On September 9, the FTC rescinded its 2021 policy that extended the Health Breach Notification Rule to health apps and wearables not covered by HIPAA, calling the guidance "obsolete."

What changed

The 2021 policy treated fitness trackers, period apps, and similar tools as if they had to tell you when your health data was breached, or shared without your permission. With the rescission:

  • App makers outside HIPAA are no longer treated as "health care providers" who must send breach notices.

  • The broad trigger that pulled ordinary wellness apps into the rule is gone.

  • Sharing your data without permission, including with ad-tech, no longer by itself triggers a notification duty.

The FTC's power to police "unfair or deceptive" practices still stands, but this specific breach-notice duty for health apps is gone.

Why the timing matters

In April, Medicare launched an app library steering seniors toward health apps, partly citing those 2021 protections as a reason to trust them. Reporting has already found some of those listed apps sharing user data with big tech for advertising, exactly what the rescinded policy was meant to flag.

What to do

  • Treat non-HIPAA health apps (fitness, period, wellness, most apps you download) as if no one is required to warn you when your data leaks or is sold.

  • Favor apps that store data on your device (like Euki for cycle tracking) and don't sign in with Google or Facebook.

  • Use your state rights. Laws like Washington's My Health My Data Act still cover many health apps, check whether your state has one.

Quick tip

Before installing a health app, check whether it's HIPAA-covered, most consumer apps aren't. If it isn't, assume the data can be shared, and pick one that keeps it on your device.

Up next · Wednesday

A free tool that shows you exactly what a health or shopping app collects before you install it.