Since 2021, the FTC has returned to the same story again and again: a health app tells people their data is private, then shares it with Meta, Google, or an advertising vendor anyway. Fertility trackers, telehealth platforms, and mental health services have all ended up in this position. Collecting health data isn't inherently the problem. The problem was the gap between what these companies promised and where the data actually went.
Four of those cases, Flo Health, GoodRx, BetterHelp, and Premom, point to five practical lessons for healthtech teams.
1. Your privacy policy is a promise the FTC will hold you to
The FTC's case against Flo Health centered on the fertility app's promise not to share details about users' cycles, pregnancies, symptoms, and notes with third parties. The agency alleged Flo broke that promise by disclosing this data to marketing and analytics services from Facebook and Google. GoodRx followed a similar pattern. The FTC alleged the company shared users' prescription and health condition data with Facebook and Google despite privacy policy language promising it would "never" do so.
The lesson: a privacy policy is a factual statement about your data flows. Regulators will compare it against what your SDKs and pixels actually do. If your policy says data stays internal, every integration has to honor that, not just the ones your legal team reviewed.
2. Third-party trackers and SDKs are your responsibility, not your vendor's
GoodRx didn't just pass data to advertisers in the abstract. According to the FTC, the company sent medication and health condition details to Facebook, Google, and others through trackers on its site, and uploaded lists of users who had bought specific medications to Facebook to target them with health-related ads. BetterHelp's case followed a similar pattern. Its intake questionnaire asked about experiences like depression and suicidal thoughts, and the FTC alleged the company shared questionnaire information, email addresses, and IP addresses with Facebook, Snapchat, and other platforms through pixels and uploaded contact lists.
The lesson: most companies don't set out to sell health data. They add an analytics or ad SDK, and it collects more than anyone signed off on. Every third-party script on a health page or in a health app belongs on an inventory, even if it's "just analytics."
3. Not being covered by HIPAA doesn't put you outside the FTC's reach
GoodRx and Premom (the ovulation tracker from Easy Healthcare) both operated largely outside HIPAA, and the FTC brought cases against both. GoodRx was the first company charged under the FTC's Health Breach Notification Rule, for failing to notify people of its disclosures to Facebook, Google, and others. A few months later, Premom became the second. Easy Healthcare agreed to a $100,000 civil penalty, plus an additional $100,000 to Connecticut, Oregon, and the District of Columbia.
The lesson: the Health Breach Notification Rule, along with state laws like Washington's My Health My Data Act and Nevada's consumer health data law, reaches far more apps than HIPAA does. "We're not a covered entity" is not the same as "we're not regulated."
4. "De-identified" and "aggregated" need to hold up under scrutiny
Premom's policy said the data it shared with third parties was non-identifiable and used only for internal analytics. The FTC alleged otherwise. According to the agency, the shared data included precise location and device identifiers that can't be changed without buying a new device, identifiers the FTC said can be used to identify individuals. Flo's case raised a similar issue: according to the complaint, data from an app used by more than 100 million people was sent to third parties along with a unique advertising identifier that could be matched to a device or user profile.
The lesson: if a data set includes device IDs, precise timestamps, or location, calling it "de-identified" may not hold up once the recipient combines it with data it already has. Before you describe data as anonymous, test whether the party receiving it could realistically re-identify it.
5. Consent has to come before the data moves
BetterHelp's intake questionnaire asked people about sensitive experiences before they had even been matched with a counselor, and the company assured them their health information would stay private between them and their counselor. The FTC alleged BetterHelp then shared questionnaire information with advertisers without people's consent for that use. The timing mattered. People shared this information believing it would help them get care, not that it would be used for ad targeting.
The lesson: tie consent to a specific use, get it before data moves, and be clear about who receives the data. A general "I agree" at signup doesn't cover it, and people shouldn't have to dig through settings to find or withdraw consent.
Closing the gap between policy and practice
In each of these cases, the privacy policy described one thing and the company's data practices did another. Closing that gap takes work on both sides. On the practice side, that means the inventory work described above: knowing which SDKs, pixels, and data-sharing agreements are in place and what each one collects.
On the policy side, it means a policy that accurately describes those practices and keeps pace with the laws that apply to you. This is where Common Sense Privacy's tools are designed to help. The Privacy Wizard guides you through a 150+ point rubric to draft a policy tailored to your actual practices, and identifies which US and EU privacy laws apply to your business. The Privacy Dashboard tests your existing policy against specific laws and best practices, highlights potential gaps, and helps you keep the policy current as regulations and your business change.
A clear, rigorous picture of what your policy promises, so you can check it against what your product does - and the changing laws that may affect you.

