Skip to content

FTC Health Breach Notification Rule: 2021 app policy withdrawn

Filip LuchianencoUpdated 3 min read

Last updated: 2026-10-03

On September 9, 2026, the Federal Trade Commission rescinded its "Statement of the Commission On Breaches by Health Apps and Other Connected Devices" of September 15, 2021, which "purported to apply" the FTC Health Breach Notification Rule (16 CFR Part 318) to health apps. The Commission states the 2024 amendments to the rule, in force since July 29, 2024, superseded the statement.

What did the FTC rescind on September 9, 2026?

From the Commission statement:

Protecting the privacy of Americans' sensitive health information remains a top priority of the Commission. However, the Commission has determined that the statement—contentious at the time of issuance—provided minimal benefit and has been superseded by rulemaking.

Its footnotes cite the 2021 dissents of Commissioners Phillips and Wilson (for "contentious"), three deregulation executive orders and the FTC's July 29, 2026 action against Hims & Hers. The statement and the FTC release give no vote; CyberScoop reported that the Commission "voted unanimously", without a count.

Does the FTC Health Breach Notification Rule still cover health apps?

Yes. The FTC release states that in 2024 the Commission updated the rule "to cover health apps and connected devices like fitness trackers".

Point 2021 policy statement (rescinded) 16 CFR 318.2 as amended in 2024 (in force)
Apps as health care providers "the developer of a health app or connected device is a 'health care provider'" "Health care services or supplies" covers "any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track [...] fitness, fertility, [...] mental health"
Multiple sources covered "if they are capable of drawing information from multiple sources" a personal health record "has the technical capacity to draw information from multiple sources"
Sharing as a breach "sharing of covered information without an individual's authorization, triggers notification obligations" "A breach of security includes an unauthorized acquisition [...] that occurs as a result of a data breach or an unauthorized disclosure."

Sources: 2021 statement, 16 CFR 318.2.

A breach requires notice to affected individuals, and to prominent media in any state with 500 or more affected residents, "without unreasonable delay and in no case later than 60 calendar days after the discovery". For 500 or more affected people, the FTC gets notice contemporaneously with the individuals; smaller breaches may be reported annually, within 60 days after year end. Notice to individuals describes the information involved, such as "the individual's use of a health-related mobile application, or device identifier (in combination with another data element)".

Violations carry civil penalties (16 CFR 318.7) of up to $53,088 per violation, an amount the FTC left unchanged for 2026. The rule excludes HIPAA-covered entities and entities to the extent they act as their business associates; whether an app is a "vendor of personal health records" turns on the 318.2 definitions and the app's facts.

Has the FTC enforced the Health Breach Notification Rule against apps?

Twice, in 2023. In its first action under the rule, the FTC alleged that GoodRx made unauthorized disclosures of health information to Facebook, Google and other companies; GoodRx agreed to a $1.5 million civil penalty. The FTC then alleged Easy Healthcare, developer of the Premom ovulation tracking app, disclosed users' health data to AppsFlyer and Google; the proposed order included a $100,000 civil penalty. The 2024 joint statement of Chair Khan and Commissioners Slaughter and Bedoya describes Premom sharing information "through software development kits ('SDKs') embedded in the application".

The FTC's cases database, filtered to the Health Privacy topic on October 3, 2026, lists GoodRx and Easy Healthcare as the actions under the rule, and Hims & Hers as the one case filed after July 29, 2024. Cases tagged only under other topics are outside that filter. The Hims & Hers complaint pleads FTC Act, ROSCA and Utah and California state-law counts; "breach notification" appears nowhere in it.

Is the rule itself under review?

The 2024 amendments were adopted "Commissioners Holyoak and Ferguson dissenting". Holyoak's dissent, joined by Ferguson, now FTC Chairman, states the rule "exceeds the Commission's statutory authority, puts companies at risk of perpetual non-compliance, and opens the Commission to legal challenge".

On September 15, 2026, the FTC published notice of a petition for rulemaking from a private individual, docket FTC-2026-1321. The petition asks the FTC to repeal 318.2 (definitions) and 318.4 to 318.9, including notice timing, method and content (318.4 to 318.6), and to keep only amended versions of 318.1 and 318.3. Comments close on October 15, 2026; the Commission "will not consider the petition's merits until after the comment period closes."

What a CITT scan shows for a health or fitness app

My static scan of a health app lists the ad, analytics and attribution SDKs in the binary; only a traffic capture shows what was sent. While a tester logs a cycle, symptom, medication or workout, the capture records which host received which event name and parameters, with which device and advertising identifiers, and whether each request came before or after consent (what a scan checks, the limits of a scan). A capture covers one build on one day. Whether the app is a vendor of personal health records and whether a disclosure was authorized are legal questions outside a capture.

Related: the Rodriguez v. Google verdict concerned app activity data collected through Google SDKs.

I run these investigations for lawyers and researchers working with lawyers, one app or many. Sign up for a CanITrustThat (CITT) account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.