Telehealth Privacy: What Health Websites Do With Your Data
The page you visit can reveal your condition before you have typed anything. Regulators have started treating that as health information, and not every site has caught up.
You do not have to type anything for a health website to disclose something about you. The address of the page you loaded can be enough — and for years a great deal of that was being sent, automatically, to advertising companies.
The short version
- Third-party analytics and advertising scripts embedded in a page can transmit the URL you visited alongside identifiers that single you out.
- On a health site the URL is often the sensitive part. A page about depression treatment or HIV testing reveals the condition by itself.
- HHS Office for Civil Rights has treated this pattern as a potential disclosure of protected health information, and the FTC has brought enforcement actions against health companies over tracking-based data sharing.
- A Business Associate Agreement is the contract that must be in place before a vendor handles protected health information on a covered entity's behalf. Most large advertising platforms will not sign one for this purpose.
- You can check what a site loads yourself, in a couple of minutes, using tools already in your browser.
This is an uncomfortable subject because the industry has been sloppy about it. Investigations over the past several years repeatedly found tracking pixels on hospital websites, telehealth platforms, mental health services and prescription apps, transmitting information most patients would assume was private — partly carelessness, partly marketing departments doing what marketing departments do, on infrastructure nobody had thought about clinically.
How the leak actually works
Almost every website loads code from other companies. Analytics to count visitors. Advertising pixels to measure whether an ad produced a signup. Chat widgets, video players, font libraries, session-replay tools.
Each is a script running inside your browser, on the page you are reading, with access to that page's context. When it phones home it typically sends the full URL, the referring page, your IP address, your user agent, and whatever cookie or advertising identifier that company has already set on your browser from every other site you have visited that uses it.
Two of those pieces are the problem in combination. The identifier is persistent and tied to a profile that may include your real name, because you logged into that platform's own service years ago. And the URL is descriptive: a path ending in treatment-resistant-depression tells you what the visitor was reading without needing anything else.
It gets worse in two situations. Some sites put information in query strings — a form submission that ends up in the URL, or an email link containing an account identifier. And session-replay tools can capture what you typed into a form even if you never pressed submit.
Why the page you visit is itself health information
People reasonably assume the protected part is the medical record: the diagnosis, the prescription, the note. Browsing feels anonymous by comparison.
But the inference is what matters. Someone reading a page about opioid dependence treatment very likely has a personal interest in opioid dependence treatment. The same holds for fertility, HIV, abortion, eating disorders, gender-affirming care, cancer and mental health. Combine that with a persistent identifier and you have a probable health condition attached to an identifiable person, sitting in an advertising database, potentially available to whoever that database is sold or subpoenaed to.
This is why the regulatory position landed where it did. When an identifiable individual visits a covered entity's page in a way that relates to their health, care or payment for care, that combination can constitute protected health information — though nobody typed a diagnosis into a form.
What regulators have said
In late 2022 HHS Office for Civil Rights issued a bulletin on the use of online tracking technologies by HIPAA covered entities and business associates. Its central point: covered entities may not use tracking technologies in a way that discloses protected health information to third parties unless HIPAA permits it, which in practice means either valid patient authorisation or a Business Associate Agreement restricting what the vendor may do with the data. Website banner consent does not substitute for HIPAA authorisation.
The bulletin was later challenged in litigation and parts of it were vacated, narrowing how far OCR's specific guidance reaches, particularly around unauthenticated public pages. The underlying statute did not change, and neither did the practical exposure, because HIPAA is not the only regime in play.
The Federal Trade Commission has pursued health companies over tracking-based data sharing, using both its authority over unfair and deceptive practices and the Health Breach Notification Rule, which reaches health apps outside HIPAA entirely. State privacy laws increasingly define health data broadly, and there is an active body of class-action litigation.
The reasonable summary for a patient: what is prohibited by which authority is still being argued, and a site sending your visit to an ad platform is taking a position on an unsettled question with your data.
