10 ms·
FTC bars GoodRx from sharing consumers’ sensitive health info for advertising
- ThaDood 4y agoDoesn't allow data sharing from GoodRX to FB, Google etc. But does allow Amazon to purchase One Medical. I feel like both are pretty bad. But I am trying to understand the logic between allowing one and not the other? Am I missing something? Also $1.5 million, in relative terms, seems pretty small. So again, data violations just seem to be the cost of doing business.
- mfer 4y agoDo you realize that you are talking about two very different situations. In one situation you have a company sharing data with other companies and the laws around that form of data sharing. In the other situation you have what companies can own or buy in terms of other companies. The situations are very different.
- ThaDood 4y agoI might not be articulating my point super well since this is HN and I hate typing long drawout thoughts on boards. That being said I understand the situations are different but to me, the sentiment still feels like it should be applied? On one hand you have the FTC fining a company for violations of data sharing, which I am assuming of the one of the concerns is patient privacy. Which to me, seems like a net good thing. Again I would prefer it to be more, but better then not doing nothing at all I suppose. On the other hand, you have one giant company with access to mounds of consumer data purchasing even more sensitive healthcare data without even a blink of the eye. Why was this not challenged? Why fine one company? I might be overthinking it but it seems like a misalignment of priorities. The point of the FTC is to protect consumers, shouldn't both have been investigated? I guess that was the point I was trying to make. Idk, I feel like I'm just rambling at this point.
- 8ytecoder 4y ago(Someone more knowledgeable should correct me if I’m wrong) But my basic understanding of LLCs, subsidiaries …etc is to create boundaries with parent company - usually to shield the parent company. I really doubt if what you’re claiming is true that Amazon has access to one medical data, they’ll have any form of protection at all. Hypothetically speaking, one medical did something horrid and so disastrous that they’re going to have to pay billions of dollars, Amazon would just wind down that unit and not suffer any major consequences. How would this be allowed if there’s no boundary? Edit: so I looked it up https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-gives-it-access-to-my-most-personal-info.html https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-give... “As required by law, Amazon will never share One Medical customers’ personal health information outside of One Medical for advertising or marketing purposes of other Amazon products and services without clear permission from the customer,” an Amazon spokesperson said in an email. “Should the deal close, One Medical customers’ HIPAA Protected Health Information will be handled separately from all other Amazon businesses, as required by law.” Basically, like I thought, they can’t commingle or share data between the two companies. But if something being clearly illegal isn’t enough to convince people (or even the journalist), then that’s a different much bigger issue. Also this: https://www.investopedia.com/terms/s/subsidiary.asp https://www.investopedia.com/terms/s/subsidiary.asp A subsidiary is an independent company that is more than 50% owned by another firm—called the parent company or holding company. Subsidiaries are separate and distinct legal entities from their parent companies.
- ThePowerOfFuet 4y ago> Edit: so I looked it up > https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-gives-it-access-to-my-most-personal-info.html https://www.cnbc.com/2022/07/23/amazon-one-medical-deal-give... > > “As required by law, Amazon will never share One Medical customers’ personal health information outside of One Medical for advertising or marketing purposes of other Amazon products and services without clear permission from the customer,” an Amazon spokesperson said in an email. “Should the deal close, One Medical customers’ HIPAA Protected Health Information will be handled separately from all other Amazon businesses, as required by law.” > Basically, like I thought, they can’t commingle or share data between the two companies. Unfortunately, that's not at all what it says. Amazon has included so many qualifiers that they are disclaiming only a very specific subset of data transfer. I invite you to read it again, word by word and clause by clause.
- aj7 4y agoExactly. People are exercising their rage and frustration over the pharma system, when they should be learning to use GoodRx.
- LesZedCB 4y agohey, they made amazon pinky-swear they wouldn't violate HIPAA. and companies have never reneged immediately after promising not to do bad things. https://www.cnbc.com/2023/01/25/the-live-nation-and-ticketmaster-monopoly-of-live-entertainment.html https://www.cnbc.com/2023/01/25/the-live-nation-and-ticketma... https://www.nytimes.com/2022/11/18/technology/live-nation-ticketmaster-investigation-taylor-swift.html https://www.nytimes.com/2022/11/18/technology/live-nation-ti...
- adrr 4y agoHIPAA is a law with real teeth.
- olliej 4y agoyet as we see here those teeth are only applicable to specific classes of businesses - it offers no protection against medical companies selling or leaking your private medical data unless HIPPA applies to the business. There needs to be a law governing the handling of any private medical or health data regardless of business, and that law needs to preclude T&Cs that let a company ignore the law
- mulmen 4y agoThis is a civil penalty. It opens the door for class action and criminal investigation, both of which can carry much steeper fines.
- renewiltord 4y agoThat's nothing. While the law doesn't allow me (a complete rando) to buy data from United Healthcare, it allows me (a complete rando) to buy shares of AMZN!
- aj7 4y agoForget about UHC. Buy your drugs over the counter with the help of the GoodRx app. Cheaper than Optum.
