GLP-1 Telehealth Privacy Audit: Public Disclosures From 12 Providers (2026)

By the WPG Research Team · Weight Loss Provider Guide Research

GLP-1 Consumer Research — the self-funded, independent research and reference section of Weight Loss Provider Guide. Research pages carry no affiliate links, product recommendations, advertisements, or calls to action.

Last verified: August 1, 2026 · Dataset version 1.0.0 · Dataset ID: wpg-glp1-privacy-audit-2026-08-01

On August 1, 2026, we read the public privacy documents of 12 U.S. GLP-1 telehealth services without creating a single account. All 12 published language disclosing advertising or analytics technology. Only 8 published a HIPAA Notice of Privacy Practices you can read without logging in, and only 5 published a separate consumer health data notice that applied to the audited service. This GLP-1 telehealth privacy audit measures what a prospective patient can verify before signing up — not what any company actually does with your data.

The gap that matters most isn't in that list.

A company can publish every document we looked for and still become the defendant in a federal privacy case. That is not hypothetical. It happened three days before we ran this audit.


The headline numbers

GLP-1 telehealth public privacy disclosures, 12-provider cohort, verified August 1, 2026

Table 1a. Headline counts across 12-provider cohort, verified August 1, 2026.
Public disclosure fieldProviders
Advertising or analytics technology disclosed12 of 12
At least one covered opt-out route12 of 12
Access, correction, or deletion route12 of 12
Dated general privacy policy11 of 12
General retention period or criteria10 of 12
Public no-login HIPAA Notice of Privacy Practices8 of 12
Clear HIPAA / non-HIPAA data boundary8 of 12
Non-HIPAA denied-request appeal route6 of 12
Separate consumer health data notice5 of 12

Source: GLP-1 Telehealth Privacy Audit 2026, Weight Loss Provider Guide Research. Dataset wpg-glp1-privacy-audit-2026-08-01, version 1.0.0, verified August 1, 2026. The provider-level source record is in the evidence ledger.

Use the qualifiers with the numbers. Opt-out scope and eligibility varied by state, browser, device, mechanism, and data category. “Not found” means we did not locate it in the official public materials we reviewed without logging in. It does not prove that no document, account-only notice, internal process, or legally sufficient mechanism exists.

Here is the shape of it. On what their public documents disclose about advertising and analytics, the cohort is unanimous: every provider names at least one relevant technology or activity, and every provider publishes at least one route tied to sale, sharing, targeted advertising, or interest-based tracking. On which document and legal entity govern which data, the cohort breaks apart. For four services, we did not locate a no-login medical privacy notice. Only five published a qualifying separate consumer health data notice, with one additional notice that expressly excluded the audited clinic population. For half the cohort, we found no published route to appeal a refused non-HIPAA privacy request.

Public tracking disclosures were easier to locate than a public map of who is legally responsible for the information entered into an intake form.


What did the 2026 GLP-1 telehealth privacy audit find?

Answer: Across a purposive cohort of 12 U.S. GLP-1 telehealth services reviewed on August 1, 2026, disclosure of advertising technology and basic privacy-request routes was universal, while medical privacy notices, consumer health notices, data-boundary explanations, and appeal routes were inconsistent. All 12 disclosed advertising or analytics technology and provided some request route; 8 published a no-login HIPAA notice, 8 clearly separated HIPAA-covered data from other data, 6 published a non-HIPAA appeal route, and 5 published a separate consumer health data notice. These are disclosure-accessibility findings, not security, data-flow, or legal-compliance findings.

Legend

F = Found  ·  P = Partial or limited scope  ·  NF = Not found in reviewed public materials

Table 1. Document availability and boundary clarity

Table 1. Document availability and boundary clarity across 12 GLP-1 telehealth providers, verified August 1, 2026.
ProviderDated policyPublic NPPConsumer health noticeClear data boundary
Hims & HersFFFF
RoFNFFNF
Noom MedFFFF
WeightWatchers ClinicNFFPF
FoundFFNFF
Form HealthFFNFP
LifeMDFFNFF
PlushCareFFFF
SesameFNFNFNF
Mochi HealthFNFNFF
Henry MedsFFNFF
EdenFNFFNF

Source: GLP-1 Telehealth Privacy Audit 2026, Weight Loss Provider Guide Research, verified August 1, 2026. Source URLs and row-level evidence are listed in the evidence ledger.

Table 2. Technology disclosures and user controls

Table 2. Technology disclosures and user controls across 12 GLP-1 telehealth providers, verified August 1, 2026.
ProviderAd-tech disclosedCovered opt-outRetentionRights routeAppeal route
Hims & HersFFFFF
RoFFFFF
Noom MedFFFFNF
WeightWatchers ClinicFFFFF
FoundFFFFF
Form HealthFFNFFNF
LifeMDFFFFNF
PlushCareFFFFF
SesameFFFFNF
Mochi HealthFFFFNF
Henry MedsFFNFFNF
EdenFFFFF

Source: GLP-1 Telehealth Privacy Audit 2026, Weight Loss Provider Guide Research, verified August 1, 2026. “Ad-tech disclosed” is a document finding; it is not a technical observation that a tool was active during the audit.

Download the underlying data

Both files are available without registration. The evidence ledger contains 108 provider-field determinations, each with a status, evidence summary, primary-source URL, verification date, confidence label, and reproduction step.

How old are these documents?

