BetterHelp Tracking Pixel Litigation
BetterHelp is the case that put the most sensitive data of all — mental-health therapy information — at the centre of a federal enforcement action. The online-counseling firm paid $7.8 million to settle FTC charges that it shared what users disclosed while seeking therapy with Facebook, Snapchat, and other advertisers, after promising to keep it private.
- Matter
- In the Matter of BetterHelp, Inc. (FTC administrative action, File No. 2023169)
- Who acted
- U.S. Federal Trade Commission
- Defendant
- BetterHelp, Inc. — online-counseling platform (owned by Teladoc Health)
- Legal basis
- Section 5 of the FTC Act (unfair & deceptive practices) — not HIPAA, not the Health Breach Notification Rule
- Conduct period
- Approx. 2017 – 2020
- Tracking tech
- Meta (Facebook) Pixel & custom-audience uploads, plus tags/data feeds to Snapchat, Pinterest & Criteo
- Data shared
- Email addresses, IP addresses, and health-questionnaire answers revealing mental-health information
- Settlement
- $7.8 million — used for partial consumer refunds
- Status
- Final. Order finalized July 2023; refund notices to ~800,000 people began in 2024.
- Defendant's position
- Denies wrongdoing; called the conduct "standard for the industry"
What BetterHelp allegedly did
BetterHelp is one of the largest online therapy platforms in the US. New users complete an intake questionnaire — answering questions about their mental-health history and what they're seeking help with — and BetterHelp matches them with a licensed therapist for counseling by video, chat, or phone. By the FTC's account, the platform had signed up more than two million users and earned over $345 million in revenue.
The FTC alleged that BetterHelp took the information users shared in that context — email addresses, IP addresses, and answers to the health questionnaire — and disclosed it to Facebook, Snapchat, Pinterest, and Criteo for advertising, despite repeatedly promising users it would keep their health information private and use it only for limited purposes such as providing counseling.
This is the highest-sensitivity data in the entire healthcare pixel wave. The other cases involve the fact that someone is a patient, or an appointment, or a medication. BetterHelp involves what a person said while reaching out for mental-health help — and the platform's own promise that it would stay private.
The most striking allegation isn't a passive pixel — it's an active one. The FTC alleged that BetterHelp uploaded the email addresses of all of its current and former clients to Facebook, so that Facebook could find and target similar people ("lookalike" or custom audiences) with ads for BetterHelp's mental-health services. That practice allegedly brought in tens of thousands of new customers and millions in revenue.
The email addresses were hashed — turned into a scrambled string — but according to the FTC's complaint, BetterHelp knew Facebook could reverse the hashing to identify the individuals who had sought mental-health counseling. In other words, the very list of "people who came to us for therapy" allegedly became an advertising asset. That is what turned a data-handling lapse into a landmark deception case.
The law — Section 5, deception, and a broken promise
BetterHelp is instructive because of which law the FTC used. Unlike the GoodRx action, which was the first-ever use of the Health Breach Notification Rule, the BetterHelp action rested on Section 5 of the FTC Act — the broad prohibition on unfair and deceptive practices.
The "deceptive" hook was central:
- BetterHelp made privacy promises. It told users, in its interface and its policies, that it would keep their health information private and use it only for limited purposes.
- It then allegedly did the opposite — sharing that information with advertising platforms. The gap between the promise and the practice is what made it deceptive under Section 5.
Two points matter for other operators. First, this was not a HIPAA case. The FTC did not need BetterHelp to be a HIPAA-covered entity; Section 5 reaches deceptive privacy practices regardless of whether HIPAA applies. Second, the promise created the liability. A privacy policy or an on-screen reassurance is not just marketing — it's an enforceable representation. Saying you protect data and then sharing it via ad-tech is the classic deceptive-practice pattern.
The FTC's theory in one line: BetterHelp promised privacy, then shared the very data users disclosed while seeking therapy — the gap is the deceptive practice under Section 5.
Does your site share what users tell it before consent?
BetterHelp's exposure came from tags and data feeds firing on its pages. See which trackers fire before consent on your site, in about 10 seconds — the exact surface these cases target. It's the same scan a regulator would run.
Scan your site free →No account needed · then a 14-day free trial, no credit card, from $8.99/mo
Where it stands
This case is fully resolved and money has reached consumers:
- Settlement amount: $7.8 million, used to provide partial refunds to affected consumers — the first FTC action to return money to consumers whose health data was compromised in this way.
