FTC Health Breach Notification Rule for Health Apps: What Startups Must Do After GoodRx and BetterHelp
The FTC's Health Breach Notification Rule covers non-HIPAA health apps — and enforcement is accelerating. After GoodRx, BetterHelp, and Premom, here's what health tech startups must do to comply.
Why HIPAA Isn't the Only Health Data Law That Matters
Most health tech founders we talk to assume one thing: if they're not a HIPAA-covered entity or business associate, health data privacy law doesn't apply to them. That assumption is wrong—and it's getting expensive. The FTC's Health Breach Notification Rule (HBNR), codified at 16 CFR Part 318, applies specifically to health apps and connected devices that fall outside HIPAA's scope. And the FTC has been aggressively enforcing it.
Three enforcement actions in 2023—against GoodRx ($1.5 million), BetterHelp ($7.8 million), and Premom ($100,000 initially, later increased)—sent a clear signal that non-HIPAA health apps are not operating in a regulatory vacuum. Then in 2024, the FTC finalized amendments that broadened the Rule's reach even further. If your startup collects health information from users and you're not covered by HIPAA, the HBNR likely applies to you. Here's what you need to know and what you need to do about it.
What Is the FTC Health Breach Notification Rule?
The Health Breach Notification Rule was originally issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act. It requires vendors of personal health records (PHRs) and related entities that are not covered by HIPAA to notify individuals, the FTC, and in some cases the media, when there is a breach of unsecured individually identifiable health information. The Rule is authorized under 42 U.S.C. 17937 and 17953.
For more than a decade after its enactment, the Rule sat largely dormant. That changed in September 2021, when the FTC issued a policy statement warning health app developers and connected device companies that they must comply with the HBNR. The FTC made clear that "health apps" — including fitness trackers, fertility trackers, mental health apps, and diet apps — are "vendors of personal health records" subject to the Rule. The enforcement actions followed within 18 months.
Who Triggers the HBNR? Which Apps Are Covered
The HBNR applies to "vendors of personal health records" and "PHR-related entities" that are not covered by HIPAA. Under the FTC's expanded interpretation, this covers a remarkably broad range of health tech products, including:
- Prescription discount apps (like GoodRx)
- Online therapy and mental health platforms (like BetterHelp)
- Fertility and ovulation tracking apps (like Premom)
- Fitness trackers and wellness apps that collect health data
- Diet and nutrition apps
- Sleep tracking apps and connected devices
- AI-powered symptom checkers and health chatbots
The key question is whether your app collects "identifiable health information" — data that relates to an individual's physical or mental health condition, treatment, or payment for healthcare — and whether you are not a HIPAA-covered entity or business associate. If you're a startup offering direct-to-consumer health services without billing insurance or partnering with covered providers, you almost certainly fall outside HIPAA and inside the HBNR's scope. We've written more about the HIPAA side of this equation in our guide to HIPAA and AI compliance for health tech founders.
The Enforcement Track Record: GoodRx, BetterHelp, and Premom
GoodRx: $1.5 Million and a Ban on Sharing Health Data for Ads
In February 2023, the FTC announced its first-ever enforcement action under the HBNR against GoodRx. The FTC alleged that GoodRx shared users' personal health information — including data about sensitive health conditions and medications — with third-party advertising platforms like Facebook and Google, despite telling users that their health information would be protected. GoodRx also displayed a "HIPAA Secure: Patient Data Protected" seal on its website, which the FTC said was misleading because GoodRx was not actually a HIPAA-covered entity.
The settlement required GoodRx to pay a $1.5 million civil penalty and prohibited the company from sharing health data with third parties for advertising purposes. The FTC also alleged that GoodRx violated the HBNR by failing to notify users when their health data was disclosed to these third parties — the unauthorized sharing itself constituted a "breach" requiring notification.
BetterHelp: $7.8 Million in Consumer Refunds
Just one month later, in March 2023, the FTC announced a settlement with BetterHelp, the online therapy platform. The FTC alleged that BetterHelp shared sensitive mental health information — including data about users' depression, anxiety, and therapy preferences — with advertising platforms including Facebook, Snapchat, Criteo, and Pinterest, despite promising users that their data would be kept private and confidential.
The settlement required BetterHelp to pay $7.8 million in consumer refunds — the first FTC health data settlement requiring direct refunds to affected consumers. BetterHelp was also banned from sharing health data with third parties for advertising. Notably, BetterHelp operated multiple sub-brands (Pride Counseling, Faithful Counseling, Teen Counseling) and the FTC found that data sharing occurred across all of them.
