Does the FTC Regulate Health Data If You're Not a HIPAA Covered Entity?
Last updated: August 10, 2026 ยท By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
Yes. The FTC is the regulator for everyone HIPAA doesn't cover. "We're not a covered entity" is the most expensive misconception in health marketing. If HIPAA doesn't reach you, the FTC does — and its recent health-data cases needed no HIPAA hook at all.
The cases that set the line
GoodRx, BetterHelp, and Cerebral each paid to settle FTC actions for sharing consumers' health information with ad platforms. None turned on HIPAA. The FTC used its authority over unfair and deceptive practices and its Health Breach Notification Rule to reach companies that assumed they were outside the health-privacy regime. If you sell a health product and share behavioral data with Meta or Google, you are in the same category those companies were.
What the FTC actually polices
- Deceptive privacy promises. Saying "we don't share your health data" while a pixel does exactly that is the classic case.
- Unfair disclosure. Sending sensitive health data to advertisers without clear, affirmative consent, regardless of what your policy says.
- Health Breach Notification. The FTC has stretched this rule to cover unauthorized disclosures via tracking technologies, not just classic data breaches.
What a non-covered health brand should do
Behave as if HIPAA's discipline applied even though its letter doesn't. Keep health-inferring data out of ad platforms, gate tags behind real consent, and make sure your privacy policy describes what actually happens. The gap between your policy and your pixel is the FTC's whole case. See whether HIPAA itself reaches your brand.
FAQ
We're a supplement brand, not a clinic. Are we really exposed?
Yes. GoodRx wasn't a clinic either. If your data can infer a health interest and you share it with advertisers, the FTC theory fits.
Does a privacy policy disclosure protect us?
Only if it is accurate and the sharing is consented. A disclosure that contradicts your actual data flows makes the deception case easier, not harder.
Is consent enough to share health data with Meta?
Consent addresses the FTC's deception and unfairness concerns; it does not make Meta a compliant recipient. Keep true PHI out regardless.
Sorting out your exposure?
Coast Studio runs compliance-first paid media for regulated health brands — we map your legal exposure and build tracking that holds up. Not legal advice.
Book a Consultation