Most of the health-data stories on this site start with somebody breaking in. This one starts with nobody breaking in at all. A growing set of legal claims argues that the sensitive answers people type into telehealth intake forms — weight, symptoms, mental-health questions, which treatment they came looking for — are handed to advertising and analytics companies as a routine, designed part of how the page works. And in the sharpest version of the allegation, it happens before the visitor has agreed to anything, on a form they never even finished.
Table of Contents
- This is not a breach, and that is the point
- The LifeMD example
- Why the abandoned form is the exposed one
- What a tracking tag can actually see
- The Nevada case that already paid
- The California investigation that is open
- How to check your own exposure
- What to do before you fill in the next one
- Frequently asked questions
This is not a breach, and that is the point
A data breach is an unauthorised event. Somebody phished an employee, exploited a vulnerable server, or bought a stolen credential, and data left through a door that was supposed to be shut. The company finds out afterwards and sends a notice.
Tracking-pixel claims describe the opposite situation. Nothing was forced. The marketing team installed a tag from an advertising platform — a Meta pixel, a Google tag, a TikTok pixel, a session-replay script — so that ad spending could be measured, and the tag did exactly what tags do: it reported what happened on the page back to the company that issued it. There is no intrusion to detect, no incident to report, and often no notice, because from the operator’s point of view nothing went wrong.
That is why this category never shows up in a breach-notification database and why a lookup service will return a clean result for it. The exposure is real; the reporting machinery simply was not built for it.
The LifeMD example
LifeMD, Inc. is a direct-to-consumer telehealth company that also runs the Rex MD and ShapiroMD brands. Its front door is a questionnaire: you pick a topic — weight loss, men’s health, women’s health, cardiovascular health, mental health, prescriptions and refills, primary care — click “Get Started,” and begin answering. Only later does a screen ask you to tick a box agreeing to the Terms, the Privacy Policy, the Notice of Privacy Practices and a telehealth consent, and only after that do you create an account or pay for anything.
The company has been the subject of two separate privacy matters built on that structure. One has been through court and paid out. The other is an open attorney investigation limited to California, and it is aimed squarely at the part of the funnel that happens before the consent box. Both are covered below. LifeMD has denied wrongdoing throughout, no court has found it liable on any of these allegations, and nothing in the open matter has been proven.
Why the abandoned form is the exposed one
The intuition most people carry is that risk grows with commitment: sign up, hand over a card, become a patient, and only then do you have something to lose. On the tracking side that intuition runs backwards.
- Consent comes last. The agreement screen sits at the end of the flow, so every question answered before it was answered under no agreement at all.
- Trackers fire first. Advertising and analytics tags typically load with the page, long before any consent state exists to check.
- Abandonment is the most valuable signal in the funnel. A visitor who starts and quits is precisely who the retargeting budget exists to chase, so the abandoned form is the one the marketing stack is most motivated to observe.
- You are not in any customer list. If a case is ever brought and settled, the class is usually assembled from account records. Someone who never made an account is often invisible to that process — and got no notice email either.
The result is a group of people with the weakest consent record and the least chance of ever being told. That is the group the California review is about.
What a tracking tag can actually see
It is worth being precise, because the two extremes are both wrong. A third-party tag is not reading your medical chart, and it is also not blind to everything but a page count.
- The URL and page title. On a health site these are frequently self-describing — a path segment naming a condition or a treatment category is a disclosure on its own.
- Clicks and form interactions. Depending on configuration, which option you selected and which fields you completed can be captured as events.
- Identifiers that persist. Cookie IDs, advertising IDs, IP address, device and browser fingerprints — the material that lets an anonymous visit be joined to a known profile elsewhere.
- Timing and sequence. How long you spent, where you stopped, whether you came back.
The legal argument is rarely that a diagnosis was transmitted verbatim. It is that the combination of a self-describing health page and a durable identifier lets a third party infer a health interest and attach it to a real person. Inference is the mechanism, and under California law inferences drawn about health are themselves treated as sensitive personal information.
The Nevada case that already paid
In W.M.F. & Matthew Marden v. LifeMD, Inc., filed in Clark County, Nevada, users alleged that tracking technologies on LifeMD and RexMD websites potentially transmitted identifiable health information to third parties including Meta, Google and TikTok. LifeMD denied the allegations and denied that protected information was actually disclosed. The parties settled with no admission of liability.
The dates are worth keeping straight, because a copy of the unsigned agreement still circulates online and reads like an open claim. It is not. Claims, exclusions and objections closed on September 22, 2025. Final approval was entered September 30, 2025. Distribution of benefits — $10 in cash or a $25 voucher per timely, valid claimant — began January 21, 2026. The potential class was put at roughly 835,159 people. There is nothing left to file. The full timeline is on our sister site at LifeMD & RexMD Privacy Settlement Closed: Payment Status.
Note who that class covered: LifeMD and RexMD members and purchasers. People who only ever started a questionnaire were largely outside it.
