How the FTC started fining health apps for feeding your data to advertisers
A dormant breach-notification rule became an enforcement tool in 2023, when the FTC fined GoodRx and BetterHelp for sharing users' health data with ad platforms. A 2024 rule change locked apps into its reach.
The Health Breach Notification Rule is a US regulation that requires makers of health apps and similar services not covered by HIPAA to tell users, and the government, when their identifiable health data is disclosed without authorisation [s3]. For more than a decade it was a dead letter — until, in 2023, the Federal Trade Commission used it for the first time to fine two of the best-known health apps in the country for quietly routing users' data to advertisers [s1][s2].
That shift is the story, because it changed what the rule is for. Written in 2009 and modelled on data-breach laws, it was assumed to cover the classic case: a hacker steals records. The FTC's 2023 enforcement treated a company's own decision to share health data with ad platforms as itself the reportable "breach" — a reading that turns a disclosure statute into a check on the everyday business of monetising health data [s1].
The two cases
On 1 February 2023 the FTC announced a proposed order against GoodRx, the prescription-discount and telehealth app, with a $1.5 million civil penalty — the agency's first enforcement action under the Health Breach Notification Rule [s1]. The FTC alleged GoodRx had promised users it would not share their health information, then shared prescription medications and health conditions with advertising platforms including Facebook, Google, Criteo, Branch and Twilio, and used the data to target users with ads on Facebook and Instagram [s1]. The proposed order permanently bars GoodRx from disclosing health data to third parties for advertising [s1].
A month later, on 2 March 2023, the FTC moved against BetterHelp, the online counselling service, requiring it to pay $7.8 million to be returned to consumers [s2]. The agency charged that BetterHelp had used and revealed consumers' email addresses, IP addresses and the answers to a mental-health intake questionnaire to Facebook, Snapchat, Criteo and Pinterest for advertising, after promising to keep that information private [s2]. The sensitivity is the point: the data described whether a person was seeking therapy, and for what.
Neither company admitted wrongdoing in settling, and the sums are modest against their revenues. What made the actions land was the precedent — a regulator demonstrating that sending health data to an ad network is enforceable, and expensive to defend.
Then the rule was rewritten to match
Enforcement built on a novel interpretation is fragile until the rule itself is updated, and in 2024 the FTC did that. Its final rule amending the Health Breach Notification Rule was published on 30 May 2024 and took effect on 29 July 2024, at 89 FR 47028 [s3]. The amendments were written to make explicit that the rule reaches health apps and connected devices, and that an unauthorised disclosure — not only a security intrusion — can trigger the duty to notify [s3]. The reinterpretation the GoodRx and BetterHelp cases relied on is now written into the text.
What it does, and what it still doesn't
It is worth being precise about the limits, because the rule is easy to oversell. A breach-notification rule governs disclosure after the fact: it can compel a company to report an unauthorised sharing and punish a failure to do so, but it does not, on its own, forbid an app from sharing data with advertisers in the ordinary course of business, provided it does so lawfully and discloses it [s3]. The bite in the GoodRx and BetterHelp cases came from the gap between what the companies promised and what they did — a deception the FTC could reach [s1][s2]. An app that is candid in its privacy policy about selling data is on firmer ground.
This is the same limit that runs through the patchy rules covering cycle-tracking apps, whose menstrual and pregnancy data mostly falls outside HIPAA, and through the finding that the health data your wearable generates isn't covered by the clinical-privacy law most people assume protects it. The through-line is that consumer health technology has grown up in the space between medical-privacy law, which does not reach it, and consumer law, which reaches it only case by case. The FTC's move partly closes that gap for breaches — and only for breaches.
Why it matters
Health apps of exactly the kind at issue here — a discount-drug service, a therapy platform — are used by tens of millions of people who reasonably assume "health" implies "confidential." These cases established that the assumption has some legal backing when a company breaks an explicit promise, and the 2024 rule extended that backing [s1][s2][s3]. They also mark out what is still legal: transparent data-sharing that a user technically consented to in a policy few read. The same tension shadows the newer frontier of remotely prescribed care that the site has tracked in telehealth prescribing rules, and the question of what a person is really consenting to inside a mental-health app.
What to watch
Whether the FTC keeps bringing Health Breach Notification Rule cases now that the amended rule is in force, or the pace slows; how the "unauthorised disclosure" standard is tested when a company points to consent buried in its terms; and whether any of this changes the default behaviour of the ad-tech trackers that sit, often invisibly, inside health apps.
This article is informational and is not medical advice.
Sources
- [s1] "FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising." U.S. Federal Trade Commission, news release, 1 February 2023. https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising
- [s2] "FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others for Targeted Advertising." U.S. Federal Trade Commission, news release, 2 March 2023. https://www.ftc.gov/news-events/news/press-releases/2023/03/ftc-ban-betterhelp-revealing-consumers-data-including-sensitive-mental-health-information-facebook
- [s3] "Health Breach Notification Rule." Final rule, Federal Register, 89 FR 47028, published 30 May 2024, effective 29 July 2024. https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule
Sources
- FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising — U.S. Federal Trade Commission , February 1, 2023
- FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others for Targeted Advertising — U.S. Federal Trade Commission , March 2, 2023
- Health Breach Notification Rule (final rule, 89 FR 47028) — Federal Register / U.S. Federal Trade Commission , May 30, 2024
What cycle-tracking apps do with your data, and the patchy rules that cover it
A review of 23 women's health apps found 87% shared user data with outside firms. The main US rule that covers them orders breach disclosure — it does not stop the sharing.
Your wearable's health data isn't covered by the law you think protects it
An audit of 17 manufacturers' privacy policies found transparency the weakest area, with wide variation between brands. The data these devices generate largely falls outside HIPAA and GDPR's clinical protections.
A hypnotherapy app for IBS helped patients. It could not prove it matched a therapist
In a 230-patient randomised trial, self-guided app hypnotherapy produced a 33% pain response versus 48% with an in-person therapist and 22% with education — falling short of non-inferiority.
The 'digital pill' that reports when you swallow it, and what it can't prove
Abilify MyCite embeds a sensor in an antipsychotic tablet to log each dose to an app. Nearly a decade on, its own FDA label still says it has not been shown to improve whether patients take their medicine.