๐Ÿš€ Decoda raises $4.5M, led by Y Combinator. Read more

Journal/Reference library
Updated August 4, 2026ยท7 min read
What the FTC Health Data Enforcement Means for Elective Care August 2026

What the FTC Health Data Enforcement Means for Elective Care August 2026

FTC enforcement on health data is no longer a gray area. Get your med spa or telehealth clinic compliant before regulators call. August 2026.

Kevin Cheng
Co-Founder & CPO, Decoda Health

TL;DR

5 key points
  • 01Tracking pixels on booking pages can trigger FTC violations even when no data breach occurs
  • 02HIPAA compliance alone does not protect you; the FTC Act and Health Breach Notification Rule apply separately
  • 03A single pixel firing can generate simultaneous federal and state enforcement across multiple jurisdictions
  • 04Audit third-party scripts, confirm vendor BAAs, and build ad claim substantiation files before regulators ask
  • 05Decoda's AI Scribe, AI Front Desk, and Ask Decoda keep patient data out of third-party ad pipelines

The FTC vs. Hims & Hers: What Just Happened

In June 2025, the FTC settled with Hims & Hers over allegations that the telehealth company shared sensitive patient data with advertisers without proper consent. The company had been routing health information through tracking pixels embedded in its site, sending data to Meta and Google that the FTC argued patients never agreed to share. The case is active and pending court resolution; Hims has disclosed a $15 million probable-loss accrual related to the matter. The case sent a clear signal: regulators are no longer treating pixel-based tracking as a gray area in elective and telehealth care.

This Is Not an Isolated Case

The FTC's enforcement on GoodRx was a warning shot. Since then, regulators have broadened their scope well beyond pharmacy apps to include telehealth providers, weight loss clinics, and elective-care practices that run retargeting ads or use pixel-based analytics. The agency's updated Health Breach Notification Rule now covers a far wider category of "health apps and connected devices," and enforcement actions through 2025 have followed. For med spa and telehealth owners, the pattern is clear: if your website collects health-related data and shares it with third parties for advertising, you are operating in active regulatory crosshairs.

Why Med Spas and Telehealth Clinics Are in the Crosshairs

Med spas and telehealth clinics sit at an uncomfortable intersection: they collect sensitive health data, and they spend heavily on digital advertising. That combination has drawn direct FTC scrutiny. These practices routinely feed patient data into ad networks through tracking pixels, use browsing behavior to retarget prospective patients, and share appointment or condition data with third-party vendors. The FTC's Health Breach Notification Rule and recent enforcement actions make clear that this data handling is no longer a gray area. Independent elective-care practices, often without dedicated compliance staff, carry real exposure every time a pixel fires on a booking page, which is why choosing HIPAA medical spa software is one of the first lines of defense.

What to Do Before the FTC Comes Calling

The enforcement pattern is clear. What follows is a compliance review any practice can run before a regulator runs it for you.

  • Audit every third-party script on your website and patient-facing pages. If a pixel fires during booking or intake, document exactly what data it captures and where it goes.
  • Confirm that advertising vendors have signed Business Associate Agreements where required. Many ad-tech vendors won't sign one, and that answer tells you something.
  • Compare your privacy policy to your actual data practices. The FTC targets aspirational language that doesn't match real behavior, and outright deception is far from the only trigger.
  • Obtain written, HIPAA-compliant authorization for every patient photo or testimonial before it appears in any ad or post.
  • Build a substantiation file for every outcome claim before the ad runs, not after a complaint arrives.
  • Train your marketing team on FTC disclosure requirements. Staff-generated content and influencer posts both count, even when unpaid.

The goal is defensible marketing, not less marketing.

How Tracking Pixels Become a Patient Data Problem

When a prospective patient visits your med spa website and browses a treatment page, the Meta Pixel or Google Tag embedded in your site captures that visit and ties it to their identity. If that person later books a consultation, you've effectively disclosed a health-seeking behavior to a third-party advertiser without their explicit consent.

The FTC treats this as a privacy violation. Under the Health Breach Notification Rule, sharing identifiable health data with advertising networks without authorization qualifies as an unauthorized disclosure, which is exactly why choosing medspa EHR software with compliant data handling matters, regardless of whether a breach occurred. For telehealth clinics running retargeting campaigns, this exposure is often invisible until regulators come looking.

HIPAA Alone Will Not Protect You

Many practice owners assume HIPAA compliance is their legal ceiling. It is not. The FTC Act, Section 5, prohibits unfair or deceptive practices regardless of whether patient data is technically "protected health information." The FTC's Health Breach Notification Rule now covers health apps and pixel-tracking vendors that sit entirely outside HIPAA's reach. If your Meta Pixel fires when a patient books a Botox consultation, that may constitute an unauthorized disclosure under FTC rules, not HIPAA. Regulators are increasingly treating these as separate violations requiring separate remediation, and med spas and telehealth clinics are squarely in their sights.

