Skip to content
MarketScale
‹ Back to IndustriesHealthcare

BetterHelp & GoodRx Are a Good Lesson. The FTC Health Privacy Rule Will Come for You If You’re “Deceiving” Patients.

Health data privacy has a new enforcer in town. This year has been a year of federal crackdowns in the healthcare industry as digital health companies have faced the hammer of the Federal Trade Commission for allegedly sharing customers’ health data for advertising purposes. Last month, the FTC put GoodRx in its scopes for “failing…

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Share

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Request an invite

Health data privacy has a new enforcer in town. This year has been a year of federal crackdowns in the healthcare industry as digital health companies have faced the hammer of the Federal Trade Commission for allegedly sharing customers’ health data for advertising purposes. Last month, the FTC put GoodRx in its scopes for “failing to report its unauthorized disclosure” of personal health information with Big Tech giants Google and Facebook, landing on a $1.5 million civil penalty for the company. GoodRx is now prohibited from “sharing user health data” for advertising purposes, the first time the FTC and the Department of Justice have proposed an order like this, and one of few times the FTC’s health privacy rule, the Health Breach Notification Rule to be more precise, has been enforced in almost 15 years.

Though GoodRx admitted to no wrongdoing, the FTC is feeling eager to keep up the heat on supposed rule-breakers. At the beginning of March, the FTC announced another proposed order that would prohibit the online therapy company, BetterHelp, from “sharing consumers’ personal information with certain third parties for re-targeting.” This was after the FTC determined the company was “deceiving consumers after promising to keep sensitive personal data private.” In an even more unprecedented move, a first of its kind, the FTC is demanding BetterHelp pay its customers back to the tune of $7.8 million. The mental health company acknowledged that it had reached a settlement regarding alleged practices and denied any wrongdoing as well.

There has been quite an increase in data privacy lawsuits in the healthcare and technology sectors in recent years. So, what does the renewed enforcement of the FTC Health Breach Notification Rule mean for digital health companies that rely on consumer information for sustaining their business model?

Melanie’s Thoughts

How can companies maneuver the FTC’s new standards of enforcement while also doing their due diligence to protect customers’ health data? Melanie Musson, healthcare and insurance writer with Clearsurance, shares her thoughts on how companies can move forward to reduce the risk of being in the line of fire of the FTC.

“The public has an idea of what HIPAA is, and for the most part, they think it’s just this broad brushed medical privacy thing. And so, they think anybody that they tell medical information to is going to keep it a secret because everybody is held legally to HIPPA.

So that’s kind of where this deception has come in, where the FTC has cracked down on companies for sharing information because the consumers believe that all their medical information is a secret, so they just give it. And so even though these companies may technically be complying with HIPAA, when they say that they’re HIPAA compliant, what that means to the consumer is that they won’t share information, but that’s not actually what it means to the company. So going forward, I think companies need to pay careful attention to what the FTC is doing.

They’re making an example of the people that are sharing information, kind of misleading the public. And so, I think that the main thing is not to mislead. If you’re going to share information that you can legally share, make sure that your customers understand that and agree to that. So don’t try to pretend like you’re not sharing any information and then share it.” 

Herman’s Thoughts

How can businesses that rely on consumer information as an essential revenue stream continue without running afoul of the FTC? Herman DeBoard III, CEO & co-founder of Huvr Inc. and a former program manager for the state immunizations department for the Center of Disease Control, offer his advice to those digital health companies looking to keep on the right side of the FTC.

“If you look at that rule, it refers to vendors of personal health records, and it requires them to notify consumers following a breach involving unsecured information. There appears to be no breach here. This looks like a case where one company was sharing user information with third parties so they could provide more targeted advertising to those people.

To me, this all goes back to HIPAA. Basically, if you’re a company that collects personal health data, like what prescriptions people are taking, you can’t say that you’re not going to share personal information and then turn around and sell it. So, my advice is, if you are collecting personal health data and plan to share or sell that data, first, get your attorney to add these scenarios to your terms of service and your privacy policy.

Second, in your app, give the users a chance to say, “Do not sell my information,” and make sure your code is honoring that. And if you’re still worried that there’s a legal issue, as long as you de-identify the records, removing information like patient names, locations, and phone numbers, you can give or sell the data to partners for research as much as you want to.

You just have to follow the letter of the law. My company is currently in 50 countries, and the privacy rules around the world are very different in each one. We live in a world where no one has any privacy whatsoever, yet privacy’s a very hot topic politically. So my advice to business owners is to make sure that you take the time to understand the privacy laws in the countries where you operate.

Communicate to your users exactly how you intend to use their information, and always give them the opportunity to opt out.”

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

AAO-HNSF hearing loss guideline moves audiograms and amplification into primary care

AAO-HNSF’s new age-related hearing loss guideline calls for screening adults starting at age 50 and escalating to otoscopy, audiogram, and appropriately fit amplification. It shifts hearing loss from “patient complaint” to a routine primary-care workflow. The pressure shows up in audiology capacity, referral design, and documentation standards.

  • 01Screening at age 50 becomes a repeatable workflow, so capacity planning shifts from episodic ENT referrals to steady primary-care volume, especially where annual wellness visits are a dominant access point.
  • 02The guideline’s escalation sequence, screen, otoscopy, audiogram, amplification, then cochlear implant candidacy evaluation, creates a measurable funnel that health systems can instrument in the EHR and manage like any other pathway.
  • 03Asymmetric loss remains a separate trigger for MRI in many settings, and 2026 pre-proof work using NHANES and SEER highlights why imaging criteria choices can swing scan volume, a budgeting and radiology access issue, not a clinical footnote.

Sep 7, 2026

ADHA shifts My Health Record to multi-supplier ops as Accenture signs new 3-year contract

ADHA shifts My Health Record to multi-supplier ops as Accenture signs new 3-year contract

Accenture will keep supporting Australia’s My Health Record under a new three-year contract. ADHA is moving the platform to a multi-supplier operating model. The shift raises questions about shared integration discipline, tooling, and accountability when changes hit production.

  • 01Multi-supplier delivery is spreading across national-scale health platforms, as ADHA's My Health Record shift shows, moving risk from vendor selection to integration, runbooks, and accountability.
  • 02GenAI model upgrades are arriving with healthcare-specific claims, but the procurement work moves to evidence, safety controls, and monitoring once models sit inside clinical workflows.
  • 03Embedded AI expands the cyber asset inventory problem: if teams cannot discover the AI components across endpoints and devices, they cannot reliably secure or audit them.

Sep 7, 2026

Hospitals need a shortlist as cardiology AI clearances hit 225

Hospitals need a shortlist as cardiology AI clearances hit 225

Cardiology now has 225 FDA-cleared AI algorithms when imaging is included. That volume is the problem. Health systems now need tighter governance, integration checks, and clinical workflow evidence to decide what ships.

  • 01The useful benchmark for governance committees is scale: FDA-cleared AI totals 1,524 overall, with radiology at 1,163 and cardiology at 225 when CV imaging is included, according to Cardiovascular Business.
  • 02Procurement risk is shifting from “is it cleared?” to “where does it run?” because new clearances span cath lab guidance, echo quantification, remote monitoring, and image assessment tools that touch different systems of record.
  • 03AliveCor shows the long game: Healio reported 510(k) clearance for an ECG AI suite in 2020, and Cardiovascular Business listed a new clearance in 2026, a reminder to vet update cadence and post-clearance support.

Sep 7, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512