Government Regulations, Privacy, Compliance Management, Breach

FTC withdraws health app data breach notification policy

The Federal Trade Commission has rescinded a policy statement that previously extended federal data breach notification regulations to health and fitness apps. The commission cited the policy's minimal benefit and its supersession by rulemaking as reasons for the withdrawal, aligning with a deregulatory agenda, following insights from cyberscoop.

The original policy, enacted during the Biden administration, aimed to include health apps, fitness trackers, and other connected devices under regulations requiring companies to disclose health-related data breaches to consumers. This would have covered vendors of personal health records containing individually identifiable health information. The rule also mandated automatic notification for security breaches, including unauthorized disclosure of sensitive health information to third parties.

The FTC had previously stated its intention to enforce this rule, citing gaps in major health privacy laws like HIPAA. However, the commission recently voted unanimously to rescind the policy. This shift occurred after a change in FTC commissioner composition, with Republican appointees now forming the majority. The withdrawal is seen as a move towards deregulation, impacting how health and fitness app companies handle and report data breaches.

Source: cyberscoop

You can skip this ad in 5 seconds