This is the first issue of a monthly digest. Each issue lists the enforcement actions, rule changes, and court decisions that touched telehealth marketing and patient data in the prior month, with the date, the agency, what happened, who it applies to, and what to check. Every entry links to the primary document.

The reason for a digest is that no single agency is running this. In twelve months the FDA sent 113 warning letters to telehealth companies, the FTC sued the largest one, the federal breach-notification rule changed, a court narrowed HHS's tracking guidance, a state private right of action got its first test, and HHS proposed the first rewrite of the HIPAA Security Rule in twenty years. Each agency reads a different part of the same website, on its own clock. A small telehealth team cannot follow four clocks. One page a month can.

In brief: Between September 2025 and August 2026, telehealth marketing drew 113 FDA warning letters over website claims, an FTC complaint against Hims & Hers over health data shared with advertising platforms, an amended federal breach rule, narrowed HHS tracking guidance, and the first suit under Washington's health-data law. This digest lists each action with what to check.

This first issue covers September 2025 through August 2026, the period in which the pattern formed. Later issues cover one month each and publish in the first week of the following month.

FDA: the claims front

September 9, 2025 · FDA, Office of Compounding Quality and Compliance · 58 warning letters. Sent to telehealth companies selling compounded semaglutide and tirzepatide. The dominant citation was the sameness claim, some version of "the same active ingredient as Ozempic," in 31 of the 58, followed by "clinically proven" in 12. Applies to: any company marketing compounded GLP-1s direct to consumers. Check: every equivalence, generic, or clinical-evidence claim, on every surface. Representative letters: Remedy Meds and Dr. Gater's.

February 20, 2026 · FDA · 30 warning letters. The sameness theory stayed and a second was added. In all 30, the product photos showed a vial carrying the seller's name, which under 21 CFR 201.1 represents the seller as the manufacturer. Applies to: anyone whose product imagery shows a branded vial. Check: every product photo and label mock, on the site and in ads; the label must name the actual compounder. FDA press release, March 3, 2026.

June 8, 2026 · FDA · 25 warning letters. A third theory joined the first two: "FDA-licensed" or "FDA-approved" pharmacy or facility language, in 11 of the 25. The agency licenses neither. Packaging was cited in 21 letters and sameness in 8. Check: every supplier description. "State-licensed 503A pharmacy" and "registered 503B outsourcing facility" are accurate; "FDA-licensed" is not. Representative letters: Eden and OrderlyMeds.

June 15, 2026 · FDA · guidance page for telehealth companies. The agency published what to know when promoting compounded drugs, a plain-language list of the claims it treats as false or misleading. It is the closest thing to a checklist the FDA has issued for this market. Check: your site against the agency's own list.

June 2026 · Congress · appropriations report language. The House committee report on FDA's fiscal 2026 funding directs the agency to refer "egregious cases" of mass marketing of compounded GLP-1s to the Department of Justice and to brief the committee on its strategy within 60 days, per Hyman, Phelps & McNamara's reading of the riders. Report language is not binding. Applies to: companies still carrying flagged claims after a letter. Check: whether your response to a letter is complete and documented, because the next step the committee is asking for is not another letter.

Our full read of all 113 letters, wave by wave, with the compliant version of each flagged claim: The FDA Sent 113 Telehealth Warning Letters. None of Them Were About the Drug.

FTC: the data front

July 29, 2026 · FTC, with Utah and California through Los Angeles County Counsel · complaint against Hims & Hers. The complaint alleges the company shared customers' health information with Meta, Snap, and other platforms in two ways: by uploading customer lists to those platforms, and through tracking tools on its website that automatically reported what visitors did. It also alleges that Hims charged for prescriptions almost immediately after intake despite promising a consultation first, and made cancellation difficult, in violation of the Restore Online Shoppers' Confidence Act. Applies to: any direct-to-consumer telehealth company running ad pixels, custom audiences, or subscription billing. Check: what your pixels and audience uploads send, and from which pages; whether your privacy promises match what the tags do; whether your billing and cancellation match your copy.

Precedent. The theory is three years old. GoodRx, February 1, 2023: a $1.5 million civil penalty, the first case under the Health Breach Notification Rule, for disclosing health information to Facebook, Google, Criteo, Branch, and Twilio without notice. BetterHelp, March 2, 2023: $7.8 million for sending email addresses, IP addresses, and intake-questionnaire answers to Facebook, Snapchat, Criteo, and Pinterest.

Cerebral, April 15, 2024: more than $7 million after sharing the sensitive information of nearly 3.2 million consumers with LinkedIn, Snapchat, and TikTok through tracking tools. Monument, April 11, 2024: an order to stop disclosing health data for advertising, with a $2.5 million penalty suspended only because the company could not pay. And on July 20, 2023 the FTC and HHS wrote jointly to about 130 hospital systems and telehealth providers, naming the Meta Pixel and Google Analytics as the concern.

July 29, 2024 · FTC · amended Health Breach Notification Rule in effect. The rule now covers health apps and websites that HIPAA does not reach, and treats an unauthorized disclosure, not only a hack, as a breach. Notice to affected individuals is due without unreasonable delay and no later than 60 days after discovery; for 500 or more people, notice to the FTC is due at the same time. Applies to: any telehealth company holding health information outside HIPAA's reach, which includes much of the marketing stack. Check: that your incident plan treats a pixel or an audience upload as a reportable event with a clock.

HHS Office for Civil Rights: the HIPAA front

March 18, 2024 · OCR · tracking-technologies guidance updated. June 20, 2024 · a court narrows it. August 29, 2024 · the appeal is withdrawn. OCR's bulletin on online tracking technologies says a tracker that sends identifiable information to a vendor without a business associate agreement is an impermissible disclosure. The Northern District of Texas vacated the part of the bulletin that reached unauthenticated public pages, and OCR withdrew its appeal. Authenticated pages, meaning portals and anything behind a login or inside an intake, remain covered. Applies to: covered entities and their business associates. Check: every tracker on every authenticated page, and a signed BAA with every vendor that receives PHI.

January 6, 2025 · OCR · proposed rewrite of the HIPAA Security Rule. The proposed rule would make multi-factor authentication and encryption mandatory rather than "addressable," require a written inventory of every system that touches ePHI and a map of how it moves, and set a 240-day compliance window after finalization. The comment period closed March 7, 2025 with more than 4,000 comments, and HHS has since moved final action to July 2027 on its long-term agenda. Applies to: every covered entity and business associate, if finalized. Check: whether you could produce the asset inventory and the data map today. The list in the companion article below is a start on the map.

States: the private-right-of-action front

February 10, 2025 · Washington · first lawsuit under the My Health My Data Act. Maxwell v. Amazon is the first class action to use the statute's private right of action, over location and health data collected through software development kits and used for advertising. Applies to: any company collecting consumer health data from Washington residents, whether or not HIPAA applies. Check: separate, affirmative consent for collecting and for sharing consumer health data, and a health-data privacy policy that lists every category you collect.

Nevada and Connecticut. Nevada SB 370, in effect since March 31, 2024, requires affirmative consent to collect and a separate consent to share consumer health data, and written authorization to sell it. Connecticut's consumer health data provisions, in effect since July 1, 2023, add consent, contracting, and geofencing requirements. Neither carries Washington's private right of action; both are enforced by the state attorney general. Check: one consent flow that satisfies the strictest of the three, applied to every patient, rather than a state-by-state branch that has to be kept current.

What to check this quarter

  1. Every equivalence, "clinically proven," and "FDA-licensed" claim, on every surface, mapped to evidence you hold or removed.
  2. Every product photo and label mock: the label names the actual compounder.
  3. Every pixel, tag, and custom-audience upload: what it sends and from which pages, with nothing on an intake or condition page unless a BAA covers the path.
  4. Your billing disclosure and cancellation flow, read against your own marketing copy.
  5. Your incident plan, retention rule, and data map: a pixel disclosure is a breach with a 60-day clock, abandoned intakes are purged on a schedule, and you can draw where patient data goes.

Where patient data actually sits in a telehealth company, and how to check each place: Where PHI Actually Leaks in a Telehealth Company. It Is Not the EHR.

How this digest works

Sources are the FDA warning-letter database and newsroom, FTC press releases and complaints, the HHS Office for Civil Rights, state attorney general releases, court opinions, and the client alerts that regulatory law firms publish, which we read and link rather than paraphrase. Collection is automated. The reading and the selection are not, and one person signs each issue. Each entry links to the primary document so you can read the source instead of our summary. We report what happened and what to check. What it means for your company is a question for your counsel.

This article reports public enforcement actions from the primary documents linked below, and is current as of the date above. Matters described as complaints or proposed actions are allegations that have not been decided, and a settlement is not an admission of liability. Agencies and courts change positions, and we do not revise articles as matters progress. This is general information, not legal advice, and reading it does not create an attorney-client relationship. Igility is not a law firm. Do not act on this, or decide not to act, without advice for your own situation. What your company concedes, defends, or discloses is a decision for your regulatory counsel, on your facts and in the states where you operate. We build the systems that make the next letter less likely.


References