Forgotten Dairies

When Telehealth Turns Illness Into Advertising Inventory -By Fransiscus Nanga Roka

Strategic reform must begin now. Government should ban behavioural advertising targeted because of health data not simply bury opt in deep within unread consent screens. Telehealth providers should remove advertising trackers from their clinical pathways, limit collection, split medical and marketing databases, set tight vendor controls and commission independent pixel assessments.

Published

on

No hacker needed: the most dangerous medical-data breach. Occasionally somebody puts their secrets into a healthcare platform, only to find out that the star chamber of consultation had alleged invisible overhead advertising trackers.

On July 29, 2026, US Federal Trade Commission sued Hims & Hers Health in Los Angeles County and Utah. According to the complaint, health information disclosing users was sent out by the telehealth company to Meta and Snap despite a pledge of confidentiality. Hims & Hers, which denies the allegations, calls the case “headline-driven.”

The who goes well beyond one corporation. This encompasses patients seeking treatment for anything from erectile dysfunction, hair loss, mental-health conditions and obesity, the very personal vulnerabilities that people divulge in the expectation of clinical confidentiality rather than behavioral surveillance.

Hence, the “what” is more alarming than a common cybersecurity incident. However, regulators did not claim that foreign hackers breached Hims & Hers. They claim that the company’s own digital architecture shared health information with advertising companies without obtaining appropriate consent. Not just leaking data but an allegedly systemic conversion of illness into marketing intelligence.

The “how” reveals the anatomy of telehealth whereas least expected. Tracking pixels, SDKs and analytics tools can log page views, form interactions, identifiers and treatment interests. These signals, when transmitted, may help advertising systems determine that a person is worried about depression, sexual potency or losing weight. A patient logs into a virtual clinic; an advertisement stuffed profile may exit it.

Advertisement

The case also goes for Hims & Hers’ commercial machinery. Regulators accuse the firm of deceptive billing practices, charging for prescriptions before they were sent and making it difficult to cancel orders. That cocktail is important: monetizing not only patients anxieties, but also their difficulties escaping subscriptions are not just healthcare offerings, they verge into a business model that derives revenue from therapeutic dependency.

Why could this happen? The reason: Because American health privacy is still in a dangerous state of fragmentation. While covered entities and their business associates are tightly governed by HIPAA, consumer health technologies often function out of its traditional perimeter. The FTC Act and Health Breach Notification Rule. These laws cover some of these gaps in consumer protection. However, enforcement post-distribution cannot replace privacy; once sensitive data penetrates the advertising pipeline it becomes technically non-removable and difficult to live down.

This lawsuit is an early-warning siren that Indonesia should not only hear but also heed. According to the provisions of Law No. 27 of 2022 on Personal Data Protection, health information is part of personal data that has special treatment, which includes sensitive and indivisible conditions. The regulation requires that controllers inform those affected, as well as authorities, after just three days of a breach in protection and imposes fines on Controllers of up to 2% of annual revenue. Yet statutory language divorced from an independent, technically capable enforcement authority is merely window dressing.

Strategic reform must begin now. Government should ban behavioural advertising targeted because of health data not simply bury opt in deep within unread consent screens. Telehealth providers should remove advertising trackers from their clinical pathways, limit collection, split medical and marketing databases, set tight vendor controls and commission independent pixel assessments.

Algorithmic disgorgement: Regulators should impose that health data be deleted (not just the original files) along with the models, audiences and profiles derived from illegally obtained health data. Individual Violations and Consequences Executives should personally certify compliance; repeat or deliberate noncompliance should be punishable by individual liability.

Advertisement

Above all, privacy law should acknowledge the blunt truth revealed by this case: consent taken from patients in fear, shame or desperation is not a commercial carte blanche. When a hidden ad exchange disguised as a digital clinic becomes the place for care, In essence, it has evolved into a thriving marketplace where vulnerability itself is the commodity.

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version