Your weight loss journey is also a data pipeline for retailers

TL;DR
Does filling out a GLP-1 telehealth intake form send my data to advertisers?
Often yes. Tracking scripts embedded in intake and checkout pages capture form entries, IP addresses, and device data, then pass them to ad networks like Meta, Google, and TikTok.
Is that legal under HIPAA?
It depends on the page. Authenticated patient portals and intake forms are still covered by HIPAA. Unauthenticated public pages are not automatically covered under HIPAA just because a visitor’s IP address is logged, after a 2024 court ruling.
Can retailers really tell I’m on a GLP-1 medication and target me for clothes?
Yes. Data brokers combine browsing signals, app activity, and loyalty card data into audience segments with names like “Active Weight Loss Seekers,” which retail advertisers then bid on directly.
What is bracket shopping, and why does it matter here?
It’s ordering the same item in multiple sizes to try on at home and return what doesn’t fit. GLP-1-driven weight loss makes this common, and it’s a major driver of apparel return costs across the industry.
Have telehealth companies actually been sued over this?
Yes. Teladoc is currently defending a federal wiretapping and privacy case in New York, and firms including Henry Meds and MEDVi have faced investigations over tracking pixels on intake pages.
What is Washington’s My Health My Data Act?
A 2024 state law that treats inferred health status, not just clinical records, as protected data, and bans geofencing within 2,000 feet of health facilities for tracking or ad targeting.
How much have healthcare organizations paid out over pixel tracking so far?
Over $100 million between 2023 and 2025, including an $18.4 million settlement from Mass General Brigham and a $12.225 million settlement from Advocate Aurora Health.
Breaking news: GLP-1 users tend to buy more clothes. Shocking, right?
That’s not really the interesting part. Firms like 84.51°, NielsenIQ, and Circana have already published the consumer behavior data confirming what common sense would tell you: people who lose a lot of weight need new pants. What’s worth sitting with is the machinery underneath that finding. How does a person filling out a symptom questionnaire on a telehealth site turn into a line item in a retail advertiser’s targeting dashboard, and how fast does that happen?
We started digging into this because it sits at a genuine crossroads for two industries we work in, healthcare and technology, and because GLP-1 has become impossible to avoid in ordinary conversation. That made us curious about something more specific: do people actually understand what happens to their data once it leaves a clinical intake form? Health information feels like it should sit behind one of the more locked-down doors on the internet. As it turns out, that assumption doesn’t hold up nearly as well as most people think, even inside what looks like a gated garden.
How intake forms turn into ad data
For most of the last decade, digital health platforms relied on client-side tracking pixels: small pieces of JavaScript from Meta, Google, TikTok, Snapchat, or Microsoft, dropped directly into a webpage. When someone visits a telehealth portal, fills out a medical intake questionnaire, or books a consultation, those scripts fire automatically in the browser. They capture URL parameters, form field entries, button clicks, IP addresses, and device fingerprints, then send it all back to the ad platform.
A Rutgers University study published in PNAS Nexus looked at 1,201 U.S. hospital websites between 2012 and 2023. It found that 66% actively deployed third-party tracking pixels, while only 14% had switched to privacy-preserving first-party alternatives. The same study tied third-party pixel deployment to a 46% increase in overall data breach risk and a 13% increase in unintended disclosures of sensitive patient information.
Partly in response to browser privacy controls and ad blockers, many platforms have shifted to server-side tracking, using tools like Meta’s Conversions API or Google’s server-side Tag Manager. In this setup, data routes from the browser to the health platform’s own server before being forwarded to the ad network’s API, which sounds more private. In practice, it introduces its own problem: personal identifiers like email and phone number get run through SHA-256 hashing before transmission, but because that hashing is deterministic, ad networks can match the hash against their own user databases and re-identify the person instantly. If the payload includes a conversion event tied to a clinical action, like completing a symptom assessment or a semaglutide subscription, the ad platform now has that pharmaceutical activity attached to a named commercial profile.
Telehealth companies are already being sued over this
Legal filings and investigative reporting have named several direct-to-consumer telehealth providers, including Remedy Meds, Fridays, Remmy, Henry Meds, and MEDVi, for embedding ad network trackers directly on pages where patients disclose weight, BMI, metabolic conditions, and formulation preferences. Patients who complete these forms routinely describe getting hit with retargeted ads on social media almost immediately, matching the exact conditions or drug preferences they just typed in.
The clearest legal test case so far is the Teladoc Health privacy litigation, filed in the Southern District of New York in June 2025. Plaintiffs alleged Teladoc used tracking pixels and server-side conversion APIs to send protected health data to third-party ad networks for marketing purposes. The court denied Teladoc’s motion to dismiss and let eight claims move forward, including a federal wiretapping claim under the Electronic Communications Privacy Act. The judge’s reasoning is worth sitting with: the court found Teladoc was acting as a healthcare provider, not a neutral tech platform, and that using tracking tools to harvest health data for marketing created what the ruling described as an independent criminal purpose under HIPAA, which knocked out Teladoc’s one-party consent defense.
Where the data goes after it leaves the clinic
Once health telemetry leaves the clinical environment, commercial data brokers and identity resolution platforms take over. Using deterministic and probabilistic matching, they connect a person’s digital and physical touchpoints into a single cross-device profile: browsing logs, app usage, loyalty card purchases, all stitched together.
When someone is flagged as starting GLP-1 therapy, that signal gets folded into demographic files to build custom audience segments. These get names like “Active Weight Loss Seekers” or “Rapid Sizing Transitions” and are loaded into demand-side platforms, where retail advertisers bid on them in real-time programmatic auctions across connected TV, social media, and display ads.
Why retailers are chasing this specific audience
The economics here are straightforward once you see the underlying behavior shift. Rapid weight loss from GLP-1 therapy forces people to replace clothing across several sizing phases within a 6 to 12 month window, a pattern retailers call wardrobe obsolescence. That sizing uncertainty drives what the industry calls bracket shopping: ordering a garment in Small, Medium, and Large at once, trying everything on at home, and returning what doesn’t fit.
Bracket shopping inflates a retailer’s initial order value, which looks good on a dashboard, but it comes with real back-end costs. Industry data shows 42% of all e-commerce returns stem directly from sizing mismatches, and apparel returns tied to fit alone reach 70%. To manage that friction while still capturing sales, fashion brands lean on ad-tech to serve targeted sizing promotions, stretch-fabric campaigns, and virtual fitting tools like 3DLOOK’s YourFit, all aimed at people whose body measurements are actively changing.
It doesn’t stop at clothes
Grocery and CPG brands are watching the same signal. NielsenIQ consumer panel data shows GLP-1 users are 1.5 times more likely to shop online grocery and club channels, and 1.7 times more likely to use grocery delivery, compared to non-users. As appetite suppression drives down overall grocery volume, spending shifts toward high-protein foods, nutrient-dense items, and premium personal care.
Side effects are a targeting category too. Roughly 70% of GLP-1 users report gastrointestinal discomfort, and that discomfort is a major reason 58% of patients discontinue therapy within 3 to 12 months. Advertisers treat that drop-off as a retention problem to solve with ads: a Digitas campaign built around GLP-1 users experiencing GI symptoms reportedly achieved a 47% higher conversion rate, a 7-point increase in brand consideration, and double the return on ad spend compared to baseline wellness campaigns. Six months of sustained use can also trigger cross-device matching into higher-income luxury, cosmetics, and body contouring segments, assuming people who hit their weight goals are ready to spend more on how they look.
The regulatory patchwork trying to catch up
For years, healthcare organizations assumed public, unauthenticated web pages sat entirely outside HIPAA. In December 2022, and again in a March 2024 revision, HHS’s Office for Civil Rights said otherwise: connecting an IP address or device ID to a visit on a page about a specific medical condition counted as an impermissible PHI disclosure.
The hospital industry pushed back in American Hospital Association v. Becerra. In June 2024, a federal court in the Northern District of Texas ruled that OCR had overstepped its authority and vacated that guidance, on the reasoning that an IP address plus a public page visit doesn’t prove someone is seeking care for themselves rather than just researching. HHS dropped its appeal in August 2024, making the ruling final.
The ruling is narrower than a lot of marketing teams assume. It only limits federal HIPAA enforcement on unauthenticated public pages. Authenticated portals, login-gated telehealth platforms, and intake forms are untouched, still fully covered by HIPAA, and still require a signed business associate agreement. The ruling also does nothing to block state wiretap claims or consumer protection lawsuits, which is exactly the gap the Teladoc case is testing.
That gap has already cost real money. Between 2023 and 2025, healthcare organizations paid over $100 million in settlements and penalties tied to tracking pixels, including Mass General Brigham ($18.4 million), Advocate Aurora Health ($12.225 million), Duke Health ($3.7 million), University of Rochester Medical Center ($2.85 million), and WakeMed ($2.45 million).
