Telehealth companies keep exposing their customers’ medical data. What should they do?远程医疗公司不断泄露客户的医疗数据。他们应该怎么办?
Increasingly, government regulators are accusing companies of deceptive, unethical business practices, including disclosing customers’ health data, signing them up for hard-to-cancel subscriptions and bypassing real-time consultations with doctors.

Hiraman/E+/Getty Images
The appeal of telehealth is easy to explain: Instead of calling a doctor, booking an appointment and hoping to eventually get a prescription, you can log onto an app or website and get approved for a new medication within minutes.
Since the COVID-19 pandemic, scores of online health services have launched with the promise of quick, convenient access to drugs for ADHD, sexual dysfunction, anxiety, weight loss and more.
Increasingly, though, government regulators are accusing these companies of deceptive, unethical business practices , including disclosing their customers’ health data, signing them up for hard-to-cancel subscriptions and bypassing real-time consultations with doctors.
The Federal Trade Commission’s latest lawsuit alleges that telehealth pioneer Hims & Hers engaged in all of those tactics, running afoul of U.S. consumer protection laws.
Hims has disputed the government’s claims, calling them “an effort to generate headlines at our expense.”
In recent years, FTC officials have filed similar cases against more than a half-dozen telehealth companies, including online therapy provider BetterHelp and pharmacy discount service GoodRx . In both cases, regulators said the companies shared users’ health data with online platforms such as Meta and Google, without getting permission.
Zorica Nastasic/E+/Getty Images
Here’s what to know before you upload your medical data to an AI program
Experts say part of the problem is that federal laws that govern the handling of health information generally don’t apply to telehealth companies.
“There’s an entire universe of companies collecting huge amounts of consumer health data every day that aren’t covered by our current health sector-specific laws,” said Andrew Crawford, an attorney with the nonprofit Center for Democracy and Technology.
Here are some things to know before signing up for a telehealth service:
Nearly all telehealth visits begin with a questionnaire in which users provide details about their medical history and possible medications they’re interested in.
According to the FTC’s lawsuit, Hims customers were automatically enrolled and billed for recurring prescriptions with “virtually no opportunity to review the provider’s recommended treatment.”
Researchers have documented similar practices across the industry, even for injectable weight-loss drugs that typically require a physical exam and other precautions before beginning treatment.
A recent analysis of nearly 50 telehealth companies selling GLP-1 drugs found that less than a third actually required any real-time video or audio consultation with a physician. In some cases, the prescriptions were approved within minutes.
“What we saw overwhelmingly was that it was incredibly easy to get access to the GLP-1s,” said Dr. Reshma Ramachandran of Yale University, who led the study. “Most of the time, the prescription was automatically sent, without even an opportunity to stop the dispensing.”
The lack of a real-time conversation means many patients aren’t getting the type of care recommended by medical societies that prescribe GLP-1s, including discussions about weight-loss goals, past efforts and eating disorders.
Only a little more than half the websites had a question about eating disorders — which GLP-1 drugs can induce or worsen — on their intake questionnaires, the researchers found.
Opinion: If you think your health is a private matter, see what’s happening to your data
Americans often assume that any personal health information they share is protected by HIPAA, the federal privacy law that governs the handling of medical information. But the law generally only applies to specific types of health businesses, including medical offices, hospitals and insurers, not telehealth companies offering prescriptions, counseling, DNA tests and other online services.
Privacy experts say that legal gap is one reason companies continue to disclose sensitive health information to advertisers and search engines.
“There isn’t a clear federal law saying: ‘Don’t do this,’” said Justin Brookman, Consumer Reports’ director of technology policy. “There’s just a body of soft law and settled cases with the FTC that many companies probably aren’t even aware of.”
Because HIPAA does not cover every direct-to-consumer health platform, the FTC has generally used its broader authority to take action against “fraudulent, deceptive or unethical business methods.” In practice, that means showing that telehealth companies disclosed their customers’ health information after initially saying they wouldn’t.
Hims told customers that its platform offered a “100% online, private and secure” means of sharing information with the company’s medical professionals, according to the FTC complaint. But instead the company shared the data with Meta and other online platforms, the FTC alleges.
Michael A. McCoy/For The Washington Post/Getty Images
VA watchdog finds nearly a million calls from vets seeking care had key tracking data missing
Still, experts say the penalties available to regulators are limited. In most cases, companies sign a legal agreement stating that they’ll stop the practices cited by regulators.
Lawmakers in California, Connecticut, Maryland and other states have passed new online privacy laws that include special protections for health information. But there’s been little enforcement against telehealth companies that break those rules.
For now, privacy experts recommend using ad blockers and private web browsers — sometimes called “incognito” windows — when logging onto telehealth websites. Those tools can make it harder for companies to track your location, online history and other personal information.
It’s also a good idea to read any user agreements to get a sense of how the company plans to use your personal data, said Crawford. Some telehealth sites, for example, explicitly state in their privacy policies that they have the right to sell data about users’ sex lives.
The only surefire way to protect your information may simply be to decline the terms of service, usually one of the first steps required before accessing telehealth.
“The system we have now overly burdens consumers to do a ton of work in terms of understanding how each piece of technology collecting their personal data is going to handle it,” he said. “But even if you do all that work, you often have little agency.”
