[HN Gopher] FTC bars GoodRx from sharing consumers' sensitive he...
___________________________________________________________________
FTC bars GoodRx from sharing consumers' sensitive health info for
advertising
Author : vector_spaces
Score : 168 points
Date : 2023-03-08 17:35 UTC (5 hours ago)
(HTM) web link (www.ftc.gov)
(TXT) w3m dump (www.ftc.gov)
| aj7 wrote:
| Let me tell you, having saved $thousands from GoodRx's exposure
| of pharma's underbelly, and the actual first-time competition
| that it fosters, I can forgive them for this underhand revenue
| stream.
|
| Just yesterday $60.25, Walgreen's, returned --> $7.20, Safeway,
| GoodRx e-coupon.
|
| My wife is finally a believer, and it paid for more than half of
| a $100 birthday gift for a poor cousin 1500mi away.
| jeffbee wrote:
| """GoodRx created Custom Events with names like "Drug Name" and
| "Drug Category" that tracked and shared the prescription
| medication name and health condition(s) associated with each
| unique GoodRx Coupon that users accessed. As a result, at times,
| when GoodRx shared a Custom Event, it was sharing its users'
| health information."""
|
| Seems kinda dumb! I for one would probably not have written that
| code.
| rqtwteye wrote:
| A site like GoodRx should be run as a non profit that's
| completely independent from advertisers. Once they start to rely
| on advertisers they will go down the same corrupt path like most
| other players in US health care.
| haliskerbas wrote:
| _deleted_
| [deleted]
| bretpiatt wrote:
| Mark started Cost Plus Drugs
| https://costplusdrugs.com/medications/
| singhrac wrote:
| That's the Mark Cuban Cost Plus Drugs company. This is a
| competitor. Here's a good overview of their business model:
| https://d3.harvard.edu/platform-digit/submission/goodrx-or-g...
| aj7 wrote:
| Hasn't made a dent yet. In fact, started out just trying to
| acquire data.
| mulmen wrote:
| Can someone explain to me how big of a deal this "first of a
| kind" collaboration between the DOJ and FTC actually is? Who set
| the penalty here? Is the door still open to further criminal
| investigation? What does this mean for a potential class action?
|
| The biggest takeaway here seems to be the ban on sharing data,
| not on the fine itself. I interpret that to mean sharing the data
| for advertising purposes _is_ legal, maybe with consent from the
| customer? But now GoodRx can 't do that?
| mc32 wrote:
| Absolutely right call. How can any company officer actually
| believe this was an acceptable business practice. Being in that
| business they must have heard of HIPAA and regulation around PHI.
| What would keep hospitals from selling patient info?
| SkyPuncher wrote:
| Only covered entities are bound by HIPAA:
| https://www.hhs.gov/hipaa/for-professionals/covered-entities...
|
| Notably:
|
| > [a bunch of providers] ...but only if they transmit any
| information in an electronic form in connection with a
| transaction for which HHS has adopted a standard.
|
| If you don't process a specific type of transaction, no HIPAA
| requirements.
| ThaDood wrote:
| Also if a CE enters into a BA with some company, AFAIK, data
| sharing can basically occurs without issue and still
| maintaining compliance since patient consent to data sharing
| occurs with the CEs.
| lp0_on_fire wrote:
| > How can any company officer actually believe this was an
| acceptable business practice.
|
| Because the penalty is small enough that it's a "cost of doing
| business". Until these fines are large enough to cause hardship
| to the company, or we start piercing the corporate veil and go
| after executives in their personal capacity this is going to
| keep happening.
|
| I simply do not believe there is a good-faith argument that
| GoodRX wasn't familiar with the law in this case.
| godelski wrote:
| $1.5 million? What a joke. That's a tax, not a penalty.
|
| I don't think many are surprised that GoodRX was sharing data
| (violating its own privacy policy) but come on, have some teeth.
| You'd think with HIPPA that we'd treat anything medical more
| seriously.
| lmkg wrote:
| The thing is, HIPAA doesn't apply here. HIPAA doesn't actually
| cover "anything medical." It only covers (approximately) things
| involved in getting insurance to pay for medical treatment.
| GoodRx did not touch the consumer's insurance, so they
| "complied" with HIPAA by not being a covered entity in the
| first place.
|
| At the Federal level, the only broad general protections for
| medical data are (apparently) some FTC fine print. The fact
| that this exists _at all_ means that medical data is treated
| more seriously than other forms of personal data, but as you
| can see that is a very low bar to clear (literally doesn 't
| exist).
| jollofricepeas wrote:
| Not exactly.
|
| This is inaccurate in part.
|
| HIPAA governs covered entities and business associates (BA)
| who work on behalf of a CE. Covered Entities are healthcare
| providers or insurance companies. CEs are required to have
| their BAs sign business associate agreement where they're
| regulated under HIPAA.
|
| GoodRx convinced patients to provide them their health
| information directly. Unless, they've signed a BAA with a CE,
| the FTC is the only government body with regulatory power
| here however I would imagine there's a legal firm prepping a
| class action against GoodRx right now as well.
|
| The class action is what will be expensive for them. The fact
| that they have been fined is what should make the action
| hopefully a slam dunk.
|
| Sources:
|
| - https://www.hhs.gov/hipaa/for-professionals/privacy/laws-
| reg...
|
| - https://www.hhs.gov/hipaa/for-professionals/security/laws-
| re...
| SkyPuncher wrote:
| You've missed a part. For providers, they must be HIPAA
| compliant "only if they transmit any information in an
| electronic form in connection with a transaction for which
| HHS has adopted a standard."
|
| It seems unlikely that GoodRx was processing data that met
| that standard.
|
| https://www.hhs.gov/hipaa/for-professionals/covered-
| entities...
| jollofricepeas wrote:
| Actually, they were...
|
| There's no wiggle room here unless the data has been de-
| identified (a high barrier). It wasn't.
|
| The standard you're refering to is for e-PHI which is
| "individually identifiable health information."
|
| You'll want to see the Privacy Rule for details but
| GoodRx shared email addresses, phone numbers and mobile
| identifiers according to the FTC complaint.
|
| https://www.ftc.gov/system/files/ftc_gov/pdf/goodrx_compl
| ain...
| SkyPuncher wrote:
| The complaint pretty clearly states the FTC does not view
| them as a covered entity. There are several statements,
| but the most clear is near the end of page 23:
|
| > In truth and in fact, GoodRx is not a HIPAA-covered
| entity, and its privacy and information practices did not
| comply with HIPAA's requirements.
|
| Further, on page 25, they define them as a "vendor of
| personal health records" - which explicitly excludes
| covered entities (definition on page 19).
|
| -----
|
| This is consistent with my understanding of a covered
| entity. Without the "transactions for which HHS has
| adopted a standard", GoodRx is not a covered entity.
|
| Further, even if they were a covered entity, it's
| possible for them to segment their HIPAA and non-HIPAA
| compliant business units. This is called a "hybrid
| entity".
|
| ----
|
| Interestingly, the FTC is pinging them on for a
| misleading representation of being a covered entity.
| Since GoodRX was not a covered entity, they were not
| technically violating HIPAA.
| jollofricepeas wrote:
| A clarification...
|
| I'm not saying that they are a CE only that if they were
| then the data is clearly PHI and had not been de-
| identified per the standard that you referenced
| previously.
| mrguyorama wrote:
| Since when has a class action lawsuit EVER cost a company a
| real amount of money?
| jollofricepeas wrote:
| The class action for the WellPoint (Anthem) breach was
| $115 million.
|
| That smells like real money to me.
|
| The total cost for the biggest healthcare breach was
| around $500 million give or take.
| [deleted]
| throw93 wrote:
| I want FTC to put fear of god in bad actors like GoodRx. $1.5
| million is pocket change for a company with $765 million annual
| revenue. They've spent $400k just on lobbying. This isn't gonna
| change anything.
| aj7 wrote:
| You have no concept as to how much of a GOOD actor GoodRx is. I
| agree, they f*cked up here, and deserved to be punished.
| mulmen wrote:
| > I want FTC to put fear of god in bad actors like GoodRx.
|
| I'm not sure I do. The FTC does civil enforcement and
| investigation. They identify misbehavior and issue the
| equivalent of parking tickets. If you also give them the
| ability to issue punishments then what prevents the FTC from
| using that power to line their own pockets by sabotaging (or
| threaten to sabotage) well behaved companies?
|
| This penalty may not preclude lawsuits by GoodRx customers or
| further investigations by other organizations leading to
| criminal penalties.
|
| I'm not a lawyer so I could be totally off base here but this
| is my understanding after dozens of these HN threads with
| similar comments.
|
| > $1.5 million is pocket change for a company with $765 million
| annual revenue.
|
| Is it? GoodRx hasn't turned a profit since 2019. They lost
| $32.8 million on $766.5 million in revenue in 2022.
| throw93 wrote:
| FTC was created to protect consumers though "strong and
| effective law enforcement"(their mission statement). This FTC
| action is not "strong" enough, it's just a slap on the wrist.
|
| > If you also give them the ability to issue punishments then
| what prevents them from using that power to sabotage (or
| threaten to sabotage) well behaved companies to line their
| own pockets?
|
| "Own pockets" - FTC is not a for profit company. GoodRx is a
| for profit company. Companies have more to gain by acting in
| bad faith than FTC. So I would trust FTC any given day over a
| for profit company.
|
| > GoodRx hasn't turned a profit since 2019
|
| This doesn't necessarily mean company is in bad shape. This
| happens when company is investing in growth at the cost of
| profit margins during it's initial years. If they can shell
| out half million dollars on lobbying then $1.5 million is
| indeed a pocket change for them.
| mulmen wrote:
| Sure but this FTC action has opened the door for class
| action and criminal investigation. So does the FTC penalty
| actually need to be steeper? It's an honest question, how
| should that value be set?
| shakna wrote:
| There are countries where fines for speeding or parking are
| proportional to the offender's income. So that it leaves a
| message, and actually discourages future choices.
|
| Proportionality, also means that if you have less to give,
| you give less.
| inetknght wrote:
| > _then what prevents them from using that power to sabotage
| (or threaten to sabotage) well behaved companies to line
| their own pockets?_
|
| Well-behaved companies won't line their own pockets out of
| fear that the FTC will sue them out of existence.
| mulmen wrote:
| The FTC would be doing the pocket lining here.
|
| I edited that sentence to try and clarify.
| [deleted]
| thfuran wrote:
| But is there anything precluding them from re-issuing those
| parking tickets every day until the problem goes away?
| mulmen wrote:
| Well GoodRx would have to re-offend for that to work.
| 988747 wrote:
| But if they don't re-offend that means that this "parking
| ticket" actually worked, right? The goal is to make the
| company follow the law, not push it to bankruptcy as a
| revenge.
| alistairSH wrote:
| The problem is the "small" fine might dissuade GoodRx
| from re-offending in the short term.
|
| But, it probably isn't enough to prevent other bad
| actors. Or from GoodRx re-offending in a few years, once
| the CEO/BoD/etc have rotated on to other pursuits.
| rchaud wrote:
| > GoodRx displayed a seal at the bottom of its telehealth
| services homepage falsely suggesting to consumers that it
| complied with the Health Insurance Portability and Accountability
| Act of 1996 (HIPAA),
|
| $900m in funding[0] and their business practices are straight out
| of a fly-by-night MLM brand.
|
| [0] https://www.crunchbase.com/organization/goodrx
| SkyPuncher wrote:
| There's such thing as a hybrid-entity. I had looked into it for
| a prior HealthTech company.
|
| Essentially, they can remain "HIPAA compliant" by segmenting
| their HIPAA and non-HIPAA business units.
| rchaud wrote:
| If this were true, I imagine they would have brought this up
| before the FTC fined them. Just went on their site now, no
| mention of this hybrid entity structure.
| SkyPuncher wrote:
| It looks like the FTC is actually alleging that they
| misrepresented their status as a HIPAA covered entity.
| aj7 wrote:
| Utter nonsense. I've saved thousands with them. I used to have
| to keep Excel spreadsheets for prescription prices. And that's
| AFTER I realized that pharma benefits (including yours) and
| Medicare Part D were utter bullshit (I'm NOT kidding. Words
| chosen carefully.), and the trick was to buy drugs, over-the-
| counter, for cash, on the open market. (Imagine that being "a
| trick." Imagine my surprise when my prescription OTC in cash
| was cheaper than Optum-UHC's pharmacy "benefit.")
|
| GoodRx makes the entire process a few iPhone clicks.
| olliej wrote:
| They complied by afaict not being a covered entity. You could
| make a site that lets people log their health issues, but allow
| _anyone_ to access that data and not be violating HIPPA.
|
| HIPPA is not a medical privacy bill.
| alistairSH wrote:
| But, apparently, they claimed there were compliant. So,
| fraud, or at least super-sketchy.
| mulmen wrote:
| HIPPA doesn't exist. HIPPA is a mistaken acronym that adds
| the p-for-privacy.
|
| HIPAA (Health Insurance Portability and Accountability Act) -
| a real 1996 law.
|
| HIPPA (Health Information Privacy and Portability Act) - not
| a thing.
| zacharyvoase wrote:
| Does this preclude their users from suing them for violating the
| privacy policy (and other laws)?
| olliej wrote:
| what privacy policy? I'm guessing any agreement included the
| standard "we may share your data with our partners" text. There
| aren't any laws stopping them sharing medical data.
| lmkg wrote:
| The linked article explicitly states that part of the fine is
| because the data sharing violates GoodRx's own privacy
| policy.
| ctvo wrote:
| Unsure why there aren't percentage based fines in the US. Strong
| lobbying preventing legislation with teeth from passing?
|
| We know they're a publicly traded company, we know their revenue,
| profit, etc. -- why not fine them a percent based on this data?
| It's a little more tricky with private companies, but a
| certification process, and a undisclosed fine in those cases work
| too.
| adamrezich wrote:
| > Unsure why there aren't percentage based fines in the US.
| Strong lobbying preventing legislation with teeth from passing?
|
| that is the basic gist. our federal government doesn't do much
| of anything for the people it represents, compared to what it
| does for corporations, lobbyists, and career politicians.
| ThaDood wrote:
| Doesn't allow data sharing from GoodRX to FB, Google etc. But
| does allow Amazon to purchase One Medical. I feel like both are
| pretty bad. But I am trying to understand the logic between
| allowing one and not the other? Am I missing something?
|
| Also $1.5 million, in relative terms, seems pretty small. So
| again, data violations just seem to be the cost of doing
| business.
| mfer wrote:
| Do you realize that you are talking about two very different
| situations.
|
| In one situation you have a company sharing data with other
| companies and the laws around that form of data sharing.
|
| In the other situation you have what companies can own or buy
| in terms of other companies.
|
| The situations are very different.
| ThaDood wrote:
| I might not be articulating my point super well since this is
| HN and I hate typing long drawout thoughts on boards. That
| being said I understand the situations are different but to
| me, the sentiment still feels like it should be applied?
|
| On one hand you have the FTC fining a company for violations
| of data sharing, which I am assuming of the one of the
| concerns is patient privacy. Which to me, seems like a net
| good thing. Again I would prefer it to be more, but better
| then not doing nothing at all I suppose.
|
| On the other hand, you have one giant company with access to
| mounds of consumer data purchasing even more sensitive
| healthcare data without even a blink of the eye.
|
| Why was this not challenged? Why fine one company? I might be
| overthinking it but it seems like a misalignment of
| priorities. The point of the FTC is to protect consumers,
| shouldn't both have been investigated? I guess that was the
| point I was trying to make. Idk, I feel like I'm just
| rambling at this point.
| 8ytecoder wrote:
| (Someone more knowledgeable should correct me if I'm wrong)
| But my basic understanding of LLCs, subsidiaries ...etc is
| to create boundaries with parent company - usually to
| shield the parent company. I really doubt if what you're
| claiming is true that Amazon has access to one medical
| data, they'll have any form of protection at all.
| Hypothetically speaking, one medical did something horrid
| and so disastrous that they're going to have to pay
| billions of dollars, Amazon would just wind down that unit
| and not suffer any major consequences. How would this be
| allowed if there's no boundary?
|
| Edit: so I looked it up
|
| https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-
| give...
|
| "As required by law, Amazon will never share One Medical
| customers' personal health information outside of One
| Medical for advertising or marketing purposes of other
| Amazon products and services without clear permission from
| the customer," an Amazon spokesperson said in an email.
| "Should the deal close, One Medical customers' HIPAA
| Protected Health Information will be handled separately
| from all other Amazon businesses, as required by law."
|
| Basically, like I thought, they can't commingle or share
| data between the two companies. But if something being
| clearly illegal isn't enough to convince people (or even
| the journalist), then that's a different much bigger issue.
|
| Also this:
|
| https://www.investopedia.com/terms/s/subsidiary.asp
|
| A subsidiary is an independent company that is more than
| 50% owned by another firm--called the parent company or
| holding company. Subsidiaries are separate and distinct
| legal entities from their parent companies.
| mfer wrote:
| > the sentiment still feels like it should be applied
|
| The FTC doesn't operate based on sentiment. Even if the
| people who work on this have the same feelings they need to
| operate within laws.
| aj7 wrote:
| Exactly. People are exercising their rage and frustration
| over the pharma system, when they should be learning to use
| GoodRx.
| renewiltord wrote:
| That's nothing. While the law doesn't allow me (a complete
| rando) to buy data from United Healthcare, it allows me (a
| complete rando) to buy shares of AMZN!
| aj7 wrote:
| Forget about UHC. Buy your drugs over the counter with the
| help of the GoodRx app. Cheaper than Optum.
| LesZedCB wrote:
| hey, they made amazon pinky-swear they wouldn't violate HIPAA.
|
| and companies have never reneged immediately after promising
| not to do bad things.
|
| https://www.cnbc.com/2023/01/25/the-live-nation-and-ticketma...
|
| https://www.nytimes.com/2022/11/18/technology/live-nation-ti...
| adrr wrote:
| HIPAA is a law with real teeth.
| olliej wrote:
| yet as we see here those teeth are only applicable to
| specific classes of businesses - it offers no protection
| against medical companies selling or leaking your private
| medical data unless HIPPA applies to the business. There
| needs to be a law governing the handling of any private
| medical or health data regardless of business, and that law
| needs to preclude T&Cs that let a company ignore the law
| mulmen wrote:
| This is a civil penalty. It opens the door for class
| action and criminal investigation, both of which can
| carry much steeper fines.
___________________________________________________________________
(page generated 2023-03-08 23:01 UTC)