01. Health data shared via pixels
Prescription and condition information was transmitted to Meta, Google, Criteo, and other advertising platforms through standard tracking pixels.
The first FTC Health Breach Notification Rule action: GoodRx paid $1.5M for sharing prescription and condition data with Meta, Google, and other advertising platforms via tracking pixels — without consumer consent or breach notification.
Last updated
Technical failure modes
Prescription and condition information was transmitted to Meta, Google, Criteo, and other advertising platforms through standard tracking pixels.
Consumers were never notified that their health data had been disclosed to third parties — a violation of HBNR.
Privacy policies stated that GoodRx would never share personal health information with advertisers — directly contradicted by the pixel behavior.
Inferred conditions were used to build advertising audiences, including for sensitive categories.
Remediation path
More enforcement analysis
Next step
GoodRx made it official: pixel-based sharing of health data is a breach when consumers were not asked. The FTC reached the same conclusion under HBNR that California's AG would later reach for SPI under CCPA. The case is the cleanest example of why pixel inventory and purpose-bound consent are non-optional.
Get started in less than 5 min