FTC fines GoodRx for unauthorized sharing of health data

Feb 1, 2023, 2:06 PM | Updated: Feb 2, 2023, 3:05 pm

In a first-of-its-kind enforcement, the Federal Trade Commission has imposed a $1.5 million penalty on telehealth and prescription drug discount provider GoodRx Holdings Inc. for sharing users’ personal health data with Facebook, Google and other third parties without their consent.

Under a settlement, California-based GoodRx also accepted that it will be prohibited going forward from sharing user health data with third parties for advertising purposes, the FTC said. GoodRx admitted no wrongdoing and said in a blog post that it settled “to avoid the time and expense of protracted litigation.” The agreement is pending federal court approval.

Consumer protection advocates hailed Wednesday’s announcement as a potential game-changer that could seriously curtail a little-known phenomenon: The trafficking in sensitive health data by businesses not strictly classified as health care providers.

“Digital health companies and mobile apps should not cash in on consumers’ extremely sensitive and personally identifiable health information,” Samuel Levine, head of the FTC’s Bureau of Consumer Protection, said in a statement. “The FTC is serving notice that it will use all of its legal authority to protect American consumers’ sensitive data from misuse and illegal exploitation.”

The enforcement is the first under a 2009 law, the Health Breach Notification Rule, which applies to personal health record vendors and related providers not covered by HIPAA, the federal privacy rules that govern the health care industry,

It comes three years after Consumer Reports discovered that GoodRx was sharing people’s personal health information with more than 20 companies. “People told us they’d never expected that their sensitive information was being shared with the likes of Google and Facebook,” Marta Tellado, president and CEO of Consumer Reports, said in a statement Wednesday. “This is a win for consumers, and it could have a profound effect on how our health information is kept private moving forward.”

In a legal complaint filed on the FTC’s behalf, Justice Department lawyers said GoodRx’s actions had “unjustly enriched” the company at the expense of users — many sufferers of chronic health conditions — who could face “stigma, embarrassment or emotional distress” as well as discrimination if facts it shared were disclosed.

GoodRx said the focus of the FTC’s concerns was “proactively addressed” nearly three years ago, before the FTC inquiry began.

Justin Brookman, the director of technology policy at Consumer Reports, said he believed the FTC inquiry began after his organization’s Feb. 25, 2020 report. Prior to that, the government said, “GoodRx had no sufficient formal, written, or standard privacy or data-sharing policies or compliance programs in place. And, even after GoodRx’s practices came to light, it failed to notify users that their health information had been disclosed without their authorization.”

Company spokeswoman Lauren Casparis said via email that GoodRx “used vendor technologies to advertise in a way that we believe was compliant with all applicable regulations and that remains common practice among many websites.”

Those technologies included embedded web beacons known as “pixels” and other tracking and data-collection tools from companies including Google and Facebook, the government said.

“They put pixels on their site,” Brookman of Consumer Reports said by telephone. “They don’t have to do that.”

In a statement, Brookman said “health apps and websites have been giving away our personal data for years without consequence. This case should be a turning point — now companies have to understand that sharing customer data without clear permission will lead to investigations and fines.”

On its website, GoodRx says it has helped consumers save more than $45 billion since 2011.

The FTC said more than 55 million consumers have visited GoodRx’s website or mobile apps since January 2017. It said the company collects personal and health information from its users and from pharmacy benefit managers — the companies that manage prescription drug benefits — that confirm when one of its coupons has been used in a purchase.

The FTC said in a news release that GoodRx “deceptively promised its users that it would never share personal health information with advertisers or other third parties” while sharing information on their prescriptions and health conditions with third-party advertising companies and platforms including Facebook, Google and Criteo. That process helped GoodRx target personalized ads on Facebook and Instagram and other platforms, the FTC said.

Other provisions of proposed federal court order oblige GoodRx to direct third parties with whom it shared consumer health data to delete it and inform consumers.

GoodRX spokeswoman Casparis said the company believes “the requirements detailed in the settlement will have no material impact on our business or on our current or future operations.”

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

This photo provided by Robert Wilkes, owner of a house boat management company, shows smoke rising ...

Associated Press

Houseboats catch fire while docked at Wahweap Marina on Lake Powell

More than half a dozen house boats momentarily caught fire at a popular boating destination on the Utah-Arizona line on Friday.

3 days ago

File - Women work in a restaurant kitchen in Chicago, Thursday, March 23, 2023. On Friday, the U.S....

Associated Press

US hiring, unemployment jump in May and what that says about the economy

The nation’s employers stepped up their hiring in May, adding a robust 339,000 jobs, well above expectations.

3 days ago

(Pixabay Photo)...

Associated Press

Oath Keeper from Arizona sentenced for role in Jan. 6 riot at US Capitol

Edward Vallejo, a U.S. Army veteran from Phoenix, oversaw a “Quick Reaction Force” at a Virginia hotel that was prepared to deploy an arsenal of weapons into Washington if needed, authorities say.

4 days ago

FILE - U.S. Border Patrol Chief Raul Ortiz listens during a news conference, Jan. 5, 2023, in Washi...

Associated Press

US Border Patrol chief is retiring after seeing through end of Title 42 immigration restrictions

The head of the U.S. Border Patrol announced Tuesday that he was retiring, after seeing through a major policy shift that seeks to clamp down on illegal crossings at the U.S.-Mexico border following the end of Title 42 pandemic restrictions.

5 days ago

FILE - President Joe Biden talks with House Speaker Kevin McCarthy of Calif., on the House steps as...

Associated Press

House OKs debt ceiling bill to avoid default, sends Biden-McCarthy deal to Senate

The House approved a debt ceiling and budget cuts package late Wednesday, as President Joe Biden and Speaker Kevin McCarthy assembled a bipartisan coalition of centrist Democrats and Republicans against fierce conservative blowback and progressive dissent.

5 days ago

Sean Bickings (Family Photo via city of Tempe)...

Associated Press

Family of man who drowned last year in Tempe Town Lake files wrongful death lawsuit

The family of a man who drowned in Tempe Town Lake a year ago filed a wrongful death lawsuit against the city Wednesday, noting that its police department doesn't have a policy requiring officers to go into the water to save someone.

5 days ago

Sponsored Articles

...

SANDERSON FORD

Thank you to Al McCoy for 51 years as voice of the Phoenix Suns

Sanderson Ford wants to share its thanks to Al McCoy for the impact he made in the Valley for more than a half-decade.

...

Desert Institute for Spine Care

Spinal fusion surgery has come a long way, despite misconceptions

As Dr. Justin Field of the Desert Institute for Spine Care explained, “we've come a long way over the last couple of decades.”

(Desert Institute for Spine Care in Arizona Photo)...

Desert Institute for Spine Care in Arizona

5 common causes for chronic neck pain

Neck pain can debilitate one’s daily routine, yet 80% of people experience it in their lives and 20%-50% deal with it annually.

FTC fines GoodRx for unauthorized sharing of health data