The provider policies do not aggregate their own revision dates, so we calculated the age of every dated general privacy policy. Of the 11 providers displaying a date, the median policy was 183 days old on August 1, 2026. The mean was 293 days. The range ran from 37 days to 729 days — a 692-day spread.

Table 3. General privacy policy age in days as of August 1, 2026 (11 providers displaying a date).
ProviderPolicy date shownDays old
Henry MedsJune 25, 202637
Form HealthJune 11, 202651
RoApril 2, 2026121
Hims & HersMarch 26, 2026128
Mochi HealthMarch 12, 2026142
EdenJanuary 30, 2026183
PlushCareDecember 15, 2025229
LifeMDNovember 17, 2025257
Noom MedOctober 1, 2024669
SesameSeptember 23, 2024677
FoundAugust 2, 2024729
WeightWatchers ClinicNo date visible on reviewed page

Source: the official general privacy policies linked in the table, as displayed on August 1, 2026. Some documents use “Effective Date”; others use “Last Updated.” Day counts are calendar-day differences from the displayed date to August 1, 2026.

Three of the eleven dated policies were more than a year old. One provider displayed no date on the reviewed general policy page.

An old date is not a defect. A policy that has not changed does not need to be re-dated, and a company that revises quarterly is not automatically more careful than one that revises annually. A visible date tells you whether the document predates a new law, a revised advertising practice, or a restructuring of the entities involved. Without a visible date, you cannot make that comparison.

Why there is no overall score

We do not total the nine fields into a score, grade, percentage, or star rating. Here is the concrete reason.

Hims & Hers returned “Found” on all nine fields, tied with PlushCare for the highest field count. Every document we looked for was public and accessible without an account: a dated general policy, a Notice of Privacy Practices, a consumer health data policy, a clear statement of which entity governs which data, advertising disclosures, opt-out routes, retention criteria, a rights portal, and an appeal process.

On July 29, 2026 — three days before we ran this audit — the Federal Trade Commission, joined by Utah and California acting through Los Angeles County Counsel, filed a federal complaint alleging that Hims shared consumers' sensitive health information with Meta, Snap, and other third parties despite promising to protect patient privacy. Those are allegations. The case has not been decided. Hims disputes the claims and says it will vigorously defend itself. See the FTC announcement and the company response.

Both things are true at once. The company published one of the two most complete sets of public privacy documents in this cohort, and it is the defendant in a pending federal privacy case. A composite score would have put it at the top, tied for the highest count. That is precisely why a composite score would be worthless.

Document availability measures whether you can read what a company says. It does not measure what the company does. Any number that blends those two things manufactures precision it has not earned.


What this audit shows — and what it does not

Answer: This audit shows what an unauthenticated visitor could find in official public provider materials on one specific date, measured against nine definitions fixed before any counting began. It does not test cybersecurity, actual data flows, live tracker deployment, consent implementation, account-only notices, mobile apps, contracts, breach history, or legal compliance. A “Not found” result is a statement about our review, not evidence of a violation.

What it shows

  • Which privacy documents a prospective patient can locate before creating an account
  • How each company describes its own advertising and analytics practices, in its own words
  • Which notice or entity each company says governs particular categories of data
  • Which controls, request routes, and appeal processes are publicly documented
  • How consistent — or inconsistent — those disclosures are across this 12-service cohort

What it does not show

  • Which trackers are actually loaded on any site today
  • Which data elements are actually transmitted, and to whom
  • Whether any consent control technically works
  • Whether any company follows its own stated policy
  • Whether any company has suffered a breach
  • Whether encryption, access controls, logging, or incident response are adequate
  • Whether business associate agreements are in place
  • Whether any company is a covered entity in a particular interaction
  • Whether any disclosure or practice is lawful
  • Whether one provider is safer, more private, or more trustworthy than another

That last line is the one to carry away. A privacy policy is a description, not a measurement. The only way to know what a website actually transmits is to capture the traffic under controlled conditions. That is a different study, requiring different tools, and one we did not perform.


How was this GLP-1 telehealth privacy audit conducted?

Answer: We reviewed official, publicly accessible materials for a purposive cohort of 12 U.S. consumer GLP-1 telehealth services on August 1, 2026, without creating an account or entering any authenticated portal. Each provider was assessed against nine definitions established before aggregate results were calculated, producing 108 provider-field determinations, each with a status, evidence summary, source URL, confidence assessment, and verification date.

The cohort

  1. Hims & Hers
  2. Ro
  3. Noom Med
  4. WeightWatchers Clinic
  5. Found
  6. Form Health
  7. LifeMD
  8. PlushCare
  9. Sesame
  10. Mochi Health
  11. Henry Meds
  12. Eden

This is a purposive cohort, not a market census. It is not the 12 largest providers, not a statistically representative sample, and not a random sample. It is a set of publicly marketed U.S. consumer GLP-1 telehealth programs selected for a reproducible first edition. Percentages drawn from it describe these 12 services and nothing else.

The no-login protocol

This is the part that makes the audit reproducible, so we are specific about it.

For each provider we opened the active GLP-1 program page, then worked through the footer and legal navigation: general privacy policy, HIPAA Notice of Privacy Practices or equivalent medical notice, consumer health data notice, state privacy addenda, privacy-choice pages, and public request forms. Where a document was not exposed through site navigation, we ran targeted searches restricted to the provider's official domain for common document-title variants.

We did not create accounts. We did not complete or submit intake forms. We did not enter authenticated portals. We did not open mobile apps.

That constraint is deliberate. A prospective GLP-1 patient decides whether to hand over medical history before an account exists. Anything visible only after signup is not available at the moment that decision is made.

