Health and Lifestyle
Telehealth’s Dirty Secret: Your Health Data Is for Sale -By Fransiscus Nanga Roka
But now AI has thrown gasoline on an already reckless industry. Examples include algorithms that have been trained on patient records without informed consent and clinicians pasting sensitive clinical notes into public AI chatbots which store this data and may reuse it. Discrimination against racial and demographic minorities in algorithm-based diagnostics, aka a scandal looking the other way.
The telehealth revolution held the promise of privacy, convenience and dignity for patients too vulnerable, remote or embarrassed to sit in a waiting room. But it silently turned into one of the most exploitable data marketplaces out there, regulators are only just now beginning to catch up.
The brand of digital clinics is attractive, but mental health disclosures, prescription histories and diagnostic details have been harvested, sold and turned into ad ammunition. This is not an abstract risk. It takes the form of records, legal processes and large bills.
Consider Cerebral Inc., an online mental health provider that in 2024 was penalized $7 million by the US Federal Trade Commission for disclosing patients’ psychiatric histories and prescription records to third parties for marketing purposes. The FTC didn’t merely slap the company with a fine; it also permanently prohibited Cerebral from using sensitive health data for advertising ever again.
GoodRx underwent a similar reckoning in 2023 when it paid $1.5 million in civil penalties under the FTC’s Health Breach Notification Rule for furtively routing prescriptions and condition information to Google and Facebook, advertisers that had no business knowing what drugs American patients were taking. Subsequent investigations found that pixel trackers and similar analytics technologies built into telehealth websites routinely leaked patient identifiers and disease statuses to marketing networks.
Michael is a London based journalist specialising in defence issues; he is also the founder of the UK Defence Blog. In the US, Protected Health Information is subject to HIPAA (the Health Insurance Portability and Accountability Act) governing how it must be handled, while the FTC’s Health Breach Notification Rule catches all those not covered by HIPAA – and so conveniently escapes its custodial shackles.
This reckoning extends to Indonesia as well. Health data is defined as specific personal data (data teridentifikasi), which requires enhanced protection and compliant with Law No. 27 of 2022 on Personal Data Protection (UU PDP) subject to administrative punishment and criminal sanctions against violations of such provisions. Administrative fines alone render 2% of a company’s annual revenue, and provide for individual criminal liability for those who leak the data. Of legal importance, Ministry of Health Regulation No. 24 of 2022 makes it a legal requirement for healthcare facilities to safeguard electronic medical records something a lot digital platforms treat as optional.
But now AI has thrown gasoline on an already reckless industry. Examples include algorithms that have been trained on patient records without informed consent and clinicians pasting sensitive clinical notes into public AI chatbots which store this data and may reuse it. Discrimination against racial and demographic minorities in algorithm-based diagnostics, aka a scandal looking the other way.
The consequences are no longer hypothetical. Law suits: thousands of patients whose most personal health information was sold without their consent are filing class action lawsuits Now regulators in Jakarta and Washington have the power to suspend AI powered services outright or take away a platform’s operating license for good.
Telemedicine was marketed to the masses as a great equalizer within healthcare. Instead, what it has too frequently provided is a doctor in the surveillance pipeline. HIPAA and UU PDP compliance should not be seen as bureaucratic red tape, they are the last ditch effort to protect patients from an industry that, given enough time, will repeatedly violate trust for ad dollars until forced by law to stop.
The communication from Washington and Jakarta alike should be crystal clear: platforms that believe patient data is a commodity will pay in fines, lawsuits and ultimately the ability to continue to operate at all.
Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia