FTC Health Privacy Actions: A Reference List
Every major FTC health privacy enforcement action, the statute behind it, the penalty amount, and what each one tells you about advertising with health data.
The FTC has brought health privacy enforcement actions against Flo Health, GoodRx, BetterHelp, Easy Healthcare, Monument, Cerebral, Evoke Wellness, and Hims and Hers, with penalties ranging from $100,000 to $7.8 million, and it reaches companies HIPAA does not. The common allegation in almost every case is the same: health data was sent to advertising platforms after the company promised it would not be. Curve is HIPAA-compliant ad tracking with a signed BAA on every plan, built so what reaches an ad platform carries no health context in the first place.
What the FTC is actually enforcing
Four authorities do most of the work, and knowing which one applies to you changes what you have to worry about.
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices. In health privacy cases, the deception is usually a gap between a privacy policy and the actual data flow. Civil penalties under the FTC Act are capped at $53,088 per violation, a figure that carried into 2026 because the annual inflation adjustment was not made.
The Health Breach Notification Rule applies to vendors of personal health records and related entities that are not covered by HIPAA. Its central feature, confirmed by the 2024 amendments, is that a "breach" includes voluntary disclosures, not only intrusions. Sending data to an advertising platform on purpose can be a breach under this rule.
ROSCA, the Restore Online Shoppers' Confidence Act, governs negative-option and subscription billing. It appears in health cases because subscription telehealth companies are often charged with billing and privacy violations in the same complaint.
OARFPA, the Opioid Addiction Recovery Fraud Prevention Act, gives the FTC civil penalty authority over substance use disorder treatment and recovery services.
The reach point matters most. HIPAA applies to covered entities and their business associates. The FTC applies to companies making representations to consumers, which includes health apps, direct-to-consumer telehealth, digital therapeutics, and publishers, none of which may be HIPAA-regulated at all.
The reference list
- Flo Health, January 2021, order finalized June 2021. Section 5. The FTC alleged that the fertility tracking app shared health information from millions of users with Facebook, Google, and other analytics firms despite promising to keep it private. The order required affirmative consent before sharing health information, an independent privacy review, instructions to third parties to destroy the data received, and notice to affected users. It was the first FTC order requiring notice of a privacy action.
- GoodRx, February 2023, $1.5 million civil penalty. The first enforcement action ever brought under the Health Breach Notification Rule. The FTC alleged GoodRx disclosed personally identifiable health information, including prescription medications, to Facebook, Google, and other advertising platforms, and failed to notify consumers. The order bans GoodRx from sharing health data with third parties for advertising.
- BetterHelp, March 2023, $7.8 million. Section 5. The FTC alleged the online counseling service disclosed consumers' email addresses and health questionnaire responses to Facebook, Snapchat, Criteo, and Pinterest for advertising after promising confidentiality. The money went to consumer refunds rather than the Treasury.
- Easy Healthcare, May 2023, $100,000 civil penalty. The second Health Breach Notification Rule action. The FTC alleged the Premom fertility app used third-party software development kits that shared users' health information without adequate safeguards or notification.
- Monument, April 2024, $2.5 million civil penalty. Brought under OARFPA and Section 5. The FTC alleged the alcohol addiction treatment service disclosed users' health data to Meta and Google for advertising after promising confidentiality. The penalty was suspended based on inability to pay, and becomes due if the company misrepresented its finances. Monument is banned from disclosing health information for advertising.
- Cerebral, April 2024, more than $7 million in monetary relief and civil penalties. Privacy and cancellation practices in one action, with a further $8 million in penalties suspended for inability to pay. Cerebral had separately notified more than 3.17 million individuals of tracking-related disclosures covering October 2019 through January 2023.
- Evoke Wellness, June 2025, $1.9 million. Not a data-sharing case. The FTC alleged the substance use disorder treatment operator used deceptive Google search ads and telemarketing to impersonate other treatment providers. It is on this list because it shows the FTC will treat ad copy and search campaigns as enforceable conduct on their own.
- Hims and Hers, complaint filed July 29, 2026. The FTC, the State of Utah, and Los Angeles County filed in the Northern District of California under Section 5 and ROSCA. The complaint alleges the telehealth company shared customer lists identified by health condition or treatment type directly with Meta and Snap for targeted advertising, and that pixels and SDKs on its properties transmitted user events revealing engagement with health content. This is a pending complaint, not a resolved matter, and no penalty has been determined.
One adjacent action is worth knowing even though it is not an FTC case. In July 2025, the California Attorney General reached a $1.55 million settlement with Healthline Media, the largest CCPA settlement to date, over targeted advertising and health-related tracking. State attorneys general are increasingly running the same theory in parallel.
The three allegations that keep repeating
Across eight actions spanning six years, the substance barely changes.
The privacy policy said one thing and the tags did another. This is the deception. Not the sharing itself in most cases, but the mismatch between the promise and the data flow. Companies that never made a privacy promise are in a different position, and almost none of them exist.
The data was shared to buy advertising, not by accident. The FTC has been explicit that a voluntary disclosure counts. "We configured it that way on purpose" is not a defense, it is the finding.
Identity travelled with the health signal. Email addresses, hashed or otherwise, cookie identifiers, advertising IDs, and phone numbers are what turn a page view into a health disclosure about a specific person. The Hims and Hers complaint puts this in its starkest form: customer lists organized by condition, uploaded directly to ad platforms.
Being HIPAA-covered does not put you outside this
A common assumption is that HIPAA-covered entities answer to OCR and everyone else answers to the FTC. That is not how the jurisdictions work.