- Timeline: the FTC announced the proposed order in March 2023 and finalized it in July 2023. In 2024, the FTC announced that about 800,000 people would begin receiving refund-eligibility notices.
- The advertising ban: the order permanently prohibits BetterHelp from disclosing consumers' health data to third parties for advertising, and — for other purposes — requires it to obtain affirmative express consent first.
- Other requirements: BetterHelp must implement a comprehensive privacy program and direct the third parties that received the data to delete it.
BetterHelp did not admit any wrongdoing, and characterised the conduct at issue as standard industry practice. The FTC's Bureau of Consumer Protection framed it very differently — noting that people reaching out about mental health do so in a moment of vulnerability, with an expectation that the service will protect their privacy.
How BetterHelp fits the 2026 landscape
BetterHelp and GoodRx are the twin FTC actions that anchor the regulatory side of the healthcare tracking wave. Since 2023, US healthcare organisations have reportedly paid $100M+ across roughly 19 analysed pixel cases, and the Markup's 2022 investigation found the Meta Pixel on 33 of the 100 largest US health systems. The hospital cases were driven by private plaintiffs; BetterHelp and GoodRx are where the federal regulator drew hard lines.
| Factor | BetterHelp | GoodRx (FTC) | Hospital cases |
|---|---|---|---|
| Who acted | FTC | FTC | Private plaintiffs |
| Legal basis | Section 5 (deception) | HBNR + Section 5 | CIPA / WESCA / ECPA |
| Sector | Mental health / telehealth | Pharmacy | Hospitals |
| Data type | Therapy intake answers | Prescriptions | Patient status |
| Money | $7.8M (refunds) | $1.5M (penalty) | Cash settlements |
| Status | Final (2023) | Final (2023) | Varies |
Together, the two FTC actions establish a clear regulatory posture toward health-adjacent apps: the agency will use both the Health Breach Notification Rule (GoodRx) and its Section 5 deception authority (BetterHelp), and it will impose outright bans on sharing health data for advertising — not just fines.
Why this case matters for website operators
First: your privacy promises are enforceable. The core of the BetterHelp action was the gap between what the company said and what it did. If your site tells users their information is private or protected, your actual tag and data-sharing behaviour has to match. The representation is the liability hook.
Second: custom-audience uploads are tracking too. Much of the pixel conversation focuses on scripts that fire in the browser. BetterHelp is a reminder that server-side and list-based data sharing — uploading customer emails to build ad audiences — carries the same exposure, and can be even more direct.
Third: the FTC reaches apps HIPAA doesn't. Many health-adjacent services aren't HIPAA-covered entities. That does not put them out of reach — Section 5 covers deceptive privacy practices regardless. "We're not a HIPAA covered entity" is not a defense to a broken privacy promise.
Fourth: sensitivity raises the stakes. Mental-health information is about as sensitive as consumer data gets. The more sensitive the data your site touches, the more consequential a pre-consent leak becomes — in penalties, in refunds, and in reputational terms.
What this means for your site
The controls that address this class of risk are technical and operational, not just legal:
- Block before consent, everywhere. Advertising pixels and tags should not fire and transmit until the visitor affirmatively agrees — especially on intake forms, questionnaires, and any page where a user discloses something about themselves.
- Audit list-based and server-side sharing too. Custom-audience uploads and conversion APIs move data to ad platforms outside the browser. A consent tool addresses browser tags; your marketing operations need a parallel review of what customer data is being fed to ad platforms directly.
- Make your privacy claims true. Reconcile every promise in your policy and interface with your actual data flows. If you can't honour a "we keep this private" statement, don't make it.
- Treat intake and questionnaire data as the crown jewels. What a user types about themselves — symptoms, conditions, concerns — is the most sensitive payload and the least defensible to leak.
- Keep an auditable consent log. Timestamped proof of affirmative consent is the record that supports both litigation defense and a regulatory response.
ConsentPixel — Privacy · Verified blocks Meta, Google, and other third-party trackers at the browser level until the visitor consents — on the intake and questionnaire pages where the most sensitive disclosures happen — and logs each decision. It governs your website's browser-side tracking layer; list-based ad uploads, server-side feeds, and native-app SDKs are separate surfaces that need their own review.
Frequently asked questions
What is the BetterHelp tracking case about?
