What happened

The Federal Trade Commission has rescinded its 2021 policy statement that treated health and fitness apps as covered entities under federal data breach notification rules. In a half-page statement posted on Wednesday, the commission said the policy "provided minimal benefit and has been superseded by rulemaking," and that withdrawing it aligns with White House guidance to pursue a deregulatory agenda and avoid "unnecessary use of subregulatory guidance." It added that each of its reasons was independently sufficient, and that guidance "generally creates neither substantive rights nor binding obligations."

The original policy passed on a divided 3 to 2 vote under then-chair Lina Khan. It brought health apps, fitness trackers and other connected devices under a rule covering "vendors of personal health records that contain individually identifiable health information created or received by health care providers." The rule triggers automatic notification when a covered entity suffers a breach of security, which includes the disclosure of sensitive health information to third parties without authorization. That would have put apps on the hook for selling customer data to data brokers. When the FTC adopted the interpretation in 2021 it cited digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act and gaps in HIPAA, and said it would enforce the rule with daily fines of $43,792 per violation.

This week's vote to rescind was unanimous, though CyberScoop notes the commission's makeup has changed since the Democratic commissioners who backed the original policy were replaced.

Why this is a GRC story

The first lesson is about the shelf life of guidance. A policy statement can be issued by one commission and reversed by the next with a memo of a few paragraphs. Compliance programs built on subregulatory guidance are only as durable as the current politics. Programs should track statutes and formal rules, and treat agency statements as an input, not the foundation.

The second lesson is that the underlying risk did not change on Wednesday. Health data in consumer apps remains sensitive, remains largely outside HIPAA's protections, and remains attractive to data brokers and attackers. Removing the FTC's notification interpretation does not remove breach impact. State breach notification laws, contract duties and customer expectations still apply, and the commission has continued to police health privacy through individual enforcement actions.

For privacy teams the practical takeaway is to keep health data controls where they are, document the reasoning, and keep breach response ready regardless of which regulator is watching. A rescinded policy statement is not a license to downgrade data protection.

What to watch

Watch what the FTC means by "superseded by rulemaking." If the commission intends to replace the policy statement with a formal rule, that process would be harder to reverse and would give companies a clearer target. Also watch the states, which have been active on health privacy, and the gap that experts already flag for AI companies building healthcare models that handle patient records without clear regulatory coverage.

Attribution: Analysis based on CyberScoop and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News