[HN Gopher] FTC bars GoodRx from sharing consumers' sensitive he...
       ___________________________________________________________________
        
       FTC bars GoodRx from sharing consumers' sensitive health info for
       advertising
        
       Author : vector_spaces
       Score  : 168 points
       Date   : 2023-03-08 17:35 UTC (5 hours ago)
        
 (HTM) web link (www.ftc.gov)
 (TXT) w3m dump (www.ftc.gov)
        
       | aj7 wrote:
       | Let me tell you, having saved $thousands from GoodRx's exposure
       | of pharma's underbelly, and the actual first-time competition
       | that it fosters, I can forgive them for this underhand revenue
       | stream.
       | 
       | Just yesterday $60.25, Walgreen's, returned --> $7.20, Safeway,
       | GoodRx e-coupon.
       | 
       | My wife is finally a believer, and it paid for more than half of
       | a $100 birthday gift for a poor cousin 1500mi away.
        
       | jeffbee wrote:
       | """GoodRx created Custom Events with names like "Drug Name" and
       | "Drug Category" that tracked and shared the prescription
       | medication name and health condition(s) associated with each
       | unique GoodRx Coupon that users accessed. As a result, at times,
       | when GoodRx shared a Custom Event, it was sharing its users'
       | health information."""
       | 
       | Seems kinda dumb! I for one would probably not have written that
       | code.
        
       | rqtwteye wrote:
       | A site like GoodRx should be run as a non profit that's
       | completely independent from advertisers. Once they start to rely
       | on advertisers they will go down the same corrupt path like most
       | other players in US health care.
        
       | haliskerbas wrote:
       | _deleted_
        
         | [deleted]
        
         | bretpiatt wrote:
         | Mark started Cost Plus Drugs
         | https://costplusdrugs.com/medications/
        
         | singhrac wrote:
         | That's the Mark Cuban Cost Plus Drugs company. This is a
         | competitor. Here's a good overview of their business model:
         | https://d3.harvard.edu/platform-digit/submission/goodrx-or-g...
        
           | aj7 wrote:
           | Hasn't made a dent yet. In fact, started out just trying to
           | acquire data.
        
       | mulmen wrote:
       | Can someone explain to me how big of a deal this "first of a
       | kind" collaboration between the DOJ and FTC actually is? Who set
       | the penalty here? Is the door still open to further criminal
       | investigation? What does this mean for a potential class action?
       | 
       | The biggest takeaway here seems to be the ban on sharing data,
       | not on the fine itself. I interpret that to mean sharing the data
       | for advertising purposes _is_ legal, maybe with consent from the
       | customer? But now GoodRx can 't do that?
        
       | mc32 wrote:
       | Absolutely right call. How can any company officer actually
       | believe this was an acceptable business practice. Being in that
       | business they must have heard of HIPAA and regulation around PHI.
       | What would keep hospitals from selling patient info?
        
         | SkyPuncher wrote:
         | Only covered entities are bound by HIPAA:
         | https://www.hhs.gov/hipaa/for-professionals/covered-entities...
         | 
         | Notably:
         | 
         | > [a bunch of providers] ...but only if they transmit any
         | information in an electronic form in connection with a
         | transaction for which HHS has adopted a standard.
         | 
         | If you don't process a specific type of transaction, no HIPAA
         | requirements.
        
           | ThaDood wrote:
           | Also if a CE enters into a BA with some company, AFAIK, data
           | sharing can basically occurs without issue and still
           | maintaining compliance since patient consent to data sharing
           | occurs with the CEs.
        
         | lp0_on_fire wrote:
         | > How can any company officer actually believe this was an
         | acceptable business practice.
         | 
         | Because the penalty is small enough that it's a "cost of doing
         | business". Until these fines are large enough to cause hardship
         | to the company, or we start piercing the corporate veil and go
         | after executives in their personal capacity this is going to
         | keep happening.
         | 
         | I simply do not believe there is a good-faith argument that
         | GoodRX wasn't familiar with the law in this case.
        
       | godelski wrote:
       | $1.5 million? What a joke. That's a tax, not a penalty.
       | 
       | I don't think many are surprised that GoodRX was sharing data
       | (violating its own privacy policy) but come on, have some teeth.
       | You'd think with HIPPA that we'd treat anything medical more
       | seriously.
        
