FTC bars GoodRx from sharing consumers’ sensitive health info for advertising
ftc.gov
ftc.gov
I don't think many are surprised that GoodRX was sharing data (violating its own privacy policy) but come on, have some teeth. You'd think with HIPPA that we'd treat anything medical more seriously.
At the Federal level, the only broad general protections for medical data are (apparently) some FTC fine print. The fact that this exists at all means that medical data is treated more seriously than other forms of personal data, but as you can see that is a very low bar to clear (literally doesn't exist).
This is inaccurate in part.
HIPAA governs covered entities and business associates (BA) who work on behalf of a CE. Covered Entities are healthcare providers or insurance companies. CEs are required to have their BAs sign business associate agreement where they’re regulated under HIPAA.
GoodRx convinced patients to provide them their health information directly. Unless, they’ve signed a BAA with a CE, the FTC is the only government body with regulatory power here however I would imagine there’s a legal firm prepping a class action against GoodRx right now as well.
The class action is what will be expensive for them. The fact that they have been fined is what should make the action hopefully a slam dunk.
Sources:
- https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...
- https://www.hhs.gov/hipaa/for-professionals/security/laws-re...
That smells like real money to me.
The total cost for the biggest healthcare breach was around $500 million give or take.
It seems unlikely that GoodRx was processing data that met that standard.
https://www.hhs.gov/hipaa/for-professionals/covered-entities...
There’s no wiggle room here unless the data has been de-identified (a high barrier). It wasn’t.
The standard you’re refering to is for e-PHI which is “individually identifiable health information.”
You’ll want to see the Privacy Rule for details but GoodRx shared email addresses, phone numbers and mobile identifiers according to the FTC complaint.
https://www.ftc.gov/system/files/ftc_gov/pdf/goodrx_complain...
> In truth and in fact, GoodRx is not a HIPAA-covered entity, and its privacy and information practices did not comply with HIPAA’s requirements.
Further, on page 25, they define them as a "vendor of personal health records" - which explicitly excludes covered entities (definition on page 19).
-----
This is consistent with my understanding of a covered entity. Without the "transactions for which HHS has adopted a standard", GoodRx is not a covered entity.
Further, even if they were a covered entity, it's possible for them to segment their HIPAA and non-HIPAA compliant business units. This is called a "hybrid entity".
----
Interestingly, the FTC is pinging them on for a misleading representation of being a covered entity. Since GoodRX was not a covered entity, they were not technically violating HIPAA.
I’m not saying that they are a CE only that if they were then the data is clearly PHI and had not been de-identified per the standard that you referenced previously.
> on page 25, they define them as a "vendor of personal health records"
So the FTC itself considers GoodRX an entity primarily focused on selling the health information of individuals.
Just in case anyone though it was something else.
It is claimed something like half the population can be uniquely identified just with DOB, gender, and zip code.
"A high barrier" is ambiguous - it could mean that it is high because it's difficult and expensive to comply with the legal standards - or it could mean it provides a high level of protection against uniquely identifying subjects.
I'm betting 100% of the former and 0% of the latter.
All of the major enterprise healthcare organizations have dedicated analysts who work solely on de-identifying datasets so that the data can be used for commercial purposes.
It's such a hard problem that it is not achievable except in very specific circumstances, such as if the data is just a single single datapoint or if the data is aggregated with a lot of other data, and the original individual datapoints are deleted.
In practice, whenever you hear anyone claim they've "anonymized" or "de-identified" your data, if you assume that's not true, you're much more likely to be right than wrong.
If that doesn't make them a CE, then somebody has some 'splaining to do.
Here is who qualifies as a CE:
https://www.hhs.gov/hipaa/for-professionals/covered-entities...
How does GoodRx fit into any of these categories? I don't see it.
It's possible some health care providers (think large hospitals) enforce HIPAA via contractual obligations without federal law directly requiring PBMs to be covered entities.
That would give a path for GoodRx to interact without being in violation of HIPAA.
Already filed:
https://www.classaction.org/news/class-action-alleges-goodrx...
