GoodRx Holdings Inc., the prescription drug discount platform used by tens of millions of Americans to find lower-cost medications, agreed to pay $1.5 million to resolve charges that it shared users' highly sensitive prescription drug and health condition data with Facebook, Google, and other advertising technology platforms in violation of its own privacy promises and in violation of the Health Breach Notification Rule — a federal regulation requiring companies that collect personal health records to notify users when their health data is disclosed to unauthorized third parties.DOCUMENTED
GoodRx's privacy policy stated that the company would never share users' personal health information with advertisers. In practice, GoodRx had embedded advertising tracking pixels — including Facebook's Pixel and Google Analytics — in its website and mobile application. These pixels transmitted data about users' interactions with the platform directly to the advertising companies, including information about specific prescription drug searches, drug fills, the medications users were taking, and the health conditions those medications treated. The advertising companies used this data to serve targeted advertising to GoodRx users and to build advertising profiles that included health condition inferences.DOCUMENTED
- GoodRx's privacy policy explicitly stated health information would never be shared with advertisers — a promise the company violated through tracking pixel implementations
- Facebook's Pixel, Google Analytics, and other third-party advertising trackers received prescription drug names, fill dates, and condition-linked medication data from GoodRx
- The shared data enabled Facebook and Google to serve users targeted advertising for products and services related to their specific medications and inferred conditions
- GoodRx used the shared data to run retargeting campaigns targeting users who had searched for or filled specific medications
- The $1.5 million penalty marked the first use of the Health Breach Notification Rule in an enforcement action
What the Pixels Transmitted
Advertising pixels work by loading a small piece of code on a website or app that sends user behavior data to the advertising platform in real time. A standard Facebook Pixel implementation sends the advertising platform information about the pages a user visits, the searches they conduct, and the conversions they complete — in a standard retail context, this might mean sending information about products browsed and purchases completed. On a prescription drug platform, the same pixel implementation sends information about the medications a user searched for, the drug fill confirmations they viewed, and the prescription details they entered — information that directly reveals health conditions and treatment decisions.REVIEWED
GoodRx used this data in multiple ways. The advertising platforms received the health data and incorporated it into their advertising targeting systems, enabling health-condition-based advertising targeting that the platforms' own policies may have limited if the conditions had been declared rather than inferred. GoodRx also used the data to run retargeting campaigns — sending users advertising for related products after they had searched for or filled a specific prescription — in a way that depended on the advertising platform having received the prescription data to identify which users to target.DOCUMENTED
The Health Breach Notification Rule
The Health Breach Notification Rule requires vendors of personal health records — companies that collect individuals' identifiable health information outside of the traditional healthcare provider relationship — to notify affected individuals, regulators, and in some cases the media when their health records are disclosed to unauthorized third parties. The rule was designed to extend breach notification obligations to health data held by consumer-facing health technology companies that are not covered by HIPAA's notification requirements because they are not healthcare providers, insurers, or their business associates.REVIEWED
Regulators determined that GoodRx's sharing of prescription and health data with advertising platforms through its pixel implementations constituted a breach under the rule — a disclosure of personal health records to third parties who were not authorized by users to receive that information. The $1.5 million penalty for GoodRx's failure to provide required notification marked the first enforcement action under the Health Breach Notification Rule, establishing it as an active enforcement mechanism for consumer health data held by technology companies outside the HIPAA framework.DOCUMENTED
GoodRx's privacy policy told users their health data would never go to advertisers — while its tracking pixel implementation was actively sending Facebook and Google information about the specific medications users were searching for and picking up at pharmacies.
Health Data and the Advertising Ecosystem
The GoodRx case illustrates a systemic tension in consumer health technology: platforms that collect sensitive health information to provide consumer services have strong business incentives to monetize that data through advertising, but consumers using these platforms often have reasonable privacy expectations based on the health context in which they are sharing the information. A user who searches for HIV medication or antidepressants on a prescription discount platform is sharing information about their health that they may reasonably expect to remain private — not to be transmitted to advertising platforms that will use it to categorize them for targeted advertising.REVIEWED
The settlement requires GoodRx to cease sharing users' health data with advertising platforms for advertising purposes, to delete health data previously transmitted to advertising partners that is used for advertising targeting, and to implement enhanced privacy disclosures that accurately describe how health data is used. GoodRx is also prohibited for a defined period from making representations about its privacy practices without adequate substantiation. Users who used GoodRx services during the relevant period and whose medication and health data was shared with advertising platforms should be aware that the settlement's data deletion requirements may address data currently held by those advertising platforms.DOCUMENTED
Protecting Your Health Data Online
The GoodRx case highlights why consumers should approach health-related apps and websites with the same caution they would apply to sharing sensitive health information with any third party. Before using a prescription discount, telehealth, or health tracking app, consumers should read the privacy policy to understand specifically which third parties will receive their data and for what purposes. Terms like "advertising partners," "analytics providers," and "business partners" in privacy policies may encompass advertising platforms like Facebook and Google. If an app's privacy policy is vague about third-party sharing, consumers should assume the worst until they can verify otherwise. For prescription drug information specifically, the most privacy-protective approach is to use the prescription discount programs offered by pharmacies directly — where the data stays within the pharmacy relationship rather than flowing through a separate technology platform.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.