         | lmkg wrote:
         | The thing is, HIPAA doesn't apply here. HIPAA doesn't actually
         | cover "anything medical." It only covers (approximately) things
         | involved in getting insurance to pay for medical treatment.
         | GoodRx did not touch the consumer's insurance, so they
         | "complied" with HIPAA by not being a covered entity in the
         | first place.
         | 
         | At the Federal level, the only broad general protections for
         | medical data are (apparently) some FTC fine print. The fact
         | that this exists _at all_ means that medical data is treated
         | more seriously than other forms of personal data, but as you
         | can see that is a very low bar to clear (literally doesn 't
         | exist).
        
           | jollofricepeas wrote:
           | Not exactly.
           | 
           | This is inaccurate in part.
           | 
           | HIPAA governs covered entities and business associates (BA)
           | who work on behalf of a CE. Covered Entities are healthcare
           | providers or insurance companies. CEs are required to have
           | their BAs sign business associate agreement where they're
           | regulated under HIPAA.
           | 
           | GoodRx convinced patients to provide them their health
           | information directly. Unless, they've signed a BAA with a CE,
           | the FTC is the only government body with regulatory power
           | here however I would imagine there's a legal firm prepping a
           | class action against GoodRx right now as well.
           | 
           | The class action is what will be expensive for them. The fact
           | that they have been fined is what should make the action
           | hopefully a slam dunk.
           | 
           | Sources:
           | 
           | - https://www.hhs.gov/hipaa/for-professionals/privacy/laws-
           | reg...
           | 
           | - https://www.hhs.gov/hipaa/for-professionals/security/laws-
           | re...
        
             | SkyPuncher wrote:
             | You've missed a part. For providers, they must be HIPAA
             | compliant "only if they transmit any information in an
             | electronic form in connection with a transaction for which
             | HHS has adopted a standard."
             | 
             | It seems unlikely that GoodRx was processing data that met
             | that standard.
             | 
             | https://www.hhs.gov/hipaa/for-professionals/covered-
             | entities...
        
               | jollofricepeas wrote:
               | Actually, they were...
               | 
               | There's no wiggle room here unless the data has been de-
               | identified (a high barrier). It wasn't.
               | 
               | The standard you're refering to is for e-PHI which is
               | "individually identifiable health information."
               | 
               | You'll want to see the Privacy Rule for details but
               | GoodRx shared email addresses, phone numbers and mobile
               | identifiers according to the FTC complaint.
               | 
               | https://www.ftc.gov/system/files/ftc_gov/pdf/goodrx_compl
               | ain...
        
               | SkyPuncher wrote:
               | The complaint pretty clearly states the FTC does not view
               | them as a covered entity. There are several statements,
               | but the most clear is near the end of page 23:
               | 
               | > In truth and in fact, GoodRx is not a HIPAA-covered
               | entity, and its privacy and information practices did not
               | comply with HIPAA's requirements.
               | 
               | Further, on page 25, they define them as a "vendor of
               | personal health records" - which explicitly excludes
               | covered entities (definition on page 19).
               | 
               | -----
               | 
               | This is consistent with my understanding of a covered
               | entity. Without the "transactions for which HHS has
               | adopted a standard", GoodRx is not a covered entity.
               | 
               | Further, even if they were a covered entity, it's
               | possible for them to segment their HIPAA and non-HIPAA
               | compliant business units. This is called a "hybrid
               | entity".
               | 
               | ----
               | 
               | Interestingly, the FTC is pinging them on for a
               | misleading representation of being a covered entity.
               | Since GoodRX was not a covered entity, they were not
               | technically violating HIPAA.
        
               | jollofricepeas wrote:
               | A clarification...
               | 
               | I'm not saying that they are a CE only that if they were
               | then the data is clearly PHI and had not been de-
               | identified per the standard that you referenced
               | previously.
        
             | mrguyorama wrote:
             | Since when has a class action lawsuit EVER cost a company a
             | real amount of money?
        
