Telehealth companies face regulatory scrutiny as the Federal Trade Commission sues pioneer Hims & Hers over deceptive practices, including unauthorized medical data sharing and forced subscriptions. Because HIPAA privacy protections do not apply to direct-to-consumer online platforms, companies like BetterHelp and GoodRx have shared sensitive user data with Meta and Google. Additionally, a Yale study reveals that under a third of GLP-1 weight-loss telehealth sites require real-time physician consultations.
Telehealth data privacy violations
- ▪Some telehealth websites explicitly state in their privacy policies that they reserve the right to sell data regarding users' sex lives.
- ▪Telehealth companies have shared users' sensitive health data with online advertising and search platforms, including Meta and Google, without obtaining user permission.
- ▪Telehealth pioneer Hims & Hers allegedly shared customer health data with Meta and other online platforms despite promising a "100% online, private and secure" sharing process.
FTC enforcement actions against telehealth
- ▪The Federal Trade Commission has filed cases alleging unauthorized health data sharing against more than a half-dozen telehealth companies, including BetterHelp and GoodRx.
- ▪Hims & Hers disputed the Federal Trade Commission's lawsuit, characterizing the allegations as an effort to generate headlines at the company's expense.
- ▪The Federal Trade Commission filed a lawsuit against telehealth pioneer Hims & Hers alleging deceptive business practices, including unauthorized health data disclosure and hard-to-cancel subscriptions.
Deceptive telehealth business practices
- ▪The Federal Trade Commission's lawsuit alleges Hims & Hers automatically enrolled and billed customers for recurring prescriptions with virtually no opportunity to review recommended treatments.
- ▪Government regulators accuse telehealth companies of deceptive practices, including enrolling customers in hard-to-cancel subscriptions and bypassing real-time consultations with doctors.
Federal health privacy law gaps
- ▪Lawmakers in states including California, Connecticut, and Maryland have passed online privacy laws with health data protections, but enforcement against telehealth companies remains limited.
- ▪The Health Insurance Portability and Accountability Act (HIPAA) generally does not apply to telehealth companies offering direct-to-consumer prescriptions, counseling, or DNA tests.
- ▪Because the Health Insurance Portability and Accountability Act (HIPAA) does not cover direct-to-consumer health platforms, the Federal Trade Commission must rely on its broader authority to target fraudulent, deceptive, or unethical business methods.
Telehealth consultation quality concerns
- ▪A Yale University study of GLP-1 telehealth providers found that only slightly more than half of the analyzed websites included questions about eating disorders on intake questionnaires.
- ▪A Yale University study of nearly 50 telehealth companies selling GLP-1 weight-loss drugs found that less than one-third required real-time video or audio consultations with physicians.
Debatable claims
- ▪Telehealth platforms should be required to conduct real-time consultations before prescribing medications
- ▪HIPAA should cover direct-to-consumer telehealth companies
Story comments
Loading comments…