Hiraman/E+/Getty Images
远程医疗的吸引力很容易解释:无需打电话给医生、预约就诊并等待最终获得处方,只需登录应用程序或网站,即可在几分钟内获得新药批准。
自 COVID-19 疫情爆发以来,许多在线医疗服务应运而生,承诺提供快速、便捷的药物,用于治疗多动症、性功能障碍、焦虑症、减肥等疾病。
不过,越来越多的政府监管机构指责这些公司存在欺骗性、不道德的商业行为,包括泄露客户的健康数据、强迫客户订阅难以取消的服务以及绕过与医生的实时咨询。
美国联邦贸易委员会最新提起的诉讼指控远程医疗先驱 Hims & Hers 采取了所有这些策略,违反了美国消费者保护法。
Hims 对政府的说法提出异议,称其为“企图以牺牲我们为代价来制造新闻头条”。
近年来,美国联邦贸易委员会(FTC)官员已对包括在线心理咨询服务商BetterHelp和药品折扣服务商GoodRx在内的六家以上远程医疗公司提起类似诉讼。监管机构称,在这两起案件中,这些公司未经许可就将用户的健康数据分享给了Meta和谷歌等在线平台。
佐里卡·纳斯塔西克/E+/盖蒂图片社
在将医疗数据上传到人工智能程序之前,您需要了解以下事项。
专家表示,部分原因是管理健康信息处理的联邦法律通常不适用于远程医疗公司。
“每天都有大量的公司收集大量的消费者健康数据,而我们目前的医疗行业特定法律并未涵盖这些数据,”非营利组织“民主与技术中心”的律师安德鲁·克劳福德说。
以下是注册远程医疗服务前需要了解的一些事项:
几乎所有的远程医疗就诊都是从填写问卷开始的,用户需要在问卷中提供有关其病史和可能感兴趣的药物的详细信息。
根据联邦贸易委员会的诉讼,Hims 的客户被自动注册并被收取定期处方费用,而“几乎没有机会审查提供商推荐的治疗方案”。
研究人员记录了整个行业中类似的实践,即使是注射减肥药物,在开始治疗前通常也需要进行体检和其他预防措施。
最近一项针对近50家销售GLP-1药物的远程医疗公司的分析发现,只有不到三分之一的公司真正要求患者与医生进行实时视频或音频咨询。在某些情况下,处方甚至在几分钟内就获得了批准。
“我们发现,获取GLP-1类药物极其容易,”领导这项研究的耶鲁大学雷什玛·拉马钱德兰博士说。“大多数情况下,处方会自动发送,甚至没有机会阻止配药。”
缺乏实时沟通意味着许多患者无法获得医学协会推荐的、开具 GLP-1 类药物的护理,包括讨论减肥目标、过去的努力和饮食失调。
研究人员发现,只有略多于一半的网站在其调查问卷中设有关于饮食失调的问题——GLP-1 药物可能会诱发或加剧这种失调。
观点:如果你认为自己的健康属于个人隐私,那就来看看你的数据都发生了什么
美国人通常认为,他们分享的任何个人健康信息都受到《健康保险流通与责任法案》(HIPAA) 的保护。HIPAA 是一项联邦隐私法,旨在规范医疗信息的处理。但实际上,该法案通常只适用于特定类型的医疗机构,例如诊所、医院和保险公司,而不包括提供处方、咨询、DNA 检测和其他在线服务的远程医疗公司。
隐私专家表示,法律漏洞是企业继续向广告商和搜索引擎披露敏感健康信息的原因之一。
《消费者报告》技术政策主管贾斯汀·布鲁克曼表示:“目前并没有明确的联邦法律规定‘禁止这样做’。只有一些不成文的法律条文和与联邦贸易委员会达成的和解案例,很多公司可能根本就不知道这些。”
由于 HIPAA 并未涵盖所有直接面向消费者的医疗平台,联邦贸易委员会 (FTC) 通常会利用其更广泛的权力,对“欺诈、欺骗或不道德的商业行为”采取行动。实际上,这意味着要证明远程医疗公司在最初承诺不会泄露客户健康信息之后,最终还是泄露了这些信息。
根据联邦贸易委员会(FTC)的投诉,Hims公司曾向客户宣称其平台提供“100%在线、私密且安全”的信息共享方式,供客户与公司医疗专业人员分享信息。但FTC指控,该公司实际上却将数据共享给了Meta和其他在线平台。
Michael A. McCoy/《华盛顿邮报》/Getty Images
退伍军人事务部监管机构发现,近百万个退伍军人寻求医疗服务的电话缺少关键跟踪数据。
不过,专家表示,监管机构可采取的处罚措施有限。大多数情况下,公司会签署一份法律协议,声明将停止监管机构指出的违规行为。
加利福尼亚州、康涅狄格州、马里兰州和其他一些州的立法者通过了新的网络隐私法,其中包括对健康信息的特殊保护。但是,对于违反这些规定的远程医疗公司,执法力度却很弱。
目前,隐私专家建议在登录远程医疗网站时使用广告拦截器和隐私浏览模式(有时也称为“隐身窗口”)。这些工具可以增加公司追踪您的位置、上网记录和其他个人信息的难度。
克劳福德表示,最好也阅读一下用户协议,了解公司计划如何使用你的个人数据。例如,一些远程医疗网站在其隐私政策中明确指出,他们有权出售用户性生活数据。
保护您的信息的唯一万无一失的方法可能就是拒绝服务条款,这通常是访问远程医疗服务之前需要采取的首要步骤之一。
他说:“我们现在的系统给消费者带来了过重的负担,他们需要做大量的工作来了解每项收集个人数据的技术将如何处理这些数据。但即使你做了所有这些工作,你往往也几乎没有自主权。”