On September 9, 2026, the Federal Trade Commission (“FTC”) rescinded its 2021 policy statement which extended the Health Breach Notification Rule (“HBNR”) to health apps and connected devices outside the reach of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively “HIPAA”).

In its recent press release, the FTC called that prior guidance “obsolete” and “unnecessary,” concluding it provided minimal benefit and had been superseded by rulemaking. This is not a minor course correction at a moment when the Centers for Medicare and Medicaid Services (“CMS”) is actively steering seniors toward health apps that require collection and processing of identifiable consumer health information outside the reach of HIPAA.

Then: Original 2021 Policy

As we previously discussed here, the FTC interpreted the HBNR — a 2009 statute previously understood as a narrow backstop — to reach nearly the entire consumer health app and wearables market. Three key features of that interpretation are now rescinded:

  1. App developers considered “health care providers.” The FTC treated developers of health apps and connected devices as “health care providers” under the HBNR because they furnish health-related services, pulling companies with no HIPAA nexus into a breach-notification regime built for personal health record vendors.
  2. A broad, aggregation-based trigger for coverage. An app was covered even if it drew health data from just one source but pulled in non-health data (like calendar entries) from another via API — meaning ordinary fitness and wellness apps rarely escaped the HBNR’s reach.
  3. “Breach” extended beyond cybersecurity incidents. Notification obligations were triggered by cybersecurity breaches and further extended to unauthorized sharing of covered information without a user’s authorization — exposing companies with permissive data-sharing practices (including ad-tech integrations) to the same notice requirements and potential penalties.

Notably, this interpretation was contested even at the time of its issuance, with Commissioners Christine Wilson and Noah Phillips dissenting that the interpretation stretched the statutory text beyond its terms. Andrew Ferguson, then a minority commissioner, took the same position when the FTC doubled down on this approach in 2024, warning it exposed companies to “perpetual noncompliance.” These dissenting views are now the FTC’s official position.

Now:  What Changes with the New 2026 FTC Position

With the rescission, none of the three features of the 2021 interpretation carry active FTC endorsement. Health app developers outside of HIPAA’s reach are no longer treated as “health care providers” for breach-notification purposes, the aggregation theory pulling ordinary wellness apps into scope is gone, and unauthorized data-sharing alone no longer triggers HBNR notice obligations. The FTC’s core Section 5 authority over unfair or deceptive practices is untouched — but the specific, expansive breach-notification duty impacting health app companies no longer applies.

Why the Timing Compounds the Impact to Consumer Privacy

CMS launched its Medicare App Library in April 2026 partly on the privacy protections afforded by the 2021 interpretation.  CMS officials leading the Medicare App Library efforts cited the now-rescinded privacy protections as a pillar of the vetting process assuring seniors that promoted apps were trustworthy.  Further, CMS’s associated press release states “CMS plans to add an app library to Medicare.gov to highlight trusted, personalized digital health tools focused on prevention, chronic disease management, and cost-effective care navigation.” Yet, recent reporting has already flagged some CMS-listed apps as sharing consumer data with big tech companies for advertising purposes, which is precisely the type of conduct the 2021 interpretation was designed to police as “unauthorized sharing” in the absence of adequate consumer notice.

Practical Takeaways

Companies developing or leveraging health apps that created compliance programs around the 2021 interpretation should reassess their go-forward HBNR obligations.  However, it is critical to note that despite the FTC’s shift in course, health apps that fall beyond the reach of HIPAA are increasingly governed by state comprehensive and/or health-specific privacy laws.  For example, see our previous treatment on Washington’s My Health My Data Act, a state law that may impose privacy obligations on health app developers and users beyond HIPAA.

We will continue to monitor developments and provide updates on state and federal privacy legislative, regulatory and enforcement actions as they emerge.

* * * *

If you have questions, please reach out to the author(s).

The Health Law Advisor blog is currently edited by Emily Chi Fogler.

Back to Health Law Advisor Blog

Search This Blog

Authors

Related Services

Topics

Archives

Jump to Page

Subscribe

Sign up to receive an email notification when new Health Law Advisor posts are published:

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.