/ THE SHORT ANSWER
No. The FTC says it withdrew the 2021 policy statement because the Health Breach Notification Rule was updated in 2024 to cover health apps and connected devices such as fitness trackers. Companies should rely on the current rule rather than treating the withdrawal as deregulation.
- 01The FTC rescinded a 2021 policy statement.
- 02The agency says the 2024 rule update already covers health apps and connected devices.
- 03The withdrawal does not by itself eliminate current breach duties.
- 04Teams should update playbooks and citations to the current rule.
/ dotSuper point of view
When a regulator removes guidance after codifying the underlying requirement, compliance teams must distinguish obsolete explanation from continuing legal duty.
What the FTC changed
The Federal Trade Commission has rescinded its 2021 policy statement on breaches involving health apps and connected devices. The agency describes that statement as obsolete after the Health Breach Notification Rule was updated in 2024.
The FTC says the current rule covers health apps and connected devices such as fitness trackers. The administrative withdrawal therefore changes the guidance record, not necessarily the underlying duties that apply under the amended rule.
- 2021 policy statement withdrawn
- 2024 rule update remains the current reference point
- Health apps and connected devices remain in scope according to the FTC
- Companies should remove stale policy citations
Why teams can misread the announcement
A headline about withdrawal can sound like a requirement disappeared. In this case, the FTC’s explanation is that later rulemaking made the earlier statement unnecessary.
Compliance teams should trace every alert to the operative rule, effective date, definitions, and enforcement guidance before changing controls. A press release is a starting point, not the complete legal analysis.
- Identify the exact legal instrument changed
- Check whether later rules replaced the guidance
- Review current definitions and notification triggers
- Document counsel’s interpretation before changing response plans
What health-product teams should review
Map consumer health information across apps, wearables, cloud services, analytics tools, advertising systems, support platforms, and vendors. Incident response should identify which systems can create a reportable unauthorized acquisition or disclosure.
Update contact lists, investigation evidence, notification templates, and vendor obligations. Test whether the organization can determine affected individuals and required notice timing under pressure.
- Maintain a health-data inventory and data-flow map
- Review third-party SDK and advertising access
- Define breach assessment and approval ownership
- Run a tabletop exercise using the current rule
What this page cannot conclude
- 01This article is not legal advice.
- 02Applicability depends on the product, data, entity, and facts of an incident.
- 03Organizations should review the current rule text and obtain qualified counsel.
Sources
- 01FTC withdraws obsolete policy statementFederal Trade Commission · accessed Sep 10, 2026
- 02Health Breach Notification RuleFederal Trade Commission · accessed Sep 10, 2026
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 10, 2026). FTC Withdraws Its 2021 Health App Breach Statement: What Still Applies. dotSuper. https://dotsuper.net/feeds/daily-briefing/2026-09-10-ftc-health-app-breach-rule-clarification
