FTC rescinds policy requiring health apps to notify customers after a breach
The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.
The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.
- Rescission removes federal breach-notification expectations for consumer health apps
- 2021 statement passed 3-2 under Chair Lina Khan
- Unanimous 2026 vote follows replacement of Democratic commissioners
- Experts note similar regulatory gaps persist for healthcare AI models
Full article790 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization.
Listen to this article
0:00
Learn more.
The Federal Trade Commission has rescinded a Biden administration-era policy statement that covered health and fitness apps under federal data breach notification regulations.
In a half-page statement posted Wednesday, the FTC said it “has determined that the statement – contentious at the time of issuance – provided minimal benefit and has been superseded by rulemaking.” The commission said the statement’s withdrawal also aligns with guidance from the White House to pursue a deregulatory agenda and avoid “unnecessary use of subregulatory guidance.”
“Each of these reasons is independently sufficient to support the Commission’s decision to rescind this policy statement,” the FTC continued. “Parties understand that guidance generally creates neither substantive rights nor binding obligations.”
The initial policy, passed in a divided 3-2 vote during the Biden administration under then-FTC chair Lina Khan, added health apps, fitness trackers and other connected devices to an existing regulation requiring companies to disclose health-related data breaches to customers.
The changes would cover any “vendor of personal health records that contain individually identifiable health information created or received by health care providers.” Many health and fitness apps ask users to upload medical records and other health-related data in order to function effectively.
More recently, health and cybersecurity experts have pointed to similar regulatory gaps that exist for AI companies that make healthcare specific models that can answer questions, examine patient records and dispense medical advice to users.
The rule also triggers automatic notification when a covered entity suffers a breach of security, which can include both standard breaches and data losses as well as the disclosure of sensitive health information to third parties without users’ authorization. That would potentially put health apps on the hook for selling customer data to third-party data brokers and other entities.
A Sept. 2021 statement by the FTC justifies the additions by citing digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act as well as gaps in major health privacy laws like the Health Insurance Portability and Accountability Act that allow such apps to handle and store sensitive personal health records or data without being subject to the same breach notification requirements as other health care organizations.
The FTC said it intended to enforce health apps under the law and subject violators to daily fines of $43,792 per violation.
“As many Americans turn to apps and other technologies to track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, diet, and other vital areas, this Rule is more important than ever,” the FTC said in 2021. “Firms offering these services should take appropriate care to secure and protect consumer data.”
This week, the FTC voted unanimously to rescind the policy. But that unity is in part because President Trump fired Democratic FTC commissioners who voted in favor of the original rules, while advancing party allies as their replacements.
The two dissenting votes against the rule changes in 2021 were from Republican-appointed commissioners casting their dissents under a Democratic executive. Andrew Ferguson, a Republican commissioner nominated by former Democratic President Joe Biden, is now chair of an FTC filled entirely with Republican appointees, and has defended President Trump’s authority to fire and hire new commissioners at-will.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/