Privacy & Data 6 min read

The FTC Withdrew the Health App Rule Medicare Cited in April

One federal agency rescinded the protection another had told seniors made its app library trustworthy. The library's vetting language has not caught up.

Priya Nair
Data, AI Governance & Policy Analyst
Published 13 Sep 2026, 7:44 AM (SGT)
Share:
Hands sorting tablets into a weekly pill organiser beside a phone showing a health app Hands sorting tablets into a weekly pill organiser beside a phone showing a health app Photo by cottonbro studio on Pexels
Advertisement

13 SEP 2026 — The United States Federal Trade Commission has rescinded the 2021 policy statement that extended its Health Breach Notification Rule to health apps and connected devices sitting outside HIPAA. The commission called the guidance obsolete and unnecessary. In April, a different federal agency told Medicare beneficiaries those protections were part of why its app library could be trusted.

What was withdrawn

HIPAA governs health data held by providers, insurers and their business associates. It does not reach a fitness tracker, a symptom checker, a fertility app or a sleep monitor, because none of those is a covered entity.

The 2021 statement closed part of that gap by reading the Health Breach Notification Rule to cover such apps and devices, obliging them to notify users when health information was exposed. Rescinding it removes that interpretation.

The commission's stated reasoning is that the guidance provided minimal benefit and had been superseded by later rulemaking. That is a substantive argument, not a dismissal; the rule itself was updated in 2024, so the question is whether the newer text does the work the statement was doing.

The Medicare App Library problem

The Centers for Medicare and Medicaid Services launched its Medicare App Library in April, and officials leading it cited the 2021 privacy protections as a pillar of the vetting that assured seniors the promoted apps were trustworthy.

Five months later, the agency that issued those protections has withdrawn them.

Whatever one thinks of the underlying policy, this part deserves attention. A federal programme recommended apps to an elderly population on the strength of a safeguard another federal body has now removed, and the recommendation still stands. Whether CMS revises its vetting language, and how quickly, matters more for the people using that library than the merits of the rescission do.

2021The policy statement now rescinded
April 2026Medicare App Library launched citing it
9 SepThe rescission
Outside HIPAAWhere these apps sit, and still sit

What still applies

Rescinding an interpretation is not the same as repealing a rule. The distinction affects any developer trying to work out their exposure.

The Health Breach Notification Rule still exists and was revised in 2024. State law still applies, and several states now have consumer health data statutes that reach further than the federal position ever did — which is the patchwork this leaves behind. General unfair-and-deceptive-practices authority also survives: an app that promises confidentiality and does not deliver it remains actionable on that basis alone.

The practical change is a loss of clarity. A developer reading the 2021 statement knew where they stood. Now, they have to work out whether the revised rule covers them, and users have less reason to expect a notification when their data leaks.

Why this reaches beyond the United States

Most health apps are not built for one jurisdiction. A sleep tracker sold in Singapore or Malaysia is usually the same binary as the one sold in Ohio, and its data practices are set once.

Developers generally build to the strictest regime they face and ship it everywhere, because maintaining separate data handling per market is expensive. Users benefit when the strictest regime tightens and lose when it loosens. A weakened United States floor becomes a weakened default for the app, and users elsewhere inherit it without any change to their own law.

Advertisement

The countervailing force in this region is that several regimes are moving the other way. PDPA in Singapore and Malaysia's amended act both reach personal data regardless of whether the holder is a healthcare provider, so an app operating here answers to them irrespective of what the FTC now says. The practical effect is not that protection disappears, but that it now varies more by jurisdiction.

What a user can do

Assume a health app outside your doctor's systems is not covered by medical privacy law, because it usually is not and now visibly is not in one major market.

The one setting worth checking is data sharing with third parties, which is where health app data generally goes — advertising and analytics partners rather than a breach. That is a disclosure question, not a notification question, and it was never what the rescinded statement governed.

For anyone using the Medicare App Library specifically: the vetting it advertises was described in terms of a protection that has since been withdrawn. Treat any listing there accordingly.

What to watch

Whether CMS updates the App Library's stated criteria. Track the gap between what that programme claims about safety and what currently backs the claim.

And whether states fill it. Consumer health data laws have been multiplying, and a federal step back is the condition under which that patchwork thickens rather than resolves.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement