Cerebral $500K Pixel Settlement: Telehealth Compliance Gaps That Caught the FTC
In April 2024, telehealth provider Cerebral agreed to a federal order requiring it to pay more than $7 million and accept a "first-of-its-kind" ban on using consumer health information for most...
In April 2024, telehealth provider Cerebral agreed to a federal order requiring it to pay more than $7 million and accept a "first-of-its-kind" ban on using consumer health information for most advertising purposes.[1] The Cerebral FTC settlement, often referenced alongside smaller per-violation HIPAA penalty calculations in the mid-six figures, is now a defining case study for every telehealth operator running pixels, tags, or session replay tools. According to the FTC complaint, Cerebral provided sensitive information of nearly 3.2 million consumers to third parties such as LinkedIn, Snapchat and TikTok by using or integrating tracking tools on its website or apps.[1]
This article walks through exactly what went wrong, what regulators are looking for next, and what telehealth pixel compliance looks like in practice so your marketing program doesn't end up on the FTC's docket.
The Current Enforcement Landscape
OCR Enforcement Trends
The Department of Health and Human Services' Office for Civil Rights (OCR) closed a near-record year of enforcement in 2024, including a $4,750,000 settlement with Montefiore Medical Center to resolve multiple HIPAA Security Rule violations.[2] Per OCR's own enforcement highlights, the agency has resolved the vast majority of the hundreds of thousands of HIPAA complaints it has received since the Privacy Rule took effect.[3] Per-violation exposure remains steep, with tiered civil monetary penalties that compound across pages, tools, and time when website tracking is involved.
FTC Involvement Driving the Cerebral FTC Settlement Template
The FTC has built a parallel enforcement track that reaches non-HIPAA-covered consumer health apps and telehealth platforms. BetterHelp set the template a year before Cerebral: the Federal Trade Commission finalized an order requiring online counseling service BetterHelp to pay $7.8 million and prohibiting it from sharing consumers' health data for advertising, resolving allegations the firm shared sensitive health data with third parties such as Facebook and Snapchat after promising to keep such data private.[4] For a deeper breakdown of that case, see our analysis of the BetterHelp FTC settlement.
Class-Action Lawsuit Explosion
OCR's 2022 tracking-technology guidance triggered a cascade of private litigation. The guidance triggered numerous class action lawsuits against HIPAA-regulated entities that had shared information collected via embedded online tracking technologies on both unauthenticated and authenticated webpages.[5] Settlement values have climbed quickly, with hospital and telehealth payouts producing substantial cumulative liability. Our healthcare pixel lawsuit tracker catalogs every disclosed settlement.
State-Level Actions
State attorneys general are filling enforcement gaps OCR can't reach. New York Attorney General Letitia James secured $300,000 from The NewYork-Presbyterian Hospital for disclosing the health information of individuals who visited their website. An investigation by the Office of the Attorney General found that the hospital used advertising tools on its website that collected and shared private and personal information with third-party tech companies when visitors used the website to search for doctors or book appointments, in violation of the Health Insurance Portability and Accountability Act.[6]
Specific Risks and Consequences of the Cerebral FTC Settlement Model
Financial Penalties
The financial stack of a tracking-technology violation typically includes several layers:
- OCR civil penalties: tiered penalties that compound across pages, tools, and time when website tracking is involved
- FTC monetary judgments: Cerebral faced a $2 million payment in lieu of a $10 million civil penalty, which the FTC suspended due to the company's inability to pay the full amount, plus just over $5 million for partial refunds to consumers impacted by deceptive cancellation practices[7]
- State AG penalties: $300,000 from the NY AG against NewYork-Presbyterian alone[6]
- Class-action exposure: Settlements in pixel-based healthcare class actions have ranged from seven figures into the tens of millions
- Breach response costs: Healthcare consistently ranks as one of the highest-cost industries for data breach response in annual industry reports
Reputational Damage
Cerebral was forced to file a breach notification covering its entire user base. In March 2023, Cerebral filed a notice with the Department of Health and Human Services acknowledging inappropriate use of tracking tools, affecting an estimated 3.2 million consumers. The company removed the tracking pixels, updated its privacy policies, and issued public statements of regret.[8] Once a breach involving 500 or more individuals is reported, it appears on OCR's public breach portal indefinitely.
Operational Disruption
FTC orders typically impose comprehensive program requirements that run for years. Cerebral was required to implement a "comprehensive privacy and data security program" addressing specific problems cited by the regulator; provide an easier method of canceling services; delete "most consumer data" not used for care or payment, unless it obtains user consent to data retention; and post a notification on its website informing users of the complaint's allegations and the proposed order's various requirements.[7] OCR corrective action plans similarly impose multi-year monitoring, training, and reporting cadences that consume internal resources well after the headline penalty is paid.
