CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

FTC rescinds policy requiring health apps to notify customers after a breach

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6861

As cited

Copy frozen at (site build).

regulatory

FTC rescinds policy requiring health apps to notify customers after a breach

The Federal Trade Commission rescinded a Biden-era policy statement that extended federal data breach notification requirements to health and fitness apps. The FTC stated the policy provided minimal benefit and has been superseded by rulemaking, citing alignment with White House deregulatory guidance. The original 2021 policy would have required health apps to notify users of breaches and subjected violators to daily fines, but the unanimous rescission vote came after Democratic commissioners were replaced with Republican appointees.

Why it matters: Health app vendors and users should understand that the FTC's breach notification requirement for health data no longer applies: companies handling sensitive medical records through fitness and health applications now operate without mandatory federal disclosure obligations, creating a regulatory gap for consumer data protection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary