Telehealth Firms Face Scrutiny Over Health Data and Prescription Practices
The FTC has sued Hims & Hers and other telehealth companies over data sharing and subscription tactics, as experts warn HIPAA does not cover many online health services.
Online health services have proliferated since the COVID-19 pandemic, promising rapid access to prescriptions for conditions such as ADHD, anxiety, sexual dysfunction and weight loss. But regulators are increasingly challenging the business practices of these companies, alleging deceptive conduct that includes disclosing customers' health data, enrolling them in hard-to-cancel subscriptions and skipping real-time consultations with doctors.
The Federal Trade Commission's latest lawsuit accuses telehealth pioneer Hims & Hers of engaging in all of those tactics in violation of U.S. consumer protection laws. The company has disputed the claims, describing them as an effort to generate headlines at its expense.
In recent years, the FTC has brought similar cases against more than a half-dozen telehealth companies, including online therapy provider BetterHelp and pharmacy discount service GoodRx. In both instances, regulators said the companies shared users' health data with online platforms such as Meta and Google without obtaining permission.
Experts say a core part of the problem is that federal laws governing health information generally do not apply to telehealth companies. "There's an entire universe of companies collecting huge amounts of consumer health data every day that aren't covered by our current health sector-specific laws," said Andrew Crawford, an attorney with the nonprofit Center for Democracy and Technology.
Nearly all telehealth visits begin with a questionnaire in which users provide details about their medical history and possible medications they are interested in. According to the FTC's lawsuit, Hims customers were automatically enrolled and billed for recurring prescriptions with "virtually no opportunity to review the provider's recommended treatment."
Researchers have documented similar practices across the industry, even for injectable weight-loss drugs that typically require a physical exam and other precautions before treatment begins. A recent analysis of nearly 50 telehealth companies selling GLP-1 drugs found that less than a third actually required any real-time video or audio consultation with a physician. In some cases, prescriptions were approved within minutes.
"What we saw overwhelmingly was that it was incredibly easy to get access to the GLP-1s," said Dr. Reshma Ramachandran of Yale University, who led the study. "Most of the time, the prescription was automatically sent, without even an opportunity to stop the dispensing."
The absence of a real-time conversation means many patients are not receiving the type of care recommended by medical societies that prescribe GLP-1s, including discussions about weight-loss goals, past efforts and eating disorders. Only a little more than half the websites had a question about eating disorders — which GLP-1 drugs can induce or worsen — on their intake questionnaires, the researchers found.
Americans often assume that any personal health information they share is protected by HIPAA, the federal privacy law that governs the handling of medical information. But the law generally applies only to specific types of health businesses, including medical offices, hospitals and insurers, not telehealth companies offering prescriptions, counseling, DNA tests and other online services.
Privacy experts say that legal gap is one reason companies continue to disclose sensitive health information to advertisers and search engines. "There isn't a clear federal law saying: 'Don't do this,'" said Justin Brookman, Consumer Reports' director of technology policy. "There's just a body of soft law and settled cases with the FTC that many companies probably aren't even aware of."
Because HIPAA does not cover every direct-to-consumer health platform, the FTC has generally used its broader authority to take action against "fraudulent, deceptive or unethical business methods." In practice, that means showing that telehealth companies disclosed their customers' health information after initially saying they would not.
Hims told customers that its platform offered a "100% online, private and secure" means of sharing information with the company's medical professionals, according to the FTC complaint. But instead the company shared the data with Meta and other online platforms, the FTC alleges.
Still, experts say the penalties available to regulators are limited. In most cases, companies sign a legal agreement stating that they will stop the practices cited by regulators.
Lawmakers in California, Connecticut, Maryland and other states have passed new online privacy laws that include special protections for health information. But there has been little enforcement against telehealth companies that break those rules.
For now, privacy experts recommend using ad blockers and private web browsers — sometimes called "incognito" windows — when logging onto telehealth websites. Those tools can make it harder for companies to track location, online history and other personal information.
It is also a good idea to read any user agreements to get a sense of how the company plans to use personal data, Crawford said. Some telehealth sites, for example, explicitly state in their privacy policies that they have the right to sell data about users' sex lives.
The only surefire way to protect information may simply be to decline the terms of service, usually one of the first steps required before accessing telehealth.
"The system we have now overly burdens consumers to do a ton of work in terms of understanding how each piece of technology collecting their personal data is going to handle it," he said. "But even if you do all that work, you often have little agency."