Summary
- The FTC rescinded its nonbinding 2021 health-app policy statement on 9 September 2026, saying the document provided minimal benefit, had been superseded by the Commission’s 2024 rulemaking and was unnecessary subregulatory guidance.
- The rescission does not repeal, stay or amend 16 CFR part 318. The amended Health Breach Notification Rule remains the operative text for covered non-HIPAA health-app and personal-health-record businesses, including its definitions, notice recipients and timing rules.
The withdrawn document was one layer of authority
The FTC’s announcement is brief enough to invite an overreading. It says the Commission withdrew a 2021 statement concerning breaches by health apps and other connected devices. A reader who treats every official document as equally binding could translate that event into a broader claim: the legal obligation was withdrawn too.
The Commission’s one-page rescission statement says something narrower. It calls the earlier statement nonbinding, says it yielded minimal benefit, says a 2024 rulemaking superseded it and invokes a preference against unnecessary subregulatory guidance. It also states that guidance generally creates neither substantive rights nor binding obligations. Each reason, the Commission says, is independently sufficient; together they outweigh any reliance interests.
Those are the FTC’s stated reasons for withdrawing an interpretive document. They are not a finding that nobody relied on the statement, nor a declaration that health-app breach duties vanished. Most importantly, the rescission points readers toward the instrument that replaced the statement’s role: the amended Health Breach Notification Rule.
The authority sequence matters. Congress supplied the foundation through section 13407 of the HITECH Act. The FTC issued the original rule in 2009. The Commission then used its September 2021 policy statement to explain how it viewed health apps, technical capacity to draw information from multiple sources and unauthorized disclosures. After a proposed rule and public comment, the Commission adopted a 2024 final rule that changed the legal text itself. That rule became effective on 29 July 2024.
The 2026 action removed the interpretive layer from 2021. It did not purport to unwind the statute, the 2009 foundation or the 2024 amendment. The current eCFR still codifies 16 CFR part 318, and the FTC’s rule page continues to identify the rule and its primary materials. That is the operating boundary on the public record checked for this article.
Coverage depends on definitions, not the product label
The phrase “health app” is useful in a headline and unreliable as a legal test. The amended rule applies to defined vendors of personal health records, PHR related entities and third-party service providers. HIPAA-covered entities and business associates are excluded from those definitions for covered activity and use the Department of Health and Human Services breach-notification regime instead.
That division does not mean HIPAA is absent from consumer health data, nor that every product outside HIPAA automatically falls under the FTC rule. The definitions must still be applied. A personal health record under the FTC rule is an electronic record of identifiable health information on an individual that has the technical capacity to draw information from multiple sources and is managed, shared and controlled by or primarily for the individual.
The 2024 amendment clarifies that technical capacity can be enough. A user need not activate every possible connection before the product can satisfy the multiple-source element. The FTC’s current compliance guidance gives examples, but that guidance remains explanatory; the regulation is the controlling text.
The same care applies to “breach.” The amended definition covers unauthorized acquisition of unsecured PHR identifiable health information resulting from a data-security breach or an unauthorized disclosure. It retains a rebuttable presumption of unauthorized acquisition. That formulation reaches conduct beyond an outsider breaking into a database, but it does not make every transfer of health-related data a breach. Authorization, the covered actor, the information, the incident and the rule’s definitions all matter.
The withdrawn 2021 statement had emphasized both ideas: many health apps could qualify as PHR vendors because they draw from multiple sources, and a breach could include unauthorized disclosure without a hack. The 2024 final rule discusses that statement, the proposed rule and the comments received. The current authority therefore does not depend on preserving the older PDF as a freestanding policy command.
The notice clock still belongs to the rule
For a covered breach, the rule identifies recipients and timing. Covered vendors and related entities must notify affected individuals and the FTC. If an incident involves 500 or more residents of a state or jurisdiction, notice must also go to prominent media serving that area. Notices must follow the rule’s content and delivery requirements.
The 2024 amendment changed an important timing detail. For a breach involving 500 or more individuals, notice to the FTC is due without unreasonable delay and no later than 60 calendar days after discovery, aligned with the individual-notice period. The former ten-business-day formulation is not the current rule for those incidents. Removing the 2021 statement does not revive that old clock.
This is where source confusion becomes operational risk. A compliance team may have an old memo that cites the 2021 statement, a copied checklist that cites a superseded deadline and a current reporting link in a browser bookmark. If the team responds to the withdrawal by deleting the memo but never checks the current regulation, it has performed document hygiene without verifying the duty.
As of 11 September, the eCFR text, FTC rule page, current guidance and online reporting surface remained publicly accessible. Their presence does not predict which cases the Commission will bring next. It does show that the public operating surface was not erased by the statement’s withdrawal.
Existing court orders do not dissolve by implication
The FTC’s GoodRx case page and Easy Healthcare case page record 2023 complaints alleging failures to provide Health Breach Notification Rule notices for unauthorized disclosures. Federal courts entered stipulated orders in those matters.
Those cases help show how the Commission applied the rule to particular facts. They are not universal holdings that bind every health app, and a stipulated order should not be recast as an admission of every allegation. Equally, the 2026 rescission says nothing about vacating or modifying either order. An entered court order has its own authority and modification process; it does not disappear merely because an agency withdraws a separate policy statement.
This separation guards against two opposite errors. One side may claim that rescinding the statement cancelled the enforcement history. The other may treat the prior complaints as if they permanently settle every disputed definition for every future product. The record supports neither shortcut. The rule is general, the cases are fact-bound, and future enforcement remains a future decision.
Publish an authority-version receipt
Institutional websites often arrange a rule, a press release, guidance, forms and cases on adjacent pages. Search results flatten them further. A date or a bold heading may look like an authority signal even when the underlying document is only explanatory. The result is a familiar governance failure: a source changes, but the public cannot see which obligation, interpretation or workflow changed with it.
I propose an authority-version receipt for material regulatory changes. It would record the instrument class; issuing body; matter or docket; adoption, publication and effective dates; superseded document; live rule section; definition or duty affected; current reporting route; status of any case-specific order; and a correction history. Each field should link to the authoritative record and preserve the version used for an operational decision.
For this event, the receipt would say: policy statement withdrawn; Commission statement dated 9 September 2026; 2021 interpretive document superseded; 16 CFR part 318 still live; 2024 amended rule effective 29 July 2024; current reporting route present; 2023 orders not addressed by the rescission. It would not assert that every old interpretation survived, that no compliance practice needs review or that enforcement intensity will stay constant.
This receipt is an editorial proposal, not an FTC requirement. Its method follows Heng Lu’s Policy Mirror by separating the speaker, claimed authority and supporting evidence. The running-code test asks whether an announced change altered an observable operating state. Why BTW Media Exists supplies the final restraint: report the institution’s position, but do not substitute it for the state of the rule, the form or the court record.
The FTC did make a governance choice. It reduced the number of documents through which the Commission expresses its position and moved readers toward a rule adopted through notice and comment. That can simplify authority. It can also remove explanatory emphasis that some readers found useful. Both effects are possible without pretending that withdrawal of guidance equals repeal of law.
Sources
- FTC — withdrawal announcement
- FTC — Commission statement rescinding the 2021 policy statement
- FTC — 2021 health-app policy statement
- Federal Register — 2024 final Health Breach Notification Rule
- eCFR — 16 CFR part 318
- FTC — Health Breach Notification Rule page
- FTC — current compliance guidance
- FTC — GoodRx case record
- FTC — Easy Healthcare case record
- Heng Lu — The Policy Mirror
- Heng Lu — Running Code Primary
- Heng Lu — Why BTW Media Exists
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
