FTC Health Breach Notification Rule: The Enforcement Teeth Most Fintechs Ignore
By the Legal Cyber Academy editorial team ·
The Rule That Reaches Beyond HIPAA
On April 26, 2024, the Federal Trade Commission's amended Health Breach Notification Rule took effect. The amendment, finalized in the Federal Register on May 13, 2024, significantly expanded the rule's scope — and a large portion of the companies now covered by it do not think of themselves as healthcare companies at all.
The Health Breach Notification Rule, codified at 16 C.F.R. Part 318, was originally issued in 2009 under the American Recovery and Reinvestment Act. Its core purpose: fill the gap left by HIPAA. HIPAA covers "covered entities" and their business associates. It does not cover apps, wearables, or fintech platforms that collect health data but have no relationship with a healthcare provider billing through insurance. The FTC Rule covers exactly that category.
Who Is Covered — and Why Fintech Sits Squarely in the Crosshairs
The rule applies to vendors of personal health records and related entities — defined terms that, after the 2024 amendment, explicitly include apps and services that draw health data from multiple sources, including data a user enters directly.
If your platform does any of the following, you should assume coverage applies and work backward from there:
- Allows users to log medications, symptoms, menstrual cycles, glucose readings, or mental health entries
- Aggregates health data from wearables (Fitbit, Apple Watch, continuous glucose monitors) to display spending patterns, insurance decisions, or wellness scores
- Offers a benefits or HSA management tool that receives health claims data
- Provides a "financial wellness" feature that cross-references health spending with income or credit data
The 2024 amendment clarified that a platform does not need to be primarily a health platform to be covered. If health information is collected and maintained, the rule analysis begins.
What Counts as a "Breach"
Under 16 C.F.R. § 318.2, a "breach of security" means unauthorized acquisition of identifiable health information. The 2024 amendment added unauthorized disclosure — meaning a vendor that shares or monetizes health data in a way users did not authorize may trigger notification obligations even without a traditional cyberattack.
This is a significant operational shift. A fintech platform that sells de-identified (but inadequately anonymized) health data to a third-party advertiser, or shares it with a data broker, now faces potential notification obligations — not just an FTC Act unfair-practices claim.
The Notification Obligations in Plain Terms
When a breach occurs, the rule requires:
Individual notice. Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. Notice must include a description of the breach, the types of information involved, steps the company is taking, and contact information for follow-up.
FTC notice. The FTC must be notified. For breaches affecting 500 or more individuals in a single state or jurisdiction, notice goes to the FTC no later than 60 days after discovery. For breaches affecting fewer than 500 individuals, the vendor must maintain a log and submit it annually to the FTC.
Media notice. For breaches affecting 500 or more residents of a single state or jurisdiction, the company must also provide notice to prominent media outlets in that state — a requirement borrowed from HIPAA's Breach Notification Rule and often overlooked by non-healthcare companies.
As of September 10, 2026, the FTC has not published a grace period or safe harbor for companies that self-identify as newly covered under the 2024 amendment. The rule applies, and the FTC has enforcement authority under Section 5 of the FTC Act.
What the FTC Has Actually Said
In its 2024 rulemaking statement, the FTC explained its view that the proliferation of health apps had outpaced the original rule's scope. The Commission pointed specifically to apps collecting sensitive reproductive health and mental health data as a policy driver. The statement is part of the public record in FTC File No. P145407.
The FTC has also brought prior enforcement actions under the FTC Act involving health data — including its 2023 action against GoodRx Holdings, Inc. (FTC Matter No. 2123033, settled February 2023), in which the Commission alleged unauthorized sharing of consumers' health information with advertising platforms. That action was not brought under the Health Breach Notification Rule, but the FTC's position in the rulemaking cited it as evidence of widespread industry practices it intended to reach.
Practical Steps for Platforms That May Be Covered
The compliance analysis is not optional if you handle health data. Here is where to start:
-
Map your data. Identify every field where health information is collected, stored, or transmitted. "Health information" under the rule is broader than a diagnosis — it includes any information linked to past, present, or future health conditions.
-
Review your data-sharing agreements. If you share data with analytics vendors, advertisers, or data brokers, assess whether each disclosure is within what users authorized. An unauthorized disclosure is a breach under the amended rule.
-
Build a breach response workflow specific to this rule. Your general incident response plan likely tracks your state breach notification obligations. The FTC's 60-day clock and the media notice requirement are separate obligations that need their own runbook entries.
-
Review your privacy policy against actual data practices. The FTC has consistently treated a gap between what a privacy policy says and what a company does as an unfair or deceptive act under Section 5 — independent of any breach.
-
Train your product and engineering teams. Data minimization decisions made by developers — what fields to collect, how long to retain them, what gets passed to third-party SDKs — are compliance decisions, not purely technical ones.
The Intersection With State Law
At least a dozen states, including California under the California Consumer Privacy Act (as amended by Proposition 24, the California Privacy Rights Act), Texas under the Texas Health Privacy Act (H.B. 300), and Washington under the My Health MY Data Act (effective for most businesses as of March 31, 2024), have enacted health-specific privacy laws with their own notification or consent requirements. These layer on top of the FTC Rule — they do not displace it.
For a fintech operating nationally, the compliance obligation is the FTC Rule plus any applicable state health privacy law. The FTC Rule sets a floor, not a ceiling.
If your platform sits at the intersection of financial services and health data, understanding the regulatory structure is essential before your incident response team is the one discovering you were covered all along. The Guide to Artificial Intelligence: Understanding the Technology and the Regulatory Developments course addresses how AI-driven data processing intersects with emerging regulatory obligations — relevant for any platform using machine learning to process user health inputs.
Go deeper — courses on this
Privacy LawUnderstanding the Right of Publicity in a Technology-Driven World
This seminar covers the right of publicity—an individual's control over commercial use of their name and…
Daniel B. Garrie · 1h
Cyber IncidentsGuide to Artificial Intelligence: Understanding the Technology and the Regulatory Developments
This course provides a practical overview of how artificial intelligence works, where it is already being…
Privacy Law2023 Year in Review: The State and Impact of the GDPR
Panelists provide an overview of the GDPR, its scope, and key exceptions, then walk through 2023…
Daniel B. Garrie
Keep reading
- GDPR Fines for AI Training Data: The Enforcement Gap Closing FastEuropean regulators are targeting how companies collect and use personal data to train AI models. Here is what that means for your complianc…
- NFT Royalty Disputes: Who Owns the Revenue Stream?On-chain royalty enforcement collapsed when major marketplaces bypassed creator fees in 2022–2023. Here is where the legal exposure sits tod…
- Rule 502(d) Orders: The Protection Most Litigants Never Ask ForAn FRE 502(d) order stops privilege waiver in every federal and state proceeding, not just this one. What belongs in it, and the drafting er…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.