WHAT YOU NEED TO KNOW
  • The FTC accuses Hims & Hers of exposing health data, using difficult subscriptions and bypassing real time doctor consultations.
  • Hims disputes the allegations and says the lawsuit is “an effort to generate headlines at our expense.”
  • Fewer than one third of nearly 50 GLP-1 telehealth companies required real time video or audio consultations.
  • HIPAA generally does not cover every online company offering prescriptions, counseling, DNA tests or other health services.
  • Privacy experts recommend ad blockers, private browsers and careful reviews of user agreements.

Telehealth’s attraction is obvious: Users can open an app or website, share medical information and potentially receive approval for a medication within minutes. That speed avoids the familiar sequence of calling a doctor, booking a visit and waiting for a prescription.

Since the COVID-19 pandemic, scores of online health services have launched with promises of convenient access to drugs for ADHD, sexual dysfunction, anxiety, weight loss and other conditions. But regulators are increasingly challenging the practices behind that convenience.

Government officials have accused companies of disclosing customers’ health data, enrolling users in subscriptions that are difficult to cancel and approving prescriptions without real time consultations with doctors. Those concerns now sit at the center of the Federal Trade Commission’s latest telehealth lawsuit.

The FTC alleges that telehealth pioneer Hims & Hers used all of those tactics in violation of U.S. consumer protection laws. Hims has disputed the allegations, calling them “an effort to generate headlines at our expense.”

FTC officials have filed similar cases against more than a half dozen telehealth companies in recent years. Those cases include actions against online therapy provider BetterHelp and pharmacy discount service GoodRx.

In both cases, regulators said the companies disclosed users’ health information to online platforms such as Meta and Google without permission. Privacy experts say existing federal protections often do not apply to the telehealth businesses collecting that information.

“There’s an entire universe of companies collecting huge amounts of consumer health data every day that aren’t covered by our current health sector-specific laws,” said Andrew Crawford, an attorney with the nonprofit Center for Democracy and Technology.

Telehealth visits commonly begin with questionnaires asking users about their medical histories and the medications they want. Researchers have found similar practices across the industry, including among companies selling injectable weight loss drugs that typically require physical examinations and other precautions before treatment.

With ongoing concerns about highly processed foods and long term health risks, have you reduced your consumption of ultra processed foods this year?

By completing the poll, you agree to receive emails from Being Healthy News, occasional offers from our partners and that you've read and agree to our privacy policy and legal statement.

An analysis of nearly 50 telehealth companies selling GLP-1 drugs found that fewer than one third required a real time video or audio consultation with a physician. In some instances, prescriptions received approval within minutes.

“What we saw overwhelmingly was that it was incredibly easy to get access to the GLP-1s,” said Dr. Reshma Ramachandran of Yale University, who led the study. “Most of the time, the prescription was automatically sent, without even an opportunity to stop the dispensing.”

Researchers also found that only slightly more than half of the websites asked about eating disorders on their intake questionnaires. GLP-1 drugs can induce or worsen eating disorders, according to the source analysis.

Many Americans assume HIPAA protects any personal health information they provide. But the federal privacy law generally applies to specific health businesses, including hospitals, medical offices and insurers, rather than every online company offering prescriptions, counseling, DNA tests or other health services.

Because HIPAA does not cover every consumer health platform, the FTC has relied on its broader authority over fraudulent, deceptive or unethical business methods. Regulators generally must show that a company disclosed health information after telling customers it would not do so.

According to the FTC complaint, Hims told customers that its platform provided a “100% online, private and secure” way to share information with the company’s medical professionals. The FTC alleges that Hims instead shared customer data with Meta and other online platforms.

Experts say the penalties available to regulators remain limited, with companies usually signing legal agreements promising to stop cited practices. California, Connecticut, Maryland and other states have adopted online privacy laws with specific health information protections, but enforcement against telehealth companies has been limited.

Privacy experts recommend using ad blockers and private web browsers when visiting telehealth websites because those tools can complicate tracking of a user’s location, online history and other information. Crawford also recommends reading user agreements, although declining the terms of service may be the only certain way to protect personal information.