Premom: Fertility Data Shared with Chinese Analytics Companies
In May 2023, the FTC announced a settlement with Easy Healthcare, the developer of the Premom ovulation tracking app. The FTC alleged that Premom shared users' sensitive health data — including menstrual cycle information and ovulation tracking data — with third parties including Google, the marketing firm AppsFlyer, and two Chinese mobile analytics companies (Jiguang and Umeng). Premom had told users that it would "not, and will not, ever sell any information about users' health to third parties, nor do we share it for advertising purposes."
The settlement required a $100,000 civil penalty (later increased to $200,000) and permanently barred Premom from sharing health data with third parties for advertising. The data sharing only stopped when the Google Play Store notified Easy Healthcare that the sharing violated Play Store policies — not because the company self-corrected.
What the 2024 Final Rule Changed
In April 2024, the FTC finalized amendments to the HBNR that significantly expanded its scope and requirements. The final rule, published in the Federal Register on May 30, 2024, took effect 60 days after publication. Key changes include:
- Broadened definition of "health information" — The revised Rule makes clear that health information includes data collected through health apps, connected devices, and any technology that draws health inferences from user data.
- Clarified "breach" definition — The FTC confirmed that unauthorized sharing of health data with third parties — not just hacking incidents — constitutes a "breach of security" under the Rule. This is exactly what happened in the GoodRx, BetterHelp, and Premom cases.
- Updated notification requirements — New requirements for the content of breach notifications, including specific information that must be provided to affected individuals.
- Timeline changes — The revised Rule tightens the timeframe for issuing breach notifications.
- Expanded notification methods — The Rule now permits additional methods for notifying consumers of breaches, reflecting how people actually communicate today.
The FTC's message was unambiguous: "Protecting consumers' sensitive health data is a high priority for the FTC," said Samuel Levine, Director of the FTC's Bureau of Consumer Protection. "With the increasing use of health apps and connected devices, the updated HBNR will ensure it keeps pace with changes in the health marketplace" (HIPAA Journal, April 2024).
How HBNR Interacts with HIPAA and State Laws
The Federal Layer: HIPAA vs. HBNR
HIPAA and the HBNR are designed to be complementary, not overlapping. HIPAA covers health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically — and their business associates. The HBNR covers everyone else who handles identifiable health information. If your startup is a HIPAA-covered entity or business associate, the HBNR does not apply to you. If you're not covered by HIPAA but you collect health data from consumers, the HBNR is your primary federal health data breach notification obligation.
This distinction matters enormously for direct-to-consumer health apps. A telemedicine platform that bills insurance and partners with HIPAA-covered providers will be a business associate subject to HIPAA's Breach Notification Rule. A wellness app that users download directly, without going through a covered provider, will be subject to the FTC's HBNR instead. For a deeper dive on the HIPAA side, see our guide to negotiating HIPAA business associate agreements with digital health vendors.
The State Layer: Texas TDPSA and Other State Privacy Laws
On top of the federal framework, state privacy laws are creating additional obligations. Texas's Data Privacy and Security Act (TDPSA), effective July 1, 2024, classifies "health condition" data as "sensitive data" requiring explicit consent before processing. While HIPAA-covered entities are exempt from the TDPSA, non-HIPAA health apps operating in Texas are not — meaning a health app could simultaneously be subject to the FTC's HBNR and the TDPSA's consent and notice requirements.
The TDPSA gives Texas consumers the right to know what data is being processed, obtain their data, opt out of targeted advertising, correct errors, and delete their data. Violations are enforced by the Texas Attorney General. Similar comprehensive privacy laws in California (CCPA/CPRA), Washington (My Health My Data Act), and other states add further layers. For health tech startups, this means compliance is not a single-law exercise — it's a multi-law program that must account for federal, state, and FTC enforcement risk simultaneously.
AI Health Apps and the Expanding Scope of "Health Information"
The 2024 amendments to the HBNR arrive at a moment when AI-powered health apps are proliferating rapidly. Large language models (LLMs) that provide symptom checking, mental health support, medication management, or health coaching are increasingly common in the health tech ecosystem. These apps collect vast amounts of sensitive data — conversation logs, symptoms, medication histories, mental health disclosures — and often process that data through third-party AI APIs, cloud providers, and analytics platforms.
The FTC's expanded definition of "health information" means that inferences drawn from user data can trigger the HBNR even if users never explicitly provide a diagnosis. If your AI app collects sleep patterns, mood data, or symptom descriptions and then draws health-related conclusions, that data likely qualifies as identifiable health information under the Rule. And if that data is shared with a third-party LLM provider, advertising platform, or analytics tool without proper safeguards, the FTC has shown it will treat that sharing as a reportable breach.
