Events & Resources

Learning Center
Read through guides, explore resource hubs, and sample our coverage.
Learn More
Events
Register for an upcoming webinar and track which industry events our analysts attend.
Learn More
Podcasts
Listen to our podcast, Behind the Numbers for the latest news and insights.
Learn More

About

Our Story
Learn more about our mission and how EMARKETER came to be.
Learn More
Our Clients
Key decision-makers share why they find EMARKETER so critical.
Learn More
Our People
Take a look into our corporate culture and view our open roles.
Join the Team
Our Methodology
Rigorous proprietary data vetting strips biases and produces superior insights.
Learn More
Newsroom
See our latest press releases, news articles or download our press kit.
Learn More
Contact Us
Speak to a member of our team to learn more about EMARKETER.
Contact Us

The FTC fines GoodRx for sharing users’ health data with third parties

The news: The Federal Trade Commission (FTC) fined GoodRx $1.5 million in civil penalties for sharing its customers’ health information with third parties such as Facebook, Google, and Criteo for advertising purposes.

  • GoodRx will pay the fine but denied wrongdoing, saying the charges stemmed from a previous acquisition and had already been addressed.

Digging into the violation: The FTC claims GoodRx repeatedly violated its promise that it wouldn’t share personal health information with advertisers or other third parties.

  • However, it shared information such as prescription medications, personal health conditions, personal contact information, and unique advertising and personal identifiers.
  • FTC commissioner Christine Wilson issued a statement on the decision stating, in part, that the $1.5 million fine was insufficient to cause GoodRx (current market cap of $2.3 billion) to change its business model.

First, but not last: This is the first time the FTC has charged any company with violating the Health Breach Notification Rule (HBNR), which has been on the books since it took effect in September 2009. But this is only the beginning.

  • In September 2021, the FTC issued a warning to health apps and connected device companies to comply with the HBNR.

Our take: Government oversight on digital health company practices is here to stay. The FTC took years to act, but several states have enacted strict laws around the privacy of personal health information.

  • Independent sources like STAT and Markup are investigating healthcare organizations’ data sharing with third parties. The fallout only begins with lost consumer trust.
  • Cyber criminals are zeroing in on healthcare data. Health systems and other major repositories of personal health information are being inundated with cyberattacks. It won’t be long before digital health companies are faced with ransomware demands.

This article originally appeared in Insider Intelligence's Digital Health Briefing—a daily recap of top stories reshaping the healthcare industry. Subscribe to have more hard-hitting takeaways delivered to your inbox daily.

You've read 0 of 2 free articles this month.

Create an account for uninterrupted access to select articles.
Create a Free Account