Mynd Analytics Inc., a behavioral health technology company that provided clinical decision support and population health management tools to mental health providers and health plans, faced Federal Trade Commission charges alleging the company had shared sensitive mental health and behavioral health data from its platform with third-party analytics and advertising vendors under arrangements that were not disclosed to the patients whose data was involved and that were inconsistent with the privacy representations the company made to the providers and patients who used or were covered by its platform.DOCUMENTED
The FTC's case against Mynd Analytics addressed one of the most sensitive categories of health data — information about mental health diagnoses, psychiatric treatment, psychotropic medication use, and behavioral health episodes — in a context where both the legal protections and the practical expectations of privacy are particularly strong. Mental health data has long been recognized as warranting special sensitivity, and the commercial sharing of this data without adequate notice or consent represents a particularly serious form of privacy violation.
- Mynd Analytics shared mental health and behavioral health data with third-party analytics and advertising vendors.
- The data sharing was inconsistent with the privacy representations the company made to providers and patients.
- The FTC found the practices violated the FTC Act's prohibition on deceptive practices.
- Mental health data included psychiatric diagnoses, medication information, and behavioral health treatment records.
- The settlement required a comprehensive privacy program, data deletion, and civil monetary penalties.
The Special Sensitivity of Mental Health Data
Mental health information has historically been recognized as warranting heightened privacy protection relative to other health information. HIPAA includes specific provisions limiting the disclosure of psychotherapy notes that go beyond those applicable to general medical records. Many states have enacted stricter privacy protections for mental health records than for other health data. And social and professional stigma associated with mental health diagnoses and treatment creates practical harms from unauthorized disclosure that can include employment discrimination, insurance consequences, and relationship damage in ways that other health conditions may not generate with the same frequency or severity.REVIEWED
The commercial use of mental health data for analytics and advertising purposes without patient knowledge or consent represents a form of exploitation that goes beyond the financial harm to the company's contractual relationships. Individuals whose mental health diagnoses, psychiatric medication history, or behavioral health treatment records are incorporated into commercial data products without their consent may never know the disclosure occurred — and may experience consequences from that disclosure, including targeted advertising that reveals their treatment status to others who share their devices or accounts, without any ability to identify the source of the disclosure or seek redress.DOCUMENTED
The Deceptive Privacy Representations
The FTC's case against Mynd Analytics centered on the gap between the company's privacy representations — made in its privacy policy, in its contracts with mental health providers and health plans, and in its marketing materials — and the actual data sharing practices the company engaged in. Mynd represented to providers and patients that mental health data would be used only for specified clinical and care management purposes and would not be shared with third parties for commercial purposes without appropriate consent. The company's actual practices — sharing data with analytics and advertising vendors — were inconsistent with these representations, constituting deceptive conduct under the FTC Act's prohibition on unfair and deceptive practices.REVIEWED
The deceptive representation finding in the Mynd case illustrates a pattern the FTC has addressed in multiple health data enforcement actions: a company that makes specific, limited privacy commitments in its public-facing communications while engaging in broader data sharing practices in its actual operations. The gap between the represented and actual data practices is the deception — not the data sharing in isolation, but the false promise that the data would be used only in the ways the company described. Patients and providers who rely on privacy representations when deciding whether to use a health technology platform have a legal interest in the accuracy of those representations that the FTC's enforcement protects.
A mental health platform that promises to protect your therapy records and then sells them to advertising companies has not just broken a contract. It has exposed some of the most private information in a person's life to commercial uses they explicitly trusted the company not to allow.
Provider Liability and Supply Chain Privacy Risks
Mental health providers who used Mynd Analytics' platform faced their own compliance exposure from the company's data sharing practices. Providers are covered entities under HIPAA and bear responsibility for ensuring that the business associates they engage — including health technology vendors like Mynd — handle protected health information in compliance with HIPAA's requirements and with the provider's HIPAA compliance obligations. When a business associate shares protected health information in ways that violate HIPAA or the business associate agreement — as Mynd's unauthorized third-party data sharing appears to have done — the provider may face regulatory scrutiny for the adequacy of its business associate oversight, even when the provider was not aware of the specific data sharing activities.DOCUMENTED
The Mynd case is a reminder that providers' HIPAA compliance obligations extend into their technology vendor relationships, and that vendor due diligence — including review of vendors' data sharing practices, contractual data use limitations, and audit rights — is a necessary component of a provider's privacy compliance program. Providers who assume that their business associate agreements automatically constrain all vendor data practices, without verifying those constraints through ongoing monitoring and periodic audits, may find themselves exposed when a vendor's actual practices diverge from the agreement's requirements in ways that create patient harm and regulatory liability for the provider as well as for the vendor.
Settlement Requirements and Forward-Looking Protections
The FTC's settlement with Mynd Analytics required the company to implement a comprehensive privacy program specifically tailored to the sensitivity of mental health data, including enhanced data minimization practices that limit data collection to what is necessary for specified clinical purposes, explicit consent requirements for any data use beyond those purposes, enhanced security controls for mental health data storage and transmission, and regular privacy audits by independent professionals. The settlement also required Mynd to delete data that had been shared in violation of its privacy representations and to notify affected individuals and providers of the unauthorized sharing — a notification obligation that created ongoing accountability for the harm that had already occurred even as the forward-looking compliance requirements addressed future practices. The combination of data deletion, individual notification, civil monetary penalties, and ongoing compliance requirements represents the full range of FTC privacy enforcement tools applied to a case involving particularly sensitive health information and clear deceptive conduct.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.