On September 9, 2026, the Federal Trade Commission (“FTC”) rescinded its 2021 policy statement which extended the Health Breach Notification Rule (“HBNR”) to health apps and connected devices outside the reach of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively “HIPAA”).
In its recent press release, the FTC called that prior guidance “obsolete” and “unnecessary,” concluding it provided minimal benefit and had been superseded by rulemaking. This is not a minor course correction at a moment when the Centers for Medicare and Medicaid Services (“CMS”) is actively steering seniors toward health apps that require collection and processing of identifiable consumer health information outside the reach of HIPAA.
The Federal Trade Commission (“FTC”) recently issued guidance clarifying protections applicable to consumers’ sensitive personal data increasingly collected by so-called “health apps.” The FTC press release indicated it has approved a policy statement by a vote of 3-2 offering guidance that organizations using “health applications and connected devices” to “collect or use” consumers’ personal health information must comply with the cybersecurity, privacy and notification mandates of the Health Breach Notification Rule (the “Rule”).
The ...
Recent Updates
- Comment Period Closes on California OHCA’s Proposed Emergency Regulations Expanding Private Equity, Hedge Fund, and MSO Reporting in Health Care Transactions
- DOJ Revises Justice Manual on Non-Binding Guidance and Qui Tam Dismissals: Practical Considerations
- Additional SBA Crackdown on Pandemic-Era Fraud Leads to Program and Loan Suspensions, Possible FCA Enforcement
- Federal Regulatory Views on Cybersecurity and AI Amidst a Growing Threat Landscape
- Remote Monitoring Services Under the 2027 PFS Proposed Rule: Epstein Becker Green Submits Comments to CMS