Telehealth Security And Privacy Lawsuit

Your health is personal. If hidden telehealth tracking broke your trust, we’re here to help.

Legally Reviewed By
Legally Reviewed By
This is some text inside of a div block.
Legally Reviewed By
This is some text inside of a div block.
Legally Reviewed By
This is some text inside of a div block.
Legally Reviewed By
This is some text inside of a div block.

Request A Free Consultation

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
A patient meets with his doctor over the computer. He may have grounds for a telehealth data security lawsuit.

In the ever-evolving realm of healthcare technology, telehealth has emerged as a revolutionary means of delivering medical care. While its benefits are undeniable, the surge in telehealth utilization has brought about a pressing concern – the risk of privacy violations. 

American Association for Justice Badge

When you seek medical treatment from home, you trust that your health information stays between you and your provider. Unfortunately, major online therapy networks and healthcare platforms have secretly embedded ad-tracking trackers directly into their intake pages. Instead of keeping your intimate medical history private, these platforms have leaked sensitive details to massive social media companies and third-party advertisers.

When large corporations trade your personal records for ad revenue, they cross a legal line. The Lyon Firm believes you deserve answers and fair accountability when a company misuses your private records. If you suspect your digital health history was leaked without your permission, call our team today at (513) 381-2333 or fill out our online form. We are happy to provide you with a free case evaluation and help you begin the legal process.

“I’m incredibly grateful to Joseph Lyon and The Lyon Firm. From the start, Joseph was honest, clear, and always professional. He kept me informed and made sure I understood every step. I felt supported and knew I was in good hands. His dedication and care truly made a difference. I couldn’t have asked for better representation.”

- Issa D. | Client

What Damages Are Available in a Telehealth Lawsuit?

The privacy risks of telehealth medicine should be taken seriously. In a telehealth lawsuit, the damages that may be available can vary depending on the specific circumstances of the case.

  • Additional healthcare costs: You may be able to recover medical expenses and any other financial losses directly resulting from the telehealth privacy violation.
  • Injunctions: In some cases, a court may issue an injunction. An injunction is a court order that is intended to stop ongoing privacy violations. This type of relief aims to address the issue at its source.
  • Pain and suffering: These damages are subjective and aim to address the emotional impact of the privacy breach.
  • Statutory financial damages: Some privacy laws, such as the Health Insurance Portability and Accountability Act (HIPAA) in the United States, provide for statutory damages. These are predetermined amounts specified in the law that may be awarded for each violation.
  • Punitive damages: Punitive damages may be awarded in cases of willful or seriously negligent conduct. They are intended to punish the defendant and deter similar conduct in the future. However, punitive damages are not always available and depend on the jurisdiction and the nature of the violation.

The availability of damages and the specific types of damages that can be pursued will depend on the jurisdiction, the nature of the telehealth privacy violation, and the applicable laws. Consulting with an attorney experienced in healthcare and privacy law is crucial to understanding the potential damages in your particular case.

If you suspect a telehealth privacy violation, consult with a legal professional experienced in healthcare and privacy law. An attorney can help assess the situation and determine the appropriate course of action.

Contact The Lyon Firm
online or by calling our offices at (513) 381-2333. We are here to answer your questions and help you learn more about telehealth violations and how the legal process can benefit you.

What Information Does Telehealth Collect?

When you use a telehealth website, app, or online patient portal, you may share much more than your name and email address. These services can collect sensitive health information you provide during appointments, along with technical details about the device you use to access care.

Information you provide directly may include:

  • Symptoms, medical concerns, and reasons for seeking care
  • Mental health conditions, emotional concerns, and therapy-related information
  • Medical histories, diagnoses, and treatment information
  • Current and past prescriptions
  • Information about doctors, specialists, or other healthcare providers
  • Insurance information and payment details
  • Names, dates of birth, addresses, phone numbers, and email addresses
  • Information you type into online forms or upload through a telehealth platform
  • Messages, appointment details, and other information exchanged through the service

Telehealth platforms may also collect information automatically as you browse a website or use an app. This can include your IP address, device information, browser type, operating system, and unique device or advertising identifiers. 

Depending on the technology being used, a platform may also collect information about the pages you visit, the buttons you click, how long you remain on a page, and how you move through a website or app.

Telehealth Leakage Rates: An investigation by STAT and The Markup examined 50 direct-to-consumer telehealth websites and revealed that 49 out of 50 sent user browsing details to third-party tech giants, while 35 shared personal contact details and 13 transmitted responses from private health intake questionnaires.

How Telehealth Platforms Collect Your Digital Information

Telehealth websites and apps can use tracking technologies to collect information about what patients do online. Some of these tools are easy to recognize, while others operate in the background and may not be obvious to the person using the service. 

Common tracking technologies include:

  • Tracking pixels and web beacons: Small pieces of code or nearly invisible images that can send information about a webpage visit to the website owner or a third-party technology provider.
  • Cookies: Small files stored on a device that can remember activity and preferences and, depending on how they are configured, help track a person's activity across websites.
  • Session replay tools: Technology that can record how a person interacts with a webpage or app, including movements, clicks, scrolling, and information entered into certain fields.
  • Browser and device fingerprinting: Techniques that use a combination of browser or device characteristics to recognize or distinguish a user.
  • Device and advertising IDs: Unique identifiers associated with mobile devices that can help connect activity from an app to a particular device or user profile.
  • Mobile app tracking code: Code built into an app that can collect information entered by the user as well as certain information supplied by the device, such as network information, location, or device identifiers.
  • Third-party tracking tools: Technology provided by companies outside the telehealth provider that can receive information when their code is placed on a healthcare website or app.

These tools can be used at different points in the patient experience. Tracking may occur when someone searches for a provider, reads information about a medical condition, creates an account, enters information into a registration form, schedules an appointment, or uses a patient portal.

Telehealth Privacy Violations

Telehealth privacy violations can take various forms. These violations may involve unauthorized disclosure, access to your medical records, or misuse of sensitive medical information. Some specific examples of telehealth privacy violations include:

  • Data breach: Data breaches include security incidents that lead to the exposure or theft of patient data during telehealth interactions. Sensitive data may include personal information, financial information, or even information about your medical treatments. If this data is leaked, others may be able to use it to access your bank accounts or medical records.
  • Unauthorized access: In these instances, individuals gain unauthorized access to telehealth platforms or patient records, either through hacking or other means.
  • Recording without consent: If your healthcare provider records your session without consent, this can be considered a violation of privacy. You may be entitled to compensation.
  • Misuse of information: When healthcare providers or staff inappropriately use patient information for purposes other than the intended medical care, you may be able to bring a lawsuit.
  • Failure to comply with privacy laws: Non-compliance with healthcare privacy laws, such as HIPAA (Health Insurance Portability and Accountability Act) in the United States can lead to legal action. HIPAA is just one law that governs the protection of patient information during telehealth interactions.

The U.S. Department of Health and Human Services (HHS) has provided some tips for staying safe while using telehealth medicine. Some notable tips from the HHS include:

  • Conduct your appointment in a private place
  • Use a personal device or computer
  • Turn on screen lock functions
  • Delete health information on your computer or mobile device when you don’t need it anymore.
  • Turn on multi-factor identification systems
  • Use encryption tools when available

If you are considering a telehealth privacy lawsuit, hiring an attorney is an important first step. An attorney can review the details of your case and assess its legal merit. They can help determine if there has been a violation of privacy laws or breaches of confidentiality in the context of telehealth. Your attorney can handle the difficult task of calculating damages and help you determine the proper amount to sue for.

At the Lyon Firm, we have handled violations in healthcare and privacy laws and are knowledgeable about the relevant regulations. We can help you understand how these laws apply to your situation and what the best course of action will be.

How Can Telehealth Data Be Shared With Third Parties?

When a website or app uses third-party tracking technology, information about your activity may be sent directly to the outside company that operates the tracking tool.

Third parties may include advertising and analytics companies, social media platforms, and other technology vendors. HHS has warned that tracking technologies can collect information from healthcare websites and apps and transmit it to third parties. 

Who Can Be Liable in a Telehealth Security And Privacy Lawsuit?

A telehealth data security lawsuit may involve more than the healthcare provider you interacted with. Depending on how your information was collected, used, or disclosed, several types of companies may potentially be responsible.

Companies that may be involved include:

  • Telehealth providers and healthcare companies that operate virtual care platforms, patient portals, or online appointment systems
  • Mental health and counseling platforms that collect sensitive information through online therapy sessions, assessments, and intake forms
  • Healthcare networks and medical groups that use tracking technologies on their websites, patient portals, or mobile apps
  • Technology and analytics companies that provide tracking pixels, cookies, session replay tools, analytics software, or other technology used to collect patient data
  • Social media and advertising companies that receive information through tracking technologies and may use data for advertising or audience targeting
  • Third-party vendors and service providers that process, store, analyze, or otherwise handle information on behalf of a healthcare or telehealth company

The Lyon Firm has a proven history of holding healthcare providers accountable when digital tracking tools compromise patient privacy. Our recent results in healthcare pixel data security cases include:

  • $18,520,000 Healthcare Pixel Settlement — Layman v. Legacy Health, Case No. 25cv40104 (Multnomah County, OR): Appointed Class Counsel; secured a claims-made monetary fund, CyEx Privacy Shield protections, and enhanced digital privacy practices for 954,116 class members.
  • $6,000,000 Healthcare Pixel Tracking Settlement — In re Group Health Plan Litigation, Civ. No. 23-267 (D. Minn.): Served as Plaintiff’s Counsel; established a common fund settlement providing relief to 971,305 class members.

Companies Accused of Mishandling Telehealth Data

Several telehealth and digital healthcare companies have faced lawsuits, regulatory action, or scrutiny over how patient and consumer information was collected and shared through online tracking technologies. These cases show why privacy concerns can extend beyond the healthcare provider delivering virtual care.

BetterHelp and Affiliated Websites

BetterHelp, along with websites including TeenCounseling.com, FaithfulCounseling.com, PrideCounseling.com, and Regain.us, has faced scrutiny over the handling of sensitive information collected through its online counseling services. The FTC alleged that BetterHelp shared consumers’ health information, including email addresses, IP addresses, and answers to health questions, with advertising platforms for purposes such as targeting consumers with advertising. 

The FTC also alleged that BetterHelp used tracking technologies, including pixels and cookies, to collect information about users. BetterHelp later agreed to a $7.8 million FTC order that restricted certain uses and disclosures of health information for advertising. FTC BetterHelp enforcement action

HealthPartners and Virtuwell

A lawsuit against HealthPartners alleged that the company used the Facebook Tracking Pixel on its websites, resulting in the transmission of personal and health-related information to third parties. 

The allegations included claims that information about searches, treatment sought, and appointments could potentially allow third parties to infer sensitive medical conditions. HealthPartners.com and Virtuwell.com are among the online properties identified in connection with these allegations. These are claims made in litigation and should not be treated as established facts unless proven.

Cerebral

The FTC also took action against digital mental health company Cerebral over its privacy and data security practices. The FTC alleged that Cerebral disclosed sensitive health information, including information about consumers' medical and prescription histories, pharmacy information, and health insurance—to third parties for advertising purposes. 

The agency also alleged that Cerebral failed to maintain adequate data security practices. In 2024, Cerebral agreed to pay more than $7.1 million to settle the FTC's allegations. FTC Cerebral enforcement action.

Handling Complex Data Privacy & Cyber Security Cases

Request A Free Consultation Now

Contact a Telehealth Privacy Lawyer Today

When you turn to telehealth, you are trusting someone with information you would not share with just anyone. Your health concerns, treatment choices, and personal details should not become another data point in an advertising profile.

At The Lyon Firm, we have spent more than two decades taking on companies when their business practices leave consumers paying the price. Joe Lyon has represented thousands of people across all 50 states and has played a role in more than 100 consumer class actions involving issues ranging from data privacy violations to deceptive business practices and the misuse of confidential information.

If you believe a telehealth provider shared, exposed, or misused your private information, talk with The Lyon Firm. Call (513) 381-2333 or fill out our online form for a free, no-obligation case evaluation and learn what options may be available to you.

‍

Questions About Your Telehealth Privacy Rights

What should I do if I believe I have a telehealth privacy lawsuit?

If you believe that you have experienced a telehealth privacy violation and may have grounds for a lawsuit, there are several steps you can take. Keep detailed records of the incident, including dates, times, and any communication related to the privacy breach. Seek legal advice by consulting with an attorney experienced in healthcare and privacy laws.

Your attorney can assess the details of your case and guide you on the best course of action.

Remember that legal processes can be complex, and it is important to seek professional legal advice. Consult with an attorney to understand your rights, evaluate the strength of your case, and determine the appropriate course of action.

Who can file a telehealth privacy lawsuit?

Various individuals or entities may have legal standing to file a telehealth privacy lawsuit depending on the circumstances. Anyone who has utilized telehealth services and believes their privacy rights have been violated may consider filing a lawsuit. Healthcare providers who believe their patients’ privacy rights have been compromised may take legal action against the responsible parties.

Note that the specific legal standing to file a telehealth privacy lawsuit can vary based on jurisdiction and the nature of the privacy violation. If you believe you have grounds for a lawsuit, it’s advisable to consult with an attorney specializing in healthcare and privacy law. They can provide guidance on whether you have a valid claim and the appropriate legal steps to take.

What is my telehealth privacy lawsuit worth?

Determining the potential value of a telehealth privacy lawsuit can be complex and depends on various factors. The worth of your lawsuit may include compensation for specific damages. The severity and nature of the privacy breach can impact the value of the lawsuit. For example, unauthorized access to sensitive medical information may be considered a more significant violation.

There is no set amount of damages for a telehealth privacy lawsuit. Consulting with an attorney who is experienced in telehealth and privacy law can give you a better idea of what your case is worth. They can provide a more accurate evaluation of the potential value based on the factors relevant to your situation. Keep in mind that every case is unique, and the outcome will depend on the specific circumstances surrounding the privacy breach.

When should I file my telehealth privacy lawsuit?

If you believe you have a telehealth privacy lawsuit, it is important to be aware of the statute of limitations. The statute of limitations refers to the set time limit for filing a lawsuit. The specific time frames can vary depending on the nature of the claim and the applicable laws.

Contact Joe Lyon and The Lyon Firm online or by calling our office at (513) 381-2333 to learn more about the statute of limitations. We are standing by to take the first step in the legal process.

‍

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.