FTC Withdraws Obsolete Policy Statement
The FTC rescinded its 2021 policy statement that applied the Health Breach Notification Rule to health apps and connected devices collecting consumer health data.
The Federal Trade Commission formally rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The statement had purported to apply the FTC's Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The Commission considers the statement obsolete following its 2024 update to the Health Breach Notification Rule.
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
CISA and partners issue a joint advisory pressing organizations toward transparent breach notification and incident response as cyber outages escalate.
Dark Reading reports on a new joint government advisory led by CISA that signals a regulatory shift. The advisory presses organizations to adopt more transparent breach notification protocols and incident response practices. The guidance comes as cyber outages escalate and reflects growing government expectation of disclosure over spin.
Delaware Consumer Privacy and Data-Breach Law Updates
Delaware's governor signed HB 380 and HB 381 amending the state privacy act and breach notification law.
On September 2, 2026, Delaware's Governor signed House Bill 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), enacted in 2023 and effective January 1, 2025. HB 381 separately amends Delaware's computer security breach notification law. Joseph J. Lazzarotti of JacksonLewis summarizes the changes.
FTC rescinds policy requiring health apps to notify customers after a breach
The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.
The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.