If their 11M subscribers are each worth ~$500 that might be a little more of a deterrent.
I really wish the FTC did this more often.
If you’re marketing your service as privacy focused, you can just sell your customers data.
Plenty of services start out as free-speech/privacy focused, but change their tune once advertisers make demands.
That should be allowed. If you built your community by promising privacy, you shouldn’t be able to go back in that easily.
Lock in is a real thing. Abusing it is wrong.
Our legal system was also created during an age where there weren’t so damn many billionaires with a net worth greater than tens of millions of average taxpayers combined.
I’m not sure I do. The FTC does civil enforcement and investigation. They identify misbehavior and issue the equivalent of parking tickets. If you also give them the ability to issue punishments then what prevents the FTC from using that power to line their own pockets by sabotaging (or threaten to sabotage) well behaved companies?
This penalty may not preclude lawsuits by GoodRx customers or further investigations by other organizations leading to criminal penalties.
I’m not a lawyer so I could be totally off base here but this is my understanding after dozens of these HN threads with similar comments.
> $1.5 million is pocket change for a company with $765 million annual revenue.
Is it? GoodRx hasn’t turned a profit since 2019. They lost $32.8 million on $766.5 million in revenue in 2022.
But, it probably isn't enough to prevent other bad actors. Or from GoodRx re-offending in a few years, once the CEO/BoD/etc have rotated on to other pursuits.
Well-behaved companies won't line their own pockets out of fear that the FTC will sue them out of existence.
I edited that sentence to try and clarify.
> If you also give them the ability to issue punishments then what prevents them from using that power to sabotage (or threaten to sabotage) well behaved companies to line their own pockets?
"Own pockets" - FTC is not a for profit company. GoodRx is a for profit company. Companies have more to gain by acting in bad faith than FTC. So I would trust FTC any given day over a for profit company.
> GoodRx hasn’t turned a profit since 2019
This doesn't necessarily mean company is in bad shape. This happens when company is investing in growth at the cost of profit margins during it's initial years. If they can shell out half million dollars on lobbying then $1.5 million is indeed a pocket change for them.
As with class action suites, big companies have armies of lawyers to fight such cases for ages and ultimately the victims tend to settle for less because they can’t afford to fight forever.
Armies of lawyers aren't free and even if the victims don't get paid the lawyers do. It still costs the company money, a lot more than this settlement.
As regards to the accurate number I don't have any, but it should definitely not be this low.
We could start at whatever they charged their customers for the data. Not whatever the profit may have been, the sum of the invoices.
Proportionality, also means that if you have less to give, you give less.
I never understood how this came to be, but I later became suspect when receipts and other bits of the paper trail had to first pass through their hands rather than the previous arrangement where you were responsible for keeping those records on hand should you ever be audited by the IRS. They changed the UI pattern for reimbursement to force receipt uploads, and non itemized receipts got rejected. I wonder if they too use this information for like purposes as GoodRx.
$900m in funding[0] and their business practices are straight out of a fly-by-night MLM brand.
HIPPA is not a medical privacy bill.
HIPAA (Health Insurance Portability and Accountability Act) - a real 1996 law.
HIPPA (Health Information Privacy and Portability Act) - not a thing.
Essentially, they can remain "HIPAA compliant" by segmenting their HIPAA and non-HIPAA business units.
GoodRx makes the entire process a few iPhone clicks.
Also $1.5 million, in relative terms, seems pretty small. So again, data violations just seem to be the cost of doing business.
In one situation you have a company sharing data with other companies and the laws around that form of data sharing.
In the other situation you have what companies can own or buy in terms of other companies.
The situations are very different.
On one hand you have the FTC fining a company for violations of data sharing, which I am assuming of the one of the concerns is patient privacy. Which to me, seems like a net good thing. Again I would prefer it to be more, but better then not doing nothing at all I suppose.
On the other hand, you have one giant company with access to mounds of consumer data purchasing even more sensitive healthcare data without even a blink of the eye.
