Compare with different regulatory event:

Description

FTC Ruling against GoodRx Holdings Inc. for Violating Health Breach Notification Rule

On 1 February 2023, the Federal Trade Commission (FTC) issued a complaint and stipulated final order against telehealth and prescription drug business GoodRx Holdings Inc. for failing to notify consumers about unauthorised disclosure of consumer personal health information to companies like Facebook and Google for advertising purposes. It is the FTC's first enforcement action under its Health Breach Notification Rule. According to the stipulated order, subject to approval by a federal court, GoodRx will be issued with a USD 1'500'000 civil penalty for violating the rule. The order will also permanently prohibit GoodRx from sharing health information for advertising purposes, while requiring consent for any other form of sharing. Further, GoodRx will also be required to ask third parties to delete health information, inform consumers about the breach and the FTC enforcement action, and put into place a privacy program and data retention schedule.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
other service provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-02-01
in force

On 1 February 2023, the Federal Trade Commission (FTC) issued a complaint and stipulated final orde…