The nine fields

Table 4. Nine-field audit definitions (codebook version 1.0.0).
FieldWhat qualifies as “Found”
Dated general privacy policyThe reviewed general policy displays an effective, revised, or last-updated date.
Public HIPAA noticeA no-login Notice of Privacy Practices, or a clearly equivalent medical privacy notice, is publicly accessible.
Separate consumer health data noticeA dedicated Washington, Nevada, or broader consumer health notice applies to the service or to relevant non-HIPAA data.
Clear HIPAA / non-HIPAA boundaryPublic materials identify which notice or entity governs protected health information and which governs general website, app, account, or consumer data.
Ad-tech or analytics disclosureThe materials expressly identify cookies, pixels, SDKs, analytics, behavioral advertising, targeted advertising, or advertising partners.
Covered opt-out routeA public route is expressly tied to sale, sharing, targeted advertising, or interest-based tracking.
Retention disclosureA general retention period, or the criteria used to determine retention, is stated.
Access / correct / delete routeA public portal, form, email address, or phone number exists to exercise at least some of those rights.
Denied-request appeal routeA public process exists to appeal the denial of a non-HIPAA consumer privacy request.

Source: Weight Loss Provider Guide Research codebook, dataset version 1.0.0. The definitions were fixed before headline totals were calculated.

Two decision rules changed several outcomes. A marketing-email unsubscribe link by itself does not satisfy the opt-out field; that is a communications preference, not a control over sale, sharing, or targeted advertising. A HIPAA complaint address, or HIPAA's access-denial review mechanism, does not by itself satisfy the general consumer privacy appeal field, because those are different processes under a different legal framework.

Status definitions

  • Found — direct public evidence satisfies the field definition.
  • Partial — a relevant disclosure exists but is materially limited in scope or clarity.
  • Not found in reviewed public materials — we did not locate it through the protocol above.

Only Found results are counted in the headline numerators. Partial results are reported separately and identified in the provider notes.

Final verification pass

Every Partial and Not found determination was rechecked during the final audit against the provider's official public source set. The aggregate counts were then recalculated directly from the locked 12-provider matrix. No technical test, account-only review, or provider statement supplied outside the public record was used to convert a Not found result into Found.

Commercial disclosure

This research page contains no affiliate links, no lead forms, no provider grades, no recommendations, and nothing to buy. Weight Loss Provider Guide does maintain commercial relationships elsewhere on this website, including with companies included in this audit. Those relationships had no bearing on cohort selection, field definitions, or any individual determination. Every determination is tied to a public document and a stated decision rule.


Which GLP-1 telehealth providers publish a HIPAA Notice of Privacy Practices?

Answer: Eight of the 12 reviewed providers published a no-login Notice of Privacy Practices or a clearly equivalent medical privacy notice: Hims & Hers, Noom Med, WeightWatchers Clinic, Found, Form Health, LifeMD, PlushCare, and Henry Meds. For Ro, Sesame, Mochi Health, and Eden we did not locate a publicly accessible NPP through the documented review protocol. That is a statement about public availability, not proof that no notice exists or is delivered after signup.

Under 45 CFR 164.520, an individual generally has a right to adequate notice of a covered entity's permitted uses and disclosures of protected health information, the individual's rights, and the covered entity's duties. The regulation specifies what the notice must contain. An NPP is a legal notice, not a security certification.

Table 5. Public no-login HIPAA notice availability, 12-provider cohort, verified August 1, 2026.
ProviderStatusPublic NPP URL
Hims & HersFoundhims.com/notice-of-privacy-practices
Noom MedFoundnoom.com/hipaa-notice
WeightWatchers ClinicFoundweightwatchers.com/us/npp
FoundFoundjoinfound.com/terms/privacy-practices-notice
Form HealthFoundformhealth.co/legal/medical-privacy-policy
LifeMDFoundlifemd.com/notice-of-privacy-practices
PlushCareFoundplushcare.com/hipaa-notice-of-privacy-practices
Henry MedsFoundhenrymeds.com/legal/npp
RoNot found in reviewed public materials
SesameNot found in reviewed public materials
Mochi HealthNot found in reviewed public materials
EdenNot found in reviewed public materials

Source: the official notices linked in the table and the documented no-login search protocol, verified August 1, 2026.

Two details show why the notice and the general policy need to be read separately.

Mochi Health's general policy says that protected health information held by its affiliated medical group is governed by a Notice of Privacy Practices. The boundary is described. We simply did not locate the notice itself as a no-login document. That is different from a policy that never points to an NPP, which is why boundary clarity and public NPP availability are separate fields.

The documents can run on separate revision cycles. Found's NPP shows an effective date of November 13, 2024, later than its August 2, 2024 general policy. Henry Meds' NPP shows May 6, 2026, earlier than its June 25, 2026 general policy. Reading only the newest-looking document can miss the notice that governs medical information.

What an NPP does not prove

Publishing a Notice of Privacy Practices does not establish that a company is secure, that it complies with HIPAA, that HIPAA covers every interaction, or that a public website is free of advertising technology. It establishes that a public medical privacy notice meeting this audit's accessibility definition was available. That is meaningful and it is narrow.


Which GLP-1 telehealth providers publish a consumer health data notice?

Answer: Five of the 12 reviewed providers published a separate consumer health data notice applying to relevant non-HIPAA data: Hims & Hers, Ro, Noom Med, PlushCare, and Eden. WeightWatchers Clinic was marked Partial because its consumer health statement expressly excludes WeightWatchers Clinic patients and directs them to the clinic Notice of Privacy Practices instead. The remaining six providers had no separate notice we could locate.

