Quick answer

In April 2024, a telehealth company named Cerebral was ordered to pay more than $7 million for sharing its patients’ mental health data with advertising platforms. Almost everyone who hears the story assumes OCR brought it. OCR did not. This was the Federal Trade Commission, filed through the Department of Justice, using authority that has nothing to do with HIPAA. That single fact is the lesson for every small practice: the office you have been told to fear is not the only one watching, and the others do not need HIPAA to reach you.

Here is what happened, and why a mental health startup’s mistakes should change how a small practice thinks about the code running on its website.

What did Cerebral actually do?

Cerebral is an online mental health service. People signed up, answered detailed questions about their symptoms and treatment, and handed over the kind of information you only give a provider you trust. According to the FTC’s announcement, the company promised that data would be kept confidential.

It was not. The FTC’s complaint charges that Cerebral sent the sensitive information of nearly 3.2 million people to third parties including LinkedIn, Snapchat, and TikTok, by placing tracking tools on its website and apps. Those tools quietly forwarded names, medical and prescription histories, home and email addresses, birthdates, IP addresses, and pharmacy and insurance details to the platforms, so the platforms could target ads. The company buried its actual data-sharing in dense privacy policies while telling users, in many cases, that it would not share their data for marketing without consent.

The security was careless in old-fashioned ways too. The complaint describes over 6,000 promotional postcards mailed without envelopes, carrying language that appeared to reveal patients’ diagnoses to anyone who saw them. It describes former employees who kept access to electronic medical records for months after leaving, and a sign-on system that in some cases showed one patient’s file to another. FTC Chair Lina Khan summed up the charge as Cerebral “revealing their most sensitive mental health conditions across the Internet and in the mail.”

Why the FTC, and not OCR?

This is the part small practices miss. OCR enforces HIPAA. The FTC enforces against unfair and deceptive business practices under its own, separate authority. When a company tells the public one thing about privacy and does another, that is deception, and the FTC does not need HIPAA to act on it.

So the FTC referred the case to the Department of Justice, which filed the order in the Southern District of Florida. Cerebral agreed to pay more than $7 million: roughly $5.1 million to refund consumers caught by its deceptive cancellation process, plus a $10 million civil penalty that was suspended after a $2 million payment because the company could not afford the full amount. The order also imposed a first-of-its-kind ban: Cerebral is prohibited from using any health information for most advertising purposes, and generally must get consent before disclosing it.

Read that penalty structure again. The dollars are almost beside the point. The lasting cost is a permanent restriction on how the company is allowed to operate, written by a regulator most healthcare businesses were not watching for.

Didn’t a Texas court just kill the tracking-pixel issue?

Partly, and only on one side. This is where a lot of practice owners have drawn the wrong conclusion.

OCR had issued guidance treating a broad range of website tracking as a HIPAA problem, including cases where someone who was not even a patient visited a public health page. Hospitals sued. In American Hospital Association v. Becerra, a federal court in the Northern District of Texas ruled on June 20, 2024 that OCR had exceeded its authority, and vacated the key part of that guidance. HHS withdrew its appeal that August, making the loss final.

It would be easy to read that as “tracking pixels are fine now.” They are not. The Texas ruling trimmed one specific OCR position under HIPAA. It did nothing to the FTC, which brought the Cerebral case under different law entirely. It did nothing to state attorneys general, and nothing to the class-action lawyers who have filed a wave of pixel suits. The HIPAA door narrowed slightly. The other three doors are wide open, and the FTC has made health-data-to-advertiser sharing a running priority, not a one-time case.

For a Texas practice, that distinction matters twice over. The court that limited OCR sits in Texas, and the state attorney general who can act where OCR cannot is in Austin.

What a small practice should actually do

You are not Cerebral. You probably are not selling data to TikTok on purpose. That is exactly why this is dangerous: the leak is almost never intentional. It is a marketing pixel a web designer added in 2021, a chat widget, an analytics tag, a “book appointment” button that phones home to a vendor. Nobody decided to share patient data. The code just does.

Three moves close most of the gap:

First, map the third-party code on your website and patient portal. List every pixel, script, analytics tool, and embedded widget, and find out what each one sends and where. Most owners are genuinely surprised by the answer.

Second, fix the leaks before you fix the paperwork. Anything that transmits patient information, or even the fact that someone booked a certain kind of appointment, needs either a signed business associate agreement with that vendor or valid consent from the patient, or it needs to come off the site.

Third, write it down. This inventory is not a side project. It is part of a real HIPAA Risk Analysis, the same document OCR asks for first and the gap cited in roughly 90 percent of its Security Rule enforcement actions. A Risk Analysis that maps where patient data actually flows is what protects you from all of the regulators at once, not just the one you were told to worry about. We walk through the mental health version of this exposure in the tracking-code gap for Texas practices, and the same logic applies to any specialty with a website.

The Cerebral case is not really about a telehealth startup. It is about the quiet assumption that HIPAA is the whole map. It is not. OCR is one agency at one door, and a court just made that door a little smaller. The FTC never used that door in the first place.