Jacksonville Telehealth Data Privacy Risks Exposed
Jacksonville residents using telehealth services may not realize their personal health information is being shared with advertisers and social media platforms without explicit consent. A growing number of online health companies are facing accusations of such data sharing, sparking significant privacy concerns.
The popularity of telehealth, which offers quick access to prescriptions for conditions like ADHD, sexual dysfunction, anxiety, and weight loss, has surged since the COVID-19 pandemic. However, federal regulators, including the Federal Trade Commission (FTC), are increasing their scrutiny of these companies for deceptive practices. These practices include disclosing health data, enrolling customers in difficult-to-cancel subscriptions, and bypassing real-time doctor consultations.
The FTC recently sued telehealth provider Hims & Hers, alleging the company engaged in these tactics and violated U.S. consumer protection laws. Hims disputes the claims, calling them "an effort to generate headlines at our expense." Previously, the FTC pursued similar cases against online therapy service BetterHelp and pharmacy discount service GoodRx, finding both companies shared users' health data with platforms like Meta and Google without consent.
An attorney with the Center for Democracy and Technology, Andrew Crawford, identified a gap in federal law as a key issue. He noted that health sector-specific laws like HIPAA generally do not cover many telehealth companies. HIPAA primarily applies to medical offices, hospitals, and insurers, leaving a large number of companies collecting extensive consumer health data unprotected.
This legal loophole leads many Americans to mistakenly believe their health information is protected by HIPAA when using direct-to-consumer telehealth platforms. Justin Brookman, Consumer Reports' director of technology policy, stated, "There isn’t a clear federal law saying: ‘Don’t do this.’" Instead, the FTC uses its broader authority to act against "fraudulent, deceptive or unethical business methods," typically by showing companies disclosed data after promising privacy.
For instance, the FTC complaint against Hims alleged the company shared data with Meta and other platforms despite assuring customers its service was "100% online, private and secure." Penalties for such violations often involve legal agreements where companies pledge to cease the cited practices.
Beyond data sharing, concerns also exist regarding the quality of care. Many telehealth visits begin with questionnaires and minimal real-time physician interaction. The FTC lawsuit against Hims noted customers were automatically enrolled and billed for recurring prescriptions with "virtually no opportunity to review the provider’s recommended treatment." A Yale University study found that less than a third of nearly 50 telehealth companies selling weight-loss drugs required a real-time video or audio consultation. Prescriptions were often approved within minutes, sometimes without discussing crucial factors like the potential for eating disorders, which GLP-1 drugs can induce or worsen.
Privacy experts recommend using ad blockers and private web browsers when accessing telehealth websites to protect personal information. Reading user agreements is also crucial, as some privacy policies explicitly state a company's right to sell data. Declining the terms of service may be the only guaranteed way to protect one's information.


Discussion (0)
Join the Conversation
No comments yet. Be the first to comment!