Pharma marketing compliance and privacy

The FTC Health Breach Notification Rule: What Health Marketers Need to Know

The FTC Health Breach Notification Rule explained for marketers: who it covers after the 2024 update, why pixel sharing can be a breach, and what to check.

Christian Guerrero Published 7 min read Part 6 of 10

The short answer

The FTC Health Breach Notification Rule requires health apps and similar non-HIPAA services that hold identifiable health information to notify users, the FTC, and sometimes the media after a breach. Since the 2024 amendments took effect, "breach" clearly includes unauthorized disclosures, so sending health data to an ad platform through a pixel or SDK without the user's authorization can trigger the rule. For marketers, the exposure sits in brand-owned apps, trackers, and tools.

The Health Breach Notification Rule sat quietly on the books from 2009 until 2023, when the FTC used it for the first time. Since then it has become one of the main federal tools for health data that falls outside HIPAA. This article explains who it covers, what changed in 2024, and what it means for pixels and SDKs. It is not legal advice; coverage questions are fact-specific and belong with counsel.

What the FTC Health Breach Notification Rule covers

The rule, at 16 CFR Part 318, applies to vendors of personal health records (PHRs), PHR related entities, and third-party service providers to them. It does not apply to HIPAA covered entities or business associates acting in that role.

A personal health record, under the amended rule, is broadly an electronic record of identifiable health information that can draw information from multiple sources and is managed, shared, and controlled by or primarily for the individual. The FTC has said the amendments make clear that the rule applies to most health apps and similar technologies. "Multiple sources" can include the user's own entries plus data pulled from a device, an API, or the app's own calculations.

For pharma and health marketers, candidates include symptom trackers, dose or adherence apps, condition management tools, some savings and enrollment tools that store health details, and patient community platforms. Whether a specific tool is in scope is a legal question, but the default assumption should no longer be "it's just a marketing app."

What changed in the 2024 update

The FTC announced final amendments in April 2024, and they took effect July 29, 2024. The main changes, as described by the FTC:

AreaChangeWhy marketers care
ScopeClarified that developers of health apps and similar technologies are covered, and revised key definitionsBrand-sponsored apps and tools are more likely in scope
Breach of securityIncludes unauthorized acquisition through a data security breach or an unauthorized disclosurePixel and SDK sharing without authorization can be a breach
Notice methodAllows email notice (with other electronic methods) where the consumer has agreedLess relevant to media, but shapes response plans
Notice contentExpanded what notices must say, including the third parties that received the dataYour ad platforms could be named in a notice to users

Notification timing generally runs up to 60 calendar days after discovery for affected individuals, with FTC notice and media notice requirements depending on how many people were affected. Civil penalties apply per violation and are adjusted for inflation each year. Check the current rule text for exact thresholds and amounts.

The GoodRx and BetterHelp cases

Two 2023 FTC actions explain why marketers pay attention to this rule, though they rested on different legal bases.

GoodRx (February 2023). The FTC's first Health Breach Notification Rule action. The FTC alleged that GoodRx shared users' health information, including prescription-related data, with advertising and analytics platforms, contrary to its privacy promises, and failed to notify users. The order included a $1.5 million civil penalty and a ban on sharing health data for advertising.

BetterHelp (announced March 2023, finalized July 2023). Brought under the FTC Act, not the breach rule. The FTC alleged that the online counseling service shared email addresses, IP addresses, and health questionnaire information with platforms including Facebook and Snapchat for advertising after promising not to. The order required $7.8 million for consumer refunds and banned sharing health data for advertising.

Both cases describe a familiar marketing setup: standard ad pixels and conversion events on pages or flows that revealed health information. Neither company needed to sell a list for this to happen. The FTC's view was that the data flowing through the tags was itself the problem. A related case, Premom (2023), also used the breach rule against a fertility app.

What the rule means for pixels and SDKs

If a covered app or site sends identifiable health information to a third party without the user's authorization, the FTC treats it as a breach. That makes tag configuration a breach-prevention task, not just an analytics one.

Things that commonly carry health information without anyone intending it:

  • Page URLs and titles that name a condition or drug, passed automatically by most pixels.
  • Custom event names like "completed_symptom_quiz" or "enrolled_copay_card_[brand]".
  • Form field values captured by auto-event or enhanced conversion features.
  • Mobile SDKs that log screens and in-app events by default.
  • Hashed emails sent with a conversion event tied to a health-specific action.

The fix is a governed tag inventory, consent that matches what actually flows, and server-side controls that strip or block health parameters. Tracking pixel governance on pharma and health websites covers the routine. The same caution applies to analysis: exporting event data into tools or AI assistants without controls creates its own exposure, as discussed in using AI for campaign analysis without exposing sensitive data.

A checklist for brand-owned health apps and tools

  1. List every app, tool, quiz, tracker, and portal the brand runs, including those built by agencies or vendors.
  2. For each, record what health information it collects and from which sources.
  3. Run a traffic capture (proxy or tag scanner) and list every third party that receives data.
  4. Compare that list with the privacy policy and consent flow. Gaps are your biggest risk.
  5. Remove or reconfigure tags that send health information to ad platforms without express authorization.
  6. Confirm a breach response plan exists that covers disclosure through tags, not only hacks.
  7. Repeat after every release. SDK updates change behavior without warning.

Direct-to-patient programs add more of these tools; see direct-to-patient pharma programs.

How this fits with HIPAA and state laws

The breach rule covers what HIPAA does not, and state laws like Washington's often cover the same data with consent and sharing rules of their own. A brand app could face the FTC rule, the FTC Act's deception standard, and several state laws at once. The pharma marketing compliance guide lays out how the regulators divide up the territory.

Practical takeaway

Pick the one brand-owned tool that collects the most health detail, run a network capture on it this week, and list every domain that receives data. Send that list to privacy and legal with a simple question: does each of these flows have user authorization?

Frequently asked questions

What is the FTC Health Breach Notification Rule?

It is an FTC rule requiring vendors of personal health records and related entities that are not covered by HIPAA to notify consumers, the FTC, and in some cases the media after a breach of unsecured identifiable health information. Amendments that took effect July 29, 2024 clarified that it covers most health apps and that unauthorized disclosures count as breaches.

Can sharing data with an ad platform be a breach under the rule?

Yes. The FTC's position, written into the 2024 amendments, is that a breach includes an unauthorized disclosure, not only a hack. Sharing identifiable health information with an advertising platform without the consumer's authorization can trigger notification duties.

Was BetterHelp a Health Breach Notification Rule case?

No. BetterHelp, announced in 2023, was brought under the FTC Act's prohibition on deceptive and unfair practices. GoodRx, also in 2023, was the FTC's first enforcement action under the Health Breach Notification Rule. Both involved sharing health information with advertising platforms.

Does the rule apply to HIPAA covered entities?

No. HIPAA covered entities and their business associates, when acting in that capacity, fall under HHS's breach notification rule instead. The FTC rule fills the gap for health apps and tools outside HIPAA.

Sources

External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.

Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.

Working through this decision on a real plan?

I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.