Where HIPAA doesn’t reach, the FTC has stepped in through its Health Breach Notification Rule, updated in 2024 to explicitly cover health apps and wellness platforms. Disclosing health data to ad networks without opt-in consent counts as a breach and a deceptive trade practice. Recent enforcement includes BetterHelp ($7.8 million, for sharing mental health intake data with social platforms), Cerebral ($7.1 million), GoodRx ($1.5 million plus a permanent ban on sharing prescription data with advertisers), and fertility app Premom ($100,000, for sending user data to non-U.S. ad networks). Separately, the FDA has been cracking down on marketing: it sent thousands of warning letters and roughly 100 cease-and-desist orders over misleading GLP-1 promotions in September 2025, then followed up in March 2026 with warning letters to 30 telehealth providers for illegally marketing compounded semaglutide and tirzepatide as equivalent to FDA-approved brands.
States are moving faster than either agency. Washington’s My Health My Data Act, in effect since 2024 alongside a similar Nevada law, defines “consumer health data” broadly enough to cover inferred information: if a broker infers GLP-1 use from ordinary browsing behavior, that inference is regulated the same as a medical record. The law requires separate opt-in consent for collecting versus sharing health data, bans geofencing within 2,000 feet of any healthcare facility for tracking or ad delivery, and gives individuals a private right of action to sue directly.
What compliant data practices actually look like
For platforms trying to get this right, the fix isn’t complicated in concept, even if it’s a real engineering lift. It comes down to five controls: run quarterly audits cataloging every pixel, SDK, and script on every page, and where each one sends data; strip client-side third-party scripts entirely off intake forms, symptom tools, and any authenticated portal; route outbound data through first-party server-side gateways with automated filters that redact condition-revealing URLs and form entries before anything leaves the building; sign a business associate agreement with every vendor touching identifiable data, and cut off any vendor that won’t sign one; and deploy a consent management platform that blocks non-essential tracking until a user opts in, with a timestamped log to prove it.
Why this one caught our attention
Someone scrolls social media, sees an ad for a familiar GLP-1 brand, and clicks through. They fill out an intake form assuming there’s a doctor’s office on the other end, private in the same way a conversation in a waiting room is private. That assumption is exactly what this piece has been testing.
None of what’s described above requires anyone to break the law, which is probably the most uncomfortable detail in the whole system. A tracking pixel on an intake page is defensible on its own. A hashed email address is defensible on its own. A data broker’s inferred audience segment is defensible on its own.
Stack all three together, though, and a private medical decision turns into a retail targeting profile before a prescription ever gets filled. Every settlement and lawsuit named above happened after that stacking was already routine, not before it. The guardrails get built in response, one court ruling and one state law at a time, while intake forms keep collecting data in real time.
Assuming that a weight loss ad, a wellness quiz, or a symptom checker treats your answers as private is the riskier bet. Assuming the opposite, that anything typed into one of these forms gets read by more than a clinician, is simply the more accurate read of how the system was actually built.
That’s why we’re covering it here. Healthcare and technology keep converging in exactly this way, and GLP-1 just made the pattern easy to see. STEM Search Group works across both of those industries, and the rest of the STEM landscape they touch, and crossroads like this one are what we’ll keep writing about. Tune in for more on where these industries collide, and consider this our own low-budget version of a “The More You Know” moment, shooting star included.
Sources
- FDA, HHS Taking Action Against Telehealth’s Compounded Drug Advertising
- Build Stronger Connections with GLP-1 Shoppers: 84.51°
- Who Is the GLP-1 Consumer? Data on 58,000 U.S. Adults: Morning Consult
- Marketing to GLP-1 Users: Insights from NielsenIQ’s Shopper Data
- Weight Loss Medication Telehealth Pixel Tracking Investigation: Chimicles
- Healthcare Tracking-Pixel Litigation Signals Continued Challenges: Duane Morris
- FTC Pixel Crackdown: How to Secure Your Healthcare Meta Ads
- Pixel Tracking Violations Cost US Healthcare $100M+: Feroot
- Pixels, HIPAA, and the HHS: A Healthcare Marketer’s Guide: Matchnode
- So, What’s “Consumer Health Data,” Anyway?: Faegre Drinker
- Target Audiences Not Created, Built: Digitas
- Virtual Fitting Room For eCommerce: Retail’s Best Way Forward: 3DLOOK
- Beyond the click: Pixel tracking technologies and patient data: PMC
- Third-party tracking pixels raise hospital breach risk by 46%: Paubox
- American Hospital Assn. v. Becerra: Are Tracking Tools OK Again: Holland & Knight
- HHS will not appeal AHA court victory in online tracking case: AHA
- Protecting Washingtonians’ Personal Health Data and Privacy: WA AG
- FDA Warns 30 Telehealth Companies Against Illegal Marketing of Compounded GLP-1s
- The Pixel Problem: Advertising Triggers Health Data Obligations: Holland & Knight