This is particularly important for startups building AI health features. Passing user health data to a third-party AI API — even one that claims to be HIPAA-compliant — without a proper data processing agreement and user consent can create HBNR liability. We've explored the HIPAA side of AI training in our HIPAA and AI compliance guide, and many of the same principles apply to HBNR compliance: know where your data goes, get proper agreements in place, and don't share health data with advertising platforms under any circumstances.
Building a Compliance Program: Practical Steps
For health tech startups operating outside HIPAA, building an HBNR compliance program should be a priority — not an afterthought. Here are the practical steps we recommend:
1. Determine Whether the HBNR Applies to You
Conduct a formal assessment of whether your app collects identifiable health information and whether you're outside HIPAA's scope. If you offer direct-to-consumer health services without billing insurance or functioning as a covered entity's business associate, the HBNR almost certainly applies.
2. Map Your Data Flows
Document exactly what health data you collect, where it's stored, and — critically — who it's shared with. The GoodRx, BetterHelp, and Premom cases all involved sharing health data with advertising platforms and analytics tools. If your app uses SDKs from Facebook, Google, or other advertising platforms, check whether health data is being transmitted through those SDKs. Many startups are surprised to discover that their analytics or advertising SDKs are quietly exfiltrating health data.
3. Stop Sharing Health Data with Advertising Platforms
This is the single most important step. Every FTC enforcement action under the HBNR has involved sharing health data with advertising platforms. The FTC's position is clear: sharing identifiable health data with Facebook, Google, or any other advertising platform without explicit, informed user consent is both an FTC Act violation and an HBNR breach. If you're currently doing this, stop immediately.
4. Implement a Breach Response Plan
The HBNR requires notification to affected individuals and the FTC when a breach occurs — and "breach" includes unauthorized sharing, not just hacking. Your breach response plan should define what constitutes a breach, who is responsible for assessing and reporting it, and how notifications will be issued within the required timeframe. Under the revised Rule, notifications must include specific content elements and can be delivered through expanded methods.
5. Audit Your Privacy Promises
The FTC built its cases against GoodRx, BetterHelp, and Premom largely on the gap between what those companies promised users and what they actually did. Review your privacy policy, terms of service, and in-app messaging. If you say you protect health data, you must actually protect it. If you say you don't share health data, you must not share it. Misleading privacy claims are an independent FTC Act violation — they don't require a breach to trigger enforcement.
6. Account for State Privacy Laws
If you operate in Texas, California, Washington, or other states with comprehensive privacy laws, build your compliance program to satisfy the most stringent applicable requirements. The TDPSA's classification of health data as "sensitive data" requiring consent, combined with the HBNR's breach notification requirements, means Texas-based health tech startups face a particularly complex regulatory landscape.
7. Review Third-Party AI Integrations
If your app sends user health data to a third-party AI or LLM provider, ensure you have a data processing agreement in place that restricts the provider's use of the data. Even if the provider is "HIPAA-compliant," HBNR compliance requires you to ensure that health data shared with third parties is adequately protected and that users have consented to the sharing.
Actionable Next Steps
The FTC has made clear that HBNR enforcement is not a one-time event — it's an ongoing priority. The 2024 amendments expand the Rule's scope at exactly the moment when AI health apps are creating new categories of sensitive health data. For health tech startups, the path forward is straightforward but requires diligence:
- Audit your data sharing practices today. If you're sharing health data with advertising platforms, stop. This is the single highest-risk behavior the FTC has targeted.
- Conduct a formal HBNR applicability assessment. Document whether the Rule applies to your app and why. This will be critical if the FTC ever comes knocking.
- Update your privacy policy to match your actual practices. The gap between what you promise and what you do is the FTC's primary enforcement theory.
- Build a breach response plan that covers both security incidents and unauthorized data sharing — both trigger HBNR notification obligations.
- Get legal counsel involved early. HBNR compliance intersects with HIPAA, state privacy laws, FTC Act requirements, and increasingly, AI regulation. Building the right compliance framework from the start is far less expensive than retrofitting it after an enforcement action.
If your health tech startup is navigating HBNR compliance alongside HIPAA and state privacy laws, we can help you build a compliance program that covers all the bases — without over-engineering it for a company your size.
Wondering whether the FTC Health Breach Notification Rule applies to your health app? Promise Legal helps health tech startups build compliance programs that cover HIPAA, HBNR, and state privacy laws in one integrated framework.