Tag: Company

  • FTC Alleges a Telehealth Company Sent Users’ Health Conditions to Ad Platforms After Promising Discretion

    FTC Alleges a Telehealth Company Sent Users’ Health Conditions to Ad Platforms After Promising Discretion

    Federal regulators have accused one of the largest direct-to-consumer telehealth companies of routing customers’ health conditions to advertising platforms while marketing itself on privacy.

    The Federal Trade Commission, joined by Utah and by California through Los Angeles County Counsel, sued Hims and Hers Health on July 29 in federal court in San Francisco. The complaint alleges the company shared sensitive health information about medical conditions with third-party advertising platforms despite promising privacy, and separately alleges deceptive billing and cancellation practices.

    None of this has been proven. The company disputes the allegations and says it will defend itself. A complaint is an accusation, and the court has made no findings.

    The reason it matters to readers who have never used the platform is the category. The conditions named are the ones people specifically seek online care for because they do not want to discuss them in person.


    What the Complaint Says Moved, and Where

    The alleged mechanism is a tracking pixel, a small piece of code embedded in a web page that reports visitor activity back to a third party. Pixels are ordinary infrastructure across commercial websites. They become a health privacy question when the page being tracked reveals a medical condition.

    According to the complaint as reported by TechCrunch, the company placed trackers supplied by Meta and Snap as well as Microsoft, Pinterest, Reddit, and X. The FTC also alleges the company uploaded lists of certain customers to advertising platforms, a separate practice from pixel tracking that matches known customer identities against platform user accounts.

    The service lines named in reporting on the complaint include erectile dysfunction, premature ejaculation, hair loss, weight management, and mental health. The FTC’s contention is that the company advertised privacy and discretion for exactly these categories while the data pipeline ran the other direction.

    Christopher Mufarrige, director of the FTC’s Bureau of Consumer Protection, said in the agency’s announcement that the complaint describes “consumers unknowingly locked into recurring subscriptions” alongside disclosure of private health information without consent.


    The Billing Allegations Sit Alongside the Privacy Ones

    The complaint pairs the data claims with allegations about money, which is unusual and is part of why the case is being watched.

    Regulators allege the company advertised free consultations and displayed language indicating no payment was due at intake, then charged consumers and enrolled them in recurring subscriptions once a provider wrote a prescription, in some cases before any consultation had occurred. The complaint further alleges that cancellation was made difficult, leaving some customers paying for refills they did not want.

    The cited legal authorities are the FTC Act and the Restore Online Shoppers’ Confidence Act, a 2010 statute governing online negative-option billing, which requires clear disclosure of terms, informed consent before charging, and a simple cancellation mechanism.

    The company has responded firmly. In statements reported by BioPharma Dive and others, Hims and Hers called the claims baseless, said its privacy policy makes clear that users may choose how their data is used, and said it is confident in its position. It did not explicitly deny the specific factual allegations in the statements reported.


    A Pattern the Agency Has Pursued Before

    This is not a novel theory of enforcement. The FTC brought similar actions against GoodRx and BetterHelp in 2023, and against the telehealth startup Cerebral and the alcohol recovery provider Monument, in each case alleging that consumer health data reached advertising platforms through website technology.

    The industry has responded to that pressure. Pixel deployment on hospital websites fell from about 98 percent in 2021 to roughly 30 percent in 2025, according to tracking data compiled by health marketing analytics firm Hedy and Hopp and reported by Bloomberg Law. That figure describes hospitals rather than direct-to-consumer telehealth, and should not be read as a measure of the latter.

    One legal point is worth understanding because it surprises people. Most direct-to-consumer telehealth platforms operate in a space where HIPAA’s application is contested or limited, which is part of why the FTC rather than the HHS Office for Civil Rights is the agency bringing this case. Consumers frequently assume that anything involving a prescription is covered by federal medical privacy law. That assumption does not reliably hold for app-based commercial health services.


    Steps for Anyone Who Has Used a Telehealth Platform

    Nobody should stop needed treatment over a privacy dispute, and nothing here suggests any medication is unsafe. The relevant actions are about accounts and settings.

    Check advertising controls on the platforms named. Meta, Google, and other services allow users to review and delete off-site activity that businesses have shared, and to limit how that data informs ad targeting. Those controls are typically found under account settings labeled activity, ad preferences, or data sharing.

    Review recurring charges. Anyone enrolled in a telehealth subscription can check the current billing terms, the renewal date, and the cancellation process, and should document the date and method of any cancellation request. Consumers who believe they were charged without consent can dispute the charge with their card issuer and file a complaint with the FTC at ReportFraud.ftc.gov.

    For future care, consider that browsing a condition-specific page on a commercial health site is not equivalent to a conversation in an exam room. Care delivered through a health system patient portal generally does sit under HIPAA. That is a meaningful difference for anyone who considers the condition itself sensitive.

    Several things remain unresolved. The company has not filed its formal response. No court has ruled on any allegation. How many consumers were affected, what specific data elements moved, and what remedy regulators will seek are all matters for the litigation. MedicalDaily will report the company’s answer and any rulings.



    Frequently Asked Questions

    What did the FTC allege? That Hims and Hers shared consumers’ sensitive health information with third-party advertising platforms despite promising privacy, and separately deceived users about billing and cancellation.

    Have the allegations been proven? No. The complaint was filed July 29, 2026, and no court has made findings. The company calls the claims baseless and says it will defend itself.

    What is a tracking pixel? A small piece of code embedded in a web page that reports visitor activity to a third party. It becomes a health privacy issue when the page reveals a medical condition.

    Which platforms are named? Reporting on the complaint identifies Meta and Snap along with Microsoft, Pinterest, Reddit, and X.

    Does HIPAA cover telehealth apps? Not always. Many direct-to-consumer platforms operate outside or at the edges of HIPAA, which is why the FTC rather than HHS is bringing this action.

    What can users do now? Review ad and data-sharing settings on the named platforms, check subscription billing terms and cancellation processes, and document any cancellation request.

    Has the FTC done this before? Yes. It brought similar cases against GoodRx and BetterHelp in 2023, and against Cerebral and Monument.

    Source link

  • A Telehealth Mental Health Company Billed Medicaid for Visits That Never Happened — And It Is Not Alone

    A Telehealth Mental Health Company Billed Medicaid for Visits That Never Happened — And It Is Not Alone

    A telehealth company that provided mental health services through video appointments admitted it billed Medicare and Medicaid for patient appointments that never took place — and agreed to pay $300,000 to resolve the allegations.

    The company, Aptihealth, Inc., and Aptihealth Medical, PLLC, is based in Clifton Park, New York. According to the U.S. Department of Justice’s announcement on June 23, 2026, the settlement resolves False Claims Act allegations that included billing for patient appointments where patients did not show up, billing for patient messages without regard to whether those communications involved billable clinical content, and billing for psychological testing services that were not adequately documented.

    Aptihealth also admitted to implementing a patient incentive program involving $25 gift cards that the government contends violated the Anti-Kickback Statute.


    Why This Matters

    Telehealth mental health services have transformed access to psychiatric care for millions of Americans — reducing geographic barriers, eliminating transportation requirements, and expanding appointment availability for people who previously could not access care at all.

    That growth has attracted fraudulent billing on a significant scale. The DOJ’s 2026 National Health Care Fraud Takedown, announced simultaneously with the Aptihealth settlement, charged 455 defendants — including 90 licensed medical professionals — in connection with more than $6.5 billion in alleged fraud. Telehealth and digital health billing fraud were specifically named as one of the takedown’s key targets, with 49 defendants charged in connection with $1.17 billion in allegedly fraudulent telehealth and genetic testing claims.

    When telehealth companies bill for services that never occurred, two harms result: the federal programs are defrauded, and patients may develop billing records that do not accurately reflect their care history, with consequences for insurance, disability claims, or future treatment.


    What We Know So Far

    According to the DOJ announcement, Aptihealth’s billing violations included:

    • No-show billing: Submitting claims to Medicare and Medicaid for patient appointments that did not occur because the patient did not attend.
    • Message billing: Billing for responses to patient messages without determining whether those communications involved clinically billable content.
    • Documentation failures: Billing for psychological testing services without sufficient documentation to support the claims.
    • Anti-Kickback violation: Offering $25 gift cards to patients who attended therapy sessions — a financial incentive that the government determined violated the Anti-Kickback Statute because it could improperly influence patients’ decisions to use the service.
    • Compliance program failures: Aptihealth’s compliance program did not meet New York statutory requirements for billing oversight, compliance monitoring, and training.

    The settlement was filed as a whistleblower action by a former Aptihealth employee under the False Claims Act’s qui tam provisions. The whistleblower will receive approximately $51,000 of the settlement proceeds.


    Not an Isolated Case

    The Aptihealth settlement is one of the smaller cases in the 2026 National Health Care Fraud Takedown, but it illustrates a fraud pattern that investigators say is systemic in the telehealth sector.

    According to the DOJ’s Fraud Division, the largest telehealth fraud case in the takedown was United States v. Blackman, involving Brett Blackman, founder and CEO of HealthSplash. His company, DMERx, used foreign call centers to blast spam to Medicare beneficiaries, pressuring elderly patients to accept medically unnecessary orthotic braces. The fraud involved $1 billion in allegedly fraudulent Medicare claims for equipment that, in many cases, was never ordered by a legitimate physician or needed by the patient.

    The Southern District of Florida takedown included charges against 12 defendants in connection with more than $4 billion in allegedly fraudulent claims for community mental health services, among other categories, illustrating the scale at which telehealth billing fraud now operates.


    What the Evidence Shows — and What It Does Not

    The Aptihealth settlement involves admitted conduct — the company admitted responsibility for the billing practices described. This is a settlement, not a jury trial verdict, and the $300,000 payment is not described as encompassing the full amount billed improperly. Settlement amounts in False Claims Act cases typically do not represent the full extent of alleged fraud.

    The DOJ’s 2026 Takedown data represent alleged fraud that has been charged or settled, not a comprehensive picture of the total volume of telehealth billing irregularities that may exist in the market. Experts in health care fraud have noted that telehealth billing is particularly difficult to monitor in real time because virtual care occurs without the physical presence of oversight, and documentation standards vary widely.


    Who Is Most Affected?

    • Medicaid and Medicare beneficiaries who received mental health services through telehealth platforms and may have claims in their records for sessions they did not attend
    • Patients who were billed for message-based consultations that did not meet the clinical threshold for a billable service
    • Taxpayers and program beneficiaries generally, since telehealth billing fraud increases costs borne by the Medicare and Medicaid trust funds

    What You Can Do Now

    • If you receive mental health services through telehealth and are covered by Medicare or Medicaid, review your Explanation of Benefits (EOB) or Medicare Summary Notice carefully. Check that every listed service date corresponds to an appointment you actually attended.
    • If you see a claim for a session you did not have, contact your insurance company or 1-800-MEDICARE (1-800-633-4227) to report it.
    • If you receive telehealth care, you have the right to ask your provider for a copy of your billing records. These records should reflect only services that were actually provided.
    • Report suspected Medicare or Medicaid billing fraud to the HHS OIG Hotline at 1-800-HHS-TIPS (1-800-447-8477).
    • If you work for a telehealth company and suspect fraudulent billing, the False Claims Act’s whistleblower provisions allow you to report it and, if the case results in a recovery, receive a portion of the settlement proceeds.

    Cost and Access: What Patients Should Know

    Patients whose Medicare or Medicaid records contain claims for services they did not receive should not owe out-of-pocket costs for those fraudulent claims. If a co-payment or cost-sharing was collected for a session that did not occur, patients should request a refund from the provider. If the provider does not respond, contact your insurance plan or state Medicaid agency.

    Patients who have experienced genuine fraudulent billing should not discontinue telehealth mental health care as a result of this fraud. The fraud problem lies with the billing practices of specific providers, not with telehealth as a modality for delivering legitimate mental health services.


    What Happens Next

    The DOJ’s 2026 National Health Care Fraud Takedown is ongoing, with additional enforcement actions expected. CMS has suspended billing privileges for 1,403 providers and revoked them for 1,079 more as part of the 2026 action. A newly announced Health Care Fraud Data Fusion Center will deploy artificial intelligence and cloud computing tools to identify telehealth billing fraud patterns more rapidly. MedicalDaily will continue tracking enforcement actions in the telehealth sector.


    The Bottom Line

    A telehealth mental health company admitted it billed Medicare and Medicaid for appointments that never happened, and the DOJ’s 2026 National Health Care Fraud Takedown makes clear this is not an isolated case. Telehealth billing fraud is one of the fastest-growing categories of health care fraud. Patients who use telehealth for mental health care should review their billing records regularly, confirm that every claim in their record corresponds to an actual appointment, and report any discrepancies promptly.

    References

    Source link