Washington and Nevada both require covered or regulated entities to publish consumer health data policies under their respective statutes. Washington gives covered consumers rights including access, withdrawal of consent, deletion, and an appeal after a refused request. Violations of Washington's chapter are treated as unfair or deceptive acts under the state Consumer Protection Act. Nevada's law requires a consumer health data policy and provides request and appeal procedures. Applicability depends on the entity, data, resident, and statutory exemptions. See Washington RCW 19.373 and Nevada NRS Chapter 603A.

Table 6. Separate consumer health data notice availability, 12-provider cohort, verified August 1, 2026.
ProviderStatusNotice URL
Hims & HersFoundhims.com/consumer-health-data-privacy-policy
RoFoundro.co/consumer-health-data-privacy-policy
Noom MedFoundnoom.com/consumer-health-data-privacy-notice
PlushCareFoundplushcare.com/consumer-health-data-privacy-policy
EdenFoundeden.health/policies/my-health-my-data-privacy-policy
WeightWatchers ClinicPartial — excludes Clinic patientsweightwatchers.com/us/hps
Found, Form Health, LifeMD, Sesame, Mochi Health, Henry MedsNot found in reviewed public materials

Source: the official notices linked in the table and the provider-level evidence ledger, verified August 1, 2026.

The WeightWatchers Clinic result is the clearest example of why this audit includes Partial rather than forcing every cell to yes or no.

WeightWatchers publishes a consumer health data statement. It is public and findable. It also says that it does not apply to WeightWatchers Clinic patients, who are directed to the clinic's Notice of Privacy Practices instead. Coded as a simple yes, that row would misstate the document's scope for the exact population this audit covers. Coded as a simple no, it would erase a document that genuinely exists and applies elsewhere.

Neither binary is honest. The scope exclusion is the finding.


How clearly do these providers separate HIPAA-covered data from everything else?

Answer: Eight of 12 providers publicly mapped medical or protected health information to a specific medical entity or notice and mapped other data to a general or consumer health policy. Form Health was Partial. For Ro, Sesame, and Eden we did not find a sufficiently clear public map. This measures how clearly a company explains the boundary in public documents — not whether HIPAA legally applies to a particular record.

This is the least visible field in the audit and one of the most consequential. Here is why.

Several services in this cohort use more than one legal entity and more than one privacy document: a consumer-facing platform, an affiliated professional medical group, a pharmacy or pharmacy network, and outside vendors. The brand used at signup and the medical entity that maintains a clinical record may be different entities governed by different notices.

That has a direct consequence most patients never see: the same fact about the same person can fall under different legal rules depending on which entity holds it, why it holds it, and what the information reveals. A prescription record in a covered medical group's chart can be PHI. A platform account identifier, public-page visit, or checkout event may be governed by a general policy, a state privacy statute, another federal rule, or some combination of them. The answer cannot be inferred from the fact that the subject is health.

We saw two broad document structures in this cohort.

The split-document structure. A platform policy describes account, website, or service information; an affiliated medical group publishes a separate NPP; and the general policy explains that at least some medical information is governed elsewhere. Hims & Hers, LifeMD, Henry Meds, Mochi Health, and Found describe versions of this structure.

The combined-policy structure. One general policy names or covers multiple platform, clinical, pharmacy, or affiliated entities without giving the reader a clean document-by-document map. Ro's policy collectively addresses several named affiliates. Sesame's policy discusses personal information and protected health information in one document.

Neither structure is automatically better. The audit asks only whether a reader can follow the public explanation.

Six legal layers that can touch health-related data

Table 7. Six legal frameworks that can apply to health-related data from a GLP-1 telehealth service. Educational synthesis only — not a provider-specific legal determination.
LayerWho or what it coversWhat it can provide
HIPAA Privacy, Security, and Breach Notification RulesCovered entities and business associates handling PHIPrivacy and security duties, individual rights, an NPP, and breach notification
State medical confidentiality lawClinical entities and medical records covered by state lawDuties that vary by state and may differ from HIPAA
Comprehensive state consumer privacy lawCovered businesses or controllers and qualifying personal or sensitive dataAccess, deletion, correction, and sale, sharing, or targeted-ad controls that vary by state
State consumer health data lawRegulated entities, small businesses, processors, or covered data as each statute defines themHealth-data policies, consent requirements, deletion, access, and appeal rights, subject to exemptions
FTC Health Breach Notification RuleVendors of personal health records, PHR-related entities, and third-party service providersNotice duties after certain breaches of unsecured PHR-identifiable health information
FTC Act and a company's own privacy promisesConduct within FTC jurisdictionEnforcement against unfair or deceptive practices, including material privacy misrepresentations

Source: HHS HIPAA materials, the FTC Health Breach Notification Rule, Washington RCW 19.373, and Nevada NRS Chapter 603A. This table is an educational synthesis, not a provider-specific legal determination.

A single data point can move between these layers depending on the holder, purpose, context, state, and statutory exemption. “HIPAA-compliant,” standing alone on a marketing page, does not tell you which rule governs every interaction with the service.


What do GLP-1 telehealth privacy policies actually say about advertising?

Answer: All 12 reviewed providers expressly disclosed at least one advertising or analytics category — cookies, pixels, mobile identifiers, analytics providers, behavioral advertising, or targeted advertising. But the disclosures are not equivalent. On the specific statutory question of whether a company sells or shares personal information, providers in this cohort give materially different answers in their own documents. We reviewed policy text only; we did not test which tools are currently deployed or what data they transmit.

Universal disclosure sounds reassuring until you read what is being disclosed. Three examples from the cohort, all verifiable in the linked source documents as they appeared on August 1, 2026.

Hims & Hers (policy dated March 26, 2026) publishes the notice: “We may sell your sensitive personal data.” Its policy names Google DoubleClick, X Advertising, Facebook Audiences, and Google Analytics; says marketing disclosures can include health data or information about sex life to the extent it is not Protected Information; and gives an example involving a visit to a page about balding or erectile-dysfunction treatment. The policy separately says account information such as a name, date of birth, email address, shipping address, and phone number is not Protected Information.

Ro (policy effective April 2, 2026) publishes a category table in which health information and information about sex life or sexual orientation are listed as categories disclosed to advertising partners. The policy says Ro may use treatment-related or similar sensitive data for tailored advertising where permitted, provides an opt-out route, and states that it does not use sensitive personal information for tailored advertising in Maryland, Washington, or Nevada.

LifeMD (policy dated November 17, 2025) states that it had not sold personal information to third parties during the preceding 12 months.

Three public policies. Three materially different statements about sale, sharing, or advertising-related use.

One state-specific rule buried in Ro's general policy

Ro's policy says it does not use sensitive personal information for tailored advertising in Maryland, Washington, or Nevada. Read plainly, the policy describes a state-based difference in treatment: the rules applied to a category of data can depend on where the person lives. That is not evidence of what any particular network request contained. It is a specific statement in the company's own policy, and it shows why a national yes-or-no privacy label loses information.

Why disclosure is not proof of deployment

Everything in this section is a fact about a document. A company that discloses broad advertising permissions may exercise few of them. A company with sparse language may deploy tools the policy describes only generally. Establishing what a website actually transmits requires controlled network capture, documented consent states, and payload analysis. This audit did none of those things.


What privacy controls can GLP-1 telehealth users actually exercise?

Answer: Every one of the 12 reviewed providers exposed at least one route tied to sale, sharing, targeted advertising, or interest-based tracking, and every one provided a public route to access, correct, or delete at least some information. Only 6 of 12 published a process for appealing a denied non-HIPAA privacy request. Available rights and their practical scope varied by state, browser, device, mechanism, data category, identity-verification requirement, and legal exception.

The controls in this cohort fall into four rough types, and they are not interchangeable.

  • Browser-level privacy signals. Hims and Ro expressly identify Global Privacy Control as one way to communicate covered opt-out choices. Whether the signal creates a legally enforceable result depends on the applicable law and the provider's processing. Global Privacy Control is separate from the older Do Not Track signal; Hims, for example, says it does not respond to Do Not Track.
  • Site-level choice pages. These are commonly labeled “Your Privacy Choices” or “Do Not Sell or Share My Personal Information.” Ro publishes a dedicated choice route; Hims uses a privacy portal; LifeMD provides a CCPA request form and additional contact methods.
  • Cookie or device controls. These can affect a browser or device but may not cover account data, offline disclosures, authenticated activity, or every third party.
  • Request forms, email addresses, and phone routes. These are used for access, correction, deletion, and — where offered — appeal.

The appeal gap is the notable one. Six of 12 providers published a non-HIPAA appeal route; for the other six, no qualifying route was found in the reviewed public materials. An appeal route matters because a request can be denied where identity cannot be verified, an exemption applies, another person's rights are implicated, or retention is required by law.

Two of the six appeal routes were explicitly jurisdiction-specific in the reviewed materials. Found's Colorado notice explains an appeal and a next step involving the state attorney general. WeightWatchers describes an appeal route for Colorado, Connecticut, and Virginia residents. Those are real public routes, but they are not universal promises to every user in every state.


What should you check before entering health information into a GLP-1 telehealth site?

Answer: Check five things before an intake form: the date and scope of the general policy, the public medical privacy notice, the boundary between the platform and the medical group, the consumer-health notice for non-HIPAA data, and the actual request and appeal routes. No single badge or sentence replaces that five-document check.

Table 8. Five-part public-document check before entering health information into a GLP-1 telehealth site.
CheckWhat to look forWhy it matters
1. General policy date and named entitiesA visible date and a list of the companies or affiliates the policy coversA brand name can sit above several legal entities and several revision cycles
2. Public NPP or equivalent medical noticeThe covered medical group, permitted uses and disclosures, patient rights, complaint route, and effective dateThis is the notice governing PHI for the covered entity named in it
3. HIPAA / non-HIPAA boundaryA direct explanation of which information goes to the medical group and which remains with the platformThe same intake journey can generate data governed by different rules
4. Consumer-health noticeData categories, sources, recipients, purposes, consent, deletion, and appeal languageState consumer-health law may govern information outside a HIPAA medical record
5. Working controlsSale/share or targeted-ad choice, access/deletion route, and appeal instructionsA right described without a usable route is harder to exercise

Framework: Weight Loss Provider Guide Research, derived from the nine-field audit codebook and the provider documents reviewed August 1, 2026.

A privacy seal, the word “secure,” or a statement that a service uses “HIPAA-compliant technology” does not answer all five questions. Read the entity names and scope language, not just the headline promise.


What does HIPAA cover, and what falls outside it?