The California investigation that is open
Separately, attorneys are now investigating potential cases against LifeMD for alleged privacy violations in California. The allegation under review is that the intake questionnaires on LifeMD and its Rex MD and ShapiroMD brands passed a visitor’s own answers — weight-loss goals, symptoms, treatment inquiries — to third-party advertising networks before that visitor ticked the consent box and before any account existed.
It is limited to California residents who started a LifeMD questionnaire on or before June 14, 2026, answered at least one question, never accepted the Terms, Privacy Policy, Notice of Privacy Practices and telehealth consent, never created an account or made a purchase, and are not already represented by a lawyer on the claim. Because that is a different group from the Nevada class, missing the September 2025 claim deadline does not by itself rule anyone out.
California is where this argument has the most statutory footing: the California Invasion of Privacy Act, a 1960s wiretap law that plaintiffs have applied to embedded third parties on web pages and that carries statutory damages; the CCPA as amended by the CPRA, which treats health data and health inferences as sensitive personal information; and the Confidentiality of Medical Information Act. None of those has been applied to LifeMD by any court — no complaint has been filed, no class has been certified, and nothing has been proven. Details and the free case review are on the LifeMD data privacy investigation page.
How to check your own exposure
You cannot audit what a site sent last year, but you can see what it sends now, and the answer is usually informative.
- Open the browser network panel before you load the page. In Chrome or Firefox, press F12, switch to the Network tab, then load the health site. Filter for the advertising domains — requests going out to a platform you did not visit are third-party tags.
- Watch when they fire. The question that matters is whether they load before you have interacted with any consent banner, and whether they keep firing after you decline one.
- Read the URL bar as you answer questions. If the path or query string names the condition or the treatment, that string is being sent to every tag on the page.
- Check the retargeting you get afterwards. Ads for a service you only browsed are downstream evidence that the visit was reported somewhere.
- Use a tracker-blocking browser or extension for health browsing specifically. It will not undo past visits, but it changes what the next one discloses.
What to do before you fill in the next one
- Treat the pre-consent portion of any intake as public-facing. Answer the minimum that lets you evaluate the service, and save the detail for after there is an account and an agreement.
- Prefer the app or the logged-in portal for sensitive detail over the marketing site, which is where the advertising stack lives.
- Use Global Privacy Control. California treats a GPC signal as a valid opt-out of sale and sharing, and several browsers and extensions send it automatically.
- Keep the evidence that you were there. Browser history, an abandoned-cart or “finish your visit” email, a bookmark, a screenshot. The marketing follow-up is often the cleanest proof that an intake was started.
- Do not stop or change a prescribed medication because of a privacy story. That is a conversation for a licensed clinician.
Frequently asked questions
Was there a LifeMD data breach?
No. Nothing described here is a breach in the usual sense – there is no allegation that an attacker got in. The claims concern tracking technologies that LifeMD itself placed on its websites and what those tools allegedly transmitted to advertising and analytics companies. LifeMD denied wrongdoing in the case that settled, and nothing in the open California investigation has been proven.
Can I still claim money from the LifeMD settlement?
No. Claims, exclusions and objections closed on September 22, 2025, final approval was entered September 30, 2025, and distributions of $10 cash or a $25 voucher to timely, valid claimants began January 21, 2026. No late-claim process has been announced.
I never signed up for LifeMD. Does that mean I have nothing to worry about?
Not necessarily – and on the tracking side it can be the reverse. The open California investigation is specifically aimed at people who started an intake questionnaire, answered at least one question, and then never accepted the terms, created an account or made a purchase. Those visitors gave answers under no agreement at all, and are usually absent from any customer list a settlement would be built from.
Why would a breach lookup service show nothing for this?
Because breach-notification systems are built around unauthorised access. A tracking tag that a company installed on purpose is not an incident from the operator’s point of view, so it generates no notice, no report and no database entry. A clean lookup result means no listing, not no exposure.
What can a tracking pixel on a health page actually see?
Typically the page URL and title – which on a health site often names the condition or treatment – plus clicks and form interactions depending on configuration, and persistent identifiers such as cookie IDs, advertising IDs, IP address and device fingerprints. The legal argument is usually about inference: combining a self-describing health page with a durable identifier lets a third party attach a health interest to a real person.
Who may qualify for the California LifeMD investigation?
California residents who were in California on or before June 14, 2026 when they visited LifeMD, Rex MD or ShapiroMD, clicked “Get Started” on a topic such as weight loss, men’s health, women’s health, cardiovascular health, mental health, prescriptions and refills or primary care and answered at least one question, never checked the box agreeing to the terms and never created an account or made a purchase, and who are not already represented by a lawyer on the claim. No complaint has been filed and no class has been certified.
You Might Also Like
- How to Protect Your Weight Loss Program Records
- Medical Records Breach Risk Guide: Data Exposed, Fraud and Identity Theft
- Meta Removes Tracking Controls, Expanding Data Collection in July 2026
- What Information Do Wellness Breaches Typically Expose?