
FTC: Rescinds 2021 Health App Policy, Withdraws Data Breach Guidance
Summary
- The Federal Trade Commission has officially rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices.
- The Commission deemed the specific guidance document unnecessary, leading to its formal withdrawal.
- This policy statement previously clarified how the Health Breach Notification Rule applied to certain health apps and connected devices not covered by HIPAA.
- Companies in the digital health sector must now align their data breach response strategies with broader, active regulations, rather than the rescinded guidance.
What Happened
Instead, organizations must now ensure their strategies for handling data breaches involving connected health devices align with the broader, active regulatory landscape and the FTC's general enforcement priorities.
The Federal Trade Commission (FTC) recently took formal action to rescind its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This move effectively withdraws specific guidance that had previously outlined the agency's interpretation regarding data security incidents involving consumer health applications and internet-connected health devices. The Commission characterized the now-removed document as "unnecessary," indicating a shift in its approach to communicating regulatory expectations in this evolving sector.
The decision to remove this particular guidance, which was issued in 2021, means that the specific clarifications it provided are no longer active. This action by the FTC to rescind the health app policy 2021 statement reflects a deliberate effort by the agency to streamline its publicly available policy documents, ensuring that only current and relevant guidance remains in effect for stakeholders. The official withdrawal of this obsolete FTC policy statement removal signals a clear directive from the Commission regarding its regulatory framework.
Background on the Rescinded Guidance
The 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices was originally introduced to provide clarity on the applicability of the Health Breach Notification Rule (HBNR) to a growing category of digital health tools. The HBNR mandates that vendors of personal health records and related entities notify individuals, the FTC, and in some cases, the media, following a breach of unsecured identifiable health information. Crucially, this rule applies to entities not covered by the Health Insurance Portability and Accountability Act (HIPAA), thereby extending data breach notification requirements to a broader array of health technology providers.
Prior to its rescission, the Federal Trade Commission 2021 health app guidance specifically aimed to address the unique challenges posed by health apps and connected devices, which often collect sensitive health data but fall outside HIPAA's direct purview. The policy statement sought to ensure that consumers using these technologies received timely notification in the event of a data breach, irrespective of whether the app or device was operated by a HIPAA-covered entity. Its withdrawal does not eliminate the underlying HBNR itself, nor does it diminish the FTC's broader authority to protect consumer data privacy and security.
Why This Matters for Compliance
The FTC's decision to withdraw its health app data breach policy has significant implications for companies operating in the digital health space. While the underlying Health Breach Notification Rule remains in effect, having been amended and updated, the specific interpretive lens provided by the 2021 document is no longer available.
Instead, organizations must now ensure their strategies for handling data breaches involving connected health devices align with the broader, active regulatory landscape and the FTC's general enforcement priorities. The removal of this specific guidance underscores the need for a robust and proactive approach to data privacy and security, emphasizing that compliance should be based on current statutes and established precedents rather than withdrawn interpretive statements. Companies must remain vigilant in monitoring the evolving regulatory environment to safeguard sensitive consumer health information effectively.
Practical Implications
This action removes specific FTC guidance on health app breaches, requiring legal and compliance teams to ensure their data security and breach response strategies for connected health devices align with current, active regulations and enforcement priorities, rather than relying on the rescinded 2021 statement.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