Answer: HIPAA applies to covered health care providers, health plans, health care clearinghouses, and their business associates handling protected health information. It does not automatically govern every health-related website visit, marketing interaction, or company that touches health-related information. The FTC Health Breach Notification Rule and state consumer health laws can reach some entities and data outside HIPAA, but whether any rule applies in a given case depends on facts this audit does not establish.

HIPAA and telehealth

The U.S. Department of Health and Human Services states that telehealth services provided by covered health care providers and health plans must comply with the HIPAA Rules in the same way as other covered services. See HHS telehealth guidance.

HHS also publishes guidance on online tracking technologies used by HIPAA covered entities and business associates. The guidance discusses tools such as cookies, pixels, web beacons, session-replay scripts, and device identifiers and explains the obligations of regulated entities when PHI is involved. See the HHS/OCR tracking guidance.

There is a material limitation on that guidance. HHS states that on June 20, 2024, a federal court vacated the portion that treated the combination of an IP address and a visit to an unauthenticated public webpage about a health condition or provider as automatically triggering HIPAA obligations. That limitation matters. A public-page visit plus an IP address should not be described as automatically constituting PHI under the vacated theory.

The word doing the work is regulated. HIPAA depends on the entity, information, and context — not merely the fact that the subject is health.

The FTC Health Breach Notification Rule

The FTC Health Breach Notification Rule applies to vendors of personal health records, PHR-related entities, and third-party service providers covered by the rule. Vendors and PHR-related entities must notify affected people, the FTC, and in some cases the media after certain breaches of unsecured PHR-identifiable health information; covered third-party service providers must notify the vendor or PHR-related entity they serve. The 2024 amendments clarified the rule's coverage of many health apps and similar technologies outside HIPAA and clarified that a breach can include an unauthorized disclosure, not only a security intrusion. The amendments took effect July 29, 2024. See the final rule.

The rule is not a generic label for every platform company. Coverage depends on the rule's definitions, including whether the product or service is a personal health record drawing information from multiple sources and whether the entity is a vendor, related entity, or covered service provider.

State consumer health laws

Washington's My Health My Data Act gives covered consumers rights involving access, withdrawal of consent, deletion, and appeal. It also requires covered entities and small businesses to publish consumer health data privacy policies, subject to the statute's scope and exemptions. A violation is treated as an unfair or deceptive act under Washington's Consumer Protection Act. Nevada's consumer health law likewise requires regulated entities to publish a policy and creates request and appeal procedures. See Washington RCW 19.373 and Nevada NRS Chapter 603A.

Five providers in this cohort published a separate qualifying notice; one additional provider published a notice that excluded its clinic patients. For the other six, no separate notice was found through the review protocol. That is a disclosure finding, not a conclusion that a statute applies or was violated.

This section is educational and is not legal advice. Whether a statute applies to a provider, interaction, or record is a fact-specific question for a qualified attorney or the relevant regulator.


Why does GLP-1 telehealth privacy matter right now?

Answer: Health-data advertising has drawn sustained federal enforcement since 2023, and on July 29, 2026 the FTC and state and local partners filed a complaint alleging that Hims shared sensitive health information with advertising platforms. Hims disputes the claims, and the case has not been decided. A prominent technical investigation of direct-to-consumer telehealth tracking was published in 2022, but it was not a 2026 GLP-1-specific measurement. This audit supplies a current documentary baseline, not a replacement for technical testing.

The current case

On July 29, 2026, the Federal Trade Commission — joined by Utah and California acting through Los Angeles County Counsel — filed a complaint in the U.S. District Court for the Northern District of California against Hims & Hers Health, Inc. See the FTC announcement.

The complaint alleges that Hims shared consumers' sensitive health information with Meta, Snap, and other third parties through customer lists and third-party tracking technologies that transmitted website “Events.” It also alleges deceptive billing and subscription-cancellation practices. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act; Utah alleges violations of the Utah Consumer Sales Practices Act; California alleges violations of its false advertising and unfair competition laws. The Commission vote authorizing the complaint was 2-0.

These are allegations, not findings. The FTC states that the case will be decided by the court. Hims says the lawsuit disregards evidence, disputes the claims, and will be vigorously defended. See the Hims response.

We did not change any audit determination because of the complaint, and there is no “privacy violation” field in this dataset. A pending complaint is not a measurement.

A precision note on the plaintiffs: the FTC's announcement says it was joined by Utah and California, by and through Los Angeles County Counsel.

Federal health-data advertising actions, 2021–2026

Table 9. Selected federal health-data privacy actions relevant to advertising and tracking, 2021–2026.
DateActionDocumented result or status
Sept. 15, 2021FTC policy statement on health apps and connected devicesWarned health apps and connected-device companies about Health Breach Notification Rule obligations
Dec. 2022HHS/OCR bulletin on online tracking technologiesGuidance for HIPAA regulated entities; one unauthenticated-public-page theory was vacated by a federal court in June 2024
Feb. 2023GoodRxFirst FTC Health Breach Notification Rule enforcement; court-entered order and $1.5 million civil penalty
July 2023BetterHelpFinal FTC order; $7.8 million for consumer refunds and restrictions on health-data advertising disclosures
June 2023Easy Healthcare / PremomCourt-entered federal order with a $100,000 civil penalty
Apr. 2024CerebralCerebral agreed to restrictions and more than $7 million in payments; the FTC case page remains listed as pending
June 2024MonumentStipulated order filed; $2.5 million civil penalty suspended based on inability to pay; case page listed as pending
July 29, 2024Health Breach Notification Rule amendmentsAmendments took effect, clarifying scope and unauthorized-disclosure coverage
July 29, 2026FTC, Utah, and California v. Hims & Hers Health, Inc.Complaint filed; allegations disputed and not decided

Source: the official FTC, HHS, Federal Register, and case-page links in the table, verified August 1, 2026.