Why was this not challenged? Why fine one company? I might be overthinking it but it seems like a misalignment of priorities. The point of the FTC is to protect consumers, shouldn't both have been investigated? I guess that was the point I was trying to make. Idk, I feel like I'm just rambling at this point.
Edit: so I looked it up
https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-give...
“As required by law, Amazon will never share One Medical customers’ personal health information outside of One Medical for advertising or marketing purposes of other Amazon products and services without clear permission from the customer,” an Amazon spokesperson said in an email. “Should the deal close, One Medical customers’ HIPAA Protected Health Information will be handled separately from all other Amazon businesses, as required by law.”
Basically, like I thought, they can’t commingle or share data between the two companies. But if something being clearly illegal isn’t enough to convince people (or even the journalist), then that’s a different much bigger issue.
Also this:
https://www.investopedia.com/terms/s/subsidiary.asp
A subsidiary is an independent company that is more than 50% owned by another firm—called the parent company or holding company. Subsidiaries are separate and distinct legal entities from their parent companies.
> https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-give...
> > “As required by law, Amazon will never share One Medical customers’ personal health information outside of One Medical for advertising or marketing purposes of other Amazon products and services without clear permission from the customer,” an Amazon spokesperson said in an email. “Should the deal close, One Medical customers’ HIPAA Protected Health Information will be handled separately from all other Amazon businesses, as required by law.”
> Basically, like I thought, they can’t commingle or share data between the two companies.
Unfortunately, that's not at all what it says. Amazon has included so many qualifiers that they are disclaiming only a very specific subset of data transfer.
I invite you to read it again, word by word and clause by clause.
Lots of loopholes in there. But even if there weren't, doesn't it feel dangerous to take Amazon at their word with this?
The FTC doesn't operate based on sentiment. Even if the people who work on this have the same feelings they need to operate within laws.
and companies have never reneged immediately after promising not to do bad things.
https://www.cnbc.com/2023/01/25/the-live-nation-and-ticketma...
https://www.nytimes.com/2022/11/18/technology/live-nation-ti...
Nothing odd about retailers acquiring other retailers.
There’s a similar problem for any private companies that have outstanding debt or payment obligations. If they default or go bankrupt, then the courts will force them to sell user data to help generate the missing cash. This will override any user agreements, since the creditors are generally first in line when a company goes under.
The only difference between One Medical and GoodRX here is that One Medical only sold account data to one advertising firm (that I know of).
We know they're a publicly traded company, we know their revenue, profit, etc. -- why not fine them a percent based on this data? It's a little more tricky with private companies, but a certification process, and a undisclosed fine in those cases work too.
that is the basic gist. our federal government doesn't do much of anything for the people it represents, compared to what it does for corporations, lobbyists, and career politicians.
The biggest takeaway here seems to be the ban on sharing data, not on the fine itself. I interpret that to mean sharing the data for advertising purposes is legal, maybe with consent from the customer? But now GoodRx can't do that?
Seems kinda dumb! I for one would probably not have written that code.
Just yesterday $60.25, Walgreen’s, returned —> $7.20, Safeway, GoodRx e-coupon.
My wife is finally a believer, and it paid for more than half of a $100 birthday gift for a poor cousin 1500mi away.
I can't. It doesn't matter if they give drugs away for free, GoodRx is a bad actor. Exactly the sort of company that needs to lose all their customers.
Yes, GoodRx was a bad actor in its misuse of medical data. Absolutely. Unless that practice underlies its business model, which I doubt, GoodRx is, on balance, a GOOD actor. It seems that the business model is sales lead generation, and they have been able to force it’s use by major pharmacies over time.
I suspect that this is a point that we will never agree on.
Because the penalty is small enough that it's a "cost of doing business". Until these fines are large enough to cause hardship to the company, or we start piercing the corporate veil and go after executives in their personal capacity this is going to keep happening.
I simply do not believe there is a good-faith argument that GoodRX wasn't familiar with the law in this case.
Notably:
> [a bunch of providers] ...but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard.
If you don't process a specific type of transaction, no HIPAA requirements.