The FTC Pulled the 2021 Statement. The 2024 HBNR Rule Still Covers Health Apps and Unauthorized Disclosures.

On September 9, 2026, the FTC rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The rescission does not exempt health apps from the Health Breach Notification Rule. The FTC's 2024 final HBNR rule remains in effect and expressly addresses health apps, related technologies, and unauthorized disclosures of covered health information. The immediate vendor-contract task is not to remove unauthorized-sharing obligations; it is to distinguish contractual references to the withdrawn 2021 statement from obligations that remain grounded in the 2024 rule and applicable state law.

the-stack
09/14/2026

The reflex reading is wrong — in both directions. On September 9, the Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, and within 48 hours the secondary commentary split between "health apps are now exempt from breach notification" and "nothing substantive changed." Neither is accurate.

The rescission removes a policy statement, not the Health Breach Notification Rule. The FTC's 2024 final HBNR rule remains in effect and expressly addresses health apps, related technologies, and unauthorized disclosures of covered health information. Understanding exactly what the FTC withdrew — and what is still binding — is the audit your vendor contracts need this week.

What the 2021 Statement Did

The Health Breach Notification Rule has existed since 2009 as a narrow backstop for personal health record vendors — companies that hold individually identifiable health information but are not HIPAA-covered entities or their business associates. The rule sat in relative obscurity until 2021, when the Biden-era FTC in a 3-2 vote issued a policy statement that dramatically expanded the HBNR's interpretive reach without amending the rule itself.

Three features of that 2021 interpretation are now withdrawn.

First, the 2021 statement treated developers of health apps and connected devices as "health care providers" under the HBNR because they furnish health-related services — pulling companies with no HIPAA nexus into a breach-notification framework built for PHR vendors.

Second, it applied an aggregation trigger: an app was covered even if it drew health data from a single source but pulled in non-health data (calendar entries, location data) from a second source via API.

Third: the 2021 statement extended "breach" beyond cybersecurity incidents to include unauthorized sharing of covered information without user authorization.

The FTC's rescission document says the Commission viewed the statement as "contentious," of "minimal benefit," and "superseded by rulemaking."

What Changed — and What Did Not

The key word in the rescission is "superseded." The subsequent rulemaking that superseded the 2021 statement is the FTC's 2024 final HBNR rule, announced April 25, 2024, effective July 29, 2024. That rule is still in effect and does much of what the 2021 statement did — through binding regulation rather than a policy statement.

The FTC's 2024 final rule expressly: (1) revised definitions to underscore the rule's application to health apps and related technologies not covered by HIPAA; (2) clarified that a breach of security includes unauthorized acquisition resulting from either a data-security breach or an unauthorized disclosure; and (3) covers online services, including mobile applications, offered by PHR vendors.

The practical result is narrower than both reflex readings. The rescission removes a source of subregulatory guidance and may affect arguments about the Commission's historical enforcement posture. It does not eliminate the amended HBNR's applicability to covered health apps or its treatment of qualifying unauthorized disclosures as potential breaches.

What Still Applies

Health apps and similar technologies that meet the HBNR's coverage definitions and are not subject to HIPAA remain subject to the amended HBNR. A reportable breach may arise from a data-security incident or from an unauthorized disclosure of unsecured PHR identifiable health information. The FTC's Section 5 authority over unfair or deceptive acts or practices is fully intact. And state laws — Washington's My Health My Data Act and relevant provisions in Nevada, Connecticut, and other states with health-specific privacy frameworks — may impose separate consent, disclosure, security, consumer-rights, and enforcement requirements. Applicability is state- and fact-specific and should be assessed separately from the HBNR.

The operational question is not whether the unauthorized-sharing obligation disappeared. It is whether a given vendor and data arrangement meets the amended HBNR's coverage definitions — PHR vendor, PHR-related entity, or third-party service provider — and whether the disclosure was authorized under the relevant privacy notices and consent flows. Unauthorized disclosure remains a possible HBNR breach for covered entities under the 2024 rule.

The CMS Medicare App Library Question

There is a timing question the FTC's press release did not address. CMS launched its Medicare App Library in April 2026, and secondary reporting indicates CMS officials referenced the former policy position in discussing app privacy. Some apps listed in the library have been reported as sharing consumer health data with major technology companies for advertising purposes.

The rescission raises a vendor-governance question for organizations that rely on CMS-listed digital tools: whether CMS's vetting materials, app disclosures, and privacy representations continue to provide the same assurance regarding HBNR coverage and unauthorized disclosure risk. That question requires a CMS primary-source answer before any stronger conclusion can be published.

If your organization directs patients toward CMS-listed apps as part of a care navigation or chronic disease management workflow, the vendor governance question is real — but the answer depends on what CMS's vetting process actually says, not on the status of the 2021 policy statement alone.

The Vendor Contract Audit

The practical deliverable is a targeted contract and data-flow review against three questions.

First, identify clauses that expressly cite or incorporate the 2021 policy statement. Those references should be updated because the statement has been rescinded. Do not assume, however, that the underlying obligation disappears: the amended HBNR may independently apply, and contract language may impose duties that are broader than the federal minimum. Contract enforceability depends on the contract's own language, governing law, severability clauses, incorporation-by-reference provisions, and factual circumstances — not solely on the status of an FTC statement.

Second, map each vendor's role and data flow to the amended HBNR. Determine whether the vendor is a PHR vendor, PHR-related entity, or third-party service provider; whether it holds unsecured PHR identifiable health information; whether HIPAA applies; and whether advertising, analytics, SDK, or other third-party disclosures are authorized under the relevant privacy notices and consent flows.

Third, layer in applicable state law. A vendor's federal HBNR analysis does not resolve state consumer-health-data obligations, which may establish independent duties concerning consent, sharing, security, consumer rights, and breach response.

The 2021 statement was contested at issuance. The rescission clarifies the subregulatory posture — but not in the direction the reflex reading suggests. The amended HBNR, not the withdrawn statement, is now the operative federal framework. Your contracts need to be mapped to what the rule actually says, not to what a policy statement once said about it.

Transforming Healthcare with AI Technology

Discover how Addie helps health systems, post-acute providers, and payers improve throughput, reduce avoidable days, and deliver better transitions of care.

Get Started