Personal Liability
The Cerebral case put executives directly in the line of fire. The complaint also charges Cerebral's former CEO, Kyle Robertson, alleging that he had "extensive personal involvement" in the teams and practices that led to the enforcement. However, according to the FTC's announcement, Robertson "has not agreed to a settlement and the charges against him will be decided by the court."[9] The FTC's willingness to name individual officers signals that "marketing did it" is no longer a defense at the C-suite.
How Violations Happen
Technical Configurations
Cerebral's failure mode is the canonical example of how pixels capture protected health information without anyone realizing. Cerebral utilized tracking tools (e.g., pixels) that collected and sent patients' PHI to third parties who used the PHI to provide advertising, data analytics, or other services to Cerebral. The data Cerebral sent included consumers' contact information, persistent identifiers, information about consumers' activities while using Cerebral's website and/or apps, and medical or mental health information disclosed by users when filling out Cerebral's mental health questionnaire or engaging with its website in ways that demonstrated interests in particular services and treatments. Per the complaint, Cerebral shared the sensitive information of nearly 3.2 million consumers with third party media and advertising platforms by using or integrating tracking tools on its website or apps.[9]
Most of these disclosures were not intentional configurations. Default pixel settings collect form fields, URL parameters, and button clicks. On a telehealth onboarding flow asking about depression, ADHD, or substance use, every default capture is a potential PHI transmission.
Vendor Relationships
The FTC's Cerebral order is explicit about why advertising platforms became liabilities: these tracking tools collect and send data to third parties so they can provide advertising, data analytics, or other services to the owner of the websites or apps.[1] Meta, Google, TikTok, Snapchat, and LinkedIn will not sign HIPAA business associate agreements for their advertising products. Sending PHI to them, even unintentionally, is therefore an impermissible disclosure on its face.
Staff Actions and Misleading Disclosures
Cerebral's compliance gap wasn't only technical. The complaint charges that Cerebral failed to clearly disclose that it would be sharing consumers' sensitive data with third parties for advertising and buried disclaimers about its data sharing practices in dense privacy policies. In fact, according to the complaint, the company claimed in many instances that it would not share users' data for marketing purposes without obtaining consumers' consent.[1] Misalignment between what marketing said in privacy policies and what pixels actually transmitted is precisely what the FTC frames as "deceptive."
Audit Triggers and Red Flags
Investigations are usually triggered by one of three events: a journalist or researcher pixel scan, a self-disclosed breach notification, or a consumer complaint. NewYork-Presbyterian's investigation, for example, was prompted in part by outside reporting on third-party tracking on hospital websites. For a broader pattern analysis of FTC telehealth actions, see our FTC telehealth enforcement breakdown.
Protection Strategies Inspired by the Cerebral FTC Settlement
Immediate Actions (This Week)
- Run a pixel audit on every page that collects, displays, or processes health information, including unauthenticated marketing pages tied to symptom or condition searches
- Inventory every third-party tag, including those installed via Google Tag Manager or A/B testing tools
- Compare what your privacy policy promises against what your pixels actually transmit
- Check whether any vendor handling identifiable data has signed a Business Associate Agreement (BAA)
Short-Term Fixes (This Month)
- Remove or reconfigure Meta Pixel, TikTok Pixel, and Google Ads tags on any page touching PHI
- Move to server-side tracking with PHI stripping before data leaves your environment
- Rewrite your privacy policy in plain language with explicit disclosure of any data sharing
- Train marketing, growth, and product teams on what constitutes PHI in a digital marketing context
Long-Term Compliance Infrastructure
The FTC's expectations are now codified into the Cerebral order itself, which permanently bans Cerebral from using or disclosing consumers' personal and health information to third parties for most marketing or advertising purposes, prohibits the company from misrepresenting its privacy and data security practices, and requires the company to implement a comprehensive privacy and data security program that addresses the specific problems outlined in the complaint.[1] Treat these requirements as the de facto compliance baseline, not just terms applied to Cerebral.
Vendor Evaluation Criteria
- Signed BAA: Non-negotiable for any vendor that touches identifiable data
- Server-side architecture: Data should be filtered before leaving your environment, not after
- PHI stripping logic: Vendor must demonstrate how it removes identifiers from event payloads
- Audit trails: You need documentation showing what was sent, when, and to whom
- Healthcare focus: Generic analytics vendors rarely understand the FTC/OCR overlap
How Curve Closes Each Gap Exposed by the Cerebral FTC Settlement
Curve was built specifically to prevent the failure modes that produced the Cerebral FTC settlement. Where Cerebral's pixels transmitted onboarding questionnaire answers, names, and prescription history directly to Meta and TikTok, Curve's architecture intercepts that data flow before any third party sees it.
