BetterHelp $7.8M FTC Settlement: Mental Health Marketing Lessons for Therapy Practices
In March 2023, the Federal Trade Commission ordered online counseling service BetterHelp to pay $7.8 million and banned the company from sharing consumers' health data for advertising.[1] The...
In March 2023, the Federal Trade Commission ordered online counseling service BetterHelp to pay $7.8 million and banned the company from sharing consumers' health data for advertising.[1] The proposed order required the company to pay $7.8 million to consumers and marked the first Commission action returning funds to consumers whose health data was compromised, in a matter involving disclosures to third parties such as Facebook and Snapchat for advertising after the company promised to keep such data private.[1] The BetterHelp FTC settlement is now the template enforcers use against any therapy practice running digital ads. This article breaks down exactly how the violation happened, what the FTC and OCR have done since, and the specific controls therapy practices need in place today to avoid the next mental health marketing enforcement action.
The Current Enforcement Landscape After the BetterHelp FTC Settlement
OCR Enforcement Trends
HIPAA enforcement is accelerating, not slowing. The former OCR Director confirmed at the end of 2024 that 22 investigations of data breaches and complaints resulted in civil monetary penalties or settlements that year, making it one of the busiest years for HIPAA enforcement.[2]
The most-cited violation category is not what most marketing teams expect. OCR has publicly tied the Risk Analysis Initiative to a reported 264% increase in large breaches involving ransomware attacks since 2018, and inadequate risk analysis is the recurring finding driving these enforcement actions.[3] HHS OCR also reports that since the Privacy Rule took effect it has received hundreds of thousands of HIPAA complaints, with total civil penalties and settlements reaching well into the nine figures.[4]
FTC Involvement
The BetterHelp case was not an isolated FTC action. In the final order, the FTC charged that BetterHelp used and disclosed consumers' email addresses, IP addresses, and health questionnaire information to Facebook, Snapchat, Criteo, and Pinterest for advertising purposes despite promising consumers that it would only use or disclose personal health data for limited purposes.[5] The Commission has since brought parallel actions against several digital health vendors on similar theories under Section 5 of the FTC Act and the Health Breach Notification Rule.
Crucially, the FTC has dual jurisdiction with OCR over digital health vendors that fall outside HIPAA, and the agencies have coordinated directly. In July 2023, OCR and the FTC sent a joint letter to approximately 130 hospital systems and telehealth providers warning about the privacy and security risks of online tracking technologies, calling out Meta Pixel and Google Analytics by name.[6]
Class-Action Lawsuit Explosion
Private litigation has produced larger payouts than federal enforcement. Recent pixel-related settlements include:
- Advocate Aurora Health: A $12.25 million proposed settlement resolving a consolidated class action accusing the nonprofit system of sharing users' personal information without consent with third parties like Meta and Google through a tracking pixel.[7]
- MarinHealth: A $3 million settlement to resolve claims tied to Meta Pixel on its website between 2019 and 2025.[8]
- Eisenhower Medical Center: An $875,000 settlement resolving allegations that the facility used third-party tracking technology to share consumers' personal and protected health information with Facebook, Google, and others.[9]
- Additional recent settlements: A wave of similar resolutions has involved major health systems and dental groups settling website tracking claims.
For deeper analysis of these cases, see our Healthcare Pixel Lawsuit Tracker 2024-2026, which catalogs every settlement, amount, and lesson learned.
State-Level Actions
State attorneys general have become aggressive parallel enforcers. Attorneys general often choose to pursue financial penalties against HIPAA-regulated entities under state laws rather than HIPAA, because actions for state-law violations tend to be easier to win and the penalty structure may allow higher financial penalties.[2] Plaintiffs in pixel cases have also leaned heavily on state wiretapping and medical-confidentiality statutes such as the California Invasion of Privacy Act and the California Confidentiality of Medical Information Act.