HIPAA

FTC Health Breach Notification Rule / FTC Act

Who it covers

Covered entities and their Business Associates (e.g., EHR vendors, billing services)

Health apps, pixel-tracking vendors, and any entity handling consumer health data, including those outside HIPAA's scope

What triggers a violation

Unauthorized use or disclosure of Protected Health Information (PHI)

Sharing health-related data with advertisers without explicit consumer authorization; unfair or deceptive data practices

Does pixel tracking apply?

Not directly. Pixel data to ad networks typically falls outside HIPAA's reach

Yes. A pixel firing on a booking page is treated as an unauthorized disclosure under the Health Breach Notification Rule

Key enforcement example

Data breaches, missing BAAs, improper record access

GoodRx settlement (2023), Hims & Hers settlement (2025), both for routing health data to Meta/Google without consent

Remediation required

HIPAA-specific: update BAAs, retrain staff, breach notification

Separate: overhaul data practices, penalties, and potential state-level claims under CCPA or My Health My Data Act

FTC Advertising Rules Every Practice Must Know

The FTC's advertising rules hit med spas and telehealth clinics on two fronts: endorsements and health claims. Under the updated Endorsement Guides, every paid testimonial or influencer post must carry a clear disclosure, and before-and-after photos used in ads must reflect typical results, not outliers. Practices that let patients post glowing reviews in exchange for discounts are already in violation.

On health claims, the FTC requires that any stated benefit be substantiated with competent and reliable scientific evidence. Vague promises about "rejuvenation" or "optimal wellness" may seem harmless, but regulators have cited far subtler language in enforcement actions.

  • Disclosures must be clear and conspicuous, placed where consumers will actually see them, not buried in captions or fine print.
  • Typical-results standards apply to visuals too, meaning stock-style photos that imply outcomes your average patient won't achieve can trigger liability.
  • Health claims require documented evidence on file before the ad runs, not after a complaint surfaces.

The Rise of Coordinated Federal-State Enforcement

The Hims & Hers settlement wasn't solely a federal action. Utah and California joined as co-plaintiffs, and that coordination is now a pattern. State attorneys general are active partners in FTC health data enforcement, not bystanders.

California's CCPA and Washington's My Health My Data Act each carry private rights of action independent of federal authority. A single incident can generate FTC enforcement and state-level claims simultaneously, from different jurisdictions, over the same underlying conduct.

For telehealth clinics operating across state lines, this compounds quickly. The same pixel firing on a booking page carries different statutory exposure in California versus Washington, and the FTC may be involved regardless. Practices in multi-state markets need to treat compliance as a layered obligation that follows their patients across state lines.

How Decoda Helps Practices Run Compliant Operations

Decoda is built for the realities of running an elective-care practice in a tightening regulatory environment. The AI scribe captures visit documentation without pulling sensitive data into third-party ad pipelines. AI Front Desk handles patient communication flows while keeping personally identifiable information contained within compliant workflows. Ask Decoda gives owners and physicians a way to query their own practice data without exposing it to external systems.

For practices running membership programs, tiered membership tools track patient relationships and billing without the kind of data sprawl that draws FTC scrutiny. Command+K lets staff pull records and run actions quickly, and patient communications stay contained within compliant workflows, reducing the workarounds that tend to create compliance gaps in the first place.

Final Thoughts on FTC Advertising and Data Compliance for Elective Care Practices

The FTC's recent actions aren't a warning that something might happen. They're a signal that it already is happening to practices that look a lot like yours. A pixel audit, a clear-eyed review of your privacy policy, and a clean process for patient consent go a long way. Grab a quick call with us if you want to see how Decoda supports compliant operations without adding friction to your day.

Frequently Asked Questions

Does the FTC Health Breach Notification Rule apply to med spas and telehealth clinics that use Meta Pixel or Google Tag for retargeting?

Yes, it applies directly. The FTC treats a pixel firing on a booking or intake page as an unauthorized disclosure of health-seeking behavior to a third-party advertiser, regardless of whether a HIPAA breach occurred. Med spas and telehealth clinics running retargeting campaigns carry real exposure every time that data leaves your site without explicit patient consent.

What should a med spa or telehealth clinic audit first to reduce FTC patient data advertising risk in 2026?

Start with every third-party script running on your website and patient-facing booking pages. Document exactly what each pixel captures and where that data goes, then check whether your advertising vendors have signed Business Associate Agreements. Many ad-tech vendors won't sign one, and that answer alone tells you where your exposure sits.

HIPAA compliance vs. FTC Health Breach Notification Rule for telehealth clinics: which one covers pixel tracking?

