GoodRx Tracking Pixel Litigation
GoodRx is the case that broadens the story beyond hospitals — and it is really two separate matters that are easy to confuse. One is a landmark $1.5 million FTC enforcement action, the first ever under the Health Breach Notification Rule, and it is final. The other is a private class action with a much larger headline number that a federal court has repeatedly declined to approve. Keeping them apart is the whole point.
- Defendant
- GoodRx Holdings, Inc. (incl. GoodRx Gold, GoodRx Care, Hey Doctor) — prescription-discount & telehealth platform
- Thread 1 — FTC
- $1.5M civil penalty. First-ever enforcement under the FTC's Health Breach Notification Rule. Filed Feb 1, 2023 (DOJ for the FTC); court-approved and in effect.
- Thread 2 — Class action
- Doe v. GoodRx Holdings, Inc., N.D. Cal. (No. 3:23-cv-00501), Judge Araceli Martínez-Olguín; co-defendants Meta, Google, Criteo.
- Class-action status
- No approved settlement. A $25M deal was rejected (2025); a revised $32M deal was denied preliminary approval Jan 16, 2026. Litigation ongoing.
- Tracking tech
- Meta Pixel, Google & Criteo tags, and SDKs sharing prescription, medication & health-condition data
- What was shared
- Users' medications, health conditions, and personal identifiers — sent to advertising platforms
- Defendant's position
- Denies wrongdoing; admits no liability in both matters
Because both matters involve the same conduct — GoodRx sharing prescription and health data with advertisers via pixels — they are constantly conflated, including in press that loosely says GoodRx "paid $25 million." It did not. The $1.5 million figure is the FTC penalty (final). The $25M / $32M figures are proposed private class-action settlements that have not been approved. This article treats them as the two distinct things they are.
What GoodRx allegedly did
GoodRx is a prescription-discount and telehealth platform — consumers use it to compare drug prices, find coupons, and access some telehealth services. The core allegation, common to both the FTC action and the class action, is that GoodRx used Meta Pixel, Google and Criteo tracking tags, and software development kits (SDKs) that shared users' sensitive information — including the specific medications they looked up and the health conditions those implied — with advertising and social-media companies, without users' authorization.
This is what makes GoodRx different from the hospital cases in this series. It's not a health system; it's a consumer-health platform, and the data at issue is prescription and medication data — arguably some of the most sensitive information a person can reveal, because a drug name often implies a diagnosis. Consumer Reports first surfaced the data-sharing in 2020, and it drew regulatory attention from there.
Thread 1: the FTC action — a regulatory landmark
This is the thread that matters most for its precedent, and it is fully resolved.
On February 1, 2023, the Department of Justice, acting on behalf of the FTC, filed a proposed order against GoodRx. The FTC's core theory was twofold:
- Violation of the FTC's Health Breach Notification Rule (HBNR) — GoodRx failed to notify consumers of the unauthorized disclosure of their health information to third parties. This was the first enforcement action the FTC had ever brought under the HBNR, and it rested on an expanded reading of the rule: the FTC treated unauthorized sharing of health data as a reportable "breach," even though no hacker was involved and nothing was stolen in the traditional sense.
- Violation of Section 5 of the FTC Act — unfair and deceptive practices. The FTC noted, among other things, that GoodRx had displayed a "HIPAA Secure" seal implying it was HIPAA-compliant and a covered entity when, per the FTC, it was neither.
Two firsts came out of this order. It was the first-ever use of the Health Breach Notification Rule, signalling the FTC would treat ad-tech data sharing by health apps as a reportable breach. And it included a first-of-its-kind remedy: GoodRx was permanently prohibited from disclosing user health information to third parties for advertising purposes, and required to obtain affirmative consent before sharing health data for other purposes. A monetary penalty is ordinary; a flat ban on a data-sharing business practice is not.
The outcome: GoodRx agreed to a $1.5 million civil penalty (paid to the U.S. Treasury), the advertising-sharing ban, and a corrective-action program. The settlement was approved by the court and is in effect. GoodRx denied the FTC's allegations and admitted no wrongdoing, stating it settled to avoid the time and expense of litigation and had already addressed the underlying practices.
Does your site share more than you think before consent?
GoodRx's exposure came from pixels and SDKs firing on its pages. See which trackers fire before consent on your site, in about 10 seconds — the exact surface these cases target. It's the same scan a plaintiff firm or regulator would run.
Scan your site free →No account needed · then a 14-day free trial, no credit card, from $8.99/mo
Thread 2: the class action — repeatedly rejected
Separately from the FTC action, private plaintiffs brought class-action litigation over the same data-sharing. This is the thread that carries the bigger headline numbers — and it is important to be precise, because it has not produced an approved settlement.
The consolidated case is Doe v. GoodRx Holdings, Inc., in the U.S. District Court for the Northern District of California, before Judge Araceli Martínez-Olguín. It names GoodRx alongside co-defendants Meta, Google, and Criteo, and asserts a stack of claims: federal wiretapping, the California Invasion of Privacy Act, California's Confidentiality of Medical Information Act, unjust enrichment, intrusion upon seclusion, and various state consumer-protection laws.