One point from that history is directly relevant to advertising-partner matching. In the BetterHelp matter, the FTC alleged that hashing an email address did not make the information anonymous where an advertising platform could match the hash to a user account. Several policies in this cohort describe advertising-partner matching or disclosure of identifiers. The legal significance depends on the facts; the enforcement history explains why the mechanics matter.

What the 2022 technical investigation measured

A joint investigation by The Markup and STAT, published December 13, 2022, created dummy accounts and used Chrome DevTools to inspect network traffic while completing onboarding flows on 50 direct-to-consumer telehealth sites. The investigation reported that 49 of 50 sites sent visited URLs and IP addresses to at least one outside technology company; 13 had a tracker collecting answers to medical intake questions; and 25 sent a cart or subscription-checkout event to at least one large technology platform. See the original investigation.

That was a technical traffic study. This is a public-document study. The cohorts, dates, and methods are different, so the numbers should not be merged or treated as directly comparable. The 2022 findings are not a measurement of this 12-provider cohort in 2026.


Provider-by-provider source notes

Each note identifies the documents reviewed, the reasoning behind any Partial or Not found status, and the material scope limits. These notes are descriptive. They do not label any provider compliant, noncompliant, secure, unsafe, trustworthy, or untrustworthy.

Hims & Hers

All nine fields Found. General policy dated March 26, 2026. A no-login Medical Groups Notice of Privacy Practices and a separate consumer health data policy are public. The consumer health policy says HIPAA PHI is governed by the NPP, and the general policy distinguishes platform and account information from medical-group Protected Information. This is an operator-level row using the shared Hims & Hers policy set; the GLP-1 program page reviewed was the Hims weight-loss page.

General policy · NPP · Consumer health policy

Ro

General policy effective April 2, 2026; separate consumer health data policy dated September 23, 2025. NPP marked Not found: the reviewed pages refer readers to privacy practices of physicians and other third parties, but we did not identify a no-login Ro NPP. Boundary marked Not found: the public materials do not clearly map which Ro, medical-provider, and affiliate data fall under which regime. Both are disclosure-clarity determinations, not legal conclusions.

General policy · Consumer health policy

Noom Med

Audited within Noom's public legal-document set. General policy dated October 1, 2024 — 669 days before verification. Public HIPAA notice and consumer health data notice both available. Appeal route marked Not found: no express non-HIPAA denied-request appeal process was identified in the reviewed general or consumer-health notices.

General policy · HIPAA notice · Consumer health notice

WeightWatchers Clinic

Dated policy marked Not found: the general policy refers to a Last Updated legend, but no date for the general policy was visible on the reviewed page. A separate biometric-policy date was not counted. Consumer health notice marked Partial: the statement exists but expressly excludes WeightWatchers Clinic patients and directs them to the clinic NPP. The NPP names the clinic entities and says it covers clinic PHI rather than non-PHI site-visitor information. Appeal route Found for Colorado, Connecticut, and Virginia residents.

General policy · Clinic NPP · Consumer health statement

Found

General policy dated August 2, 2024 — the oldest dated general policy in the cohort at 729 days. Public NPP available with an effective date of November 13, 2024. The general policy says HIPAA-maintained information is governed by the separate NPP. The targeted-advertising opt-out and denied-request appeal route are located in the Colorado resident notice and are jurisdiction-specific.

General policy · NPP · Colorado notice

Form Health

General policy dated June 11, 2026. A public Medical Privacy Policy was coded as an NPP-equivalent notice for the affiliated professional entity. Boundary marked Partial: separate general and medical notices exist and professional entities are named, but the public materials do not provide a clean end-to-end map of which data falls under each document. Retention and appeal route both marked Not found.

General policy · Medical privacy policy

LifeMD

General policy dated November 17, 2025. Public NPP available. The policy distinguishes general site information from medical information handled by health care providers and describes circumstances in which LifeMD is not a covered entity. Consumer health notice and appeal route both marked Not found. The public rights route includes a CCPA request form.

General policy · NPP · CCPA rights form

PlushCare

All nine fields Found. General policy dated December 15, 2025. Current documents are published under Transcarent and affiliated-company privacy materials, with PlushCare-specific clinical entities named in the NPP. A separate consumer health data policy is public. The documents distinguish general site or account information from clinical PHI.

General policy · NPP · Consumer health policy

Sesame

General policy dated September 23, 2024 — 677 days before verification. NPP, consumer health notice, and boundary clarity all marked Not found: the general policy addresses both personally identifiable information and PHI, but we did not identify a separate no-login NPP, a separate consumer health notice, or a clear public statement mapping each category to a governing document. Appeal route marked Not found.

General policy

Mochi Health

General policy dated March 12, 2026. Boundary marked Found: the policy expressly says it does not govern medical-group PHI and that an NPP governs that information. NPP marked Not found because we did not locate that notice as a no-login document. Consumer health notice and appeal route both marked Not found.

General policy

Henry Meds

General policy dated June 25, 2026 — the newest dated general policy in the cohort at 37 days. Public NPP available, showing a May 6, 2026 date. The general policy expressly says the separate NPP governs PHI. Retention and appeal route both marked Not found. The state privacy notice and cookie controls provide routes tied to advertising, sharing, and other privacy choices.

