Telehealth platforms face mounting regulatory scrutiny as the Federal Trade Commission targets companies for allegedly exposing sensitive customer medical data, enrolling users in hard-to-cancel recurring subscriptions, and bypassing real-time consultations with licensed physicians. According to federal regulators and legal experts, these online health services operate in a regulatory blind spot where standard medical privacy laws do not apply.
FTC Targets Telehealth Practices and Data Sharing
The Federal Trade Commission filed a lawsuit against telehealth provider Hims & Hers, alleging the company engaged in deceptive business practices, disclosed customer health data to third-party tech platforms without consent, and automatically billed users for recurring prescriptions. According to the FTC complaint, Hims customers faced intake processes that granted virtually no opportunity to review provider recommendations before automated enrollment.
Hims disputed the government claims. In public statements regarding the litigation, the company called the federal action an effort to generate headlines at the expense of its business.
This federal enforcement action follows similar cases brought by FTC officials against more than a half-dozen online health and wellness companies in recent years. Previous targets include online therapy provider BetterHelp and pharmacy discount service GoodRx. In those enforcement actions, regulators stated the companies shared sensitive user health information with online platforms such as Meta and Google without obtaining proper user permission.
Regulatory Gaps in Digital Health Privacy
A primary driver behind these data disclosures is a significant gap in federal privacy legislation. The Health Insurance Portability and Accountability Act, commonly known as HIPAA, governs the handling of medical information in the United States, but the law generally applies only to specific entities such as hospitals, traditional medical offices, and health insurance companies.

Online services offering direct-to-consumer prescriptions, mental health counseling, and at-home DNA test kits typically fall outside those sector-specific statutes. Andrew Crawford, an attorney with the nonprofit Center for Democracy and Technology, noted that an entire universe of companies collects massive quantities of consumer health data daily without federal health sector oversight. Justin Brookman of Consumer Reports added that no clear federal law explicitly prohibits these commercial disclosures.
Rapid Prescriptions and Limited Consultations
Regulatory scrutiny also extends to clinical practices on telehealth platforms, particularly regarding medications for attention-deficit/hyperactivity disorder, anxiety, sexual dysfunction, and weight loss. Nearly all visits begin with a digital questionnaire rather than a live conversation with a healthcare provider.
A recent analysis of nearly 50 telehealth companies selling GLP-1 weight-loss drugs found that less than a third required a real-time video or audio consultation with a physician before issuing a prescription. Dr. Reshma Ramachandran of Yale University, who led the research team, observed that prescriptions were frequently sent automatically within minutes, leaving patients with no opportunity to halt the dispensing process.
Medical societies recommend thorough pre-prescription evaluations for GLP-1 medications, including discussions regarding weight-loss goals, prior medical history, and potential eating disorders. However, researchers discovered that only slightly more than half of the analyzed telehealth websites included screening questions regarding eating disorders, conditions that GLP-1 medications can potentially induce or worsen.
Related reading