Telehealth companies keep exposing their customers' medical data. What should they do?

WASHINGTON (AP) — The appeal of telehealth is easy to explain: Instead of calling a doctor, booking an appointment and hoping to eventually get a prescription, you can log onto an app or website and get approved for a new medication within minutes.

Since the COVID-19 pandemic, scores of online health services have launched with the promise of quick, convenient access to drugs for ADHD, sexual dysfunction, anxiety, weight loss and more.

Increasingly, though, government regulators are accusing these companies of deceptive, unethical business practices, including disclosing their customers’ health data, signing them up for hard-to-cancel subscriptions and bypassing real-time consultations with doctors.

The Federal Trade Commission’s latest lawsuit alleges that telehealth pioneer Hims & Hers engaged in all of those tactics, running afoul of U.S. consumer protection laws.

Hims has disputed the government's claims, calling them “an effort to generate headlines at our expense.”

In recent years, FTC officials have filed similar cases against more than a half-dozen telehealth companies, including online therapy provider BetterHelp and pharmacy discount service GoodRx. In both cases, regulators said the companies shared users' health data with online platforms such as Meta and Google, without getting permission.

Experts say part of the problem is that federal laws that govern the handling of health information generally don’t apply to telehealth companies.

“There’s an entire universe of companies collecting huge amounts of consumer health data every day that aren’t covered by our current health sector-specific laws,” said Andrew Crawford, an attorney with the nonprofit Center for Democracy and Technology.

Here are some things to know before signing up for a telehealth service:

Don’t expect to actually talk to a physician

Nearly all telehealth visits begin with a questionnaire in which users provide details about their medical history and possible medications they’re interested in.

According to the FTC’s lawsuit, Hims customers were automatically enrolled and billed for recurring prescriptions with “virtually no opportunity to review the provider’s recommended treatment.”

Researchers have documented similar practices across the industry, even for injectable weight-loss drugs that typically require a physical exam and other precautions before beginning treatment.

A recent analysis of nearly 50 telehealth companies selling GLP-1 drugs found that less than a third actually required any real-time video or audio consultation with a physician. In some cases, the prescriptions were approved within minutes.

“What we saw overwhelmingly was that it was incredibly easy to get access to the GLP-1s,” said Dr. Reshma Ramachandran of Yale University, who led the study. “Most of the time, the prescription was automatically sent, without even an opportunity to stop the dispensing.”

The lack of a real-time conversation means many patients aren’t getting the type of care recommended by medical societies that prescribe GLP-1s, including discussions about weight-loss goals, past efforts and eating disorders.

Only a little more than half the websites had a question about eating disorders — which GLP-1 drugs can induce or worsen — on their intake questionnaires, the researchers found.

Your data may be shared with advertisers, social media companies and others

Americans often assume that any personal health information they share is protected by HIPAA, the federal privacy law that governs the handling of medical information. But the law generally only applies to specific types of health businesses, including medical offices, hospitals and insurers, not telehealth companies offering prescriptions, counseling, DNA tests and other online services.

Privacy experts say that legal gap is one reason companies continue to disclose sensitive health information to advertisers and search engines.

“There isn’t a clear federal law saying: ‘Don’t do this,’” said Justin Brookman, Consumer Reports' director of technology policy. “There’s just a body of soft law and settled cases with the FTC that many companies probably aren’t even aware of.”

Because HIPAA does not cover every direct-to-consumer health platform, the FTC has generally used its broader authority to take action against “fraudulent, deceptive or unethical business methods.” In practice, that means showing that telehealth companies disclosed their customers' health information after initially saying they wouldn't.

Hims told customers that its platform offered a “100% online, private and secure” means of sharing information with the company's medical professionals, according to the FTC complaint. But instead the company shared the data with Meta and other online platforms, the FTC alleges.

Still, experts say the penalties available to regulators are limited. In most cases, companies sign a legal agreement stating that they'll stop the practices cited by regulators.

Lawmakers in California, Connecticut, Maryland and other states have passed new online privacy laws that include special protections for health information. But there's been little enforcement against telehealth companies that break those rules.

Online privacy tools offer a bit of protection

For now, privacy experts recommend using ad blockers and private web browsers — sometimes called “incognito” windows — when logging onto telehealth websites. Those tools can make it harder for companies to track your location, online history and other personal information.

It's also a good idea to read any user agreements to get a sense of how the company plans to use your personal data, said Crawford. Some telehealth sites, for example, explicitly state in their privacy policies that they have the right to sell data about users' sex lives.

The only surefire way to protect your information may simply be to decline the terms of service, usually one of the first steps required before accessing telehealth.

“The system we have now overly burdens consumers to do a ton of work in terms of understanding how each piece of technology collecting their personal data is going to handle it,” he said. “But even if you do all that work, you often have little agency.”

___

The Associated Press Health and Science Department receives support from the Howard Hughes Medical Institute’s Department of Science Education and the Robert Wood Johnson Foundation. The AP is solely responsible for all content.

09/19/2026 08:00 -0400

News, Photo and Web Search