- pyuser583 4y agoFB and Google are marketing companies. Amazon is a retailer. Nothing odd about retailers acquiring other retailers.
- hedora 4y agoYou’re not missing anything. It’s basically illegal for public companies to hold data without offering it for sale. (Have enough money to buy 51% of Google? You can buy all their data!) This could sort of thing could be prevented by Terms of Service agreements, but in practice, companies always reserve the right to change their ToS in the future, and almost always have vague carve outs for internal use of customer data. There’s a similar problem for any private companies that have outstanding debt or payment obligations. If they default or go bankrupt, then the courts will force them to sell user data to help generate the missing cash. This will override any user agreements, since the creditors are generally first in line when a company goes under. The only difference between One Medical and GoodRX here is that One Medical only sold account data to one advertising firm (that I know of).
- mc32 4y agoAbsolutely right call. How can any company officer actually believe this was an acceptable business practice. Being in that business they must have heard of HIPAA and regulation around PHI. What would keep hospitals from selling patient info?
- lp0_on_fire 4y ago> How can any company officer actually believe this was an acceptable business practice. Because the penalty is small enough that it's a "cost of doing business". Until these fines are large enough to cause hardship to the company, or we start piercing the corporate veil and go after executives in their personal capacity this is going to keep happening. I simply do not believe there is a good-faith argument that GoodRX wasn't familiar with the law in this case.
- SkyPuncher 4y agoOnly covered entities are bound by HIPAA: https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html https://www.hhs.gov/hipaa/for-professionals/covered-entities... Notably: > [a bunch of providers] ...but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard. If you don't process a specific type of transaction, no HIPAA requirements.
- ThaDood 4y agoAlso if a CE enters into a BA with some company, AFAIK, data sharing can basically occurs without issue and still maintaining compliance since patient consent to data sharing occurs with the CEs.
- godelski 4y ago$1.5 million? What a joke. That's a tax, not a penalty. I don't think many are surprised that GoodRX was sharing data (violating its own privacy policy) but come on, have some teeth. You'd think with HIPPA that we'd treat anything medical more seriously.
- lmkg 4y agoThe thing is, HIPAA doesn't apply here. HIPAA doesn't actually cover "anything medical." It only covers (approximately) things involved in getting insurance to pay for medical treatment. GoodRx did not touch the consumer's insurance, so they "complied" with HIPAA by not being a covered entity in the first place. At the Federal level, the only broad general protections for medical data are (apparently) some FTC fine print. The fact that this exists at all means that medical data is treated more seriously than other forms of personal data, but as you can see that is a very low bar to clear (literally doesn't exist).
- jollofricepeas 4y agoNot exactly. This is inaccurate in part. HIPAA governs covered entities and business associates (BA) who work on behalf of a CE. Covered Entities are healthcare providers or insurance companies. CEs are required to have their BAs sign business associate agreement where they’re regulated under HIPAA. GoodRx convinced patients to provide them their health information directly. Unless, they’ve signed a BAA with a CE, the FTC is the only government body with regulatory power here however I would imagine there’s a legal firm prepping a class action against GoodRx right now as well. The class action is what will be expensive for them. The fact that they have been fined is what should make the action hopefully a slam dunk. Sources: - https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg... - https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html https://www.hhs.gov/hipaa/for-professionals/security/laws-re...
- mrguyorama 4y agoSince when has a class action lawsuit EVER cost a company a real amount of money?
- throw93 4y agoI want FTC to put fear of god in bad actors like GoodRx. $1.5 million is pocket change for a company with $765 million annual revenue. They've spent $400k just on lobbying. This isn't gonna change anything.
- mulmen 4y ago> I want FTC to put fear of god in bad actors like GoodRx. I’m not sure I do. The FTC does civil enforcement and investigation. They identify misbehavior and issue the equivalent of parking tickets. If you also give them the ability to issue punishments then what prevents the FTC from using that power to line their own pockets by sabotaging (or threaten to sabotage) well behaved companies? This penalty may not preclude lawsuits by GoodRx customers or further investigations by other organizations leading to criminal penalties. I’m not a lawyer so I could be totally off base here but this is my understanding after dozens of these HN threads with similar comments. > $1.5 million is pocket change for a company with $765 million annual revenue. Is it? GoodRx hasn’t turned a profit since 2019. They lost $32.8 million on $766.5 million in revenue in 2022.
- thfuran 4y agoBut is there anything precluding them from re-issuing those parking tickets every day until the problem goes away?
- zacharyvoase 4y agoDoes this preclude their users from suing them for violating the privacy policy (and other laws)?
- olliej 4y agowhat privacy policy? I'm guessing any agreement included the standard "we may share your data with our partners" text. There aren't any laws stopping them sharing medical data.
- lmkg 4y agoThe linked article explicitly states that part of the fine is because the data sharing violates GoodRx's own privacy policy.
- ctvo 4y agoUnsure why there aren't percentage based fines in the US. Strong lobbying preventing legislation with teeth from passing? We know they're a publicly traded company, we know their revenue, profit, etc. -- why not fine them a percent based on this data? It's a little more tricky with private companies, but a certification process, and a undisclosed fine in those cases work too.
- adamrezich 4y ago> Unsure why there aren't percentage based fines in the US. Strong lobbying preventing legislation with teeth from passing? that is the basic gist. our federal government doesn't do much of anything for the people it represents, compared to what it does for corporations, lobbyists, and career politicians.
- jeffbee 4y ago"""GoodRx created Custom Events with names like “Drug Name” and “Drug Category” that tracked and shared the prescription medication name and health condition(s) associated with each unique GoodRx Coupon that users accessed. As a result, at times, when GoodRx shared a Custom Event, it was sharing its users’ health information.""" Seems kinda dumb! I for one would probably not have written that code.
- haliskerbas 4y ago[flagged]
- bretpiatt 4y agoMark started Cost Plus Drugs https://costplusdrugs.com/medications/ https://costplusdrugs.com/medications/
- deleted 4y ago[deleted]
- singhrac 4y agoThat’s the Mark Cuban Cost Plus Drugs company. This is a competitor. Here’s a good overview of their business model: https://d3.harvard.edu/platform-digit/submission/goodrx-or-greatrx/ https://d3.harvard.edu/platform-digit/submission/goodrx-or-g...
- aj7 4y agoHasn’t made a dent yet. In fact, started out just trying to acquire data.
- rchaud 4y ago> GoodRx displayed a seal at the bottom of its telehealth services homepage falsely suggesting to consumers that it complied with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), $900m in funding[0] and their business practices are straight out of a fly-by-night MLM brand. [0] https://www.crunchbase.com/organization/goodrx https://www.crunchbase.com/organization/goodrx
- olliej 4y agoThey complied by afaict not being a covered entity. You could make a site that lets people log their health issues, but allow _anyone_ to access that data and not be violating HIPPA. HIPPA is not a medical privacy bill.
- mulmen 4y agoHIPPA doesn’t exist. HIPPA is a mistaken acronym that adds the p-for-privacy. HIPAA (Health Insurance Portability and Accountability Act) - a real 1996 law. HIPPA (Health Information Privacy and Portability Act) - not a thing.
- alistairSH 4y agoBut, apparently, they claimed there were compliant. So, fraud, or at least super-sketchy.
- SkyPuncher 4y agoThere's such thing as a hybrid-entity. I had looked into it for a prior HealthTech company. Essentially, they can remain "HIPAA compliant" by segmenting their HIPAA and non-HIPAA business units.
- rchaud 4y agoIf this were true, I imagine they would have brought this up before the FTC fined them. Just went on their site now, no mention of this hybrid entity structure.
- rqtwteye 4y agoA site like GoodRx should be run as a non profit that’s completely independent from advertisers. Once they start to rely on advertisers they will go down the same corrupt path like most other players in US health care.
- aj7 4y agoLet me tell you, having saved $thousands from GoodRx’s exposure of pharma’s underbelly, and the actual first-time competition that it fosters, I can forgive them for this underhand revenue stream. Just yesterday $60.25, Walgreen’s, returned —> $7.20, Safeway, GoodRx e-coupon. My wife is finally a believer, and it paid for more than half of a $100 birthday gift for a poor cousin 1500mi away.
- JohnFen 4y ago> I can forgive them for this underhand revenue stream. I can't. It doesn't matter if they give drugs away for free, GoodRx is a bad actor. Exactly the sort of company that needs to lose all their customers.
- aj7 4y agoBought for retail. GoodRx had nothing to do with the transaction, except to enforce a market mechanism on it. Yes, GoodRx was a bad actor in its misuse of medical data. Absolutely. Unless that practice underlies its business model, which I doubt, GoodRx is, on balance, a GOOD actor. It seems that the business model is sales lead generation, and they have been able to force it’s use by major pharmacies over time.
- JohnFen 4y ago> GoodRx is, on balance, a GOOD actor. I suspect that this is a point that we will never agree on.
- aj7 4y agoLearn what GoodRx is, what it does, how it works. You may be so young, you don’t take pills. So ask a relative 60+, “What did you pay for Y Rx?” Then, see if you can beat it w GoodRx.
- mulmen 4y agoCan someone explain to me how big of a deal this "first of a kind" collaboration between the DOJ and FTC actually is? Who set the penalty here? Is the door still open to further criminal investigation? What does this mean for a potential class action? The biggest takeaway here seems to be the ban on sharing data, not on the fine itself. I interpret that to mean sharing the data for advertising purposes is legal, maybe with consent from the customer? But now GoodRx can't do that?
- jxramos 4y agoI've been suspicious of FSA accounts that want all the itemized receipts when you submit a reimbursement claim. Somehow they've become the validators for the spend you make rather than just the money shuffling body they used to be in years past. I never understood how this came to be, but I later became suspect when receipts and other bits of the paper trail had to first pass through their hands rather than the previous arrangement where you were responsible for keeping those records on hand should you ever be audited by the IRS. They changed the UI pattern for reimbursement to force receipt uploads, and non itemized receipts got rejected. I wonder if they too use this information for like purposes as GoodRx.