The FTC Takes Back Its Health App Position (09/14/2026)
- › The FTC rescinded its 2021 policy statement extending the Health Breach Notification Rule to health apps and connected devices.
- › The PCI Security Standards Council published the Key Management and Operations Standard v1.0 for entities handling cryptographic keys.
- › A court upheld the False Claims Act's qui tam provisions, leaving the constitutional challenge alive but unresolved.
- › A hacking incident at Hawaii Family Dental affected nearly 46,000 people.
- › An analysis argues that human review of automated decisions frequently functions as a rubber stamp rather than as control.
A regulator withdrawing a position is a harder thing to plan around than a regulator taking one. The 2021 statement told health app makers that breach notification applied to them, and a great many of them built process on that reading. Rescinding it does not repeal the underlying rule, which leaves the obligation exactly where it was before somebody explained it.
Top 5 Critical Compliance Alerts
1. The FTC Withdraws Its Health App Breach Statement
The Federal Trade Commission rescinded the September 2021 policy statement that extended the Health Breach Notification Rule to health applications and connected devices, a reading that brought a large category of consumer health technology inside a rule most of those companies had assumed did not reach them. The rule itself still exists and the statement was interpretation rather than regulation, so the practical question is what enforcement posture replaces it. Anybody who wrote a notification procedure against that statement now owns an open question instead of a settled one. HIPAA Journal has the rescission.
Operator Note: If your breach notification playbook cites the 2021 statement by name, get counsel to tell you in writing what your obligation is now, because the playbook currently rests on a document that has been withdrawn.
2. The PCI Council Publishes a Key Management Standard
The PCI Security Standards Council released the Key Management and Operations Standard v1.0, defining security requirements, test requirements, and guidance for entities that use cryptographic keys. Key management has historically been the part of payment security handled by whoever set it up originally, documented informally, and audited by asking that person whether it was fine. A standard with test requirements attached turns that into something an assessor can examine, which is the point and also the part that will surprise people. PCI Security Standards Council has the publication.
3. Qui Tam Survives, and the Challenge Continues
A court upheld the False Claims Act’s qui tam provisions against a constitutional challenge, leaving the whistleblower mechanism intact while the broader legal question remains open and filings continue at pace. For any organization touching federal money, qui tam is the reason an internal complaint that goes unanswered can become a federal case brought by the person who raised it. The durability of that route is a live governance question rather than a legal curiosity. Corporate Compliance Insights has the analysis.
Operator Note: Measure how long an internal report sits before somebody answers it, because that interval is the window in which a complainant decides whether the internal route works.
4. Human in the Loop Is Frequently a Rubber Stamp
An analysis argues that the human review layer organizations place over automated decisions often fails to constitute meaningful control, since the reviewer lacks the time, the information, or the standing to overturn what the system proposed. Regulators increasingly accept human oversight as the mitigation that makes an automated process acceptable, which places real weight on whether the oversight is genuine. A reviewer approving four hundred items an hour is producing a record and not a decision. Corporate Compliance Insights has the argument.
5. Hawaii Family Dental Reports 46,000 Affected
A hacking incident at Hawaii Family Dental affected almost 46,000 individuals, disclosed alongside notices from several other providers. A dental practice group sits at a size where there is rarely a dedicated security function and almost always a full set of clinical records, which is the combination that keeps producing these numbers. The affected population is larger than the patient list of any single office in the group. HIPAA Journal has the disclosure.
Additional Compliance Alerts
Enforcement
- A firm paid $500,000 after ignoring its own compliance team: Independent Financial Group was censured over filing obligations its compliance function had flagged, which is the documented version of a recommendation that went nowhere. Compliance Building
- A Conti ransomware member drew four years: The sentence follows the case we covered last week and closes one thread in a long-running prosecution. HIPAA Journal
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.