On September 9, 2026, the Federal Trade Commission (“FTC”) rescinded its 2021 policy statement which extended the Health Breach Notification Rule (“HBNR”) to health apps and connected devices outside the reach of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively “HIPAA”).
In its recent press release, the FTC called that prior guidance “obsolete” and “unnecessary,” concluding it provided minimal benefit and had been superseded by rulemaking. This is not a minor course correction at a moment when the Centers for Medicare and Medicaid Services (“CMS”) is actively steering seniors toward health apps that require collection and processing of identifiable consumer health information outside the reach of HIPAA.
On May 18, 2023, the Federal Trade Commission (FTC) filed a Notice of Proposed Rulemaking and Request for Public Comment (“NPRM”) seeking to amend the Health Breach Notification Rule (“HBNR”). We previously wrote about the FTC’s policy statement, in which the FTC took the position that mobile health applications that are not covered by the Health Insurance Portability and Accountability Act (“HIPAA”) are covered by the HBNR. In our post, we highlighted concerns raised in dissent by commissioner Noah Joshua Phillips that the FTC’s interpretation of “breach of security” was too broad. Commissioner Phillips has since resigned.
Throughout 2021, we closely monitored the latest privacy laws and a surge of privacy, cybersecurity, and data asset management risks that affect organizations, small and large. As these laws continue to evolve, it is important for companies to be aware and compliant. We will continue to monitor these trends for 2022.
The attorneys of the Privacy, Cybersecurity & Data Asset Management group have written on a wide range of notable developments and trends that affect employers and health care providers. In case you missed any, we have assembled a recap of our top 10 blog posts of 2021, with links to each, below:
The Federal Trade Commission (“FTC”) recently issued guidance clarifying protections applicable to consumers’ sensitive personal data increasingly collected by so-called “health apps.” The FTC press release indicated it has approved a policy statement by a vote of 3-2 offering guidance that organizations using “health applications and connected devices” to “collect or use” consumers’ personal health information must comply with the cybersecurity, privacy and notification mandates of the Health Breach Notification Rule (the “Rule”).
The ...
Recent Updates
- Comment Period Closes on California OHCA’s Proposed Emergency Regulations Expanding Private Equity, Hedge Fund, and MSO Reporting in Health Care Transactions
- DOJ Revises Justice Manual on Non-Binding Guidance and Qui Tam Dismissals: Practical Considerations
- Additional SBA Crackdown on Pandemic-Era Fraud Leads to Program and Loan Suspensions, Possible FCA Enforcement
- Federal Regulatory Views on Cybersecurity and AI Amidst a Growing Threat Landscape
- Remote Monitoring Services Under the 2027 PFS Proposed Rule: Epstein Becker Green Submits Comments to CMS