As cited
Copy frozen at (site build).
breaches incidents
FTC Withdraws Obsolete Policy Statement
The Federal Trade Commission (FTC) withdrew its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had applied the Health Breach Notification Rule to health-related apps and connected devices collecting consumer data. The withdrawal follows the Commission's 2024 updates to the Health Breach Notification Rule itself, rendering the prior policy obsolete.
Why it matters: Health app and connected device makers should verify their compliance obligations under the updated 2024 rule rather than relying on the now-rescinded 2021 guidance.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
FTC Withdraws Obsolete Policy Statement
The Federal Trade Commission withdrew its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, following updates to the Health Breach Notification Rule in 2024. The original policy had extended Health Breach Notification requirements to health applications and internet-connected devices that handle consumer health data. The rescission eliminates the previously contentious guidance.
Why it matters: Health app and connected device developers need to verify their compliance obligations under the updated 2024 rule, as the prior policy guidance no longer applies.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
FTC Withdraws Obsolete Policy Statement
The Federal Trade Commission rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had attempted to extend the Health Breach Notification Rule to consumer health applications and connected devices. The agency replaced that guidance with updated rules in 2024 that clarified the framework for protecting health information collected by such products.
Why it matters: Health app developers and connected device manufacturers need to understand the new 2024 rules to ensure compliance with FTC breach notification requirements for consumer health data.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
FTC Withdraws Obsolete Policy Statement
The Federal Trade Commission rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices after updating the Health Breach Notification Rule in 2024. The withdrawn statement had applied notification requirements to health apps and connected devices handling consumer health data. The action removes outdated guidance that had drawn controversy.
Why it matters: Health app developers and device manufacturers must review current Health Breach Notification Rule requirements to ensure compliance, as the 2021 policy no longer applies.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
FTC Withdraws Obsolete Policy Statement
The Federal Trade Commission withdrew its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices after updating the Health Breach Notification Rule in 2024. The earlier policy had attempted to extend the Health Breach Notification Rule to health apps and connected devices that collect consumer health information.
Why it matters: Health app developers and connected device manufacturers must understand the current FTC notification requirements, as the withdrawn policy no longer applies and the updated rule may impose different obligations on their organizations.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
FTC Withdraws Obsolete Policy Statement
The Federal Trade Commission (FTC) rescinded its 2021 policy statement that extended health breach notification requirements to consumer health apps and connected devices. The move follows the Commission's 2024 update to the Health Breach Notification Rule, which superseded the earlier guidance.
Why it matters: Health app and device makers should clarify their breach notification obligations under the updated rule; compliance teams need to audit notification procedures against the current requirements rather than the withdrawn statement.
- Source published
- First seen by Cybersecurity Tracker