General policy · NPP · State privacy notice

Eden

General policy effective January 30, 2026. A separate Washington My Health My Data policy is public, and the general policy provides an express data-rights appeal email process. NPP marked Not found. Boundary marked Not found: the reviewed policies discuss health information and third-party providers but do not clearly map PHI against non-HIPAA data.

General policy · My Health My Data policy


Limitations

We publish these prominently because they determine what this dataset can honestly support.

  1. No accounts were created.
  2. No intake forms were completed or submitted.
  3. No authenticated portals were reviewed.
  4. No mobile apps were tested.
  5. No email-delivered or account-only notices were reviewed.
  6. No network traffic was inspected.
  7. No cookies, SDKs, pixels, or transmitted payloads were technically tested.
  8. No consent-state testing was performed.
  9. No penetration testing or security assessment was performed.
  10. No contracts or business associate agreements were reviewed.
  11. No legal conclusion was reached about any provider.
  12. Public policy text may differ from operational practice.
  13. Public pages may have changed after August 1, 2026.
  14. Brands may work with separate medical groups, pharmacies, laboratories, and affiliates governed by different documents than the ones reviewed.
  15. The 12-provider cohort is purposive, not statistically representative.
  16. A Not found result is not evidence of a statutory violation.

A further caution on the boundary-clarity field: it is the only field requiring meaningful reviewer judgment about whether a public explanation is sufficiently clear. The decision rule is published, and every Partial and Not found result was rechecked during the final audit, but boundary clarity remains more judgment-dependent than the eight document-or-route fields.

This research is educational. It is not medical, legal, cybersecurity, or privacy-compliance advice. Questions about your records, rights, or care should go to a qualified professional or the relevant regulator.


Frequently asked questions about GLP-1 telehealth privacy

Are all GLP-1 telehealth companies covered by HIPAA?

No. HIPAA applies to covered health care providers, health plans, health care clearinghouses, and their business associates handling protected health information. Several direct-to-consumer telehealth services in this cohort use a platform company alongside a separate affiliated medical group. Whether HIPAA covers a specific record depends on the entity, information, purpose, and context.

Does publishing a HIPAA notice mean a telehealth provider is secure?

No. A Notice of Privacy Practices explains permitted uses and disclosures of PHI, patient rights, and the covered entity's duties. It does not measure encryption, access controls, breach history, vendor management, or live website technology. In this audit, 8 of 12 providers published a no-login NPP or equivalent notice.

Can a telehealth privacy policy permit targeted advertising using health-related information?

Some reviewed policies expressly describe advertising uses or disclosures involving health-related or sensitive personal information outside the policy's PHI category. Hims states that certain non-Protected health-related data may be disclosed to advertising partners; Ro lists health information in an advertising-partner category and describes state-specific limits. Those are document disclosures, not proof of current data transmission.

What is a consumer health data privacy notice?

It is a public notice required by certain state consumer-health laws for covered or regulated entities. Depending on the statute, it can describe the health data collected, sources, purposes, recipients, consent, deletion, access, and appeal rights. Five providers in this audit published a qualifying separate notice; WeightWatchers published one that expressly excluded Clinic patients.

What does "not found in reviewed public materials" mean?

It means we did not locate the document, control, or process through the documented no-login protocol: official program and legal pages, footer navigation, and targeted searches on the provider's own domain. It does not mean the item does not exist. It may be delivered after signup, live behind an account, carry an unexpected title, or sit somewhere the protocol did not reach.

Does this audit test tracking pixels or actual data sharing?

No. We reviewed published documents. We did not capture network traffic, test consent implementations, or inspect transmitted payloads. Establishing what a site actually sends requires a separate technical study.

Why is there no overall privacy score?

Because the nine fields measure different things and document availability is not a proxy for conduct. Hims returned Found on all nine fields, tied with PlushCare for the highest count, and became the defendant in a disputed federal privacy case three days before the audit. Blending document completeness and actual conduct into one number would imply evidence the audit does not contain.

How often will this audit be updated?

Provider policy URLs and visible dates are checked monthly; the full field set is re-reviewed quarterly; and a numbered edition is rebuilt annually, with prior editions preserved. Enforcement context is updated when a material complaint, order, rule, guidance change, or court decision occurs. The visible verification date changes only after genuine re-verification.

Can a company deny a privacy request?

Yes, where applicable law permits it. Public policies commonly identify reasons such as failure to verify identity, another person's rights, a legal retention obligation, or an applicable exemption. Hims, for example, lists those kinds of grounds and provides an appeal route after a denial. The available reasons and appeal rights vary by jurisdiction and data type.


How to cite this page

Citation format

WPG Research Team. “GLP-1 Telehealth Privacy Audit: Public Disclosures From 12 Providers (2026).” Weight Loss Provider Guide Research. Last updated August 1, 2026. https://weightlossproviderguide.com/research/glp-1-telehealth-privacy-audit/

Dataset

The dataset, evidence ledger, and methodology are available without registration.

Corrections. If a determination is corrected after publication, the change will be identified in the public version history rather than made as a silent edit.

Version history

Table 10. Version history for the GLP-1 Telehealth Privacy Audit dataset.
VersionDateChange
1.0.0August 1, 2026First edition. 12 providers, 9 fields, 108 determinations.

About this research

Weight Loss Provider Guide Research is an independent research and reference resource covering access, coverage, cost, corporate activity, and policy for medical weight-management care. This page contains no affiliate links, provider grades, lead routing, or commercial recommendations.