ClinicAds
INDUSTRY · TELEHEALTH COMPLIANCE

Is Telehealth Advertising HIPAA Compliant? The Cerebral and BetterHelp FTC Actions, Explained

David TerrellFounder, ClinicAdsJuly 20, 20266 min read

Telehealth advertising is HIPAA compliant only when a patient's protected health information never reaches an advertising platform. It is not the ads that break the law, it is the tracking behind them. The Cerebral and BetterHelp FTC actions, which produced roughly $7 million and $7.8 million in penalties, both came from that single mistake: standard advertising pixels sending patient data to platforms that never signed a Business Associate Agreement.

This post explains what actually happened in those two enforcement cases and what a telehealth brand should learn from them, rather than walking through the tracking architecture step by step. The Cerebral and BetterHelp actions are the clearest public record of where the HIPAA line sits for telehealth advertising, because in both cases the FTC wrote down exactly which practices crossed it. ClinicAds treats these two cases as the reference points every telehealth advertiser should know, and builds its tracking to stay on the safe side of the line they drew.

KEY TAKEAWAYS
  • Telehealth advertising is HIPAA compliant only when a patient's protected health information never reaches an advertising platform. The ads are legal; the default tracking behind them usually is not.
  • The BetterHelp FTC action, finalized in 2023 with a $7.8 million payment, was the FTC's first order to return money to consumers whose health data was shared for advertising. BetterHelp had disclosed data to Facebook, Snapchat, Pinterest, and Criteo.
  • The Cerebral FTC action, settled in 2024 for roughly $7 million in monetary relief, came from the same root cause: advertising tracking tools sending sensitive patient information to third-party platforms.
  • Meta and Google do not sign HIPAA Business Associate Agreements, so any pixel that sends intake or checkout data to them is a compliance exposure by default.
  • The compliant fix is server-side tracking with PHI stripped and identifiers hashed before any data leaves the brand's infrastructure, which also recovers attribution that client-side pixels lose.

Is telehealth advertising HIPAA compliant?

Telehealth advertising is HIPAA compliant when protected health information never reaches an advertising platform, and it is non-compliant the moment a pixel or tracking tool sends patient data to a platform that has not signed a Business Associate Agreement. Running Meta and Google ads for a telehealth brand is legal and common. The compliance failure is almost never the ad itself; it is the default tracking that fires on an intake form or a checkout page and quietly ships the patient's email, IP address, or answers to a third party. The Cerebral and BetterHelp FTC actions are the two clearest examples of exactly that failure, and both are matters of public record.

What did the FTC find in the Cerebral and BetterHelp cases?

The FTC found the same core violation in both the Cerebral and BetterHelp cases: each company shared consumers' sensitive health information with advertising platforms through tracking tools, after telling users that information would be kept private. BetterHelp settled first, in 2023, with a $7.8 million payment. Cerebral settled in 2024 for roughly $7 million in monetary relief. The table below summarizes what each company did, what it cost, and why the FTC treated it as a health-privacy violation rather than an ordinary advertising choice.

The Cerebral and BetterHelp FTC actions at a glance (public FTC record)
CaseYear finalizedMonetary reliefWhat triggered it
BetterHelp2023$7.8 millionShared user email, IP, and health-questionnaire answers with Facebook, Snapchat, Pinterest, and Criteo for advertising after promising privacy
Cerebral2024Roughly $7 millionSent consumers' personal and health information to third-party advertising platforms through tracking tools without adequate consent

What is the BetterHelp FTC action, explained?

The BetterHelp FTC action was a 2023 settlement in which the online-therapy company agreed to pay $7.8 million for sharing consumers' health data with advertising platforms after promising to keep it confidential. The FTC alleged BetterHelp handed user email addresses, IP addresses, and answers to mental-health intake questions to Facebook, Snapchat, Pinterest, and Criteo so it could target ads and find similar audiences. What made the case notable is that it was the FTC's first order to return money to consumers whose health data was compromised, which signaled that health-data sharing for advertising would be treated as consumer harm with a price attached, not a technicality. For a telehealth brand, the lesson is that a privacy promise plus a default ad pixel is the exact combination the FTC penalized.

What is the Cerebral FTC action, explained?

