Coast Studio
Book a Consultation
  • Methodology
  • Growth LabsEcommerce & DTC Scale Regulated MarketsHealth, Fintech & Legal
  • Creative
  • Case Studies
  • Blog
  • About
  • Methodology
  • Growth Labs
  • Regulated Markets
  • Creative
  • Case Studies
  • Blog
  • About
  • Book Consultation →
Home / Blog / FTC & Non-Covered Health Brands

HIPAA Tracking · Q&A

Does the FTC Regulate Health Data If You're Not a HIPAA Covered Entity?

Last updated: August 10, 2026 ยท By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.

Yes. The FTC is the regulator for everyone HIPAA doesn't cover. "We're not a covered entity" is the most expensive misconception in health marketing. If HIPAA doesn't reach you, the FTC does — and its recent health-data cases needed no HIPAA hook at all.

The cases that set the line

GoodRx, BetterHelp, and Cerebral each paid to settle FTC actions for sharing consumers' health information with ad platforms. None turned on HIPAA. The FTC used its authority over unfair and deceptive practices and its Health Breach Notification Rule to reach companies that assumed they were outside the health-privacy regime. If you sell a health product and share behavioral data with Meta or Google, you are in the same category those companies were.

What the FTC actually polices

  • Deceptive privacy promises. Saying "we don't share your health data" while a pixel does exactly that is the classic case.
  • Unfair disclosure. Sending sensitive health data to advertisers without clear, affirmative consent, regardless of what your policy says.
  • Health Breach Notification. The FTC has stretched this rule to cover unauthorized disclosures via tracking technologies, not just classic data breaches.

What a non-covered health brand should do

Behave as if HIPAA's discipline applied even though its letter doesn't. Keep health-inferring data out of ad platforms, gate tags behind real consent, and make sure your privacy policy describes what actually happens. The gap between your policy and your pixel is the FTC's whole case. See whether HIPAA itself reaches your brand.

FAQ

We're a supplement brand, not a clinic. Are we really exposed? Yes. GoodRx wasn't a clinic either. If your data can infer a health interest and you share it with advertisers, the FTC theory fits.

Does a privacy policy disclosure protect us? Only if it is accurate and the sharing is consented. A disclosure that contradicts your actual data flows makes the deception case easier, not harder.

Is consent enough to share health data with Meta? Consent addresses the FTC's deception and unfairness concerns; it does not make Meta a compliant recipient. Keep true PHI out regardless.

Related

  • The State of HIPAA-Compliant Marketing Tracking
  • Is My Wellness or Supplement Brand Subject to HIPAA?
  • Does HIPAA Apply to My Website?
  • FTC-Safe Ad Tracking for Wellness Brands
JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

Sorting out your exposure?

Coast Studio runs compliance-first paid media for regulated health brands — we map your legal exposure and build tracking that holds up. Not legal advice.

Book a Consultation
Coast Studio

© 2026 Left Coast Agency, LLC.

AboutJason GarrettBlogPrivacyTermsContact
Google Partner