FTC's Enforcement Action Against GoodRx Reveals New Regulatory Threats: Should Digital Health Apps Be Concerned?
The U.S. Federal Trade Commission's (FTC) enforcement action against digital health company GoodRx, marking the first use of the Health Breach Notification Rule (HBNR), signals an impending regulatory storm over the sharing of sensitive medical data. This article analyzes the impact of the rule, the FTC's enforcement strategy, and the compliance risks for digital health companies.

The Federal Trade Commission's (FTC) enforcement action this month against digital health company GoodRx may only be the beginning of a series of actions against companies that misuse users' sensitive medical data, according to compliance experts. The complaint, which accuses GoodRx of sharing consumer health data with advertisers, is the first to use the Health Breach Notification Rule (HBNR), an enforcement mechanism that allows regulators to impose fines on violators.
But experts believe this is unlikely to be the last, as regulators seek to prevent other companies from adopting similar practices.
"I think this is the first, but not the last" use of HBNR, said Phyllis Marcus, a partner at law firm Hunton Andrews Kurth who worked at the FTC for nearly two decades. "I have no doubt."
Regulators say they are monitoring the digital health market, cracking down on companies that profit from users' sensitive health information, especially health apps not subject to existing consumer protection laws. Such apps, which track everything from diabetes, fertility, and heart health to sleep, increasingly collect sensitive personal information from consumers but are not governed by HIPAA privacy rules.
Although the threat HBNR poses to digital health companies is not yet clear, experts note that the order shows the FTC is willing to use every tool in its toolbox to curb data sharing as healthcare becomes increasingly online.
"I think this is the opening shot, and as health apps become more prevalent, this will become a common case," said Shawn Collins, a privacy and data security lawyer at commercial law firm Stradling. "This is the FTC signaling to all apps and startups collecting large amounts of sensitive data: We have mechanisms to enforce data privacy rules against you."
Health Breach Notification Rule
The government's complaint against GoodRx accuses the California-based company, which offers prescription drug discounts, telehealth, and other digital health services, of illegally sharing user information with advertisers such as Google and Facebook. As a result, millions of GoodRx customers suffered substantial harm, the FTC's complaint alleges.
The FTC's order, filed with the Department of Justice on February 1, will prohibit GoodRx from sharing users' health data with third parties for advertising purposes. GoodRx also agreed to pay a $1.5 million penalty. The order requires court approval to take effect. Lawyers say approval is almost certain given that the FTC and GoodRx have agreed on the terms.
The FTC's order contains eight counts. The first seven are different iterations of the FTC's general statutory authority over deceptive statements and unfair practices. The final count alleges that GoodRx violated HBNR.
HBNR, finalized in 2009, was originally designed to require companies to notify consumers when a data breach affected the information of more than 500 users. However, in September 2021, the FTC issued an opinion stating it would begin interpreting "breach" not only as malicious intrusions but also as any unauthorized sharing of data. That policy statement also clarified that health apps and fitness trackers are subject to HBNR. GoodRx, however, said it disagrees that its conduct violated the rule.
"We disagree with the FTC's allegations, and we do not admit any wrongdoing. Reaching a settlement allows us to avoid the time and expense of protracted litigation," GoodRx said in response to the enforcement action.
But according to the FTC's complaint, HBNR applies because GoodRx is a "vendor of personal health records" and maintains records of identifiable health information. The FTC alleges that from at least 2017 to 2020, the company experienced security incidents involving the disclosure of unsecured personal health information of more than 500 consumers to third parties.
"They're not focusing on the word 'breach.' They're focusing on the definition of breach, which is the distribution of data without the consent or authorization of the data owner," said Chris Leach, a partner at Mayer Brown and former FTC lawyer who focuses on consumer issues such as data privacy and false advertising. "I think it's broader than what people typically think of as a breach... but the agency is looking at the plain text of the rule," said Leach, who previously worked in the FTC's financial practices division.
Enforcement authority allows regulators to impose fines
Lawyers say the FTC's interpretation of HBNR is a novel reading of the decade-old rule with significant implications for any company found to be in violation.
"The reason the FTC is seeking such a rule, when it hasn't in the past, likely has a lot to do with losing its monetary power," Leach said. Before 2021, the FTC was able to obtain monetary penalties through "creative interpretations" of its statutes, allowing regulators to seek equitable monetary relief in federal court. But two years ago, the Supreme Court ruled that the FTC's interpretation of the statute was wrong, limiting the FTC's ability to impose financial penalties on violators.
Since then, the FTC has been trying to figure out how to impose fines in some cases. One strategy is to turn to rules that allow the agency to obtain monetary penalties even for first-time violations—such as HBNR. "It's not surprising that the FTC is seeking monetary relief and using this rule as a vehicle," Marcus said.
Could have been worse for GoodRx
Mark Bowling, vice president of security response services at cybersecurity company ExtraHop, said it's about time the FTC finally used HBNR, although it could have gone further in prosecuting GoodRx. Bowling, who worked at the FBI for nearly two decades, said the order shows GoodRx deliberately and systematically sold user data and should have been fined more and required to admit wrongdoing.
"I think they should be more aggressive in the future," Bowling said. Bowling is not the only critic of the light penalty for GoodRx. "I would have supported a larger civil penalty," FTC Commissioner Christine Wilson wrote in a concurring opinion on the settlement. "Based on economic literature, I am confident that a significant percentage of consumers would have forgone the benefits of GoodRx coupons and other services if they had known about the company's sieve-like data practices, suggesting that the company's ill-gotten gains were almost certainly many times the $1.5 million civil penalty."
The $1.5 million penalty GoodRx agreed to could have been in the billions, lawyers say. Companies that fail to comply with HBNR may face fines of up to approximately $44,000 per violation per day. Multiplying that amount by millions of affected users is a daunting calculation for any company found in violation, Marcus said—although the FTC considers other factors when determining fines, such as the degree of the company's fault, ability to pay, and history of repeat violations.
"My expectation is that $1.5 million sets the floor, and the next civil penalty will be larger," Marcus said. GoodRx also did not have to admit wrongdoing in the settlement—which lawyers say may have been a sticking point for the FTC. Combined with the relatively small fine, Collins believes this indicates the FTC is not confident in its ability to enforce its HBNR interpretation in court. That ambiguity complicates whether this new enforcement threat is likely to change the behavior of companies in the digital health market. In the absence of comprehensive data privacy legislation, much data sharing among companies remains legal, albeit controversial.
But experts say organizations engaged in health data transactions should take note. This enforcement action, along with other recent high-profile actions against digital health companies, hints at how the FTC plans to limit the sharing of sensitive health data. Even if the threat of fines is lower than in past years, it's best to avoid regulatory trouble. Therefore, companies handling health data should understand their obligations under HBNR.
"Blazing the trail is difficult. But following is easier," Leach said. "Everyone has gone through the process of resolving their views on this rule. I guess from now on this will become the norm."