Telehealth companies keep exposing their customers' medical data. What
should they do?
[September 21, 2026]
By MATTHEW PERRONE
WASHINGTON (AP) — The appeal of telehealth is easy to explain: Instead
of calling a doctor, booking an appointment and hoping to eventually get
a prescription, you can log onto an app or website and get approved for
a new medication within minutes.
Since the COVID-19 pandemic, scores of online health services have
launched with the promise of quick, convenient access to drugs for ADHD,
sexual dysfunction, anxiety, weight loss and more.
Increasingly, though, government regulators are accusing these companies
of deceptive, unethical business practices, including disclosing their
customers’ health data, signing them up for hard-to-cancel subscriptions
and bypassing real-time consultations with doctors.
The Federal Trade Commission’s latest lawsuit alleges that telehealth
pioneer Hims & Hers engaged in all of those tactics, running afoul of
U.S. consumer protection laws.
Hims has disputed the government's claims, calling them “an effort to
generate headlines at our expense.”
In recent years, FTC officials have filed similar cases against more
than a half-dozen telehealth companies, including online therapy
provider BetterHelp and pharmacy discount service GoodRx. In both cases,
regulators said the companies shared users' health data with online
platforms such as Meta and Google, without getting permission.

Experts say part of the problem is that federal laws that govern the
handling of health information generally don’t apply to telehealth
companies.
“There’s an entire universe of companies collecting huge amounts of
consumer health data every day that aren’t covered by our current health
sector-specific laws,” said Andrew Crawford, an attorney with the
nonprofit Center for Democracy and Technology.
Here are some things to know before signing up for a telehealth service:
Don’t expect to actually talk to a physician
Nearly all telehealth visits begin with a questionnaire in which users
provide details about their medical history and possible medications
they’re interested in.
According to the FTC’s lawsuit, Hims customers were automatically
enrolled and billed for recurring prescriptions with “virtually no
opportunity to review the provider’s recommended treatment.”
Researchers have documented similar practices across the industry, even
for injectable weight-loss drugs that typically require a physical exam
and other precautions before beginning treatment.
A recent analysis of nearly 50 telehealth companies selling GLP-1 drugs
found that less than a third actually required any real-time video or
audio consultation with a physician. In some cases, the prescriptions
were approved within minutes.
“What we saw overwhelmingly was that it was incredibly easy to get
access to the GLP-1s,” said Dr. Reshma Ramachandran of Yale University,
who led the study. “Most of the time, the prescription was automatically
sent, without even an opportunity to stop the dispensing.”
The lack of a real-time conversation means many patients aren’t getting
the type of care recommended by medical societies that prescribe GLP-1s,
including discussions about weight-loss goals, past efforts and eating
disorders.
Only a little more than half the websites had a question about eating
disorders — which GLP-1 drugs can induce or worsen — on their intake
questionnaires, the researchers found.

[to top of second column]
|

The Hims website is displayed on a smartphone in Philadelphia on
Wednesday, Sept. 16, 2026. (AP Photo/Jonathan Poet)
 Your data may be shared with
advertisers, social media companies and others
Americans often assume that any personal health information they
share is protected by HIPAA, the federal privacy law that governs
the handling of medical information. But the law generally only
applies to specific types of health businesses, including medical
offices, hospitals and insurers, not telehealth companies offering
prescriptions, counseling, DNA tests and other online services.
Privacy experts say that legal gap is one reason companies continue
to disclose sensitive health information to advertisers and search
engines.
“There isn’t a clear federal law saying: ‘Don’t do this,’” said
Justin Brookman, Consumer Reports' director of technology policy.
“There’s just a body of soft law and settled cases with the FTC that
many companies probably aren’t even aware of.”
Because HIPAA does not cover every direct-to-consumer health
platform, the FTC has generally used its broader authority to take
action against “fraudulent, deceptive or unethical business
methods.” In practice, that means showing that telehealth companies
disclosed their customers' health information after initially saying
they wouldn't.
Hims told customers that its platform offered a “100% online,
private and secure” means of sharing information with the company's
medical professionals, according to the FTC complaint. But instead
the company shared the data with Meta and other online platforms,
the FTC alleges.
Still, experts say the penalties available to regulators are
limited. In most cases, companies sign a legal agreement stating
that they'll stop the practices cited by regulators.
Lawmakers in California, Connecticut, Maryland and other states have
passed new online privacy laws that include special protections for
health information. But there's been little enforcement against
telehealth companies that break those rules.

Online privacy tools offer a bit of protection
For now, privacy experts recommend using ad blockers and private web
browsers — sometimes called “incognito” windows — when logging onto
telehealth websites. Those tools can make it harder for companies to
track your location, online history and other personal information.
It's also a good idea to read any user agreements to get a sense of
how the company plans to use your personal data, said Crawford. Some
telehealth sites, for example, explicitly state in their privacy
policies that they have the right to sell data about users' sex
lives.
The only surefire way to protect your information may simply be to
decline the terms of service, usually one of the first steps
required before accessing telehealth.
“The system we have now overly burdens consumers to do a ton of work
in terms of understanding how each piece of technology collecting
their personal data is going to handle it,” he said. “But even if
you do all that work, you often have little agency.”
All contents © copyright 2026 Associated Press. All rights reserved |