personal health information.

As federal agencies continue to promote interoperability, patient-directed exchange, and the use of third-party digital health tools, the question is no longer simply when a breach notice must be provided. Rather, it is whether consumers can continue to rely on the same regulatory expectations regarding how their health information may be collected, disclosed, shared, or monetized once it leaves the traditional HIPAA-regulated healthcare environment.

For healthcare providers, digital-health companies, and organizations participating in patient-access initiatives, privacy, security, consent, and downstream data-sharing practices should remain core compliance priorities. The FTC’s future enforcement posture toward consumer health applications and other non-HIPAA actors may play an important role in defining the boundaries of consumer trust in the next phase of healthcare interoperability.


Leech Tishman has extensive experience advising healthcare and digital health clients on data privacy, security, and regulatory compliance. Our team is prepared to help clients evaluate how the Health Breach Notification Rule, state privacy laws, and related requirements may apply to consumer health apps, patient-access tools, and downstream data-sharing practices outside the traditional HIPAA framework. For assistance or additional information, please contact Tara A. Davidoff at tdavidoff@leechtishman.com, Partner in Leech Tishman’s Healthcare Practice Group.

Share on:
  • Facebook
  • Twitter
  • LinkedIn
  • Careers
  • Insights
  • Payments
  • People
  • Contact
  • Chicago, IL
  • Los Angeles, CA
  • Miami/FLL, FL
  • New York, NY
  • Philadelphia, PA
  • Pittsburgh, PA
  • Sarasota, FL
  • State College, PA
  • Washington, D.C.

Sign up for our Client Alerts

Newsletter Signup
  • LinkedIn
  • Twitter
  • Facebook

Copyright © 2026 Leech Tishman: Legal Services All rights reserved.

  • Terms and Conditions
  • Privacy Policy
  • Personnel Privacy Policy
We use cookies to provide and improve your experience on our website. By clicking Accept you are agreeing to the use of these cookies. However, you do have the option to select Deny but your digital experience may be negatively impacted.