Here is the sequence, which is the instructive part:
- November 2024: plaintiffs proposed a $25 million settlement with GoodRx (GoodRx alone; the ad-tech co-defendants were not part of it).
- June 2025: the court declined to grant preliminary approval, flagging problems with the class definition, the scope of the release class members would give up, the size of the fund, and — critically — the absence of a claim-by-claim analysis showing what class members could actually recover.
- November 2025: the parties returned with a revised $32 million settlement, now adding Criteo as a settling defendant.
- January 16, 2026: the court again denied preliminary approval, finding the parties had "largely failed to address" its earlier concerns — still no claim-by-claim value analysis, still an insufficiently justified broad release, and no confirmatory discovery to support the strength of the claims. The court noted estimated per-member recovery of only roughly $4 to $12.
The court's repeated refusal is itself instructive. A large settlement number is not the same as a resolved case or a fair one — a judge can and did decline to approve a headline figure when the plaintiffs couldn't show what class members would actually get relative to what they gave up. As of mid-2026 the class action remained unresolved and not open for claims, with litigation continuing against GoodRx and the ad-tech co-defendants. Anyone citing GoodRx as a "$25 million" or "$32 million settlement" is describing a proposal a court has declined, not money paid.
The two matters share the same underlying conduct but are legally separate: one is a final regulatory penalty, the other an unresolved private settlement proposal.
How GoodRx fits the 2026 landscape
GoodRx broadens the healthcare pixel wave beyond hospitals into consumer-health and pharmacy. Since 2023, US healthcare organisations have reportedly paid $100M+ across roughly 19 analysed pixel cases, and the Markup's 2022 investigation found the Meta Pixel on 33 of the 100 largest US health systems. GoodRx's distinct contribution is the regulatory dimension: it's where the FTC drew a line.
| Factor | GoodRx (FTC) | Hospital cases (Sutter, MGB, etc.) |
|---|---|---|
| Who acted | Federal regulator (FTC) | Private plaintiffs |
| Legal basis | HBNR + FTC Act | CIPA / WESCA / ECPA / privacy |
| Sector | Pharmacy / consumer health | Hospitals / health systems |
| Data type | Prescriptions, conditions | Patient status, appointments |
| Signature remedy | Permanent ad-sharing ban | Cash + governance changes |
The GoodRx FTC action is often cited alongside BetterHelp as the pair of enforcement actions that put every health-adjacent app on notice: the FTC will treat unauthorized ad-tech data sharing as a reportable breach, and it will use its unfairness authority to ban the practice outright.
Why this case matters for website operators
First: regulators, not just plaintiffs, are watching. The hospital cases in this series were plaintiff-driven. GoodRx shows the FTC will act on its own — and its remedies (a permanent ban on a data-sharing practice) can be more consequential than a cash settlement. If you're a health-adjacent app or site, you have two categories of risk, not one.
Second: a big settlement number can be a mirage. The class action's $25M and $32M figures are widely repeated, but the court declined both. A proposed settlement is not paid money and not a resolved case. It's a reminder to read past headlines to the actual procedural posture.
Third: prescription and condition data is uniquely sensitive. A medication name often implies a diagnosis. When a pixel transmits which drug a user searched, the alleged harm is concrete and severe — which is exactly why this drew first-ever regulatory action.
Fourth: claims you make about privacy are enforceable. The "HIPAA Secure" seal issue shows that representations about your data practices can themselves be the violation. Saying you protect data, then sharing it via pixels, is the deceptive-practice hook.
What this means for your site
The controls that address this class of risk are technical, not legal:
- Block before consent, everywhere. Meta Pixel, Google and Criteo tags, and marketing SDKs should not fire and transmit until the visitor affirmatively agrees. The disclosure only happens if the tag loads.
- Treat any search or product term as potentially sensitive. On a health-adjacent site, the thing a user typed — a drug, a condition, a service — is the sensitive payload. Don't let it flow to ad platforms pre-consent.
- Make your privacy claims match your configuration. If your policy or a trust seal says you protect health data, your actual tag behaviour has to back that up. A mismatch is the enforcement hook.
- Audit SDKs, not just web pixels. GoodRx's exposure included SDKs. If you have a mobile app, its embedded kits are a separate surface with its own review.
- Keep an auditable consent log. Timestamped proof of affirmative consent is the record that supports both litigation defense and regulatory response.
ConsentPixel — Privacy · Verified blocks Meta, Google, and other third-party trackers at the browser level until the visitor consents — on the web pages where prescription and condition searches happen — and logs each decision. It governs your website's tracking layer; app-embedded SDKs and internal systems are separate workstreams that need their own review.
Frequently asked questions
What is the GoodRx tracking pixel case about?
