If you're running a telehealth platform, you're facing a critical decision that affects your regulatory compliance: should you embed third-party tracking technologies to drive growth, or should you first build a consent infrastructure before collecting any data?
The FTC's enforcement action against Him & Hers highlights the consequences of choosing poorly. The company used Meta Pixel, Meta Conversions API, and tracking tools from Snap, Microsoft, Google, and others to share sensitive consumer data for advertising. The FTC is now seeking a permanent injunction, civil penalties, and monetary awards. This isn't the first time the agency has targeted telehealth companies for similar issues, BetterHelp, GoodRx, and Premom have all settled complaints with financial penalties.
Your decision starts here: what type of data are you collecting, and what control framework governs it?
The Decision You're Facing
You must determine whether your data collection and sharing practices require explicit opt-in consent before deploying tracking technologies, or if you can rely on notice-and-choice mechanisms afterward.
This is a legal and operational question that determines your compliance with the Federal Trade Act, the Restore Online Shoppers' Confidence Act, Health Insurance Portability and Accountability Act (HIPAA) requirements (if applicable), and state consumer protection statutes.
The wrong choice puts you in the FTC's crosshairs. The right choice requires mapping your data flows before mapping your marketing funnel.
Key Factors That Affect Your Choice
Data sensitivity. If you're collecting information about mental health, sexual health, reproductive health, or chronic illnesses, you're handling sensitive health information. Even if you're not a covered entity under HIPAA, the FTC treats this data as requiring heightened protection under Section 5 of the Federal Trade Act.
Third-party recipients. If tracking technologies automatically transmit user data to advertising platforms, you're sharing data with third parties. This includes server-side APIs like Meta Conversions API, not just client-side pixels. The FTC's complaint specifies that Him & Hers transmitted data to Meta in response to certain events and sent customer lists to Meta and Snap custom audience systems.
Consumer expectations. If your marketing claims promise privacy, security, or confidentiality, your actual data practices must align with those representations. Him & Hers told consumers that "medical records and sensitive information are only accessed by the medical providers managing your care" and advertised a "100% online, private, and secure process." Those statements created enforceable expectations.
Consent mechanisms. If you're relying on implied consent, notice buried in a privacy policy, or post-collection opt-out, you're exposed. The FTC's enforcement pattern shows that sensitive health data requires affirmative, informed consent before collection.
Path A: Build Consent Infrastructure First
Choose this path if you're collecting data about specific medical conditions, prescription medications, or treatment outcomes.
When this applies:
- You operate a telehealth platform where users disclose diagnoses or symptoms.
- Your intake forms collect information about erectile dysfunction, mental health, fertility, or other sensitive conditions.
- You plan to share any consumer data with advertising platforms, data brokers, or analytics providers.
- Your business model depends on recurring subscriptions tied to prescription refills.
What you need to implement:
- A Consent Management Platform that captures explicit opt-in consent before loading tracking pixels.
- Granular consent options that allow users to accept or reject specific third-party data sharing.
- Technical controls that prevent tracking technologies from firing until after consent is granted.
- Documentation showing that consent was collected before data was transmitted.
Specific requirements:
- Under the Restore Online Shoppers' Confidence Act, you must obtain express informed consent before charging consumers in a negative option feature (automatic renewals).
- If subject to the General Data Protection Regulation for EU users, Article 9 requires explicit consent for processing health data.
- The HIPAA Privacy Rule requires authorization for uses and disclosures not otherwise permitted, even if you're not a covered entity and are handling similar data types.
Operational steps:
- Audit every tracking technology on your site and document what data it collects.
- Map data flows from collection through transmission to third-party platforms.
- Implement server-side consent enforcement, not just client-side cookie banners.
- Train your marketing team that growth targets do not override consent requirements.
Path B: Limit Tracking to Non-Sensitive Identifiers
Choose this path if you're collecting general engagement data but not health information, and you're willing to accept reduced marketing attribution.
When this applies:
- You operate a wellness platform focused on fitness, nutrition, or general health education (not diagnosis or treatment).
- Your tracking is limited to page views, session duration, and conversion events.
- You do not transmit information about specific medical conditions, prescriptions, or diagnoses.
- You can demonstrate that transmitted data does not reveal health status.
What you need to implement:
- Technical controls that strip health-related parameters from tracking pixels.
- Server-side data layer logic that filters sensitive fields before transmission.
- Regular audits of what data your tracking technologies actually collect versus what you intend to share.
- Clear privacy disclosures that accurately describe your data practices.
Specific requirements:
- Your privacy policy must list every third party that receives consumer data and describe the purpose.
- You must provide a mechanism for consumers to opt out of data sharing for advertising purposes.
- If you make privacy claims in your marketing, your Statement of Applicability must document controls that enforce those claims.
Operational steps:
- Implement tag management rules that block health-related data elements from firing.
- Review your advertising platform configurations to confirm you're not using custom audiences built from health data.
- Document your data sharing practices in a way that an FTC investigator can verify.
- Test your tracking implementation to confirm sensitive data isn't leaking through URL parameters or form fields.
Path C: Operate Without Third-Party Tracking
Choose this path if you're willing to prioritize regulatory compliance over marketing attribution and you can build growth through other channels.
When this applies:
- You're handling highly sensitive health data and cannot implement reliable consent controls.
- Your risk tolerance does not permit exposure to FTC enforcement actions.
- You can acquire customers through direct channels, content marketing, or partnerships that don't require pixel-based attribution.
- Your executive team understands that compliance risk outweighs short-term growth metrics.
What you need to implement:
- First-party analytics that keep all data on your infrastructure.
- Direct measurement of conversion events without third-party pixels.
- Marketing attribution models that rely on self-reported sources or coupon codes.
- Privacy-by-design architecture that prevents sensitive data from leaving your environment.
Specific requirements:
- You still need a privacy policy that accurately describes your data practices.
- You must implement technical and administrative safeguards appropriate to the sensitivity of the data.
- If you later decide to add tracking technologies, you must obtain consent before deployment.
Operational steps:
- Build internal analytics infrastructure that provides the insights you need without external data sharing.
- Negotiate with advertising platforms to use conversion APIs with hashed, non-sensitive identifiers only.
- Document your decision to forgo third-party tracking as a risk mitigation control.
- Monitor FTC enforcement trends to determine if your risk calculus should change.
Summary Matrix
| Factor | Path A: Consent First | Path B: Limited Tracking | Path C: No Third-Party Tracking |
|---|---|---|---|
| Data sensitivity | High (diagnoses, prescriptions) | Low (general engagement) | High (cannot reliably filter) |
| Consent mechanism | Explicit opt-in via Consent Management Platform | Notice with opt-out | Not required (no sharing) |
| Marketing attribution | Full attribution after consent | Partial attribution | First-party only |
| Regulatory risk | Low if implemented correctly | Moderate if disclosures are accurate | Lowest |
| FTC enforcement exposure | Low | Moderate | Minimal |
| Implementation complexity | High | Moderate | Low |
| Business model compatibility | Supports paid acquisition | Supports paid acquisition with constraints | Requires organic or direct channels |
The FTC's complaint against Him & Hers demonstrates that "we didn't know the pixel was collecting that data" is not a defense. You're responsible for understanding what your tracking technologies collect and where that data goes. If you're claiming privacy in your marketing while sharing sensitive health information with advertising platforms, you're building enforcement exposure into your growth strategy.
Choose your path based on the data you collect, not the growth targets your board sets. The compliance decision comes first. The marketing strategy follows.