               | jollofricepeas wrote:
               | The class action for the WellPoint (Anthem) breach was
               | $115 million.
               | 
               | That smells like real money to me.
               | 
               | The total cost for the biggest healthcare breach was
               | around $500 million give or take.
        
         | [deleted]
        
       | throw93 wrote:
       | I want FTC to put fear of god in bad actors like GoodRx. $1.5
       | million is pocket change for a company with $765 million annual
       | revenue. They've spent $400k just on lobbying. This isn't gonna
       | change anything.
        
         | aj7 wrote:
         | You have no concept as to how much of a GOOD actor GoodRx is. I
         | agree, they f*cked up here, and deserved to be punished.
        
         | mulmen wrote:
         | > I want FTC to put fear of god in bad actors like GoodRx.
         | 
         | I'm not sure I do. The FTC does civil enforcement and
         | investigation. They identify misbehavior and issue the
         | equivalent of parking tickets. If you also give them the
         | ability to issue punishments then what prevents the FTC from
         | using that power to line their own pockets by sabotaging (or
         | threaten to sabotage) well behaved companies?
         | 
         | This penalty may not preclude lawsuits by GoodRx customers or
         | further investigations by other organizations leading to
         | criminal penalties.
         | 
         | I'm not a lawyer so I could be totally off base here but this
         | is my understanding after dozens of these HN threads with
         | similar comments.
         | 
         | > $1.5 million is pocket change for a company with $765 million
         | annual revenue.
         | 
         | Is it? GoodRx hasn't turned a profit since 2019. They lost
         | $32.8 million on $766.5 million in revenue in 2022.
        
           | throw93 wrote:
           | FTC was created to protect consumers though "strong and
           | effective law enforcement"(their mission statement). This FTC
           | action is not "strong" enough, it's just a slap on the wrist.
           | 
           | > If you also give them the ability to issue punishments then
           | what prevents them from using that power to sabotage (or
           | threaten to sabotage) well behaved companies to line their
           | own pockets?
           | 
           | "Own pockets" - FTC is not a for profit company. GoodRx is a
           | for profit company. Companies have more to gain by acting in
           | bad faith than FTC. So I would trust FTC any given day over a
           | for profit company.
           | 
           | > GoodRx hasn't turned a profit since 2019
           | 
           | This doesn't necessarily mean company is in bad shape. This
           | happens when company is investing in growth at the cost of
           | profit margins during it's initial years. If they can shell
           | out half million dollars on lobbying then $1.5 million is
           | indeed a pocket change for them.
        
             | mulmen wrote:
             | Sure but this FTC action has opened the door for class
             | action and criminal investigation. So does the FTC penalty
             | actually need to be steeper? It's an honest question, how
             | should that value be set?
        
           | shakna wrote:
           | There are countries where fines for speeding or parking are
           | proportional to the offender's income. So that it leaves a
           | message, and actually discourages future choices.
           | 
           | Proportionality, also means that if you have less to give,
           | you give less.
        
           | inetknght wrote:
           | > _then what prevents them from using that power to sabotage
           | (or threaten to sabotage) well behaved companies to line
           | their own pockets?_
           | 
           | Well-behaved companies won't line their own pockets out of
           | fear that the FTC will sue them out of existence.
        
             | mulmen wrote:
             | The FTC would be doing the pocket lining here.
             | 
             | I edited that sentence to try and clarify.
        
             | [deleted]
        
           | thfuran wrote:
           | But is there anything precluding them from re-issuing those
           | parking tickets every day until the problem goes away?
        
             | mulmen wrote:
             | Well GoodRx would have to re-offend for that to work.
        
               | 988747 wrote:
               | But if they don't re-offend that means that this "parking
               | ticket" actually worked, right? The goal is to make the
               | company follow the law, not push it to bankruptcy as a
               | revenge.
        
               | alistairSH wrote:
               | The problem is the "small" fine might dissuade GoodRx
               | from re-offending in the short term.
               | 
               | But, it probably isn't enough to prevent other bad
               | actors. Or from GoodRx re-offending in a few years, once
               | the CEO/BoD/etc have rotated on to other pursuits.
        
       | rchaud wrote:
       | > GoodRx displayed a seal at the bottom of its telehealth
       | services homepage falsely suggesting to consumers that it
       | complied with the Health Insurance Portability and Accountability
       | Act of 1996 (HIPAA),
       | 
       | $900m in funding[0] and their business practices are straight out
       | of a fly-by-night MLM brand.
       | 
       | [0] https://www.crunchbase.com/organization/goodrx
        
         | SkyPuncher wrote:
         | There's such thing as a hybrid-entity. I had looked into it for
         | a prior HealthTech company.
         | 
         | Essentially, they can remain "HIPAA compliant" by segmenting
         | their HIPAA and non-HIPAA business units.
        
           | rchaud wrote:
           | If this were true, I imagine they would have brought this up
           | before the FTC fined them. Just went on their site now, no
           | mention of this hybrid entity structure.
        
             | SkyPuncher wrote:
             | It looks like the FTC is actually alleging that they
             | misrepresented their status as a HIPAA covered entity.
        
         | aj7 wrote:
         | Utter nonsense. I've saved thousands with them. I used to have
         | to keep Excel spreadsheets for prescription prices. And that's
         | AFTER I realized that pharma benefits (including yours) and
         | Medicare Part D were utter bullshit (I'm NOT kidding. Words
         | chosen carefully.), and the trick was to buy drugs, over-the-
         | counter, for cash, on the open market. (Imagine that being "a
         | trick." Imagine my surprise when my prescription OTC in cash
         | was cheaper than Optum-UHC's pharmacy "benefit.")
         | 
         | GoodRx makes the entire process a few iPhone clicks.
        
         | olliej wrote:
         | They complied by afaict not being a covered entity. You could
         | make a site that lets people log their health issues, but allow
         | _anyone_ to access that data and not be violating HIPPA.
         | 
         | HIPPA is not a medical privacy bill.
        
           | alistairSH wrote:
           | But, apparently, they claimed there were compliant. So,
           | fraud, or at least super-sketchy.
        
           | mulmen wrote:
           | HIPPA doesn't exist. HIPPA is a mistaken acronym that adds
           | the p-for-privacy.
           | 
           | HIPAA (Health Insurance Portability and Accountability Act) -
           | a real 1996 law.
           | 
           | HIPPA (Health Information Privacy and Portability Act) - not
           | a thing.
        
       | zacharyvoase wrote:
       | Does this preclude their users from suing them for violating the
       | privacy policy (and other laws)?
        
         | olliej wrote:
         | what privacy policy? I'm guessing any agreement included the
         | standard "we may share your data with our partners" text. There
         | aren't any laws stopping them sharing medical data.
        
           | lmkg wrote:
           | The linked article explicitly states that part of the fine is
           | because the data sharing violates GoodRx's own privacy
           | policy.
        
       | ctvo wrote:
       | Unsure why there aren't percentage based fines in the US. Strong
       | lobbying preventing legislation with teeth from passing?
       | 
       | We know they're a publicly traded company, we know their revenue,
       | profit, etc. -- why not fine them a percent based on this data?
       | It's a little more tricky with private companies, but a
       | certification process, and a undisclosed fine in those cases work
       | too.
        
         | adamrezich wrote:
         | > Unsure why there aren't percentage based fines in the US.
         | Strong lobbying preventing legislation with teeth from passing?
         | 
         | that is the basic gist. our federal government doesn't do much
         | of anything for the people it represents, compared to what it
         | does for corporations, lobbyists, and career politicians.
        
       | ThaDood wrote:
       | Doesn't allow data sharing from GoodRX to FB, Google etc. But
       | does allow Amazon to purchase One Medical. I feel like both are
       | pretty bad. But I am trying to understand the logic between
       | allowing one and not the other? Am I missing something?
       | 
       | Also $1.5 million, in relative terms, seems pretty small. So
       | again, data violations just seem to be the cost of doing
       | business.
        
         | mfer wrote:
         | Do you realize that you are talking about two very different
         | situations.
         | 
         | In one situation you have a company sharing data with other
         | companies and the laws around that form of data sharing.
         | 
         | In the other situation you have what companies can own or buy
         | in terms of other companies.
         | 
         | The situations are very different.
        