Specific Risks and Consequences of a BetterHelp-Style FTC Settlement
Financial Penalties
Under the inflation-adjusted HHS civil monetary penalty schedule, therapy practices face substantial per-violation exposure across four tiers, with the top tier reaching $2,190,294 per violation and the same figure as the annual cap published in the Federal Register.[10] Key features of the current framework:
- Tier 1 (Did Not Know): $145 to $73,011 per violation.[10]
- Tier 2 (Reasonable Cause): $1,461 to $73,011 per violation.
- Tier 3 (Willful Neglect, corrected): $14,602 to $73,011 per violation.
- Tier 4 (Willful Neglect, not corrected): $73,011 to $2,190,294 per violation.
- OCR enforcement discretion: Since April 2019, OCR has applied lower annual caps for Tiers 1 to 3, which remain in effect unless superseded by rulemaking.[2]
- Class-action settlements: Recent pixel cases have ranged from under $1 million to over $12 million.
Reputational Damage
The BetterHelp matter reached a substantial number of consumers directly: the FTC and its refund administrator sent eligibility notices to roughly 800,000 people in connection with the 2023 settlement.[1] For a therapy practice, that level of patient-trust erosion is rarely recoverable. Breaches affecting 500 or more individuals are also posted publicly on the OCR breach portal, where they remain searchable indefinitely.[4]
Operational Disruption
Beyond fines, FTC orders impose lasting operational constraints. The final BetterHelp order requires the company to pay $7.8 million, prohibits it from sharing consumers' health data for advertising, and bans BetterHelp from sharing consumers' personal information.[5] OCR investigations typically conclude with multi-year corrective action plans that require external monitoring, policy rewrites, and recurring audits.
Personal Liability
Executives can be reached individually. The American Medical Association explains that directors, employees, or officers of a covered entity may also be directly criminally liable under HIPAA, that the DOJ has interpreted the "knowingly" element of the statute as requiring only knowledge of the actions that constitute an offense, and that individuals can be charged with conspiracy or aiding and abetting where they are not directly liable.[11]
How Violations Happen
Technical Configurations
The BetterHelp violations followed a familiar technical pattern documented in the FTC's complaint: the company disclosed users' email addresses, IP addresses, and detailed answers from intake questionnaires to advertising platforms including Facebook, Snapchat, Criteo, and Pinterest for targeted advertising and lookalike audience building, despite public promises of confidentiality.[5]
The technical mechanisms most commonly implicated:
- Meta Pixel default events: automatic capture of form field values, button clicks, and URL parameters.
- Google Analytics: client ID, IP address, and event parameters transmitted to ad accounts.
- Advanced Matching: hashed email and phone passed back for lookalike audiences.
- URL parameters: condition keywords, intake form IDs, and therapist names appearing in query strings.
- Session replay tools and chat widgets embedded directly in intake flows.
For mental health practices specifically, our guide on running compliant Meta campaigns for therapy and counseling practices details how to reconfigure these tools.
Vendor Relationships
The OCR position on vendor agreements is unambiguous. The agency's joint guidance with the FTC reiterates that HIPAA-regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to third parties, and that disclosures to tracking vendors generally require a HIPAA-compliant business associate agreement.[12] Meta, Google Ads, TikTok, and most major ad platforms refuse to sign BAAs, which is the structural reason their standard pixels cannot be used directly on therapy intake pages.
Staff Actions
Marketing teams installing pixels through Google Tag Manager, agency contractors deploying conversion tags without security review, and content managers cross-posting intake links to social platforms all create disclosure events. The BetterHelp record also shows that denying the practice publicly creates additional liability: the FTC charged that BetterHelp misled users and the public in 2020 by falsely denying news reports that it revealed consumers' personal information, including health information, to third parties.[1]
Audit Triggers and Red Flags
Investigations are typically triggered by patient complaints, journalist exposés (the original Markup reporting on Meta Pixel in hospitals seeded much of the current litigation wave), competitor referrals, or breach notifications. In late 2024 OCR launched its Risk Analysis Initiative; the first enforcement action was a $90,000 settlement with an Oklahoma county ambulance authority following a ransomware breach affecting roughly 14,273 patients.[3]
Protection Strategies Informed by the BetterHelp FTC Settlement
Immediate Actions (This Week)
- Inventory all tracking scripts on intake forms, therapist directories, condition pages, and the patient portal.