HIPAA does not cover pixel-based tracking to ad networks, and that gap is where FTC enforcement lands. The FTC Act, Section 5, prohibits unfair or deceptive data practices independent of whether the information qualifies as protected health information under HIPAA. The Hims & Hers settlement was an FTC action, not a HIPAA violation, and regulators are treating the two as separate obligations requiring separate remediation.

How does Decoda Health help elective-care practices keep patient data out of third-party advertising pipelines?

Decoda's AI Scribe captures visit documentation within compliant workflows, keeping sensitive data out of external ad systems entirely. The AI Front Desk handles patient communication while keeping personally identifiable information contained inside the platform. Ask Decoda lets owners query their own practice data without exposing it to outside systems, and tiered membership tools track patient relationships and billing without the data sprawl that draws FTC scrutiny.

What's the fastest way for a med spa to get its FTC advertising disclosures right before running influencer or before-and-after ad campaigns?

Build your substantiation file before the ad runs, not after a complaint arrives. Every outcome claim needs documented evidence on file, every paid post or influencer mention needs a clear disclosure placed where patients will actually see it, and every before-and-after photo must reflect results a typical patient can expect, not your best-case outlier.

Can a telehealth clinic get hit by both the FTC and a state attorney general over the same pixel on one booking page?

Yes, and that is exactly the pattern that emerged from the Hims & Hers settlement, where federal and state regulators acted together. California's CCPA and Washington's My Health My Data Act each carry independent enforcement authority, so a single pixel firing can trigger simultaneous claims from the FTC and multiple state AGs over the same underlying conduct.

What is the My Health My Data Act and does it affect med spas operating outside Washington State?

Washington's My Health My Data Act extends health data privacy protections to any business that collects health information from Washington residents, regardless of where the business is located. If your telehealth or med spa patients include anyone in Washington, that law may apply to your data practices and advertising workflows.

Should I use a consent management tool or just update my privacy policy to cover FTC pixel tracking requirements?

Updating your privacy policy alone will not protect you. The FTC targets aspirational language that does not match your actual data practices, so the fix is changing what the pixel does, not what the policy says. A consent management tool that blocks pixels from firing until a patient actively opts in is a more defensible approach than a revised disclosure buried in fine print.

How do I set up telehealth virtual visits inside my practice management software without opening up patient self-booking to those appointment types?

Decoda lets you configure virtual locations and appointment types independently of your public-facing booking flow. You can make telehealth visits bookable only by staff, keeping post-operative follow-ups and remote consultations off your online scheduling menu while still managing them inside the same calendar and clinical documentation system.

What is the difference between a HIPAA Business Associate Agreement and FTC consent for advertising vendors?

A BAA governs how a vendor handles protected health information under HIPAA, but many ad-tech vendors sit entirely outside HIPAA's reach and won't sign one. FTC consent is a separate obligation: it requires explicit patient authorization before health-related data flows to an advertising network, and no BAA substitutes for that authorization under the FTC Health Breach Notification Rule.

My staff is generating social content about patient results. How do I make sure those posts don't create FTC liability?

Every piece of content that implies a patient outcome, whether it comes from staff, a paid influencer, or an unpaid patient, must meet the FTC's typical-results standard and carry a clear disclosure if there is any material connection. Before-and-after photos must reflect what an average patient can expect, and your substantiation file for any outcome claim needs to exist before the post goes live.

How does an AI-native EMR keep patient data out of third-party ad pipelines compared to a traditional med spa software setup?

Traditional setups rely on website pixels and third-party booking widgets that route data to ad networks as a side effect of normal use. Decoda keeps booking, intake, and communication flows inside the platform, so patient data stays in a contained, compliant environment rather than passing through external scripts that report back to Meta or Google.

What's the difference between a package and a membership in a medical practice management system, and why does that distinction matter for FTC data compliance?

A package is a prepaid bundle of a fixed number of services, while a membership is a recurring subscription that grants ongoing access to discounts, credits, or services on a billing cycle. The distinction matters for compliance because membership data, including renewal behavior and treatment cadence, is richer health-related information that warrants tighter controls over how it flows to third-party vendors or ad systems.

How does an all-in-one EMR replace a separate CRM for patient communication in a way that reduces FTC advertising exposure?

A standalone CRM typically syncs patient data with marketing tools that are connected to ad networks, creating the exact third-party data flow the FTC scrutinizes. Decoda's Communications module keeps patient messaging, follow-ups, and campaign targeting inside one system, so re-engagement campaigns reach patients without that data leaving the platform and entering an external ad pipeline.

What documentation should a med spa keep on file to defend its advertising claims if the FTC opens an inquiry?

You need a substantiation file for every outcome claim before the ad runs, written HIPAA-compliant authorization for every patient photo or testimonial used in marketing, records showing that paid or incentivized posts carried required disclosures, and documentation of your pixel audit and vendor BAA review. Regulators expect this evidence to already exist, not to be assembled after a complaint surfaces.