It is a Federal Trade Commission enforcement action, In the Matter of BetterHelp, Inc. The FTC charged that BetterHelp — a large online-counseling platform owned by Teladoc — shared consumers' sensitive information, including email addresses, IP addresses, and answers to a mental-health intake questionnaire, with third parties such as Facebook, Snapchat, Pinterest, and Criteo for advertising, despite promising users it would keep their health information private. BetterHelp agreed to pay $7.8 million, used to provide partial refunds to affected consumers, and accepted a ban on sharing health data for advertising. BetterHelp did not admit wrongdoing and described the conduct as standard for the industry.
How much did BetterHelp pay, and is the case final?
BetterHelp agreed to pay $7.8 million, which is being used to provide partial refunds to affected consumers rather than as a penalty paid to the government. This made it the first FTC action to return money to consumers whose health data was compromised in this way. The case is fully final: the FTC announced the proposed order in March 2023 and finalized it in July 2023. In 2024, the FTC announced that roughly 800,000 people would begin receiving refund-eligibility notices. So unlike some private class actions, this matter is resolved and money has actually reached consumers.
Was BetterHelp a HIPAA violation?
No. The FTC brought the case under Section 5 of the FTC Act, which prohibits unfair and deceptive practices — not under HIPAA and not under the Health Breach Notification Rule (which is what the FTC used in the related GoodRx action). The FTC did not need BetterHelp to be a HIPAA-covered entity. The theory was deception: BetterHelp promised users it would keep their health information private and use it only for limited purposes, then allegedly shared it with advertising platforms. This is an important point for health-adjacent apps that assume being outside HIPAA puts them outside privacy enforcement — the FTC's authority reaches deceptive privacy practices regardless of whether HIPAA applies.
What data did BetterHelp share, and how?
According to the FTC, BetterHelp shared users' email addresses, IP addresses, and answers to its health-intake questionnaire — information that revealed users were seeking mental-health treatment and details about their conditions — with Facebook, Snapchat, Pinterest, and Criteo for advertising. The most striking mechanism was that BetterHelp allegedly uploaded the email addresses of all of its current and former clients to Facebook so that Facebook could target similar people ("lookalike" audiences) with ads for BetterHelp's services. The emails were hashed, but the FTC alleged BetterHelp knew Facebook could reverse the hashing to identify the individuals. This list-based sharing is different from a passive browser pixel and shows that data sent directly to ad platforms carries the same exposure.
Why is the BetterHelp case considered especially significant?
Two reasons. First, the data involved — what people disclosed while seeking mental-health therapy — is among the most sensitive consumer information there is, which raised the stakes of the alleged sharing considerably. Second, the remedy was precedent-setting: the FTC not only secured $7.8 million in consumer refunds but permanently banned BetterHelp from disclosing health data to third parties for advertising and required affirmative express consent for other disclosures. Together with the GoodRx action, it signalled that the FTC would treat health-adjacent apps' ad-tech data sharing as a serious enforcement priority and would impose outright bans, not just fines. It reframed privacy promises as enforceable commitments.
What should my website do to avoid a case like this?
Make sure your privacy promises match your actual data flows — the gap between the two is exactly what the FTC treated as deceptive. Block advertising pixels and tags until the visitor affirmatively consents, especially on intake forms and questionnaires where users disclose sensitive information. Critically, audit list-based and server-side sharing too — uploading customer emails to build ad audiences, or sending conversions via server-side APIs, moves data to ad platforms outside the browser and carries the same risk; a browser consent tool handles the browser layer, but your marketing operations need a parallel review. Treat anything a user types about themselves as the most sensitive payload, and keep a timestamped consent log. This is general information, not legal advice.
Related cases & reading
Sources
- Federal Trade Commission, "FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others for Targeted Advertising" (March 2, 2023) — charges, data categories, third parties.
- Federal Trade Commission, "FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising, Requiring It to Pay $7.8 Million" (July 2023) — final order, $7.8M for refunds, advertising ban.
- Federal Trade Commission consumer refund notice (2024) — ~800,000 people receiving refund-eligibility notices; email/IP/health-question data shared with Facebook, Snapchat and others.
- Arnold & Porter, "FTC Announces $7.8 Million Fine as Part of Settlement With BetterHelp" — Section 5 theory, custom-audience email upload to Facebook, hashed-email reversal allegation, first FTC action returning funds to consumers.
- Associated Press, "BetterHelp customers begin receiving refund notices from $7.8M data privacy settlement" — refund distribution and BetterHelp's "standard for the industry" response.