What a Business Associate Agreement is, and why it matters
Under HIPAA, a covered entity is a health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically in connection with certain transactions. A business associate is an outside organisation that creates, receives, maintains or transmits protected health information on its behalf — a billing company, a cloud host, a records vendor, a transcription service.
Before a business associate touches that information, a Business Associate Agreement must be in place. It is a binding contract that limits what the vendor may do with the data, requires them to safeguard it, prohibits use for their own purposes, requires breach reporting, and flows the same obligations to their subcontractors. It also makes them directly liable under HIPAA.
Here is the crux. General-purpose advertising and analytics platforms typically will not sign a BAA for standard advertising products, because their business model depends on using the data for their own purposes — precisely what a BAA forbids. Some vendors offer HIPAA-eligible configurations of specific services, under specific settings, with a BAA; those exist and are narrower than the default product.
So when you see an ad pixel from a major platform on a provider's condition pages, the likely explanation is that no BAA exists and none was sought.
Worth knowing
"We don't sell your data" is a narrower promise than it sounds. Sharing data with an advertising platform in exchange for ad targeting and measurement is frequently not classified as a sale by the company doing it, though several state privacy laws now define sale broadly enough to capture it. Read for what is disclosed and to whom, not for the word sold.
How to check a site yourself
No technical skill needed for a basic version, and it takes about two minutes.
Open the network panel. In Chrome, Firefox or Edge, press F12 or right-click and choose Inspect, then select Network and reload. You will see every request the page makes. Scan the domain column: anything that is not the site you are on is a third party. Recognisable ad and analytics domains on a page about a medical condition is the finding.
Use a tracker-blocking extension. Reputable privacy extensions display a count and list of blocked trackers per page, which gives you the answer without opening developer tools.
Read the privacy policy for the specific words. What is shared with third parties for advertising or analytics, whether the provider states it operates as a HIPAA covered entity, whether it names categories of recipients, whether there is an opt-out. Vagueness here is itself informative. Ours is at the privacy policy page, alongside the terms and conditions.
Check the URL after a form submission. If your answers appear in the address bar, they were in the URL, and the URL goes to every third-party script on the page.
What a responsible site does
- Keeps third-party scripts off pages that reveal a condition, and off any authenticated patient area, entirely.
- Uses first-party or self-hosted analytics where measurement is genuinely needed, or a vendor that will sign a BAA under an appropriate configuration.
- Never places health information in URLs or query strings.
- Keeps the patient portal on separate infrastructure from the marketing site.
- Says in its privacy policy what it loads and why, in language a patient can check against the network panel.
- Uses no session-replay tooling where clinical information is entered.
- Reviews the scripts periodically, because tags get added by marketing teams and nobody removes them.
Be careful here
If you are researching something you would not want linked to your name — a mental health condition, substance use, sexual health, reproductive care — assume default browsing is not private. An incognito window limits what persists on your device but does not stop the site or its third parties seeing the visit; a reputable tracker blocker helps more. And be careful with links from marketing emails, which frequently carry an identifier tying the visit directly to your email address.
Where this fits in the broader picture
Privacy is one of the things you can ask a provider about directly, alongside licensure, records access and referral. Those are set out in your rights as a telehealth patient, with the complaint routes — the practice, the state board, HHS Office for Civil Rights, the FTC.
It also correlates with everything else about how a service is run. An operation treating your condition data as advertising inventory is usually not the one running careful clinical screening, and the structural warning signs are the same ones in how to spot a prescription mill. For the wider question of what remote care suits, start with what telehealth is actually good for. If you have questions about how we handle your information specifically, ask before you book.
The honest position is that much of the industry got this wrong for years, some of it still does, and the regulatory picture is not finished. The check takes two minutes and is worth doing on any health site you are about to give real information to.
Talk to a licensed clinician
Reading about a treatment is not the same as knowing whether it fits your history. A consultation is a conversation about your own situation — not a sales call, and not a promise of any outcome.
Book a consultation