FTC Rescinds 2021 Guidance on Health Breach Notification Rule
On September 9, 2026, the Federal Trade Commission (FTC) withdrew what it considered a “controversial” 2021 Policy Statement (Statement) that it had previously issued to provide guidance on the application of the FTC’s Health Breach Notification Rule (Rule) to health applications and connected devices.
In its announcement, the FTC indicated that the Statement, which was contentious when issued, provided minimal benefit and had been superseded by the 2024 revisions to the Rule (2024 Rule).
History of the Rule and Statement.
By way of background, the Rule was initially issued in 2009 as mandated by section 13407 of the American Recovery and Reinvestment Act of 2009, P.L. 115-5, 123 Stat. 115 (2009), which established protection for “personal health records” (PHR) that were not subject to the privacy and security requirements of the Health Information Portability and Accountability Act (HIPAA), such as vendors of PHR and other PHR-related entities that collect consumer health information. Under the 2009 Rule, vendors of PHR and PHR-related entities are required to provide notice of a breach of unsecured PHR to: (1) the consumers whose unsecured PHR was breached; (2) the FTC; and (3) prominent media outlets serving a State or jurisdiction in cases where 500 or more residents are affected.
Due to the increased use of direct-to-consumer apps and health technologies (i.e., fitness trackers and wearable blood pressure monitors), in 2021, the FTC issued the Statement following review of the public comments it had solicited regarding the need for changes due to these new technologies. Thereafter, the FTC finalized the 2024 Rule, which:
- clarified the Rule’s scope, including its application to developers of health apps and similar technologies not covered by HIPAA;
- clarified what it meant for a vendor of personal health records to draw PHR identifiable health information from multiple sources;
- revised the definition of breach of security to clarify that a breach of security included data security breaches and unauthorized disclosures;
- revised the definition of a PHR-related entity;
- modernized the method, content and timing of notice; and
- articulated the penalties for non-compliance.
What does the FTC’s Withdrawal of the Statement Mean to Entities Covered by the Rule?
As noted above, the Statement’s redundancy with the 2024 Rule led to the FTC’s withdrawal. Additionally, the FTC indicated that its action was consistent with the current Administration’s deregulatory agenda and the FTC’s policy of avoiding unnecessary sub-regulatory guidance, noting that the guidance does not create substantive rights or binding obligations. Given that the 2024 Rule is unaffected, it still applies to those entities that are subject to it. Thus, any covered entity must still report a breach of unsecured PHR.
Immediately after withdrawing the Statement, and in furtherance of the FTC goals of deregulation and avoiding sub-regulatory guidance, on September 10, 2026, the FTC Bureau of Consumer Protection (BCP) launched a new process for interested stakeholders to submit inquiries to the BCP regarding potential ambiguities in any FTC rules and/or substantive conflicts between an FTC rule and existing laws and other rules. Interested stakeholders can submit their inquiries through an online form on the newly-created BPC Rule Guidance Program webpage.
While time will tell how this will affect the FTC’s enforcement of the 2024 Rule, app developers and other entities that are subject to the 2024 Rule need to ensure that they remain diligent in protecting the security of the information they maintain.
For more information, please contact the authors of this Client Alert or your Butzel attorney.
Debra Geroux
248.258.2603
geroux@butzel.com
Claudia Rast
734.213.3431
rast@butzel.com