Your Telehealth Data May NOT Be Private

Woman on laptop having video call with doctor in home office
Photo: DC Studio / Shutterstock

In consumer telehealth, the most sensitive thing you trade isn’t your credit card — it’s the trail of signals your clicks, forms, and subscriptions emit. The hard lesson of recent enforcement is simple: if a platform embeds ad-tech the way an e-commerce site does, your health life can leak at Internet speed.

The Short Version

  • Regulators allege some telehealth firms shared sensitive health signals with advertising platforms via trackers and pixels despite privacy promises.
  • The legal risk isn’t abstract: the FTC and state partners have filed suit, citing deceptive privacy and cancellation practices.
  • Tracking technologies can expose inferences about conditions even without a formal diagnosis; design choices determine what escapes your screen.
  • You can materially reduce exposure: choose low-tracker providers, harden your browser, control consent, and use clean channels with your clinician.

What regulators are actually alleging — and why it matters

The most consequential development is not a think‑piece about data capitalism but a concrete enforcement move: the Federal Trade Commission, joined by Utah and by California through Los Angeles County Counsel, sued Hims & Hers, alleging it shared consumers’ sensitive health information with third‑party advertising platforms such as Meta and Snap while representing that its services protect privacy; the complaint also targets the company’s billing and cancellation design as deceptive negative‑option practices. These are not esoteric HIPAA disputes. They are classic deception claims: what you promised versus what your code and flows actually did. That posture matters because the law gives the FTC sharper tools when a company says one thing to consumers and builds another into production.

Why focus on “pixels” and “trackers”? Because tiny snippets of JavaScript embedded for analytics or ad attribution can exfiltrate page paths, form events, and identifiers. In a health context, page titles, URL parameters, or button clicks (“Start ED treatment,” “Acne consult”) can function as proxies for a condition. Academic work has shown that third‑party pixel use in patient‑data environments materially increases breach risk — not only through outright compromise but by expanding the surface area for unintended transmission and inference. Put bluntly: if your telehealth visit shares breadcrumbs with ad networks, your browser session may be telling on you.

How this data escapes: the mechanics in plain sight

Most consumer telehealth sites operate two data planes. The “clinical” plane (secure messaging, video consults, e‑prescribing) often lives behind authentication and is engineered to healthcare norms. The “growth” plane (landing pages, intake flows before a clinician is involved, subscription management, reminders) is commonly wired like a retail site: tags for analytics, conversion pixels, A/B testing SDKs, social sign‑ins. The alleged leakage tends to happen in that second plane. A Meta or Snap pixel fires when a user lands on a page tied to a specific therapy, or when an intake step is completed; hashed emails or device IDs can tie that event back to an advertising profile. Even if the company never exports a diagnosis code, the combination of page context and event timing can reveal plenty to a determined listener.

Negative‑option subscriptions introduce a second risk surface: cancellation friction. The FTC has been unambiguous that sellers must provide a simple mechanism to stop recurring charges; engineered hurdles — hidden buttons, long call trees, constrained windows — can move a routine subscription into unlawful territory. The Hims complaint alleges precisely this sort of friction, including obscured cancellation pathways even after an online option existed. Whether or not a given company ultimately prevails, the compliance signal for consumers is clear: don’t assume ease of sign‑up implies ease of exit.

What the company says — and how to read it

Hims & Hers publicly denied the allegations, arguing the FTC’s case disregards evidence provided during a multi‑year investigation, misreads industry norms, and that its privacy policy allows users to choose how their data is used while reserving clinical data exclusively for care. Terms posted by the company describe multiple cancellation routes — in‑app, account portal, help center, or phone — with timing requirements before renewal. These statements are material because they preview the defense: disclosure and choice. In deception law, disclosures are necessary but not sufficient; the question is whether a reasonable consumer, confronted with a site’s design and language, would be misled about what actually happens. That is the fight regulators have chosen to bring.

What you can do now: concrete protections that work

Shop for the right architecture. Before you ever create an account, evaluate the marketing site like a skeptical engineer. Load the homepage in a tracker‑blocking browser and check the console: do you see calls to multiple ad networks? Does the privacy policy commit to no third‑party tracking on pages where you discuss symptoms or begin intake? If you cannot quickly confirm a restrained tracking stack pre‑login, choose another provider. A growing set of telehealth operators advertise zero third‑party pixels on any health‑context pages for precisely this reason.

Control consent with real tools, not wishful thinking. Use browsers with built‑in tracking protection, DNS‑level blockers, or privacy‑oriented extensions that strip URL parameters and block known pixels. When a consent banner appears, reject non‑essential cookies; if the site walls off access without broad consent, that is itself a signal about priorities. For mobile apps, disable ad tracking at the OS level and decline analytics permissions when presented. Remember that “de‑identification” is less protective than it sounds when page context already signals your condition.

Keep the clinical channel clean — and separate from growth surfaces

Once you’re in care, communicate inside the platform’s authenticated, clinician‑facing tools — not over regular email, DMs, or social channels. The professional standard is that remote care must meet the same duty of care and privacy expectations as in‑person practice; providers should conduct robust consultations before prescribing and use secure systems for records and messaging. Ask your clinician’s office directly: are any third‑party trackers loaded in the patient portal? Are visit links routed through marketing shorteners? A provider that can answer these questions crisply is generally one that has thought through the risks.

Mind the subscription rails. If you opt into auto‑ship medications or membership fees, test the exit before you need it. Locate the cancellation control in your account, confirm the timing window, and screen‑capture the interface. The FTC’s Negative Option Rule and policy statements emphasize the right to a simple cancellation mechanism; if the only workable path is a phone call with limited hours, consider paying à la carte or choosing a provider with a one‑click stop in the portal. Calendar your renewal dates and follow up with a written confirmation if you cancel.

When to escalate — and to whom

If you suspect your health browsing is driving targeted ads, document it: save screenshots of the telehealth pages visited, note timestamps, and capture any subsequent ads that appear correlated. Submit a complaint to the FTC and your state attorney general; patterns across consumers often drive action. If you were billed after an attempted cancellation, dispute the charge with a record of your steps. Regulators have made clear they consider unreasonable cancellation barriers unlawful; the evidentiary burden is lighter when consumers keep their own paper trail.

Finally, distinguish promise from proof. Allegations are not adjudications, and companies will litigate both facts and law. But consumers do not need a final judgment to defend themselves effectively. The practical measures above — choosing low‑tracker providers, using hardened browsers, insisting on secure clinical channels, and verifying cancellation controls — reduce risk across platforms, regardless of which brand is in the headlines this month.

Bottom line

In telehealth, privacy is a design choice, not a press release. Look past slogans to the code paths and controls that govern your data. If a provider treats your first click like marketing inventory, take your care — and your trust — elsewhere.

Sources:

youtube.com, ftc.gov, cnbc.com, mcdermottlaw.com, npr.org, theregister.com, investors.hims.com