GoodRx: $1.5M United States privacy settlement

The first FTC Health Breach Notification Rule action: GoodRx paid $1.5M for sharing prescription and condition data with Meta, Google, and other advertising platforms via tracking pixels — without consumer consent or breach notification.

  • FTC HBNR
  • United States
  • Last updated

Enforcement snapshot

Amount
$1.5M
Regulator
Federal Trade Commission
Sector
Digital health
Published
February 2023

Technical failure modes

What failed

01. Health data shared via pixels

Prescription and condition information was transmitted to Meta, Google, Criteo, and other advertising platforms through standard tracking pixels.

02. No breach notification

Consumers were never notified that their health data had been disclosed to third parties — a violation of HBNR.

03. Vague disclosures and broken promises

Privacy policies stated that GoodRx would never share personal health information with advertisers — directly contradicted by the pixel behavior.

04. Targeted ad campaigns from health data

Inferred conditions were used to build advertising audiences, including for sensitive categories.

Next step

Do not wait for a demand letter to find the gap

GoodRx made it official: pixel-based sharing of health data is a breach when consumers were not asked. The FTC reached the same conclusion under HBNR that California's AG would later reach for SPI under CCPA. The case is the cleanest example of why pixel inventory and purpose-bound consent are non-optional.

Get Started Free

Get started in less than 5 min