           | ThaDood wrote:
           | I might not be articulating my point super well since this is
           | HN and I hate typing long drawout thoughts on boards. That
           | being said I understand the situations are different but to
           | me, the sentiment still feels like it should be applied?
           | 
           | On one hand you have the FTC fining a company for violations
           | of data sharing, which I am assuming of the one of the
           | concerns is patient privacy. Which to me, seems like a net
           | good thing. Again I would prefer it to be more, but better
           | then not doing nothing at all I suppose.
           | 
           | On the other hand, you have one giant company with access to
           | mounds of consumer data purchasing even more sensitive
           | healthcare data without even a blink of the eye.
           | 
           | Why was this not challenged? Why fine one company? I might be
           | overthinking it but it seems like a misalignment of
           | priorities. The point of the FTC is to protect consumers,
           | shouldn't both have been investigated? I guess that was the
           | point I was trying to make. Idk, I feel like I'm just
           | rambling at this point.
        
             | 8ytecoder wrote:
             | (Someone more knowledgeable should correct me if I'm wrong)
             | But my basic understanding of LLCs, subsidiaries ...etc is
             | to create boundaries with parent company - usually to
             | shield the parent company. I really doubt if what you're
             | claiming is true that Amazon has access to one medical
             | data, they'll have any form of protection at all.
             | Hypothetically speaking, one medical did something horrid
             | and so disastrous that they're going to have to pay
             | billions of dollars, Amazon would just wind down that unit
             | and not suffer any major consequences. How would this be
             | allowed if there's no boundary?
             | 
             | Edit: so I looked it up
             | 
             | https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-
             | give...
             | 
             | "As required by law, Amazon will never share One Medical
             | customers' personal health information outside of One
             | Medical for advertising or marketing purposes of other
             | Amazon products and services without clear permission from
             | the customer," an Amazon spokesperson said in an email.
             | "Should the deal close, One Medical customers' HIPAA
             | Protected Health Information will be handled separately
             | from all other Amazon businesses, as required by law."
             | 
             | Basically, like I thought, they can't commingle or share
             | data between the two companies. But if something being
             | clearly illegal isn't enough to convince people (or even
             | the journalist), then that's a different much bigger issue.
             | 
             | Also this:
             | 
             | https://www.investopedia.com/terms/s/subsidiary.asp
             | 
             | A subsidiary is an independent company that is more than
             | 50% owned by another firm--called the parent company or
             | holding company. Subsidiaries are separate and distinct
             | legal entities from their parent companies.
        
             | mfer wrote:
             | > the sentiment still feels like it should be applied
             | 
             | The FTC doesn't operate based on sentiment. Even if the
             | people who work on this have the same feelings they need to
             | operate within laws.
        
           | aj7 wrote:
           | Exactly. People are exercising their rage and frustration
           | over the pharma system, when they should be learning to use
           | GoodRx.
        
         | renewiltord wrote:
         | That's nothing. While the law doesn't allow me (a complete
         | rando) to buy data from United Healthcare, it allows me (a
         | complete rando) to buy shares of AMZN!
        
           | aj7 wrote:
           | Forget about UHC. Buy your drugs over the counter with the
           | help of the GoodRx app. Cheaper than Optum.
        
         | LesZedCB wrote:
         | hey, they made amazon pinky-swear they wouldn't violate HIPAA.
         | 
         | and companies have never reneged immediately after promising
         | not to do bad things.
         | 
         | https://www.cnbc.com/2023/01/25/the-live-nation-and-ticketma...
         | 
         | https://www.nytimes.com/2022/11/18/technology/live-nation-ti...
        
           | adrr wrote:
           | HIPAA is a law with real teeth.
        
             | olliej wrote:
             | yet as we see here those teeth are only applicable to
             | specific classes of businesses - it offers no protection
             | against medical companies selling or leaking your private
             | medical data unless HIPPA applies to the business. There
             | needs to be a law governing the handling of any private
             | medical or health data regardless of business, and that law
             | needs to preclude T&Cs that let a company ignore the law
        
               | mulmen wrote:
               | This is a civil penalty. It opens the door for class
               | action and criminal investigation, both of which can
               | carry much steeper fines.
        
       ___________________________________________________________________
       (page generated 2023-03-08 23:01 UTC)