Leak Customer Data or Go Dark: The Third Option Telehealth Teams Are Not Being Told
A Nixon Peabody alert on August 10 put the FTC at the center of tracking consent, not HHS. Growth teams responded by shutting tracking off, which stops new disclosures and leaves the old ones in place.

On August 10 the law firm Nixon Peabody published a client alert with a title that reads like a jurisdictional footnote: "FTC enters the conversation regarding consent for tracking technologies."
It is not a footnote. It is the clearest statement yet of which regulator owns your media plan.
The alert wraps the case filed at the end of July, when the Federal Trade Commission, the People of the State of California, and the Utah Division of Consumer Protection sued Hims & Hers Health, Inc. in the Northern District of California. The case number is 3:26-cv-7871. Hims has denied the allegations and intends to defend the case. Nothing has been proven. What is public is the theory, and the theory is what you plan around.
Why This Landed at the FTC and Not at HHS
Most direct-to-consumer telehealth is not a HIPAA covered entity and is not a business associate of one. No covered entity, no HHS enforcement. For years that gap was read as breathing room by growth teams and as a technicality by their lawyers.
Section 5 of the FTC Act does not care about the gap. Neither do California's Unfair Competition and False Advertising Laws or the Utah Consumer Sales Practices Act. Consumer protection law reaches the company whether or not the privacy rule does, and it reaches the marketing claims alongside the data practices.
The signal has been building for three years. The FTC and HHS sent a joint letter on July 20, 2023 to roughly 130 hospital systems and telehealth providers, warning specifically about tracking technologies. GoodRx settled in 2023 for 1.5 million dollars. BetterHelp settled the same year and ultimately paid 7.8 million. Those were negotiated resolutions announced alongside the complaints, which is a very different posture from a filed case with two states attached and their own penalty tracks.
The one line in the complaint that changes engineering decisions is paragraph 70. It names both the Meta Pixel and the Conversions API. Server-side moved the transport. It did not move the disclosure. If the payload still describes a person and a condition at the same time, the machine that sent it is not the question anyone is asking.
What Growth Teams Actually Did
They shut it off.
Hospital website pixel use reportedly fell from 98 percent in 2021 to roughly 30 percent in 2025, according to Bloomberg Law reporting by Christopher Brown. That is the slow institutional version, four years of legal review grinding a whole sector toward zero measurement.
The telehealth version of that took about ten days. Legal asks marketing a question after the Hims filing. Marketing cannot answer it with confidence, because nobody on the team has ever read the outbound payload field by field. The tag comes off the site by Friday.
Nobody in that room made a bad call. They were given two options and picked the only one a general counsel can sign. Keep sending everything and hope, or go dark.
What Going Dark Costs, and When
Meta's delivery system is a prediction engine. It decides who sees your ad by learning which people produced conversions, from the conversion events you send it. Remove the events and you have not made the optimization more conservative. You have removed the target.
What the system falls back on is whatever is left, which is usually link clicks or landing page views. Those are the cheapest actions to buy and the least correlated with revenue. Delivery drifts toward the audience most willing to click and least likely to complete an intake. Campaigns stop exiting learning. Cost per actual patient climbs while cost per reported click looks fine, which is the worst possible reporting shape because the dashboard stays green while the business does not.
Then the second problem arrives. You cannot tell your good creative from your bad creative anymore, so the next three production cycles are guesses. You cannot defend the budget in the quarterly review, because the only number you can produce is spend.
Here is the part that gets skipped. Going dark stops new disclosures. It does nothing about the ones already made, the custom audiences already built from condition-page visitors, or the privacy claims already sitting in your own ad copy and on your own homepage. Teams take the full revenue hit and keep most of the legal exposure. That is not a trade. That is paying twice.
The Third Option
Keep the conversion signal. Strip the health information before it reaches the ad platform.
Concretely, that means a server-side pipeline you control sitting between your site and Meta. It receives the event with everything your site knows. It removes or generalizes the fields that describe a condition: the URL path, the page title, the content category, the product or medication name, the free-text form values, the referrer that carries the condition in a query string. Then it sends the conversion.
Meta learns that a conversion happened, what it was worth, and which ad drove it. Meta does not learn what the person has. Optimization keeps working because optimization never needed the diagnosis. It needed the outcome and a match key.
Curve is a HIPAA-compliant conversion tracking platform built for exactly this problem, and a typical telehealth implementation goes live in under a week. That is the whole pitch. Back to the news.
One warning, because paragraph 70 exists. Renaming your event from "started_glp1_consult" to a neutral alias is real work, and it is not sufficient on its own. The condition can walk back into the payload through the page URL, the event source URL, the value tier that only one product line uses, or the audience rule you wrote in Ads Manager six months ago. If the platform can reconstruct the condition from what you sent, you did not strip anything. You renamed it.
What To Do This Week
Read one real payload. Not the tag manager configuration, not the vendor's architecture diagram. Capture an actual outbound event from a condition page and read every field. Most teams have never done this once. It takes twenty minutes and it settles the argument.
Audit the audiences separately from the pixel. A custom audience built from visitors to a specific treatment page is a list of people and their apparent condition, and it bypasses every consent banner you have. List uploads usually run on a different schedule, by a different person, with no review.
Decide who signs. If the answer to "is this payload safe to send" is currently nobody's job, that is the finding. Going dark is what happens by default when no one owns the question.
The Honest Version
The choice being presented to telehealth growth teams right now is between two bad outcomes: send health information to ad platforms and hope the FTC is looking somewhere else, or stop measuring and watch acquisition costs climb while the historical exposure sits untouched.
Both of those are failures of architecture, not failures of nerve. The data that makes Meta work and the data that makes a complaint readable are not the same data. They only travel together because nobody separated them.
If you want a second set of eyes on what your site is currently sending, and to which platforms, book a walkthrough. We will read the payload with you.
Related articles
- GuideGA4 Is Not HIPAA Compliant: 3 Analytics Alternatives That Are
- GuideWhy Healthcare Teams Are Switching from Freshpaint: The Analytics Gap
- GuideCustomer List Uploads Are a Health Privacy Risk: The Vector Most Marketers Never Audit
- GuideCookie Consent Banners vs HIPAA Authorization: Why They Are Not the Same Thing
Want to stay up to date on the latest in healthcare marketing?
Sign up for our newsletter to receive our articles directly in your inbox—covering compliance updates, platform changes, and industry insights.
We respect your privacy. Unsubscribe at any time.