WellthCareContact
Employer Benefits StrategyOpinionFor HR & Benefits Leaders

The Telemedicine Data Leak No Employer Is Auditing

Your employees love telemedicine. It's fast, easy, and they don't have to sit in a waiting room. But a quiet problem is brewing, subtler than a hacker in a hoodie stealing records and more dangerous if you run a self-funded health plan.

Your telemedicine platform is likely sharing data about your employees with third parties you'd never expect. The Federal Trade Commission has sued digital health platforms GoodRx, BetterHelp, and Cerebral for sending consumers' sensitive health information to advertising platforms through hidden tracking tools, and in July 2026 it sued the telehealth company Hims & Hers on the same grounds. That data isn't confined to research or quality improvement. In a self-funded plan, any signal that predicts future claims has underwriting value, and that is what a data broker sells. The vendor you hired to lower costs could be handing your underwriter the ammunition to raise your rates.

The Three Ways Data Leaks Without You Noticing

Most benefits leaders ask one question during vendor vetting: is the vendor HIPAA compliant? The answer is always yes. But HIPAA is the floor, not the ceiling. Part of the reason is structural: a direct-to-consumer telehealth app may not be a HIPAA covered entity at all, and data that clears the de-identification threshold is no longer protected health information under HIPAA. Standard vetting misses three leak paths.

1. Metadata is a goldmine

Every time an employee opens the app, the vendor collects metadata: time of day, condition category, frequency of visits. A sudden spike in mental health visits after a restructuring, or a surge in GLP-1 inquiries, is a leading indicator for future claims. FTC complaints against these platforms describe tracking tools that share this kind of event data with third parties, and data brokers buy and sell de-identified health records at scale. None of it is anonymous in practice.

2. De-identified data is a myth

Many platforms sell aggregated data to pharma companies and data brokers, and they claim it is anonymous. In a plan with 500 employees, one person with a rare condition is effectively identifiable. HHS guidance on the HIPAA de-identification standard warns that rare clinical events can make someone identifiable even in a de-identified dataset, and research finds that re-identification risk falls disproportionately on people with rare conditions. The promise of de-identification is often a legal fiction.

3. The PBM connection is the real danger

A growing number of telemedicine platforms are owned by, or have deep data-sharing deals with, pharmacy benefit managers (PBMs). Cigna's Evernorth unit, which houses the Express Scripts PBM, acquired the telehealth platform MDLive in 2021. Data on what your doctor prescribed can then flow straight to a PBM, the same PBM you may be auditing for spread pricing and hidden rebates. You are handing the adversary the playbook.

Why This Is an ERISA Time Bomb

Under ERISA, plan fiduciaries must act solely in the interest of plan participants, a duty the Department of Labor enforces. If your telemedicine vendor shares data that lets a stop-loss carrier reprice your renewal after seeing the group's rising GLP-1 usage, that is a breach of duty exposure for the plan's fiduciaries. And if an employee's sensitive health information reaches a life insurer or a future employer, participants have a clear breach of fiduciary duty claim to bring.

Move past the HIPAA checkbox and ask these questions instead:

  • Who owns the metadata?
  • Do you sell any data, aggregated or otherwise, to third parties?
  • Do you have a data-sharing agreement with my PBM?
  • Can you guarantee that no claim-relevant data leaves your system?

If the answers are vague, you have a problem that won't show up on a compliance checklist until it's too late.

What Regulators Have Already Found

Employers are not auditing this, but regulators are. The FTC ordered GoodRx and BetterHelp to stop sharing health information for advertising, and it banned Cerebral from using health data for ads without affirmative consent. In July 2023, the FTC and HHS jointly warned hospitals and telehealth providers that online tracking tools can disclose patient information to third parties. In July 2026, the FTC sued Hims & Hers over allegations that it shared consumers' health information with advertising platforms while promising privacy.

These cases matter to an employer because they show the data flow is real, and because regulators are treating undisclosed health-data sharing as an enforcement priority. A vendor that has already been ordered to change its practices is a vendor whose contract deserves a second read.

The Solution: Data Sovereignty as a Fiduciary Tool

This is why the next generation of benefits platforms, like the integrated Health-to-Wealth systems being built today, offer a different approach. WellthCare™ is that system: an integrated ecosystem where all data stays in-house, used only to improve health and lower costs, never shared with underwriters or data brokers. Instead of a patchwork of point solutions that each own a slice of your data, one integrated system keeps every record in one place.

Keeping the data in-house is both a privacy feature and a fiduciary advantage. It is the cleanest way to stop the silent leak already running through thousands of employer plans.

What to Do This Week

  1. Audit your telemedicine vendor's data agreements. Do not accept boilerplate. Ask for a clear description of every third party that touches the data.
  2. Demand a no-data-sharing clause. Require that the vendor cannot share, even in de-identified form, any data that could be used for underwriting or pricing.
  3. Request a data hygiene certification. A third-party audit of data flows, not just a SOC 2 report.
  4. Consider an integrated ecosystem. Fewer hands on the data means less risk.

Telemedicine isn't going anywhere. But the way you buy it, and the way you trust it, needs to change. The leak is silent, but the consequences are loud.

This article is for general information only and is not legal, tax, or medical advice. Employers should consult their own advisors.

← Back to Blog

This isn't insurance as usual.

Get Your Eligibility Results

30-minute call • Personalized Pension & Store projections

• No disruption to your current plan