{"id":6615,"date":"2023-02-13T18:31:00","date_gmt":"2023-02-13T18:31:00","guid":{"rendered":"https:\/\/www.dinsmore.com\/?post_type=publications&#038;p=6615"},"modified":"2025-11-24T20:36:52","modified_gmt":"2025-11-24T20:36:52","slug":"the-ftc-announces-first-health-breach-notification-rule-enforcement-action","status":"publish","type":"publications","link":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/","title":{"rendered":"The FTC Announces First Health Breach Notification Rule Enforcement Action"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" height=\"369\" width=\"1024\" src=\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?w=1024\" alt=\"\" class=\"wp-image-6621\" srcset=\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png 2084w, https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?resize=300,108 300w, https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?resize=768,277 768w, https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?resize=1024,369 1024w, https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?resize=1536,554 1536w, https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?resize=2048,738 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>On February 1, the Federal Trade Commission (\u201cFTC\u201d) <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/02\/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising\">announced<\/a> enforcement action for the first time under its Health Breach Notification Rule<a href=\"#_ftn1\" id=\"_ftnref1\">[1]<\/a>. The complaint against telehealth and prescription drug discount provider GoodRx Holdings Inc. (\u201cGoodRx\u201d), alleges its failure to notify consumers and others of its unauthorized disclosures of consumers\u2019 personal health information to Facebook, Google&nbsp;and other companies.<\/p>\n\n\n\n<p>In a first-of-its-kind proposed order, filed by the Department of Justice on behalf of the FTC, GoodRx will be prohibited from sharing user health data with applicable third parties for advertising purposes, and has agreed to pay a $1.5 million civil penalty for violating the rule. The proposed order must be approved by the federal court to go into effect. The Health Breach Notification Rule requires vendors of personal health records and related entities, which are not covered by the Health Insurance Portability and Accountability Act (HIPAA), to notify consumers and the FTC of unauthorized disclosures. In a September 2021&nbsp;<a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1596364\/statement_of_the_commission_on_breaches_by_health_apps_and_other_connected_devices.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">policy statement<\/a>, the FTC warned health apps and connected devices that they must comply with the rule.<\/p>\n\n\n\n<p>According to the FTC\u2019s&nbsp;<a href=\"https:\/\/www.ftc.gov\/system\/files\/ftc_gov\/pdf\/goodrx_complaint_for_permanent_injunction_civil_penalties_and_other_relief.pdf\">complaint<\/a>, for years GoodRx violated the FTC Act by sharing sensitive personal health information with advertising companies and platforms\u2014contrary to its privacy promises\u2014and failed to report these unauthorized disclosures as required by the Health Breach Notification Rule.&nbsp; Specifically, the FTC claims GoodRx shared personal health information with Facebook, Google, Criteo&nbsp;and others.&nbsp;According to the FTC, since at least 2017, GoodRx deceptively promised its users that it would never share personal health information with advertisers or other third parties. GoodRx repeatedly violated this promise by sharing sensitive personal health information\u2014such as including its users\u2019 prescription medications and personal health conditions.&nbsp;<\/p>\n\n\n\n<p>The FTC also alleges GoodRx monetized its users\u2019 personal health information, and used data it shared with Facebook to target GoodRx\u2019s own users with personalized health&nbsp;and medication-specific advertisements on Facebook and Instagram.&nbsp;<\/p>\n\n\n\n<p>The FTC further alleges that GoodRx:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Failed to Limit Third-Party Use of Personal Health Information:\u00a0<\/strong>GoodRx allowed third parties it shared data with to use that information for their own internal purposes, including for research and development or to improve advertising.<\/li>\n\n\n\n<li><strong>Misrepresented its HIPAA Compliance:\u00a0<\/strong>GoodRx displayed a seal at the bottom of its telehealth services homepage falsely suggesting to consumers that it complied with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), a law that sets forth privacy and information security protections for health data.<\/li>\n\n\n\n<li><strong>Failed to Implement Policies to Protect Personal Health Information<\/strong>: GoodRx failed to maintain sufficient policies or procedures to protect its users\u2019 personal health information. Until a consumer watchdog publicly revealed GoodRx\u2019s actions in February 2020, GoodRx had no sufficient formal, written, or standard privacy or data sharing policies or compliance programs in place.