Saturday, September 19, 2026

Person checking a smartwatch health tracker, matching an article about health app and connected-device breach notification rules

FTC Pulled an Old Health-App Statement. The Breach Rule Still Applies.

The FTC rescinded a 2021 health-app breach policy statement, but the updated Health Breach Notification Rule still covers many health apps, wellness tools, fitness trackers, and related vendors outside HIPAA.

The Federal Trade Commission just removed an old health-app policy statement. That does not mean health apps are suddenly outside the breach-notification rule.

On Sept. 9, the FTC said it rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The agency called the statement obsolete because the Commission updated the Health Breach Notification Rule in 2024 to expressly cover health apps and connected devices such as fitness trackers.

That distinction matters for small businesses. A founder, clinic-adjacent software vendor, wellness coach, fitness platform, or connected-device startup could read "withdraws obsolete policy statement" and hear "less compliance." The better reading is narrower: the old statement is gone because the newer rule now carries the compliance load.

What The Rule Still Covers

The FTC's Health Breach Notification Rule page says vendors of personal health records and related entities must notify consumers after a breach involving unsecured information. If a service provider to one of those entities has a breach, the service provider must notify the covered entity, which then notifies consumers.

The 2024 update also made the rule more relevant to modern small companies. In its final-rule announcement, the FTC said the changes clarify that the rule applies to health apps and similar technologies not covered by HIPAA. The agency also said a breach can include an unauthorized disclosure of identifiable health information, not just a classic hack.

That is the line many small businesses miss. A wellness app that sends health data to an analytics, advertising, AI, or marketing partner without proper authorization may have a notification problem even if nobody broke into a server.

The Owner Takeaway

If your business handles consumer health data outside a traditional HIPAA workflow, do not treat this withdrawal as a permission slip.

Instead, use it as a reason to check four things:

  • whether your product collects health, fitness, fertility, medication, mood, symptom, or treatment information
  • whether that data comes from more than one source, such as user entries, connected devices, wearable integrations, or third-party services
  • which vendors can receive identifiable health information
  • whether your incident-response plan says who notifies consumers, the FTC, media, or business partners if data is acquired or disclosed without authorization

The most practical move is a data-flow audit. Pull up the product, intake forms, app permissions, CRM, analytics tools, ad pixels, AI tools, support desk, and cloud vendors. For each one, write down what health information it touches, whether it is identifiable, where it goes, and who would need notice if that flow went wrong.

Small health businesses often think privacy compliance belongs only to hospitals and insurers. That is outdated. The modern risk sits with any company that turns consumer health information into an app, dashboard, device, coaching workflow, or marketing segment.

The plain takeaway: the FTC removed an old guidance document, not the duty to notify. If your tool collects health data, your breach plan should be written before the breach happens.

Sources: FTC withdrawal announcement, FTC Health Breach Notification Rule summary, FTC 2024 final-rule announcement.

This article was produced by The Useful Daily's AI-assisted editorial system and reviewed for small business relevance. It is informational only and is not legal, tax, medical, or financial advice.

Related Coverage

Are you overpaying for AI tools?

Most small businesses waste $150+/month on tools they don't need. Find out in 2 minutes.

Take the Free AI Audit →

Liked this? There's more where that came from.

Every Sunday we send the week's best AI tips for your business. Free. No spam. Ever.