In July 2023, the FTC and OCR jointly sent letters to roughly 130 hospital systems and telehealth providers warning about the privacy and security risks of online tracking technologies. The FTC's half of that letter did not depend on HIPAA status. If a covered entity makes privacy representations to consumers, Section 5 applies to those representations independently.
The practical reading: a healthcare organization running ads can face an OCR investigation, a state attorney general action, a private class action, and an FTC inquiry over the same configuration, on four different legal theories, with four different remedies.
What the 2024 HBNR amendments changed
The amended Health Breach Notification Rule took effect on July 29, 2024, and it broadened the scope meaningfully. It reaches health apps, websites, and internet-connected devices holding health information. It confirms that unauthorized disclosures count as breaches even when voluntary. And it requires notification to the FTC for breaches involving 500 or more individuals contemporaneously with notice to individuals, without unreasonable delay and no later than 60 calendar days after discovery.
For a direct-to-consumer health business that has never considered itself regulated, that is the rule most likely to apply. Our write-up on how privacy, billing, and tracking end up in a single complaint covers how these theories get bundled, and our analysis of what changes for DTC telehealth after the Hims and Hers action goes deeper on the newest case.
How Curve changes what an ad platform receives
Every action on this list involves data reaching an advertising platform in a form that revealed something about a person's health. Curve is built so that does not happen, and the mechanism is worth being specific about.
Curve's tracking script installs in place of the Meta Pixel and Google tag, so events go to Curve's US-hosted infrastructure rather than directly to platforms that will not sign a BAA. From there, per-destination field mapping controls what forwards, and the default is that nothing does. A field reaches Meta only because someone mapped it to Meta. Identifiers are SHA-256 hashed per each platform's conversion API requirements. Neutral event aliases mean the platform receives a generic conversion name instead of the service line, so an ad account never displays a condition. PHI-pattern detection flags payloads containing PHI-shaped values so an upstream form change surfaces immediately.
Applied to the fact patterns above: a customer list organized by condition never gets assembled for upload, because segmentation stays inside a BAA-covered system. A page event on a treatment page forwards as a neutral conversion with a hashed identifier and no URL context. The privacy policy and the data flow can match, because the data flow is enumerated field by field rather than inherited from a tag's defaults. Curve includes a signed BAA on every plan, which is the contract the ad platforms themselves will not offer.
What to check against this list
Three questions, in order.
Does your privacy policy accurately describe every destination that receives user data today? Not the destinations you intended, the ones actually receiving traffic. Most gaps found in these cases were introduced by a tag manager change or a marketing tool added without review.
Does any list you upload to an ad platform imply a health condition through its membership? A custom audience named for a treatment is a health disclosure about everyone in it, regardless of what fields it contains.
Do your email and SMS tools sit under a BAA, and do their click and open events flow anywhere else? Our assessment of whether Klaviyo is HIPAA compliant for DTC health covers that layer, which is where several of these cases actually started.
Frequently asked questions
Does the FTC have jurisdiction over us if we are HIPAA-covered?
Yes, over your representations to consumers. HIPAA compliance does not immunize a privacy policy that misdescribes your data flows. The July 2023 joint letter to hospital systems and telehealth providers came from both agencies together for exactly this reason.
Is sharing data with an ad platform a "breach" if we did it deliberately?
Under the Health Breach Notification Rule, yes. The 2024 amendments confirm that unauthorized disclosures count as breaches even when they are voluntary. Intent goes to culpability, not to whether the rule was triggered.
Do these penalties get paid to consumers or to the government?
Both, depending on the authority. Civil penalties under the HBNR and OARFPA go to the Treasury. The BetterHelp $7.8 million was consumer redress. Several orders suspend the penalty for inability to pay while keeping the conduct bans permanent.
Are hashed email addresses safe to upload?
Hashing protects the value in transit. It does not change what membership in the list implies. If the list is defined by a health condition, uploading it is a disclosure about every person on it whether the emails are hashed or not.
What did the Hims and Hers complaint actually allege about tracking?
Two mechanisms. Customer lists identified by health condition or treatment type shared directly with Meta and Snap, and website tracking technologies including pixels and SDKs that automatically transmitted user events revealing engagement with health-related content.
Which of these orders bans advertising outright?
None. The bans are on disclosing health information to third parties for advertising purposes. Advertising continues under every one of these orders. What changes is what the ad platform is allowed to receive.
Where to start
Put your privacy policy next to a live network trace of your own site and read them against each other. That comparison is the case the FTC brings, and you can run it yourself in an afternoon. Then look at every audience you have ever uploaded to an ad platform and ask what its membership implies.
Our free compliance scanner identifies the tracking scripts currently live on your site, which is the fastest way to find the gap. To see how server-side tracking with a signed BAA changes what leaves your infrastructure, visit curvecompliance.com.
Reviewed August 2026. This is general information, not legal advice. Pending matters may resolve differently than filed, and penalty amounts reflect the orders as entered. Consult qualified counsel about your own obligations.
Related articles
- GuideFTC Healthcare Task Force 2026: What Every Healthcare Marketer Must Do Before Enforcement Begins
- GuideFTC Telehealth Enforcement: Recent Actions Against Virtual Care Advertising
- GuideBetterHelp FTC Settlement: 5 Privacy Mistakes Every Therapy Platform Must Avoid in 2026
- GuideSemaglutide Advertising Restrictions: FTC Enforcement Actions and Compliance Requirements
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit