A 2021 policy statement that leaned on health app makers to tell users about data breaches is gone, pulled by the Federal Trade Commission as unnecessary.
The document had stretched the agency’s Health Breach Notification Rule over consumer apps and gadgets that gather health data, from fitness bands to period trackers. The Commission rewrote that rule in 2024 to name those products directly, which in its view left the standalone guidance with nothing to add. An executive order directing agencies to sweep out outdated guidance sealed the decision.
None of that loosens the rule itself, which stays on the books. The FTC said it will keep deploying both the rule and its broader consumer protection powers against companies that mishandle health data.
That distinction matters for healthcare. The rule reaches direct-to-consumer tools that sit outside HIPAA, including remote monitoring apps, wearables and symptom checkers that hospitals and digital health vendors increasingly fold into patient care. Records held by a covered entity or business associate still follow HIPAA, but a consumer app fed by the same patient often does not. Enforcement has instead come from the FTC and state attorneys general, most recently in the agency’s suit against Hims and Hers over health data sharing.
Privacy teams should confirm which patient-facing apps and devices fall outside HIPAA, and review breach clauses in vendor contracts before assuming HIPAA notification rules cover them.