⚠ FTC & HIPAA Enforcement Watch

Telehealth Privacy & Data Leak Auditor

Analyze health platforms for invisible advertising pixels, questionnaire interception, non-HIPAA cash loopholes, and consumer health data broker sharing before you submit sensitive medical info.

MindWellness Online Therapy — Privacy Exposure

Live simulation of data transmitted when filling out onboarding questionnaires.

HIGH EXPOSURE RISK
Leak Risk Index 84 / 100 Critical Data Spill
Ad Pixels Active 4 Trackers Meta, Google, TikTok
HIPAA Shield Unshielded Cash-pay Terms Exemption
Broker Sharing Allowed De-identified aggregation

Interactive Intake Form & Network Interceptor

Adjust simulated answers to see real-time outbound payloads

Intercepted Network Requests (Live Packet Stream)

5 outbound requests recorded

Security & Legal Diagnostic Findings

Key vulnerability vectors identified from regulatory precedents (FTC BetterHelp, GoodRx, Premom cases).

Ready. Platform audit recalculated.

How Telehealth Platforms Share Data Without Patients Knowing

Direct-to-consumer health companies frequently blur the line between clinical medicine and e-commerce advertising.

1. The "Non-Covered Entity" Trap

Many patients assume any app with a doctor on it is bound by HIPAA. Under federal law, if a company does not electronically transmit standard healthcare claims (such as billing Medicare or private insurance) and does not act as a Business Associate to an insurer, HIPAA does not legally apply to their tech platform.

2. Invisible Ad Pixels in Intake Quizzes

When you answer questions about mental health, weight, or reproductive wellness before creating an account, marketing scripts like the Meta Pixel or Google Tag Manager often intercept form inputs (DOM scraping or custom events), sending your IP address, condition interest, and hashed email straight to advertising networks.

3. "Anonymized" Data Isn't Anonymous

Terms often permit companies to monetize "de-identified" or aggregated medical data. Numerous computer science studies have proved that combining just a few attributes (such as ZIP code, birth date, and medical specialty) allows commercial data brokers to re-identify 87% of individuals.

Frequently Asked Questions Before Signing Up

What did the FTC's recent actions against telehealth platforms find?

In actions against BetterHelp, GoodRx, and Premom, the Federal Trade Commission penalized companies for sharing sensitive health information with advertising platforms like Facebook, Google, Snapchat, and Criteo. Disclosed data included mental health struggles, prescription names, and ovulation cycles, despite prominent promises that health data remained confidential.

How can I protect my medical data when using online care?

Use a separate, pseudonymous email alias (like Apple's Hide My Email or SimpleLogin) for consumer apps. Use content blockers (like uBlock Origin) or privacy-focused browsers to prevent third-party tracking pixels from capturing your intake answers. Refuse optional marketing cookies, and request an explicit Business Associate Agreement (BAA) confirmation if you require strict HIPAA protections.

Does this auditor send any of my typed information to a server?

No. This auditor operates 100% locally inside your web browser. None of the platform names, terms, or simulated intake answers are transmitted to any remote server or third party.

Enjoy this tool? Build your own with Super