- BetterHelp, an online counseling service App, falsely claimed it was certified “HIPAA Compliant” and maintained the privacy of consumer information.
- BetterHelp failed to obtain the express consent of consumers before sharing their identifiable health information with FaceBook, Snapchat, and other 3rd parties.
- The FTC Health Breach Notification Rule was found to not apply here because records were not “drawn from multiple sources.”
Subscribe to HERE to Legal HIE’s compliance library to gain access to sample policies, documents and tools to help you stay on top of the newest compliance challenges in 2023!
Today, the FTC issued a proposed order requiring BetterHelp, Inc., an online counseling service App, to pay $7.8 million to consumers to settle charges that it shared consumers’ health data (including sensitive mental health information) with third-party advertising platforms, including Facebook, Pinterest, Snapchat, and Criteo, after promising to keep such data private. The FTC Commissioner agreed that this alleged conduct violated Section 5 of the FTC Act. In addition, the FTC’s proposed order will require BetterHelp to:
- obtain affirmative express consent before disclosing personal information to certain third parties for any purpose;
- put in place a comprehensive privacy program that includes strong safeguards to protect consumer data;
- direct third parties to delete the consumer health and other personal data that BetterHelp revealed to them; and
- limit how long it can retain personal and health information according to a data retention schedule.
FTC Commissioner Christine S.Wilson accepted the consent agreement with BetterHelp and issued a concurring statement resolving all allegations. The FTC will publish a description of the consent agreement package in the Federal Register, and it will be subject to public comment for 30 days after publication in the Federal Register after which the Commission will decide whether to make the proposed consent order final.
Summary of the Facts
The real JUICE of this is in the FTC Compliant, which I’ve republished at the end of this post and highly recommend reading. As with most cases like these, the details are important to understanding exactly what went wrong. That said, the FTC’s Press Release offers a good overview, which I will briefly summarize.
BetterHelp offers online counseling services under several names, including BetterHelp Counseling. Consumers interested in BetterHelp’s services must fill out a questionnaire that asks for sensitive mental health information—such as whether they have experienced depression or suicidal thoughts and are on any medications. They also provide their name, email address, birth date and other personal information. Consumers are then matched with a counselor and pay between $60 and $90 per week for counseling.
At several points in the signup process, BetterHelp expressly promised consumers that it would not use or disclose their personal health data except for limited purposes, such as to provide counseling services. In addition (and my personal favorite), from September 2013 to December 2020, BetterHelp displayed “HIPAA seals” indicating its compliance with HIPAA. Here are snapshots the FTC provided in its Compliant:

By displaying these HIPAA seals on every page of its multiple websites, FTC found that BetterHelp signaled to consumers that a government agency or other third party had reviewed BetterHelp’s privacy and information security practices and determined that they met HIPAA’s requirements. The FTC also concluded that BetterHelp outright represented to consumers that it was in fact “HIPAA certified.” Yet, no government agency or other third party actually reviewed BetterHelp’s information practices for compliance with HIPAA, let alone determined that the practices met the requirements of HIPAA. In addition, hundreds of BetterHelp’s therapists were not subject to HIPAA, presumably because they did not engage in “electronic standard transaction” (e.g., billing consumers health insurance for the services rendered). As a result, the identifiable health information of consumers who engaged with those therapists was not protected by HIPAA. In December 2020, after receiving a Civil Investigative Demand from the FTC, BetterHelp removed the “HIPAA” seals from the Multi-Sites.
Despite its promises of privacy and HIPAA compliance, BetterHelp shared consumers’ email addresses, IP addresses, and health questionnaire information with Facebook, Snapchat, Criteo, and Pinterest for advertising purposes. The FTC found that BetterHelp failed to maintain sufficient policies or procedures to protect consumer data and did not obtain consumers’ affirmative express consent before disclosing their health data. BetterHelp also failed to place any limits on how third parties could use consumers’ health information—allowing Facebook and other third parties to use that information for their own internal purposes, including for research and development or to improve advertising.
Violation of Section 5 of the FTC Act
For their indiscretions, BetterHelp was charged with eight (8) violations of Section 5 of the FTC Act, 15 U.S.C. 45(a) or/and (n):
- Count I Unfairness – Unfair Privacy Practices
- Count II Unfairness – Failure to Obtain Affirmative Express Consent Before Collecting, Using, and Disclosing Consumers’ Health Information
- Count III Failure to Disclose – Disclosure of Health Information for Advertising and Third Parties’ Own Uses
- Count IV Failure to Disclose – Use of Health Information for Advertising
- Count V Privacy Misrepresentation – Disclosure of Health Information for Advertising and Third Parties’ Own Uses
- Count VI Privacy Misrepresentation – Use of Health Information for Advertising
- Count VII Privacy Misrepresentation – Disclosure of Health Information
- Count VIII Privacy Misrepresentation – HIPAA Certification
Why Doesn’t this Trigger the FTC Health Breach Notification (HBN) Rule?
Notably, the complaint does not include an allegation that BetterHelp violated the HBN Rule. The Commissioner supported this approach to the application of the HBN Rule, particularly given the FTC Policy Statement on Breaches by Health Apps and Other Connected Devices. One could argue that BetterHelp would fall within the ambit of the FTC’s HBN Rule because it offers a health platform and App, particularly under the expansive view espoused in its Policy Statement. However, the Commission did not take that approach to interpreting the HBN Rule. Their rationale for not finding that the HBN Rule applies here was because the information BetterHelp collected from consumers and provided to therapists on its platform did not constitute a “personal health record” of identifiable health information under the FTC HBN Rule — specifically, because it does not include records that “can be drawn from multiple sources,” as required by the existing formulation of the Rule. Here, a consumer provided his or her information to BetterHelp but the companydid not pull additional health information from another source or vendor.
Impact for HIPAA-covered Health Care Providers, Facilities and Organizations
As the health care industry continues to march “towards the FHIR,” cases like this one (and GoodRx) are important to consider as more health care Apps approach HIPAA-covered health care providers, facilities and organizations for access to electronic health information. Importantly, the Office of National Coordinator (ONC) indicated in its discussion with the Information Blocking Rule that certain practices which may involve educating consumers about about privacy and security risks posed by third-party apps that the patient choses would generally NOT violate the Information Blocking Rule. Here is ONC’s specific FAQ on this topic:
It will not be considered an “interference” with the access, exchange, or use of EHI if:
— Foremost, the information provided by actors focuses on any current privacy and/or security risks posed by the technology or the third-party developer of the technology;
— Second, this information is factually accurate, unbiased, objective, and not unfair or deceptive; and
— Finally, the information is provided in a non-discriminatory manner.
For example, actors may establish processes where they notify a patient, call to a patient’s attention, or display in advance (as part of the app authorization process within certified API technology) whether the third-party developer of the app that the patient is about to authorize to receive their EHI has attested in the positive or negative as to whether the third party’s privacy policy and practices (including security practices) meet particular benchmarks. However, such processes must be non-discriminatory in that they must be used in the same manner for all third-party apps/developers.
The particular benchmarks an actor might identify in this example could be the minimum expectations described below, more stringent “best practice” expectations that may be set by the market, or some combination of minimum and “best practice” expectations.
As described in the Final Rule at 85 FR 25816, all third-party privacy policies and practices should, at a minimum, adhere to the following:
1. The privacy policy is made publicly accessible at all times, including updated versions;
2. The privacy policy is shared with all individuals that use the technology prior to the technology’s receipt of EHI from an actor;
3. The privacy policy is written in plain language and in a manner calculated to inform the individual who uses the technology;
4. The privacy policy includes a statement of whether and how the individual’s EHI may be accessed, exchanged, or used by any other person or other entity, including whether the individual’s EHI may be sold at any time (including in the future); and
5. The privacy policy includes a requirement for express consent from the individual before the individual’s EHI is accessed, exchanged, or used, including receiving the individual’s express consent before the individual’s EHI is sold (other than disclosures required by law or disclosures necessary in connection with the sale of the application or a similar transaction).