Skip to content

Security1 publisher3 min readPublished

FTC withdraws the 2021 statement that pulled health apps under its breach disclosure rule

The commission calls the withdrawn guidance minimal in benefit and superseded by rulemaking, without saying which rulemaking, which leaves anyone holding users' uploaded medical records arguing from the rule text instead.

The Watch · Security desk

Illustration accompanying FTC withdraws the 2021 statement that pulled health apps under its breach disclosure rule

What happened

  • The FTC has rescinded the Biden-era policy statement that brought health and fitness apps under the federal regulation requiring companies to disclose health-related data breaches to customers.
  • Its stated grounds are that the statement was contentious when issued, provided minimal benefit, and has been superseded by rulemaking, with each reason described as independently sufficient.
  • The 2021 statement passed on a divided 3-2 vote under then-chair Lina Khan; this week's vote to rescind it was unanimous.
  • Under the withdrawn statement the FTC said it would enforce against health apps and subject violators to daily fines of $43,792 per violation.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Disclosure playbooks that cite the 2021 statement as their authority now have to be re-anchored to rule text the FTC has not quoted, which is a drafting job for counsel rather than a policy question.
  • exposure Apps that resell uploaded health data lose the clearest published federal hook for telling users about it, since that hook was an interpretation rather than a line in the rule.
  • contradiction If guidance truly created no binding obligations, then either the withdrawal changes nothing or the 2021 fine threat was never enforceable, and the commission's notice reconciles neither reading.

The 2021 document was the FTC's reading of an existing rule. The FTC read "vendor of personal health records that contain individually identifiable health information created or received by health care providers" to reach apps, fitness trackers and connected devices [8], on the reasoning that many of those products only work once a user uploads medical records [9], and that HIPAA leaves those uploads outside the notification duties binding hospitals and insurers [11]. Digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act supplied the statutory hook [11].

The trigger is what made it operational. The duty fires not only on intrusion or data loss but on disclosure of sensitive health information to third parties without the user's authorization [10]. Under that reading, selling customer data to a broker is a reportable breach [10], which asks a compliance program to treat a revenue line as an incident.

The commission now writes that parties understand guidance generally creates neither substantive rights nor binding obligations [6]. Taken at face value, that sentence makes the withdrawal legally uneventful and also deflates the 2021 promise to pursue violators at $43,792 per violation in daily fines [12]. Carry one unremediated violation for a month and that notice priced it at $1,313,760 [17].

The supersession claim is the part worth chasing, and it is the part the notice leaves undeveloped. The published grounds name no rulemaking and say nothing about whether the successor rule text keeps app vendors in scope [18]. Two readings follow, with different consequences: coverage survived and only the citation moved, or coverage narrowed and this withdrawal is the visible edge of it. The record here does not choose between them, so the conservative position for a product team holding uploaded records is that the duty outlived the guidance.

State law is often offered as the backstop. The FTC's statement, as reported, does not address state enforcement at all [19], and there is no state response on the record to point at.

The unanimity owes more to the changed roster than to a shift in the merits. Trump fired the Democratic commissioners who had voted for the statement and advanced party allies as their replacements [14]. Both 2021 dissents had come from Republican appointees serving under a Democratic president [15]. Andrew Ferguson, a Republican commissioner nominated to the FTC by Biden, now chairs a commission composed entirely of Republican appointees and has defended the president's authority to fire and hire commissioners at will [16]. The FTC also cited White House guidance to pursue a deregulatory agenda and avoid unnecessary use of subregulatory guidance as a ground for the withdrawal [4], and said each of its reasons was independently sufficient [5].

This week's change is the citation the FTC now leans on, with no demonstrated change in duty behind it. The argument moves to the rule text, and the FTC has not shown its work there.

What to watch

  • Whether the FTC identifies the rulemaking it says superseded the statement, and whether that rule text keeps app vendors in scope.
  • Any FTC enforcement action against a health app for unauthorized third-party disclosure after the withdrawal.
  • Litigation over the commissioner removals that produced this week's all-Republican-appointee commission.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories