Telehealth has transformed access to prescription drugs, allowing patients to obtain treatment for conditions ranging from weight loss and ADHD to anxiety and sexual dysfunction with unprecedented speed. But that convenience is colliding with serious questions about medical oversight, recurring billing and, most significantly, the handling of highly personal health information. Federal regulators have accused multiple digital-health companies of sharing consumer health data with advertising and technology platforms, sometimes despite privacy assurances. The underlying problem is a regulatory gap: Americans often assume medical information submitted to a health-related website is automatically protected by HIPAA, although many direct-to-consumer platforms may operate partly or entirely outside those protections. Recent federal action underscores a broader question policymakers and consumers can no longer ignore: whether rapid online prescribing has expanded faster than the privacy and accountability safeguards needed to protect patients.
Key Takeaways
- Federal regulators allege that some telehealth companies have transmitted consumers’ health information to advertising and technology platforms without adequate permission, highlighting how digital medicine can expose information patients traditionally expect to remain confidential.
- HIPAA does not automatically protect every piece of health information entered into every health-related website or application; depending on the company and its relationship to covered health-care entities, other federal consumer-protection rules may instead provide the primary safeguards.
- Privacy concerns coincide with questions about medical oversight: research cited in current reporting found that fewer than one-third of nearly 50 telehealth companies offering GLP-1 medications required a real-time video or audio consultation with a physician.
In-Depth
Telehealth’s great selling point is speed: answer a questionnaire, submit payment information and potentially receive a prescription without the delays of an office visit. But convenience has exposed a serious weakness in America’s patchwork health-privacy system. Many consumers assume that information entered into a medical website is protected by HIPAA. That assumption can be wrong because some direct-to-consumer platforms and health apps fall outside HIPAA’s traditional framework.
Federal regulators have alleged that digital-health companies disclosed information to advertising or technology companies without adequate consent. The government’s 2026 case against Hims & Hers alleges that health information was shared with third parties while consumers were also subjected to billing and cancellation practices. The company disputes the allegations. Earlier enforcement involving other digital-health businesses focused on disclosures of health information for advertising.
The concern extends beyond privacy. Research cited in reporting found that fewer than one-third of nearly 50 telehealth companies offering GLP-1 drugs required a real-time audio or video consultation. That model may be efficient, but prescription medicine is not e-commerce. Convenience should not erase medical review or informed consumer choice.
The sensible standard is straightforward: patients should know who receives their information, why it is collected, how long it is retained and whether it is used for advertising. Companies handling private medical information should not rely on technical gaps in federal law as permission to treat health data like ordinary marketing data. Innovation deserves room to grow, but privacy, transparency and genuine medical oversight should remain the price of admission.
Sources
- https://apnews.com/article/telehealth-prescription-glp1-ftc-hims-e6821ac2ff88d76bbfe71c08ad21cc3a
- https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-states-act-against-hims-hers-deceptive-unlawful-privacy-practices
- https://www.ftc.gov/news-events/news/press-releases/2023/07/ftc-hhs-warn-hospital-systems-telehealth-providers-about-privacy-security-risks-online-tracking
- https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach

