การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Regulatory Updates

FTC Withdraws Obsolete 2021 Policy Statement on Health Apps Following Rule Modernization

FORTSECURE GLOBAL· 2026-09-11🛰 DataBreaches.net
#Regulatory Updates#Compliance#Privacy#Healthcare#Data Breach

The Federal Trade Commission has formally rescinded its 2021 policy statement regarding breaches in health apps, transitioning enforcement to the finalized Health Breach Notification Rule update.

The U.S. Federal Trade Commission (FTC) has officially rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. Initially issued to address regulatory gaps surrounding consumer digital health tools, the policy clarified that developers of health tracking applications and connected hardware were subject to the FTC's Health Breach Notification Rule (HBNR). Following the formal modernization of the HBNR in 2024, the commission determined that the interim policy statement had become redundant and could cause confusion among covered entities.

Evolution of Health Data Privacy Enforcement

Historically, consumer digital health applications fell into a legal gray area because many non-traditional wellness tools were outside the scope of HIPAA. The FTC utilized its 2021 policy to bridge this gap, asserting that unauthorized disclosures of health information—including tracking pixels sharing sensitive personal records with advertisers—constituted reportable breaches under the HBNR. With the codification of the revised rules in 2024, the updated HBNR explicitly incorporates direct-to-consumer health services, connected wellness trackers, and third-party data analytics pipelines into binding federal law.

Actionable Guidance for Digital Health Vendors

  • Review Third-Party Trackers: Audit tracking pixels, software development kits (SDKs), and embedded analytics across digital health platforms to avoid unauthorized dissemination of sensitive customer metrics.
  • Align Notification Workflows: Update corporate breach response plans to comply strictly with the updated HBNR timelines, ensuring regulatory reporting obligations are fully met.
  • Adopt Privacy-by-Design: Enforce strict data minimization policies and end-to-end encryption for all consumer health telemetry and cloud-stored records.

แหล่งที่มา: DataBreaches.net เผยแพร่ครั้งแรก: Thu, 10 Sep 2026 13:40:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: DataBreaches.net

เผยแพร่ครั้งแรก: Thu, 10 Sep 2026 13:40:00 +0000

บทความต้นฉบับ: https://databreaches.net/2026/09/10/ftc-withdraws-obsolete-policy-statement/

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog