A laptop showing a padlock and a secured badge, representing patient data privacy for a medical practice website
Your website says a patient's information is private. The tracking code running behind it decides whether that is actually true. Photo via Pexels.

In July 2026, the Federal Trade Commission, along with Los Angeles County and the state of Utah, sued Hims and Hers, one of the largest telehealth brands in the country. If you run an independent practice, your first instinct is probably to scroll past. Big company, big lawyers, not my world. That instinct is exactly the mistake. The things the government says this company did are things a normal medical website does by accident every day.

So it is worth slowing down on what the complaint actually alleges, because two of the three claims could be sitting on your site right now.

What the FTC says happened

According to the FTC's announcement, the agency alleged three things. First, that the company shared users' sensitive health information with advertising platforms, including Meta, Snap, Microsoft, Pinterest, Reddit and X, through tiny bits of tracking code on its website, even while telling customers their data was private. Second, that it charged people for prescriptions before they ever met a provider. Third, that it made the subscription hard to escape by hiding the cancel button. As TechCrunch reported, the company called the claims baseless and said it would fight them.

Whether this particular company wins or loses in court, the playbook the FTC is describing is the one every practice should check itself against. Two of those three claims, the data sharing and the hard cancel, are not exotic telehealth problems. They are things a chiropractor, a med spa, or a therapy group can trip over without ever meaning to.

What a tracking pixel actually does

Here is the part most practice owners have never had explained plainly. When you run ads or just want to see where your website visitors come from, platforms like Meta and Google hand you a small piece of code called a pixel or a tag. You paste it on your site. From then on, it reports back what people do: which page they landed on, what they clicked, whether they booked. For measuring marketing, that is genuinely helpful.

The trouble in healthcare is that the page itself can give away a secret. Someone lands on your page about anxiety treatment, or a weight loss program, or a men's health service. The pixel sees the page, the person's device, and often their ad platform account all at once. Nobody typed out a diagnosis. The pixel put it together anyway, and shipped it off to a company whose whole business is building profiles of people. The patient never agreed to that, and in many cases neither did the practice owner, who had no idea the tag reached that page.

This is not a rare edge case. Lawyers working these cases told the court they identified at least 664 hospital and provider web properties where Meta received patient data through its tracking pixel, according to reporting on the ongoing pixel litigation. That is before you count the clinics too small to make a headline.

$100M+ Paid out by hospitals and health companies in tracking pixel settlements since 2023, per industry tallies. The cases are not slowing down.

This is not only a hospital problem

It is tempting to file this under things that happen to giant health systems. The settlement numbers make that easy: Advocate Aurora Health agreed to pay about 12.25 million dollars after patient data was exposed through the Meta Pixel, and in February 2026 a court gave final approval to a 21.5 million dollar settlement with Sutter Health over tracking tools on its patient portal.

But the law does not have a size cutoff. The federal guidance that started much of this, the HHS Office for Civil Rights bulletin on online tracking technologies, applies to any covered practice, from a solo dermatologist to a three hundred bed hospital. Plaintiff lawyers file class actions against the names with the deepest pockets first, but the exposure is the same when a two provider clinic leaks the same kind of data. You are not too small to be in the wrong. You are just a smaller check, and that has not stopped anyone from filing.

The cancellation trap

The second lesson has nothing to do with code. More practices now sell memberships and recurring programs: a med spa membership, a direct primary care monthly fee, a weight loss plan billed every month. That model is good for a practice, when it is run cleanly. The FTC's complaint flags the version that is not clean: charging before the promised service happens, and burying the way to cancel so people keep paying.

Even setting the legal risk aside, think about what a hidden cancel button does to trust. A patient who feels trapped does not just cancel when they finally find the exit. They tell friends, they leave a one star review that mentions the word scam, and they never refer anyone again. The honest version costs you a few cancellations and buys you a reputation. The sneaky version saves a few months of billing and costs you the practice's good name. For healthcare, where a patient is trusting you with their body, that trade is not close.

So should you rip every tracker off your site?

No, and that is the part people overreact to. Measuring your marketing is not the crime. You should absolutely know which ads bring patients and which pages turn visitors into booked appointments. Running this blog, measuring general traffic on your public pages, seeing that a Google ad led to a call, all of that is normal and fine, because none of it ties a real person to a private health fact.

The line is about identifiable health information. That is where care has to live. A few practical rules we hold to:

If reading that list made you realize you have no idea what is running on your own site, you are in the majority. Most practice owners inherited their tracking setup from a web person who left years ago. That uncertainty is not a character flaw, it is just an unopened box. The fix starts with opening it.

664 Hospital and provider web properties where experts found Meta received patient data through its tracking pixel, as cited in the pixel litigation.

How EtherealMinds handles this

We only work with healthcare, so this is not a surprise we deal with once a year. When we build or take over a practice site, measuring results and protecting patients are the same job, not competing ones. We map every tag and chat tool already on the site, pull trackers off the pages that could reveal a health issue, keep condition names out of every event, and report conversions from the system rather than the browser. You still see what your marketing is doing. The ad platforms just stop learning things about your patients that they were never supposed to know.

That approach is baked into the websites we build and into the wider patient acquisition system that runs the booking and follow up behind them, including membership flows where canceling is as easy as signing up. If you want to go deeper on the two questions this raises most, we covered them already in plain language: whether the Facebook pixel can be used on a medical practice site, and whether your own contact form is a hidden liability.

A clinic called us this summer, a little rattled after seeing a headline much like this one. They were sure they had a pixel somewhere but could not say where. We found it loading on every page, including the intake form, passing along the service each person had asked about. Nobody put it there on purpose. It took an afternoon to fix and gave them something they could not buy back once it was gone: the ability to tell a patient their information is private and mean it.

Not sure what is tracking your patients?

Book a free strategy call and we will map every tool running on your website, show you where patient data might be leaking, and tell you straight whether it is a quick fix or a rebuild. Honest read, healthcare only, across the United States.

Book a free strategy call →