FTC Retires Health App Data Breach Policy, but Underlying Rule Remains in Force

Federal · Published · Last verified September 10, 2026

Short answer

FTC Retires Health App Data Breach Policy, but Underlying Rule Remains in Force

The Federal Trade Commission (FTC) has withdrawn its 2021 policy statement regarding data breach notifications for health apps and connected devices. This action was taken because a 2024 update to the Health Breach Notification Rule made the policy statement redundant. Employers offering wellness programs using such technology should understand that the underlying notification obligations remain in effect, as they are now formally part of the rule itself.

At a glance

Status
Policy Rescinded
Jurisdiction
Federal
Primary topic
Data Breach Notification
Effective date
September 9, 2026
Who may be affected
Vendors of health apps and connected devices; employers offering wellness programs using such technology

What changed

On September 9, 2026, the Federal Trade Commission (FTC) announced the rescission of its "2021 Policy Statement on Breaches by Health Apps and Other Connected Devices." The FTC deemed the policy statement obsolete and unnecessary. This action does not change the substantive requirements for entities covered by the Health Breach Notification Rule; it merely removes a redundant guidance document because the policy's contents were formally incorporated into the rule itself in 2024.

Who is affected

This action primarily affects vendors of health apps and connected devices, such as fitness trackers. It is also relevant for employers who offer wellness programs that utilize such technologies, as they or their vendors may have obligations under the FTC's Health Breach Notification Rule if they handle covered health information and experience a data breach.

When does it take effect

The Federal Trade Commission announced the rescission on September 9, 2026.

Why HR should care

HR professionals managing employee wellness programs should not misinterpret this action as a weakening of data breach notification rules. The FTC's withdrawal of the 2021 policy statement is a procedural cleanup, not a substantive change in obligations. The requirements that the policy sought to clarify are now explicitly codified in the updated Health Breach Notification Rule (HBNR) as of 2024. This means that if a wellness program using a health app or fitness tracker experiences a data breach, notification duties still apply. The source of the obligation is now the rule itself, not a policy statement. This move simplifies the regulatory landscape by removing a redundant document, but the compliance burden for protecting employee health data and notifying individuals of a breach remains firmly in place under the HBNR.

What employers should consider

• Employers should review their wellness programs to determine if they use health apps or connected devices that collect consumer health information. • It is crucial to understand that the rescission of the 2021 policy statement does not eliminate data breach notification requirements for these technologies. • The obligations are now directly contained within the FTC's updated Health Breach Notification Rule. • Employers should confirm that their wellness program vendors are compliant with the HBNR. • Given the complexities of data privacy, employers should consider reviewing their wellness program agreements and data handling practices with qualified counsel to ensure compliance with the HBNR and other applicable privacy laws.

SafestHires perspective

The FTC's decision to rescind its 2021 policy statement is a logical step in regulatory housekeeping. By incorporating the policy's principles directly into the Health Breach Notification Rule in 2024, the Commission created a clearer, more direct source of authority. For employers, this action underscores the permanence of data breach notification duties related to employee wellness technology. Relying on the formal rule rather than a policy statement provides greater certainty but also reinforces the FTC's focus on this area. Employers should treat this development as a reminder to audit their wellness programs and vendor agreements for compliance with the now-codified HBNR requirements.

Key takeaways

  • The FTC has rescinded its 2021 policy statement on data breaches for health apps.
  • The action was taken because a 2024 update to the Health Breach Notification Rule (HBNR) made the policy obsolete.
  • The underlying requirements for breach notification for health apps and connected devices remain in effect under the HBNR.
  • The rescission was announced on September 9, 2026.

Common employer questions

Did the FTC remove the requirement to notify users of a health app data breach?

No. The FTC did not remove the requirement. It rescinded a 2021 policy statement because the requirements were formally added to the Health Breach Notification Rule (HBNR) in 2024. The obligation to notify users of a breach remains in effect under the HBNR itself.

Why did the FTC withdraw this policy statement?

The FTC withdrew the policy statement because it was rendered unnecessary and obsolete after the Commission updated the Health Breach Notification Rule in 2024 to explicitly cover health apps and connected devices. This action simplifies the regulatory landscape by removing a redundant document.

Does this affect our company's employee wellness program?

It may. If your employee wellness program uses health apps or connected devices (like fitness trackers) that collect consumer health information, your company or your vendor may have compliance obligations under the Health Breach Notification Rule. This FTC action confirms that those obligations are grounded in the formal rule, not just a policy statement.

Sources

Last verified September 10, 2026. Citing an organization does not imply it endorses, sponsors, or approves SafestHires or this explanation.

Does this development affect your screening process?

SafestHires helps employers maintain efficient background-screening workflows with built-in compliance safeguards and U.S.-based support.

More employment law coverage

Important: SafestHires strives to provide timely, well-sourced information based on authoritative materials available at the time of publication. This content is provided for general informational purposes and is not legal advice. Because legal requirements can change and vary by jurisdiction, employers should consult qualified counsel regarding their specific obligations.

How SafestHires researches and verifies this brief