Skip to content
GLP Loss
← Research
Safety

What Happens to Your Data in Cash-Pay GLP-1 Telehealth

HIPAA reaches a health care provider only where it transmits health information electronically in connection with an insurance transaction — so for much of this market the law most buyers assume applies is the one that does not.

Tessa Whitfield9 min read
Which privacy rule reaches a cash telehealth siteHIPAA turns on one question, and it is a billing questionDoes the provider bill a health plan electronically?NO — the common case hereNot a HIPAA covered entityFTC Act section 5 appliesHealth Breach Notification RuleState health-data law, if anyNo notice of privacy practicesYES — the minority hereThe HIPAA rules applyBreach reporting runs to HHSThe FTC breach rule does notWebsite trackers still leak96 of 100 hospital sites didA court vacated part of the federal tracking guidance in 2024HHS has said it is evaluating next steps ever since40 of 286 sellers here state they take no insurance; 8 state they do.Compounded drugs are not FDA-approved or reviewed before dispensing.

Buying a GLP-1 online means handing over a weight, a medical history, a set of symptoms, a home address and a card number, usually inside ten minutes and usually to a company nobody has heard of. The assumption most buyers carry into that form is that health information given to something that prescribes medicine is covered by the federal health privacy law. That assumption turns on a question about billing, and for much of this market the answer runs the other way.

HIPAA reaches a provider through one door

The definition of a health care provider in the privacy regulations is deliberately wide. It covers a provider of services, a provider of medical or health services, and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.[1] A cash telehealth company that prescribes drugs is comfortably inside that sentence.

Being a health care provider is not what makes the rules apply. The applicability section lists three kinds of entity, and the third is a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.[1] The word doing the work is “transaction,” which the same part defines as a transmission between two parties to carry out financial or administrative activities related to health care, and then enumerates: health care claims, payment and remittance advice, coordination of benefits, claim status, enrollment and disenrollment in a health plan, eligibility for a health plan, premium payments, referral certification and authorization, first report of injury, and claims attachments.[1]

Every item on that list is an insurance transaction. A provider that never bills a plan does not conduct one, and the Department of Health and Human Services states the consequence without hedging: if an entity does not meet the definition of a covered entity or business associate, it does not have to comply with the HIPAA Rules.[2] Its list of covered providers — doctors, clinics, pharmacies and the rest — carries the qualifier in the same breath: but only if they transmit any information in an electronic form in connection with a transaction for which the department has adopted a standard.[2]

That is a rule about paperwork, not about sensitivity. The same questionnaire answers are equally private either way. Of the 286 sellers written up here, 40 record that the company states it takes no insurance and 8 record that it bills or accepts it — and the cash-pay structure of this market is itself the subject of the insurance article.

Being covered is not the same as being protected

Before reading the paragraph above as a scandal, look at what happens inside the covered world. A cross-sectional study of a nationally representative sample of 100 nonfederal acute care hospital websites — institutions that are unambiguously covered entities — measured tracking and then read the policies. 96 of 100 (95% CI 90.1% to 98.9%) transferred user information to third parties. A privacy policy could be found on 71. Among those 71, 66 addressed categories of third-party recipients and only 4056.3% (95% CI 44.5% to 67.7%) — named specific companies or services receiving the information. Mean policy length was 2,527 words at a mean reading grade level of 13.7.[3]

A separate analysis of archived hospital websites from 2012 to 2023 found that 66% of the sample employed pixel tracking, and reported that third-party pixel use was associated with significantly increased data breach risk.[4] The regime that covers hospitals did not stop any of that. Coverage is a question about which agency writes the letter, not a guarantee about where data goes.

The guidance that reached the pixel was cut back in court

The Office for Civil Rights issued a bulletin in December 2022 taking the position that HIPAA obligations could be triggered where an online technology connected a visitor’s IP address with a visit to an unauthenticated public webpage about specific health conditions or providers. On June 20, 2024, the United States District Court for the Northern District of Texas declared that portion unlawful and vacated it, in American Hospital Association v. Becerra.[5]

The department’s own page now carries the court’s holding at the top and adds one sentence: HHS is evaluating its next steps in light of that order.[5] That sentence has stood since the page was last reviewed on June 26, 2024. The practical position is that the most aggressive federal reading of health privacy as it applies to a public marketing page has been vacated, and nothing has replaced it.

What covers the rest of it

Outside HIPAA is not outside the law, and the boundary is drawn explicitly. The Federal Trade Commission’s Health Breach Notification Rule applies to vendors of personal health records, related entities and their service providers, and states that it does not apply to entities covered by HIPAA or to anything acting as a business associate of one.[6] The two regimes are complements rather than overlapping layers.

Amendments published in the Federal Register on May 30, 2024 and effective July 29, 2024 widened what counts.[7] The rule now defines health care services or supplies to mean any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools.[6] An intake flow that records a condition and a medication sits inside that description on its face.

The enforcement record shows what both regimes actually do. The first action ever brought under the breach rule was settled on February 1, 2023, with a $1.5 million civil penalty against a prescription discount company for sharing users’ prescription medications and health conditions with advertising platforms; a second breach-rule action followed on May 17, 2023 with a $100,000 penalty against a fertility app.[8] Other health-data cases have run on the general prohibition on unfair or deceptive practices instead: a mental-health platform agreed in March 2023 to $7.8 million in consumer refunds over disclosures to social platforms, and in April 2024 a telehealth company settled a matter covering the information of nearly 3.2 million consumers.[8] None of those companies sells GLP-1 medication.

Where the state line changes the answer

Two state statutes took effect on the same day and give a buyer very different leverage. Washington’s My Health My Data Act defines consumer health data as personal information linked or reasonably linkable to a consumer that identifies past, present or future physical or mental health status, and its enumerated items include use or purchase of prescribed medication and data that identifies a consumer seeking health care services.[9] Its obligations bind regulated entities from March 31, 2024 and small businesses from June 30, 2024, and a violation is declared an unfair or deceptive act for purposes of the state consumer protection act — which the attorney general describes as enforceable by that office as well as through private action.[9]

Nevada’s equivalent took effect on the same March date and says the opposite about remedies: the provisions do not create a private right of action.[10] Same category of data, same month, and in one state an individual can sue while in the other the only route is a regulator. Which state’s law governs a telehealth purchase follows the same logic as the prescribing rules, which attach to where the patient is sitting.

What the structure of this market adds

Three recorded patterns matter for where data ends up, independent of any policy. 5 of the 286 write-ups here record a platform stating on its own site that it is not a medical practice or a health care provider — which places the entity holding the account, the card and the questionnaire outside the provider definition entirely. 21 record a separate clinical entity doing the prescribing, so the record crosses at least two companies before a prescription exists. And 188 record recurring billing, which means a stored payment instrument and a standing relationship rather than a single transaction.

One more count, with the loudest caveat on this page attached to it. Exactly 1 of the 286 write-ups records any statement about HIPAA, a privacy policy or personal data. That is not a finding that these companies publish no privacy terms — they almost all do, on pages linked from the footer. It is a finding about placement: privacy is not a pricing-page fact in this market, and nothing about it competes for attention with a dollar figure. What each company does publish on the pages examined is recorded in the individual seller write-ups.

What a buyer can actually check

Four things are readable from outside before any money moves. Whether the policy states that the company is a covered entity or a business associate — a specific legal claim, and its absence is informative. Whether a separate notice of privacy practices exists at all, since that document is an artifact of HIPAA and a site outside the law has no reason to publish one. Whether the policy names categories of third-party recipients or only gestures at “partners,” which is the field hospitals most often left generic. And which entity the terms are actually between, since the prescriber may be a different company from the one taking the payment.

A certification seal is a weaker signal than it looks for this particular question, for reasons set out in the certification article; 62 of the 286 sellers here state one. None of it changes the product position either: 264 of the 286 dispense compounded medication, which is not FDA-approved and which the agency does not review for safety, effectiveness or quality before it is marketed.[11]

What this page does not establish

No privacy policy belonging to any seller on this site has been read into evidence here, and nothing above describes what any individual company does with information. The enforcement matters cited are closed public records against companies that do not sell GLP-1 medication, and they are offered as evidence about what the rules reach, not as a characterization of anybody in this category.

Whether a specific seller is a covered entity is a question about that company’s billing arrangements that cannot be answered from its marketing pages, and the counts above are floors from what was recorded rather than a census. The reliable conclusion is narrower and is about the law rather than about any company: the protection most buyers assume attaches to a medical form attaches to a billing relationship instead, and where that relationship does not exist the applicable rules are a general prohibition on deception, a breach rule that was widened in 2024, and whatever the buyer’s own state has passed. How this desk handles claims it cannot verify is set out in the methodology, and this site’s own data practices are in its privacy policy.

Frequently asked

Is a cash-pay GLP-1 telehealth company covered by HIPAA?
Possibly not, and the test is about billing rather than about medicine. The rules apply to a health care provider only where it transmits health information electronically in connection with a covered transaction, and every transaction on that list — claims, eligibility, payment and remittance, enrollment, premium payments and the rest — is an insurance transaction. A provider that never bills a plan conducts none of them, and HHS states that an entity outside the covered-entity and business-associate definitions does not have to comply with the HIPAA Rules.
If HIPAA does not apply, is there no health privacy law at all?
No. The Federal Trade Commission's Health Breach Notification Rule applies to vendors of personal health records and related entities and expressly does not apply to HIPAA-covered entities, so the two regimes divide the field rather than overlap. Amendments effective July 29, 2024 defined health care services or supplies to include any online service that provides mechanisms to track health conditions, diagnoses, treatment or medications. The general prohibition on unfair or deceptive acts also applies, and several state statutes reach consumer health data directly.
Does a HIPAA-covered website keep tracking pixels out?
The evidence says not reliably. In a nationally representative sample of 100 hospital websites — institutions that are unambiguously covered entities — 96 transferred user information to third parties, a privacy policy could be found on 71, and only 40 of those 71 named the specific companies receiving information. A separate analysis of archived hospital sites from 2012 to 2023 found 66% using pixel tracking. Coverage determines which regulator has jurisdiction, not where data actually goes.
What happened to the federal guidance on health website tracking?
A federal court vacated part of it. On June 20, 2024 the Northern District of Texas declared unlawful and vacated the portion of the Office for Civil Rights bulletin providing that HIPAA obligations are triggered where an online technology connects an individual's IP address with a visit to an unauthenticated public webpage about specific health conditions or providers. The department's own page carries that holding and states that HHS is evaluating its next steps, which has been its position since the page was last reviewed in June 2024.
Does it matter which state I am in?
It can decide whether you personally have any remedy. Washington's My Health My Data Act covers consumer health data including use or purchase of prescribed medication, binds regulated entities from March 31, 2024 and small businesses from June 30, 2024, and makes a violation an unfair or deceptive act under the state consumer protection act, which the attorney general describes as enforceable through private action as well as by that office. Nevada's comparable provisions took effect the same day and state expressly that they do not create a private right of action.
What should I look for in a telehealth privacy policy before signing up?
Whether it states that the company is a covered entity or a business associate, since that is a specific legal claim and its absence is informative. Whether a separate notice of privacy practices exists, because that document is an artifact of HIPAA. Whether the policy names categories of third-party recipients rather than referring vaguely to partners. And which entity the terms are between, since the company taking the payment may not be the one writing the prescription.

Sources

  1. [1] Code of Federal Regulations (2026). 45 CFR 160.102 and 160.103 — applicability of the HIPAA administrative simplification rules, and the definitions of covered entity, health care provider and transaction (eCFR data current as of 09/11/2026; read September 15, 2026) Electronic Code of Federal Regulations. Source
  2. [2] U.S. Department of Health and Human Services (2024). Covered Entities and Business Associates — health care providers are covered only if they transmit information electronically in connection with a transaction for which HHS has adopted a standard (content last reviewed August 21, 2024; read September 15, 2026) U.S. Department of Health and Human Services. Source
  3. [3] McCoy MS, Wu A, Burdyl S, Kim Y, Smith NK, Gonzales R, Friedman AB (2024). User Information Sharing and Hospital Website Privacy Policies. JAMA Netw Open. PMID 38602678
  4. [4] Atasoy H, McDonough R, Zhang GM (2025). Beyond the click: Pixel tracking technologies and patient data security in hospitals. PNAS Nexus. PMID 41376707
  5. [5] U.S. Department of Health and Human Services, Office for Civil Rights (2024). Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates — notice of the June 20, 2024 order in American Hospital Association v. Becerra vacating part of the guidance (content last reviewed June 26, 2024; read September 15, 2026) U.S. Department of Health and Human Services. Source
  6. [6] Code of Federal Regulations (2026). 16 CFR Part 318 — Health Breach Notification Rule, sections 318.1 and 318.2, including the definitions of covered health care provider and health care services or supplies added in 2024 (read September 15, 2026) Electronic Code of Federal Regulations. Source
  7. [7] Federal Trade Commission (2024). Health Breach Notification Rule — final rule, 89 FR 47028, published May 30, 2024, amendments effective July 29, 2024 Federal Register. Source
  8. [8] Federal Trade Commission (2023). Health privacy enforcement record — the first Health Breach Notification Rule action and subsequent health-data cases brought under the FTC Act (read September 15, 2026) Federal Trade Commission. Source
  9. [9] Washington State Legislature (2023). My Health My Data Act, chapter 19.373 RCW — the definition of consumer health data, the March 31 and June 30, 2024 compliance dates, and RCW 19.373.090 declaring a violation an unfair or deceptive act under the Consumer Protection Act (read September 15, 2026) Washington State Legislature. Source
  10. [10] Nevada Legislature (2023). NRS 603A.400 to 603A.550 — Nevada consumer health data provisions, including NRS 603A.550(2)(a) stating that they do not create a private right of action (read September 15, 2026) Nevada Legislature. Source
  11. [11] U.S. Food and Drug Administration (2025). Compounding and the FDA: Questions and Answers — compounded drugs are not FDA-approved and the agency does not verify their safety, effectiveness or quality before they are marketed (content current as of 09/16/2025; read September 15, 2026) U.S. Food and Drug Administration. Source

More in Safety