<\/li>\n<\/ul>\n\n\n\n<p>In addition to the $1.5 million penalty for violating the rule, the&nbsp;<a href=\"https:\/\/www.ftc.gov\/system\/files\/ftc_gov\/pdf\/goodrx_stipulated_order_for_permanent_injunction_civil_penalty_judgment_and_other_relief.pdf\">proposed federal court order<\/a>&nbsp;also prohibits GoodRx from engaging in the deceptive practices outlined in the complaint and requires the company to comply with the Health Breach Notification Rule. To remedy the FTC\u2019s numerous allegations, other provisions of the proposed order against GoodRx also:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Prohibit the sharing of health data for advertising:\u00a0<\/strong>GoodRx will be permanently prohibited from disclosing user health information with applicable third parties for advertising purposes.<\/li>\n\n\n\n<li><strong>Require user consent for any other sharing:<\/strong>\u00a0GoodRx must obtain users\u2019 affirmative express consent before disclosing user health information with applicable third parties for other purposes. The order requires the company to clearly and conspicuously detail the categories of health information that it will disclose to third parties.\u00a0 It also\u00a0prohibits the company from using manipulative designs, known as dark patterns, to obtain users\u2019 consent to share the information.<\/li>\n\n\n\n<li><strong>Require the company to seek deletion of data:\u00a0<\/strong>GoodRx must direct third parties to delete the consumer health data that was shared with them and inform consumers about the breaches and the FTC\u2019s enforcement action against the company.<\/li>\n\n\n\n<li><strong>Limit Retention of Data:<\/strong>\u00a0GoodRx will be required to limit how long it can retain personal and health information according to a data retention schedule.\u00a0It also must publicly post a retention schedule and detail the information it collects and why such data collection is necessary.<\/li>\n\n\n\n<li><strong>Implement a Mandated Privacy Program:<\/strong> GoodRx must put in place a comprehensive privacy program that includes strong safeguards to protect consumer data.<\/li>\n<\/ul>\n\n\n\n<p>If you have any questions regarding the action filed by the FTC, your own compliance with HIPAA rules&nbsp;or the FTC\u2019s Health Breach Notification Rule, please contact your Dinsmore health care attorney.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><a href=\"#_ftnref1\" id=\"_ftn1\">[1]<\/a> 16 CFR Part 318<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On February 1, the Federal Trade Commission (\u201cFTC\u201d) announced enforcement action for the first time under its Health Breach Notification Rule[1]. The complaint against telehealth and prescription drug discount provider GoodRx Holdings Inc. (\u201cGoodRx\u201d), alleges its failure to notify consumers and others of its unauthorized disclosures of consumers\u2019 personal health information to Facebook, Google&nbsp;and other\u2026<\/p>\n","protected":false},"author":8,"featured_media":0,"menu_order":0,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"tags":[],"publication-type":[12],"class_list":["post-6615","publications","type-publications","status-publish","format-standard","hentry","publication-type-legal-alerts"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The FTC Announces First Health Breach Notification Rule Enforcement Action - Dinsmore &amp; Shohl<\/title>\n<meta name=\"description\" content=\"The FTC Announces First Health Breach Notification Rule Enforcement Action Read insights and legal analysis from attorneys at Dinsmore &amp; Shohl LLP.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The FTC Announces First Health Breach Notification Rule Enforcement Action\" \/>\n<meta property=\"og:description\" content=\"The FTC Announces First Health Breach Notification Rule Enforcement Action Read insights and legal analysis from attorneys at Dinsmore &amp; Shohl LLP.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/\" \/>\n<meta property=\"og:site_name\" content=\"Dinsmore &amp; Shohl\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-24T20:36:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?w=1024\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/\",\"url\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/\",\"name\":\"The FTC Announces First Health Breach Notification Rule Enforcement Action - Dinsmore &amp; Shohl\",\"isPartOf\":{\"@id\":\"https:\/\/www.dinsmore.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?w=1024\",\"datePublished\":\"2023-02-13T18:31:00+00:00\",\"dateModified\":\"2025-11-24T20:36:52+00:00\",\"description\":\"The FTC Announces First Health Breach Notification Rule Enforcement Action Read insights and legal analysis from attorneys at Dinsmore & Shohl LLP.