It concerns allegations that GoodRx — a prescription-discount and telehealth platform — used Meta Pixel, Google and Criteo tracking tags, and SDKs that shared users' sensitive information, including the medications they looked up and the health conditions those implied, with advertising and social-media companies without authorization. There are actually two separate matters arising from this conduct: a Federal Trade Commission enforcement action that resulted in a $1.5 million penalty and is final, and a private class action in California federal court that has proposed settlements the court has repeatedly declined to approve. The two are often confused but are legally distinct.
How much did GoodRx pay, and to whom?
The only finalized payment is the $1.5 million civil penalty GoodRx agreed to pay under its 2023 settlement with the FTC, which goes to the U.S. Treasury. The widely cited "$25 million" and "$32 million" figures are proposed private class-action settlements — not FTC penalties — and importantly, a federal court declined to approve both (the $25 million version in 2025 and the revised $32 million version in January 2026). So as of this writing, GoodRx has paid the $1.5 million FTC penalty, but there is no approved class-action settlement and no class-action money has been distributed. Anyone describing GoodRx as having "paid $25 million" is describing a rejected proposal, not a completed settlement.
Why was the GoodRx FTC action significant?
It was the first enforcement action the FTC ever brought under its Health Breach Notification Rule (HBNR). The FTC treated GoodRx's unauthorized sharing of health data with advertisers as a reportable "breach" even though there was no hack — an expanded reading of the rule that put every health-adjacent app on notice. The order also included a first-of-its-kind remedy: GoodRx was permanently prohibited from sharing user health information with third parties for advertising purposes, and required to obtain affirmative consent before sharing it for other purposes. The FTC additionally cited GoodRx's "HIPAA Secure" seal as a deceptive representation, since the FTC said GoodRx was not a HIPAA-covered entity. GoodRx denied wrongdoing and settled without admitting liability.
Why did the court reject the GoodRx class-action settlements?
Judge Araceli Martínez-Olguín of the Northern District of California declined preliminary approval of both the $25 million settlement (in 2025) and the revised $32 million settlement (on January 16, 2026). The recurring reasons were that the plaintiffs failed to provide a claim-by-claim analysis showing how much class members could actually recover if they prevailed on all claims, and to justify the discount from that figure; that the release class members were being asked to give up was overly broad and insufficiently justified; and that the plaintiffs hadn't identified confirmatory discovery supporting the strength of their claims. The court noted estimated per-member recovery of only about $4 to $12. The litigation, which also names Meta, Google, and Criteo as co-defendants, remained ongoing and not open for claims. Status can change, so verify current details on the court docket.
Is GoodRx a HIPAA case?
Not in the way people often assume. The FTC specifically took issue with GoodRx displaying a "HIPAA Secure" seal, alleging that GoodRx implied it was a HIPAA-covered entity and HIPAA-compliant when, in the FTC's view, it was neither. The FTC action was brought under the FTC's own Health Breach Notification Rule and Section 5 of the FTC Act — not HIPAA. This is an important distinction for consumer-health apps: many are not "covered entities" under HIPAA, but that does not put them outside privacy enforcement. The FTC's authority reaches them regardless, and claiming HIPAA compliance you don't have can itself be a deceptive practice.
What should my website do to avoid a claim like this?
Block Meta, Google, Criteo, and similar advertising tags and SDKs until the visitor affirmatively consents, so that sensitive inputs — the drug, condition, or service a user searches — don't flow to ad platforms before consent. Make sure your privacy claims match your actual configuration: if a policy or trust seal says you protect health data, your tag behaviour has to back that up, since a mismatch is the deceptive-practice hook the FTC used. If you operate a mobile app, review its embedded SDKs as a separate surface. Keep a timestamped consent log to support both litigation defense and any regulatory inquiry. This is general information, not legal advice.
Related cases & reading
Sources
- Federal Trade Commission, "FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising" (Feb 1, 2023) and "First FTC Health Breach Notification Rule case addresses GoodRx's not-so-good privacy practices" — $1.5M penalty, first HBNR action, permanent ad-sharing ban.
- HIPAA Journal, "Court Approves FTC Settlement with GoodRx" — court approval and in-effect status; "HIPAA Secure" seal allegation.
- WilmerHale and Davis Wright Tremaine client alerts (Feb–Mar 2023) — HBNR expanded interpretation, Section 5 unfairness theory.
- ClassAction.org and Bloomberg Law (Jan 2026) — Doe v. GoodRx Holdings, Inc., N.D. Cal.; $25M (2024) and revised $32M (Nov 2025) settlements, both denied preliminary approval (June 2025 and Jan 16, 2026), estimated $4–$12 per member.
- Justia Dockets, "Order denying Preliminary Approval of Class Settlement, Doe v. GoodRx Holdings, Inc. et al." (filed Jan 16, 2026); MLex and Law360 coverage of the denial and co-defendants Meta, Google, Criteo.
- The Markup, "The FTC Is Taking on Telehealth's Data Sharing Problem — Starting with GoodRx" (Feb 1, 2023) — pixel/SDK mechanism and prescription-data specifics.