- Pull your BAA file and verify which marketing and analytics vendors have signed agreements.
- Run a network capture of an intake form submission to see what data is actually being transmitted to third parties.
- Freeze new pixel deployments until a compliance review is complete.
Short-Term Fixes (This Month)
- Remove direct Meta Pixel and standard GA4 tags from any page that handles symptom information, scheduling, or authenticated user data.
- Move to server-side tracking with PHI filtering before any data reaches an ad platform.
- Update your Notice of Privacy Practices and online privacy policy to reflect actual data flows.
- Train marketing and IT staff on the OCR tracking technologies bulletin and the BetterHelp FTC order.
Long-Term Compliance Infrastructure
OCR has signaled stricter prescriptive controls ahead. In late 2024, HHS proposed substantial Security Rule changes, and the OCR Director has stated that the agency will expand its risk-analysis enforcement initiative to include risk management as well.[2] Therapy practices should build for that direction now: documented risk analyses, vendor inventories with BAA status, encrypted data flows, and regular auditing of marketing-data exhaust.
Vendor Evaluation Criteria
- BAA availability: the vendor must sign a HIPAA-compliant BAA without carve-outs for advertising data.
- PHI handling: documented mechanism for stripping identifiers before transmission to ad platforms.
- SOC 2 Type II: independent attestation of security controls.
- Healthcare-specific design: not a general analytics tool with HIPAA marketing added on.
- Audit trails: exportable logs of what data was sent where, and when.
For therapy-specific implementation guidance, see Curve for Mental Health Practices: Privacy-First Marketing and our walkthrough on running Google Ads for therapists without triggering mental health policy rejections.
How Curve Addresses Each Risk Exposed by the BetterHelp FTC Settlement
Curve was built specifically for the failure modes the BetterHelp settlement exposed:
- Automated PHI stripping: Curve intercepts events server-side and removes the 18 HIPAA identifiers (including IP address, email, phone number, and intake answers) before any data reaches Meta, Google, or TikTok. This directly addresses the technical pattern that produced BetterHelp's $7.8 million penalty.
- Signed BAAs included: Every Curve account ships with an executed BAA, closing the vendor gap that the OCR-FTC joint guidance identifies as a primary HIPAA violation.
- Audit trails: Every event is logged with what was captured, what was stripped, and what was forwarded, producing the documentation OCR's Risk Analysis Initiative now requires.
- Healthcare-specific design: Conversion modeling, lookalike audiences, and campaign optimization continue working because Curve sends compliant signals, not raw PHI.
- Rapid implementation: Most practices reach compliant tracking within days rather than the months required to rebuild a stack from scratch.
For a deeper read on what BetterHelp specifically got wrong, see our companion analysis: BetterHelp FTC Settlement: 5 Privacy Mistakes Every Therapy Platform Must Avoid in 2026.
Don't Wait for Enforcement
Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve.
Self-Assessment Compliance Checklist
- We have inventoried every tracking script, pixel, and tag on our website and mobile app.
- We have a signed BAA with every vendor that touches PHI, including analytics and ad platforms.
- Our intake forms, scheduling pages, and patient portal do not load Meta Pixel, standard GA4, or TikTok pixel directly.
- We use server-side tracking with PHI filtering for ad platform conversions.
- Our Notice of Privacy Practices and online privacy policy accurately describe current data flows.
- We have completed a HIPAA Security Rule risk analysis within the last 12 months that specifically covers tracking technologies.
