BetterHelp's Privacy Mistakes: Lessons for Therapy Platforms
BetterHelp's $7.8M FTC settlement exposed therapy platform data sharing. Privacy mistakes, enforcement patterns, and compliance lessons for mental health providers.
The FTC's BetterHelp order, announced March 2, 2023 and finalized July 14, 2023, bans the online therapy company from sharing consumers' health data for advertising and required it to pay $7.8 million, after the FTC alleged it passed health information to Facebook, Snapchat and other platforms despite promising to keep it private. Curve Compliance helps therapy platforms and practices avoid that exposure by replacing pixels with server-side conversion tracking under a BAA on every plan. This landmark case highlights privacy mistakes therapy platforms must avoid.
Book a call. Not sure what your therapy practice's site shares with ad platforms? Curve's team will review it with you, and Curve Compliance keeps health data out of Meta and Google. Book a call with Curve.
The Current Enforcement Landscape
OCR Enforcement Trends
The Department of Health and Human Services Office for Civil Rights (OCR) has dramatically intensified HIPAA enforcement activities. OCR publishes each settlement and civil money penalty on its resolution agreements page, and it has made risk analysis failures a stated enforcement priority.
The most common violation categories include improper disclosure of protected health information (PHI), inadequate risk assessments, and insufficient business associate agreements. Mental health providers hold some of the most sensitive data HIPAA covers.
FTC Involvement
The FTC's involvement in healthcare privacy enforcement has expanded significantly through the Health Breach Notification Rule. This rule applies to personal health record vendors and related entities, including many mental health platforms that don't qualify as HIPAA-covered entities. BetterHelp was not charged under that rule; the FTC used Section 5 of the FTC Act, and the settlement shows its willingness to seek substantial monetary relief for privacy violations in the mental health space.
Samuel Levine, then Director of the FTC's Bureau of Consumer Protection, said BetterHelp "betrayed consumers' most personal health information for profit." The agency has issued guidance specifically targeting health apps and platforms that share data with advertising networks without proper disclosure.
Class-Action Lawsuit Explosion
Mental health providers face a surge in privacy-related class-action lawsuits. Since 2022, many healthcare organizations have been sued for allegedly sharing patient data with advertising platforms through tracking pixels and similar technologies, and some health system settlements exceed $10 million.
Notable settlements include Advocate Aurora Health's $12.225 million and Kaiser Permanente's $46 million (up to $47.5 million; settlement website) settlement over website and app trackers that sent data to Google, Microsoft and X. These cases establish precedent that using standard website tracking tools can create significant legal liability when PHI is involved.
State-Level Actions
State attorneys general have launched coordinated investigations into healthcare data sharing practices. In December 2023, for example, the New York Attorney General secured $300,000 from NewYork-Presbyterian Hospital over website tracking tools. State privacy laws like the California Consumer Privacy Act (CCPA) create additional obligations for businesses outside HIPAA, with administrative fines of up to $2,663 per violation or $7,988 per intentional violation since January 2025.
Multi-state investigations also occur, and they often result in consent decrees requiring ongoing compliance monitoring and substantial financial penalties.
If you run a therapy practice rather than a platform, see what the BetterHelp FTC settlement means for practices.
Specific Risks and Consequences
Financial Penalties
Mental health platforms face multiple layers of potential financial exposure. OCR civil penalties currently range from $145 to $2,190,294 per violation, with a calendar-year cap of $2,190,294 for identical violations (Federal Register, January 28, 2026). However, these statutory limits often pale in comparison to settlement amounts in practice.
Class-action settlements for large health systems have exceeded $10 million, and legal defense costs add to that.
State-level penalties vary significantly. California's CCPA allows administrative fines of up to $7,988 per intentional violation since January 2025 (it exempts PHI covered by HIPAA), while New York's SHIELD Act allows penalties up to $5,000 per violation plus costs. Texas Health and Safety Code violations can result in penalties up to $25,000 per violation for healthcare entities.
Reputational Damage
Privacy violations in mental health carry unique reputational risks due to the sensitive nature of psychological treatment. OCR's "Wall of Shame" lists breaches affecting 500 or more individuals, creating public records of compliance failures.
Media coverage of mental health data breaches generates significantly more negative attention than other healthcare violations. The BetterHelp settlement received coverage in major outlets including The New York Times, Wall Street Journal, and Washington Post, highlighting the platform's data sharing practices and creating lasting reputational damage.
Patient trust erosion after a privacy violation can cost a practice patients. Referral networks often distance themselves from providers involved in high-profile privacy cases, further impacting revenue.
Operational Disruption
Privacy investigations can create substantial operational burdens lasting many months. Organizations must dedicate significant staff time to document review, interview participation, and compliance program development. OCR investigations typically require production of thousands of documents and comprehensive policy reviews.
Corrective action plans mandated in settlement agreements often require fundamental changes to data handling practices. BetterHelp's order required a comprehensive privacy program, deletion of data shared with third parties, data retention limits, and affirmative express consent before sharing personal data.
Resource diversion during investigations frequently delays other business initiatives and strains operational capacity. Investigations can consume significant administrative time.
Personal Liability
Healthcare executives face personal liability when privacy violations involve knowing or willful conduct. HIPAA's criminal provision, 42 U.S.C. 1320d-6, sets fines up to $50,000 and one year in prison for knowingly obtaining or disclosing PHI, rising to $250,000 and ten years when the intent is to sell or use it for commercial advantage or malicious harm.
Corporate officers and directors may face personal exposure through derivative lawsuits alleging breach of fiduciary duty for inadequate privacy oversight. Professional liability insurance often excludes coverage for intentional regulatory violations, leaving executives personally responsible for defense costs and judgments.
State licensing boards increasingly pursue disciplinary action against healthcare professionals involved in significant privacy violations, potentially resulting in license suspension or revocation regardless of criminal prosecution outcomes.
How Violations Happen
Technical Configurations
Most privacy violations in mental health platforms stem from default configurations of popular tracking tools. The Meta Pixel, when installed with standard settings, automatically captures form submissions, page URLs, and user interactions that may contain PHI. Google Analytics 4 collects user identifiers and behavioral data that can be combined with other information to identify specific patients.
Form tracking implementations frequently capture sensitive information without proper filtering. Contact forms requesting symptoms, medication names, or treatment history transmit this data directly to advertising platforms when tracking codes are present. URL parameters containing appointment types, provider names, or service categories create additional exposure risks.
Third-party chat widgets, scheduling tools, and patient portals often include embedded tracking codes that share interaction data with multiple advertising networks. These tools may transmit information including appointment times, session durations, and referral sources that constitute PHI under HIPAA.
Vendor Relationships
Mental health platforms frequently misunderstand when vendors become business associates requiring signed agreements. Any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity must execute a business associate agreement (BAA) before accessing data. Marketing technology vendors rarely qualify for BAA execution, creating compliance gaps when PHI is shared.
Popular marketing platforms including Facebook, Google Ads, and TikTok do not sign BAAs for their advertising products, and Meta's Business Tools Terms tell advertisers not to send it health information. Yet many mental health providers continue sharing patient data with these platforms through tracking pixels and conversion APIs, creating direct violations of HIPAA's minimum necessary and permitted uses rules.
Subcontractor chains complicate vendor relationships further. Third-party marketing agencies often implement tracking codes without understanding healthcare compliance requirements, inadvertently creating data sharing arrangements that violate HIPAA and state privacy laws.
Staff Actions
Marketing teams frequently implement tracking technologies without understanding healthcare-specific restrictions. Staff members trained in traditional digital marketing may install Facebook Pixel, Google Analytics, or other tools using standard practices that violate healthcare privacy requirements. These implementations often occur without involving compliance or legal teams in the decision-making process.
IT departments may misconfigure tracking implementations by failing to exclude PHI from data collection. Default settings for popular analytics tools capture extensive user data, requiring specific configuration to avoid collecting protected information. Technical staff without healthcare experience may not recognize when collected data constitutes PHI.
Content management errors create additional risks when staff members include tracking codes in patient-facing materials. Patient portal pages, appointment confirmation emails, and treatment resources may contain embedded tracking technologies that share sensitive information with advertising networks.
Audit Triggers and Red Flags
Privacy violations often surface through patient complaints to regulatory agencies. Individuals who notice targeted advertisements related to their mental health treatment frequently file complaints with OCR, FTC, or state attorneys general. These complaints trigger investigations that uncover broader data sharing practices.
Competitor complaints represent another common audit trigger, particularly when businesses discover rivals using non-compliant marketing practices to gain competitive advantages. Industry competitors may file complaints alleging unfair business practices when organizations violate privacy rules while advertising services.
Data breach discoveries during security incidents frequently reveal ongoing privacy violations. When mental health platforms investigate security breaches, they often discover that patient data has been routinely shared with advertising platforms through tracking technologies, requiring disclosure under breach notification rules.
Protection Strategies
Immediate Actions This Week
Mental health platforms must immediately audit all current tracking implementations across their digital properties. This includes reviewing website analytics, advertising pixels, conversion tracking, and any third-party tools that collect user data. Document all discovered tracking technologies and their current configurations.
Review vendor relationships to identify which services may be receiving PHI without proper business associate agreements. Create a comprehensive inventory of all technology vendors, marketing agencies, and service providers that access patient-related data. Prioritize vendors receiving the most sensitive information for immediate evaluation.
Check for PHI presence in current marketing data by reviewing analytics platforms, advertising accounts, and conversion tracking data. Look specifically for patient names, appointment details, treatment information, or other identifiable health data that may have been inadvertently collected.
Short-Term Fixes This Month
Remove or reconfigure risky tracking implementations that cannot be made compliant. This may require disabling certain analytics features, removing advertising pixels, or implementing alternative measurement approaches that don't involve PHI collection. Prioritize changes that eliminate the highest-risk data sharing relationships.
Implement server-side tracking alternatives that provide marketing insights without sharing PHI with third-party platforms. Server-side solutions allow organizations to control exactly what data gets shared with advertising networks while maintaining measurement capabilities for marketing optimization.
Update privacy policies and patient notifications to accurately reflect current data practices. Many mental health platforms have privacy policies that don't match their actual data collection and sharing practices, creating additional FTC liability beyond HIPAA violations.
Long-Term Compliance Infrastructure
Develop a comprehensive compliance technology stack designed specifically for healthcare marketing needs. This includes implementing solutions that automatically strip PHI from marketing data, provide audit trails for all data sharing activities, and maintain documentation required for regulatory compliance.
Establish ongoing monitoring systems to detect when new tracking technologies are added to websites or patient-facing systems. Many violations occur when staff members add new tools without understanding compliance implications, making automated detection capabilities essential for maintaining compliant operations.
Create regular audit schedules with quarterly reviews of all marketing technology implementations, vendor relationships, and data sharing practices. Include compliance team members in all marketing technology decisions to ensure new tools meet healthcare privacy requirements before implementation.
Vendor Evaluation Criteria
Evaluate potential marketing vendors based on their ability to execute business associate agreements and demonstrate healthcare-specific compliance capabilities. Vendors unable to sign BAAs cannot receive PHI, limiting their utility for healthcare marketing applications that involve patient data.
Require SOC 2 certifications or equivalent security audits for all vendors handling patient-related information. These certifications demonstrate that vendors maintain appropriate security controls and undergo regular third-party assessments of their compliance programs.
Prioritize vendors with healthcare-specific experience and existing compliance frameworks designed for HIPAA-covered entities. These vendors understand the unique requirements of healthcare marketing and can provide solutions that meet both marketing objectives and compliance requirements.
How Curve Solves These Critical Compliance Challenges
Curve provides a comprehensive solution specifically designed to address the privacy risks that led to BetterHelp's $7.8 million FTC settlement. Our HIPAA-compliant tracking platform automatically strips protected health information from all marketing data before any external sharing occurs, eliminating the fundamental cause of most healthcare privacy violations.
The server-side tracking architecture ensures that sensitive patient information never reaches advertising platforms while still providing the marketing insights mental health practices need. This approach directly addresses the technical configuration issues that created liability for BetterHelp and hundreds of other healthcare organizations facing similar enforcement actions.
Curve includes signed business associate agreements as a standard feature, providing the legal protection required under HIPAA for any vendor handling patient data. Built-in audit trails document all data handling activities, creating the compliance documentation needed to demonstrate good-faith efforts during regulatory investigations.
Curve's team sets up compliant tracking for healthcare organizations in about a week, not the months a custom build takes, quickly reducing exposure to the types of violations that triggered the BetterHelp settlement. The platform is designed specifically for healthcare compliance requirements, ensuring that marketing measurement capabilities don't compromise patient privacy or regulatory compliance.
Essential Compliance Checklist for Mental Health Platforms
Technical Audit Requirements
- Inventory all tracking pixels and analytics codes across your digital properties
- Document what data each tracking tool collects and where it sends information
- Identify any tools collecting patient names, contact information, or treatment details
- Review URL structures for embedded PHI in page paths or parameters
- Check form submissions for automatic data capture to third-party platforms
Vendor Relationship Assessment
- List all marketing technology vendors currently receiving any patient-related data
- Verify which vendors have signed business associate agreements
- Identify vendors that explicitly cannot serve as business associates
- Review subcontractor relationships and data sharing arrangements
- Document the business purpose for each vendor relationship
Policy and Documentation Review
- Update privacy policies to reflect actual data collection practices
- Ensure patient notifications accurately describe data sharing activities
- Document the legal basis for all marketing data collection
- Create procedures for evaluating new marketing technologies
- Establish incident response plans for potential privacy violations
Ongoing Monitoring Requirements
- Implement quarterly audits of all marketing technology implementations
- Monitor for unauthorized tracking code additions
- Review vendor compliance certifications annually
- Track regulatory guidance updates affecting mental health providers
- Maintain documentation of all compliance improvement activities
Don't Wait for Enforcement Action
The BetterHelp FTC settlement demonstrates that privacy violations in mental health carry severe financial and reputational consequences. Mental health platforms cannot afford to wait for regulatory investigations to address compliance gaps in their marketing practices. Every day without proper privacy protections increases exposure to penalties that can exceed millions of dollars.
Schedule a Compliance Assessment with Curve to identify risks in your current marketing setup and implement solutions that protect both patient privacy and your organization's future.
Frequently Asked Questions
What are the penalties for HIPAA marketing violations?
HIPAA civil monetary penalties currently range from $145 to $2,190,294 per violation, with a calendar-year cap of $2,190,294 for identical violations (Federal Register, January 28, 2026). Class-action settlements over tracking pixels have ranged into the tens of millions for large health systems, such as Kaiser Permanente's $46 million (settlement website).
Can mental health practices be sued for using Meta Pixel?
Yes, mental health practices face significant lawsuit risk when using Meta Pixel or similar tracking tools that share protected health information. Since 2022, many healthcare organizations have been sued for sharing patient data with advertising platforms through tracking pixels, and settlements have reached tens of millions of dollars.
How do I know if my mental health marketing is compliant?
Compliant mental health marketing requires that no protected health information reaches advertising platforms or other third-party vendors without signed business associate agreements. You should audit all tracking pixels, analytics tools, and marketing technologies to ensure they don't collect patient names, contact information, treatment details, or other identifiable health data. Any vendor that cannot sign a business associate agreement should not receive patient-related information.
What should I do if I discover a compliance violation?
If you discover that your mental health practice has been sharing protected health information with advertising platforms or other unauthorized third parties, immediately stop the data sharing and consult with healthcare compliance counsel. You may need to conduct a formal risk assessment to determine if the violation constitutes a reportable breach under HIPAA. Document your discovery and remediation efforts, as good-faith compliance attempts can reduce penalties in enforcement actions.
Are mental health apps subject to HIPAA if they're not traditional healthcare providers?
Mental health apps may be subject to HIPAA if they qualify as covered entities or business associates, but many fall under FTC jurisdiction through the Health Breach Notification Rule instead. The BetterHelp settlement demonstrates that non-HIPAA mental health platforms still face substantial penalties for privacy violations. Apps that share sensitive health information with advertising platforms without proper disclosure face FTC enforcement regardless of their HIPAA status, with penalties potentially reaching millions of dollars.
What did the FTC order BetterHelp to do?
The final order bans BetterHelp from disclosing health data for advertising and from sharing personal information for re-targeting. It also requires affirmative express consent before disclosing personal information to certain third parties, a comprehensive privacy program, instructions to third parties to delete the data, and the $7.8 million payment (FTC, July 14, 2023).
Which mental health platforms has the FTC acted against for sharing health data with advertisers?
BetterHelp in 2023 (FTC), Cerebral in April 2024, whose proposed order bars using or disclosing sensitive data for advertising and requires it to pay $7 million (FTC), and Monument, an alcohol addiction treatment service, in April 2024 for allegedly disclosing users' health data to platforms including Meta and Google (FTC).
Does the BetterHelp order apply to my therapy practice?
The order binds BetterHelp. A therapy practice that is a HIPAA covered entity answers to HHS instead, and HHS says disclosures of PHI to tracking vendors for marketing without patients' authorization are impermissible (HHS). Curve Compliance keeps that information out of Meta and Google with server-side tracking under a BAA.
Sources
Primary sources for the platform rules and laws on this page, checked October 6, 2026:
Related articles
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Curve's team sets up HIPAA-compliant ad tracking for you, and most customers are live in about a week.
Book a free tracking audit