Telehealth companies, which provide medical services online, are under growing scrutiny from government regulators who accuse them of misleading consumers and mishandling personal health data. The Federal Trade Commission (FTC), a U.S. agency that protects consumers from deceptive practices, has filed a lawsuit against Hims & Hers, a major telehealth company. The FTC claims Hims violated consumer protection laws by automatically enrolling customers in recurring prescription plans with limited chances to review or opt out. The company also allegedly bypassed real-time doctor consultations, which are typically required for certain treatments. Hims has denied the allegations, calling them an attempt to create media attention at its expense. This is not the first time the FTC has taken action against telehealth companies. Similar lawsuits have been filed against BetterHelp, an online therapy service, and GoodRx, a pharmacy discount platform. In those cases, the FTC alleged that these companies shared users’ health data with companies like Meta and Google without permission. However, federal laws like HIPAA, which protect health information, generally do not apply to telehealth companies. This legal gap allows such data sharing to occur without strict oversight. The FTC’s lawsuit against Hims highlights a broader trend in the telehealth industry. Many companies offer injectable weight-loss drugs, which usually require a physical exam and other precautions. However, research shows that most telehealth companies do not require real-time video or audio consultations with doctors before approving prescriptions. In some cases, prescriptions were approved within minutes, with little opportunity for patients to review or question the treatment. Dr. Reshma Ramachandran of Yale University, who studied the issue, said that accessing these drugs was “incredibly easy,” with most prescriptions being automatically sent without the chance to stop the process. Consumers often assume that HIPAA, the federal law that protects medical information, applies to all health-related businesses. However, HIPAA typically covers hospitals, doctors’ offices, and insurers, but not telehealth companies offering online prescriptions or counseling. As a result, these companies can share sensitive health data with third parties like advertisers and search engines. The FTC has used its authority to target companies that claim they will keep user data private but then share it anyway. Experts say that while some states have passed new privacy laws to protect health information, enforcement against telehealth companies remains limited. Consumers are advised to use privacy tools like ad blockers and private browsing modes when using telehealth websites. They should also read user agreements carefully, as some sites explicitly state the right to sell data about users’ health and personal lives. However, experts say the current system places too much responsibility on consumers to understand and manage their data privacy.