← All enforcement actions
FTC ActHIPAA-adjacentStateHealthcare / Telehealth

BetterHelp$7.8M HIPAA fine (2023)

Disclosed sensitive mental-health data to Meta / Snap ad pixels

Penalty
$7.8M
Regulator
US Federal Trade Commission
Jurisdiction
United States

What happened

BetterHelp shared visitor email addresses, IP addresses, and answers to mental-health intake questionnaires with Meta, Snapchat, Pinterest, and Criteo for ad-targeting — despite promises that information would be kept private. The FTC ordered $7.8M in consumer refunds and a permanent ban on disclosing health information for ad-targeting.

Root cause

What every team should do

  1. Forbid third-party ad pixels on any page collecting health, financial, or sensitive personal data
  2. Run quarterly pixel + tag audits and tie privacy-policy language to ACTUAL data flow
  3. Use server-side conversions (CAPI) with PII stripped — not browser pixels
  4. HHS OCR's Dec 2022 bulletin on tracking technologies extends this rule to all HIPAA-covered entities
Source: FTC press release (Mar 2, 2023).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which HIPAA controls you are missing — mapped to enforcement patterns like this one.

Run my HIPAA audit Generate missing policies

Related enforcement actions

Equifax
$700M+
Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days
TJX Companies
~$256M
The breach that wrote PCI DSS — 94M cards stolen via insecure WEP wireless