- Automated PHI stripping: Curve removes identifiers and health indicators from event payloads at the server before forwarding conversion data to ad platforms. The kind of onboarding-form leak that drove the FTC complaint cannot happen in this architecture.
- Server-side tracking: Browser-based pixels are replaced with a server-side pipeline, eliminating the client-side data exfiltration vector that OCR and the FTC have prioritized.
- Signed BAAs included: Curve signs a Business Associate Agreement with every healthcare customer, providing the legal scaffolding that Meta, Google, and similar platforms refuse to offer.
- Audit trails: Every event Curve processes is logged, giving compliance officers the documentation needed to demonstrate that PHI did not leave the regulated environment, exactly the kind of evidence absent from the Cerebral record.
- Rapid implementation: Most healthcare advertisers can replace risky pixels in days rather than the months a custom in-house build would take.
Don't Wait for Enforcement
Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve.
Telehealth Pixel Compliance Self-Assessment Checklist
- We have inventoried every third-party tag, pixel, and script on our website and apps
- No pixels fire on pages containing condition information, symptom assessments, or appointment flows without server-side PHI filtering
- Our privacy policy accurately describes every category of third-party data sharing
- We have a signed BAA with every vendor that handles identifiable data
- We have documented, written consent (where required) before sharing any health information for marketing
- Marketing, growth, and product teams have received HIPAA and FTC Act training in the last 12 months
- We retain audit logs showing what data is sent to advertising platforms
- We have a documented incident response plan for tracking-technology breaches
- An executive owner is accountable for tracking-technology compliance
- We conduct a quarterly pixel audit, including after every site or funnel change
Frequently Asked Questions
What are the penalties for HIPAA marketing violations?
HIPAA penalties are tiered, with substantial annual maximums per violation category, and website violations multiply quickly across pages, tools, and time. On top of that, the FTC can pursue civil penalties and consumer refunds under the FTC Act and Health Breach Notification Rule. Cerebral's combined exposure exceeded $7 million,[1] and BetterHelp paid $7.8 million.[4]
Can healthcare practices be sued for using Meta Pixel?
Yes. OCR's 2022 tracking-technology guidance triggered numerous class action lawsuits against HIPAA-regulated entities that had shared information collected via embedded online tracking technologies on both unauthenticated and authenticated webpages.[5] Hospitals, telehealth platforms, and digital health apps have been named in many class actions since that guidance was issued.
How do I know if my healthcare marketing is compliant?
Three quick tests: (1) Does any pixel fire on pages tied to a condition, symptom, or appointment? (2) Does every vendor receiving identifiable data have a signed BAA? (3) Does your privacy policy match what your tags actually transmit? Failing any of these mirrors the gaps identified in the Cerebral and BetterHelp complaints.
What should I do if I discover a compliance violation?
Document the scope, stop the data flow immediately, evaluate breach-notification obligations under HIPAA and the Health Breach Notification Rule, and engage privacy counsel before issuing public statements. Cerebral and Monument both self-reported tracking-related disclosures to OCR, which is generally viewed more favorably than waiting for a regulator-initiated investigation.
Are advertising platforms like Meta and Google liable too?
Regulators have so far focused enforcement on the healthcare entity that deployed the tracker, not the ad platform. That puts the entire compliance burden on the telehealth operator, even when defaults built into the tracking tool drive the violation.
Sources
- FTC Press Release: Proposed FTC Order Will Prohibit Telehealth Firm Cerebral from Using or Disclosing Sensitive Data for Advertising Purposes
- HIPAA Journal: State of HIPAA
- HHS OCR Enforcement Highlights
- FTC: Final Approval of Order Against BetterHelp
- Ropes & Gray: Federal Judge Vacates Key Points of OCR Tracking Technology Guidance
- New York Attorney General: $300,000 Settlement with NewYork-Presbyterian Hospital
- Fierce Healthcare: Cerebral Agrees to $7M Settlement with FTC, DOJ
- Choosing Therapy: Cerebral Controversy, News & History
- Covington Inside Privacy: FTC Health Privacy Enforcement Against Cerebral
Related articles
- ArticleIntroducing HIPAA-Compliant Session Recordings | Plus: Cerebral's $500K Pixel Settlement & Meta Policy Changes
- GuideState Attorneys General Are Joining Federal Pixel Cases: California and Utah in the Hims Complaint
- GuideBetterHelp FTC Settlement: 5 Privacy Mistakes Every Therapy Platform Must Avoid in 2026
- GuideWhat DTC Telehealth Brands Must Change After the FTC's Hims and Hers Lawsuit
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit