Buying a GLP-1 online means handing over a weight, a medical history, a set of symptoms, a home address and a card number, usually inside ten minutes and usually to a company nobody has heard of. The assumption most buyers carry into that form is that health information given to something that prescribes medicine is covered by the federal health privacy law. That assumption turns on a question about billing, and for much of this market the answer runs the other way.
HIPAA reaches a provider through one door
The definition of a health care provider in the privacy regulations is deliberately wide. It covers a provider of services, a provider of medical or health services, and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.[1] A cash telehealth company that prescribes drugs is comfortably inside that sentence.
Being a health care provider is not what makes the rules apply. The applicability section lists three kinds of entity, and the third is a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.[1] The word doing the work is “transaction,” which the same part defines as a transmission between two parties to carry out financial or administrative activities related to health care, and then enumerates: health care claims, payment and remittance advice, coordination of benefits, claim status, enrollment and disenrollment in a health plan, eligibility for a health plan, premium payments, referral certification and authorization, first report of injury, and claims attachments.[1]
Every item on that list is an insurance transaction. A provider that never bills a plan does not conduct one, and the Department of Health and Human Services states the consequence without hedging: if an entity does not meet the definition of a covered entity or business associate, it does not have to comply with the HIPAA Rules.[2] Its list of covered providers — doctors, clinics, pharmacies and the rest — carries the qualifier in the same breath: but only if they transmit any information in an electronic form in connection with a transaction for which the department has adopted a standard.[2]
That is a rule about paperwork, not about sensitivity. The same questionnaire answers are equally private either way. Of the 286 sellers written up here, 40 record that the company states it takes no insurance and 8 record that it bills or accepts it — and the cash-pay structure of this market is itself the subject of the insurance article.
Being covered is not the same as being protected
Before reading the paragraph above as a scandal, look at what happens inside the covered world. A cross-sectional study of a nationally representative sample of 100 nonfederal acute care hospital websites — institutions that are unambiguously covered entities — measured tracking and then read the policies. 96 of 100 (95% CI 90.1% to 98.9%) transferred user information to third parties. A privacy policy could be found on 71. Among those 71, 66 addressed categories of third-party recipients and only 40 — 56.3% (95% CI 44.5% to 67.7%) — named specific companies or services receiving the information. Mean policy length was 2,527 words at a mean reading grade level of 13.7.[3]
A separate analysis of archived hospital websites from 2012 to 2023 found that 66% of the sample employed pixel tracking, and reported that third-party pixel use was associated with significantly increased data breach risk.[4] The regime that covers hospitals did not stop any of that. Coverage is a question about which agency writes the letter, not a guarantee about where data goes.
The guidance that reached the pixel was cut back in court
The Office for Civil Rights issued a bulletin in December 2022 taking the position that HIPAA obligations could be triggered where an online technology connected a visitor’s IP address with a visit to an unauthenticated public webpage about specific health conditions or providers. On June 20, 2024, the United States District Court for the Northern District of Texas declared that portion unlawful and vacated it, in American Hospital Association v. Becerra.[5]
The department’s own page now carries the court’s holding at the top and adds one sentence: HHS is evaluating its next steps in light of that order.[5] That sentence has stood since the page was last reviewed on June 26, 2024. The practical position is that the most aggressive federal reading of health privacy as it applies to a public marketing page has been vacated, and nothing has replaced it.
What covers the rest of it
Outside HIPAA is not outside the law, and the boundary is drawn explicitly. The Federal Trade Commission’s Health Breach Notification Rule applies to vendors of personal health records, related entities and their service providers, and states that it does not apply to entities covered by HIPAA or to anything acting as a business associate of one.[6] The two regimes are complements rather than overlapping layers.
Amendments published in the Federal Register on May 30, 2024 and effective July 29, 2024 widened what counts.[7] The rule now defines health care services or supplies to mean any online service such as a website, mobile application, or internet-connected device that provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools.[6] An intake flow that records a condition and a medication sits inside that description on its face.
The enforcement record shows what both regimes actually do. The first action ever brought under the breach rule was settled on February 1, 2023, with a $1.5 million civil penalty against a prescription discount company for sharing users’ prescription medications and health conditions with advertising platforms; a second breach-rule action followed on May 17, 2023 with a $100,000 penalty against a fertility app.[8] Other health-data cases have run on the general prohibition on unfair or deceptive practices instead: a mental-health platform agreed in March 2023 to $7.8 million in consumer refunds over disclosures to social platforms, and in April 2024 a telehealth company settled a matter covering the information of nearly 3.2 million consumers.[8] None of those companies sells GLP-1 medication.
Where the state line changes the answer
Two state statutes took effect on the same day and give a buyer very different leverage. Washington’s My Health My Data Act defines consumer health data as personal information linked or reasonably linkable to a consumer that identifies past, present or future physical or mental health status, and its enumerated items include use or purchase of prescribed medication and data that identifies a consumer seeking health care services.[9] Its obligations bind regulated entities from March 31, 2024 and small businesses from June 30, 2024, and a violation is declared an unfair or deceptive act for purposes of the state consumer protection act — which the attorney general describes as enforceable by that office as well as through private action.[9]
Nevada’s equivalent took effect on the same March date and says the opposite about remedies: the provisions do not create a private right of action.[10] Same category of data, same month, and in one state an individual can sue while in the other the only route is a regulator. Which state’s law governs a telehealth purchase follows the same logic as the prescribing rules, which attach to where the patient is sitting.
What the structure of this market adds
Three recorded patterns matter for where data ends up, independent of any policy. 5 of the 286 write-ups here record a platform stating on its own site that it is not a medical practice or a health care provider — which places the entity holding the account, the card and the questionnaire outside the provider definition entirely. 21 record a separate clinical entity doing the prescribing, so the record crosses at least two companies before a prescription exists. And 188 record recurring billing, which means a stored payment instrument and a standing relationship rather than a single transaction.
One more count, with the loudest caveat on this page attached to it. Exactly 1 of the 286 write-ups records any statement about HIPAA, a privacy policy or personal data. That is not a finding that these companies publish no privacy terms — they almost all do, on pages linked from the footer. It is a finding about placement: privacy is not a pricing-page fact in this market, and nothing about it competes for attention with a dollar figure. What each company does publish on the pages examined is recorded in the individual seller write-ups.
What a buyer can actually check
Four things are readable from outside before any money moves. Whether the policy states that the company is a covered entity or a business associate — a specific legal claim, and its absence is informative. Whether a separate notice of privacy practices exists at all, since that document is an artifact of HIPAA and a site outside the law has no reason to publish one. Whether the policy names categories of third-party recipients or only gestures at “partners,” which is the field hospitals most often left generic. And which entity the terms are actually between, since the prescriber may be a different company from the one taking the payment.
A certification seal is a weaker signal than it looks for this particular question, for reasons set out in the certification article; 62 of the 286 sellers here state one. None of it changes the product position either: 264 of the 286 dispense compounded medication, which is not FDA-approved and which the agency does not review for safety, effectiveness or quality before it is marketed.[11]
What this page does not establish
No privacy policy belonging to any seller on this site has been read into evidence here, and nothing above describes what any individual company does with information. The enforcement matters cited are closed public records against companies that do not sell GLP-1 medication, and they are offered as evidence about what the rules reach, not as a characterization of anybody in this category.
Whether a specific seller is a covered entity is a question about that company’s billing arrangements that cannot be answered from its marketing pages, and the counts above are floors from what was recorded rather than a census. The reliable conclusion is narrower and is about the law rather than about any company: the protection most buyers assume attaches to a medical form attaches to a billing relationship instead, and where that relationship does not exist the applicable rules are a general prohibition on deception, a breach rule that was widened in 2024, and whatever the buyer’s own state has passed. How this desk handles claims it cannot verify is set out in the methodology, and this site’s own data practices are in its privacy policy.