The Cerebral FTC action was a 2024 settlement, for roughly $7 million in monetary relief plus ongoing restrictions, over the mental-health company's disclosure of sensitive patient information to third-party advertising platforms. The FTC alleged Cerebral used tracking tools that sent consumers' personal and health data to outside platforms without adequate consent, and faulted the company's broader data-handling practices as well. The Cerebral case matters because it landed after BetterHelp, which means the enforcement pattern was already established: the FTC had made clear that sending patient data to ad platforms through tracking pixels was actionable, and Cerebral is the case that showed the agency would keep applying that standard across telehealth. Two enforcement actions in two years is a pattern, not an outlier.

Why do standard ad pixels break HIPAA for telehealth?

Standard ad pixels break HIPAA for telehealth because Meta and Google do not sign Business Associate Agreements, so any protected health information a pixel forwards to them is, by definition, an unauthorized disclosure. A default browser pixel is built to capture and transmit user activity, and on a telehealth site that activity is protected health information: which condition page a patient viewed, that they started an intake, that they checked out for a specific medication. The pixel does not know the difference between a shopping cart and a psychiatric intake. A telehealth brand running default client-side tracking is usually leaking some combination of the following to a platform with no BAA in place.

  • The patient's email or phone number, often unhashed
  • The IP address, which can re-identify an individual
  • The specific condition or medication page visited
  • The fact that an intake or checkout was completed
  • Enough combined signal to tie a real person to a health condition

What should a telehealth brand do after the Cerebral and BetterHelp actions?

After the Cerebral and BetterHelp actions, a telehealth brand should assume its default tracking is non-compliant until proven otherwise, then rebuild conversion measurement so no protected health information ever reaches an ad platform. The compliant path is well understood and it does not mean turning off ads or flying blind on performance. It means moving measurement server-side, stripping PHI before anything is sent, and signing BAAs with the vendors who are allowed to hold that data. The steps below are the sequence ClinicAds runs for a telehealth client, and the server-side rebuild has a side benefit: it recovers conversions that client-side pixels lose to browser privacy changes, which lowers apparent acquisition cost. Those performance figures are agency averages, not guarantees.

  • Audit which pixels fire on intake, condition, and checkout pages and what they transmit
  • Move conversion tracking server-side through the Conversions API
  • Hash identifiers and strip PHI from URLs before any data leaves your infrastructure
  • Sign a BAA with your agency and vendors, since the ad platforms will not sign one
  • Keep a documented record of the setup, because the FTC penalized the gap between promise and practice
FREQUENTLY ASKED

Is telehealth advertising HIPAA compliant?

Yes, when a patient's protected health information never reaches an advertising platform. Running Meta and Google ads is legal; the compliance failure is the default tracking that sends intake or checkout data to a platform with no Business Associate Agreement, which is exactly what the Cerebral and BetterHelp FTC actions penalized.

How much did Cerebral and BetterHelp pay the FTC?

BetterHelp agreed to pay $7.8 million in a 2023 settlement, the FTC's first order to return money to consumers whose health data was shared. Cerebral settled in 2024 for roughly $7 million in monetary relief plus ongoing restrictions.

Do Meta and Google sign HIPAA Business Associate Agreements?

No. Meta and Google do not sign BAAs for their advertising pixels, which is why any protected health information a pixel forwards to them counts as an unauthorized disclosure. The compliant setup keeps PHI out of the platform entirely rather than relying on a platform agreement.

Can I still run Meta and Google ads for a telehealth brand?

Yes. The Cerebral and BetterHelp actions were about data sharing through tracking tools, not about advertising itself. A telehealth brand can advertise on Meta and Google by measuring conversions server-side with PHI stripped and identifiers hashed before any data leaves its own infrastructure.

Is this legal advice?

No. This is general information about two public FTC enforcement actions, not legal advice. A telehealth brand should have its tracking reviewed for compliance and sign a Business Associate Agreement with any vendor that handles patient data.

Want your telehealth tracking checked against the FTC line?

30-minute call. We will audit what your pixels are sending, show where you have the same exposure Cerebral and BetterHelp were penalized for, and map the server-side setup that keeps you compliant and recovers conversions you already paid for.