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#primaryimage\",\"url\":\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png\",\"contentUrl\":\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png\",\"width\":2084,\"height\":751},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.dinsmore.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The FTC Announces First Health Breach Notification Rule Enforcement Action\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.dinsmore.com\/#website\",\"url\":\"https:\/\/www.dinsmore.com\/\",\"name\":\"Dinsmore & Shohl\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.dinsmore.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.dinsmore.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.dinsmore.com\/#organization\",\"name\":\"Dinsmore & Shohl\",\"url\":\"https:\/\/www.dinsmore.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.dinsmore.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2025\/12\/Dinsmore-Final-Logo-Navy.svg\",\"contentUrl\":\"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2025\/12\/Dinsmore-Final-Logo-Navy.svg\",\"width\":413,\"height\":54,\"caption\":\"Dinsmore & Shohl\"},\"image\":{\"@id\":\"https:\/\/www.dinsmore.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The FTC Announces First Health Breach Notification Rule Enforcement Action - Dinsmore &amp; Shohl","description":"The FTC Announces First Health Breach Notification Rule Enforcement Action Read insights and legal analysis from attorneys at Dinsmore & Shohl LLP.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/","og_locale":"en_US","og_type":"article","og_title":"The FTC Announces First Health Breach Notification Rule Enforcement Action","og_description":"The FTC Announces First Health Breach Notification Rule Enforcement Action Read insights and legal analysis from attorneys at Dinsmore & Shohl LLP.","og_url":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/","og_site_name":"Dinsmore &amp; Shohl","article_modified_time":"2025-11-24T20:36:52+00:00","og_image":[{"url":"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?w=1024","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/","url":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/","name":"The FTC Announces First Health Breach Notification Rule Enforcement Action - Dinsmore &amp; Shohl","isPartOf":{"@id":"https:\/\/www.dinsmore.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#primaryimage"},"image":{"@id":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png?w=1024","datePublished":"2023-02-13T18:31:00+00:00","dateModified":"2025-11-24T20:36:52+00:00","description":"The FTC Announces First Health Breach Notification Rule Enforcement Action Read insights and legal analysis from attorneys at Dinsmore & Shohl LLP.","breadcrumb":{"@id":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#primaryimage","url":"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png","contentUrl":"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2023\/02\/FTC-Health-Social-Share-_1_021023_Header-02.png","width":2084,"height":751},{"@type":"BreadcrumbList","@id":"https:\/\/www.dinsmore.com\/publications\/the-ftc-announces-first-health-breach-notification-rule-enforcement-action\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.dinsmore.com\/"},{"@type":"ListItem","position":2,"name":"The FTC Announces First Health Breach Notification Rule Enforcement Action"}]},{"@type":"WebSite","@id":"https:\/\/www.dinsmore.com\/#website","url":"https:\/\/www.dinsmore.com\/","name":"Dinsmore & Shohl","description":"","publisher":{"@id":"https:\/\/www.dinsmore.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dinsmore.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.dinsmore.com\/#organization","name":"Dinsmore & Shohl","url":"https:\/\/www.dinsmore.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dinsmore.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2025\/12\/Dinsmore-Final-Logo-Navy.svg","contentUrl":"https:\/\/www.dinsmore.com\/wp-content\/uploads\/2025\/12\/Dinsmore-Final-Logo-Navy.svg","width":413,"height":54,"caption":"Dinsmore & Shohl"},"image":{"@id":"https:\/\/www.dinsmore.com\/#\/schema\/logo\/image\/"}}]}},"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/publications\/6615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/publications"}],"about":[{"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/types\/publications"}],"author":[{"embeddable":true,"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/users\/8"}],"version-history":[{"count":4,"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/publications\/6615\/revisions"}],"predecessor-version":[{"id":62187,"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/publications\/6615\/revisions\/62187"}],"wp:attachment":[{"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/media?parent=6615"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/tags?post=6615"},{"taxonomy":"publication-type","embeddable":true,"href":"https:\/\/www.dinsmore.com\/wp-json\/wp\/v2\/publication-type?post=6615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}