- Marketing, IT, and clinical staff have been trained on the OCR tracking bulletin and the BetterHelp FTC order.
- We maintain exportable audit logs of marketing data transmissions for at least six years.
- We have a documented incident-response plan for marketing-related data disclosures.
- We do not represent on our website that we "do not share" data while running pixels that share data.
Frequently Asked Questions
What are the penalties for HIPAA marketing violations?
Civil monetary penalties under the current HHS schedule are structured in four tiers, with the top tier reaching $2,190,294 per violation and the same figure as the annual cap published in the Federal Register.[10] OCR continues to apply its 2019 enforcement discretion that lowers annual caps for the three lower tiers.[2] The FTC can add separate Health Breach Notification Rule penalties, and class-action settlements in pixel cases have reached the eight-figure range.
Can healthcare practices be sued for using Meta Pixel?
Yes, and they have been, repeatedly. Recent settlements include $12.25 million from Advocate Aurora, $3 million from MarinHealth, and $875,000 from Eisenhower Medical Center, all involving Meta Pixel data sharing.[7][8][9] Plaintiffs typically bring claims under state wiretapping statutes, common-law invasion of privacy, and state consumer-protection laws rather than HIPAA directly.
How do I know if my healthcare marketing is compliant?
Two practical tests: (1) Open your intake form in a browser with network inspection on and submit a test entry. If you see requests going to facebook.com, google-analytics.com, or similar third-party domains carrying form values, email, or condition information, you have a problem. (2) Check whether you have a signed BAA with every vendor receiving that data. If either test fails, you are likely operating in violation of the OCR-FTC joint guidance on tracking technologies.[12]
What should I do if I discover a compliance violation?
Document the scope (what data, what dates, how many individuals), remove the offending tracking immediately, consult HIPAA counsel about breach notification obligations, and assess whether the FTC Health Breach Notification Rule applies. Do not deny the conduct publicly: the FTC cited BetterHelp's prior public denials as a separate violation in its complaint.[1]
Does the OCR tracking bulletin still apply after the AHA lawsuit?
Partially. A federal court ruled that one specific definitional combination (an IP address plus a visit to an unauthenticated public webpage addressing health conditions) exceeded HIPAA's statutory text and ordered HHS OCR to vacate that portion of its tracking guidance. However, the court did not address the bulletin's guidance on patient portals or other password-protected areas, so those aspects remain intact, and class-action plaintiffs continue to win settlements regardless of the bulletin's status.
Sources
- FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others for Targeted Advertising (FTC, March 2023)
- What are the Penalties for HIPAA Violations? 2026 Update (HIPAA Journal)
- OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative (HIPAA Journal)
- Enforcement Highlights (HHS OCR)
- FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising (FTC, July 2023)
- FTC and HHS Warn Hospital Systems and Telehealth Providers about Privacy and Security Risks from Online Tracking Technologies (FTC, July 2023)
- Aurora Health Agrees To $12.25M Settlement in Tracking Pixel Suit (Milberg)
- MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit (HIPAA Journal)
- California Teaching Hospital Settles Meta Pixel Data Breach Lawsuit (HIPAA Journal)
- Annual Civil Monetary Penalties Inflation Adjustment (Federal Register, January 28, 2026)
- HIPAA Violations & Enforcement (American Medical Association)
- FTC-HHS Joint Letter Gets to the Heart of the Risks Tracking Technologies Pose (FTC Business Blog)
Related articles
- GuideBetterHelp FTC Settlement: 5 Privacy Mistakes Every Therapy Platform Must Avoid in 2026
- GuideMental Health Facebook Ads: Compliant Meta Campaigns for Therapy and Counseling Practices
- GuideLearning from BetterHelp's $7M Fine: Prevention Strategies for Psychology Practices
- GuideThe Trade Desk Pixel and Healthcare Data: Lessons From the FTC's Hims and Hers Complaint
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit