Skip to content
Dose Brief
Menu

Evidence & access

GLP-1 telehealth privacy: what to check before sharing data

Separate the medical practice from the app, review data-sharing choices, and use this privacy checklist before completing an intake.

By The Dose Brief Desk, News Editor

Updated · Editorial standards

In this brief

Before entering your medical history into a GLP-1 website or app, identify who receives it and which privacy notice applies. A medical practice, pharmacy, marketing website and consumer app can play different roles. A “HIPAA compliant” badge does not, by itself, explain every organization's use of your information.

You do not need to become a privacy lawyer to compare services. You do need a usable notice, a contact for questions and a clear explanation of required versus optional data sharing before you upload sensitive records.

Identify the service behind the screen

Write down the legal name of the medical practice, the company operating the platform and the pharmacy when one is assigned. Look for a medical privacy notice as well as the website's general privacy policy. If those documents name different organizations, ask which one holds your clinical record and which one handles account or marketing data.

HHS explains that telehealth delivered by covered providers and plans must follow HIPAA, including requirements concerning technology vendors used for care.1 But HHS also explains that personal health information in many consumer apps is not protected by HIPAA unless the app is acting for a covered entity or business associate.2 The service's role matters more than the fact that the information concerns health.

Read the policy with a decision checklist

Privacy questionWhat an answer identifies
Required data: What is needed for clinical care versus marketing?Purpose of each request
Sharing: Which organizations receive identifiable information?Recipients and reasons
Advertising: Is health or intake information used for ad targeting?Applicable choices or restrictions
Account access: Can I use multifactor authentication?Available security controls
Records: How do I obtain a copy or request a correction?Responsible contact and process
Leaving: What happens after account closure?Retention, deletion and limits

This is a reader comparison tool, not a certification checklist. A long policy is not automatically better than a short one; the useful test is whether you can answer these questions without guessing. Keep the version or date of the notice you relied on.

Treat optional permissions as separate choices

A request for your location, contacts, photos or another app's health data should have an understandable purpose. For example, a clinician may need to know where you are during a visit, while continuous background location access is a different permission. Ask the service to explain what is required for care and whether a less expansive option works.

Do not assume that declining a marketing cookie also withdraws every consent you have given elsewhere. Review account settings and any separate authorization forms. Avoid uploading additional records to a general sales chat until the practice confirms the appropriate channel.

The FTC warns that companies can violate consumer-protection law by sharing health information contrary to their privacy promises, and that health apps outside HIPAA may still fall under other federal requirements.3 “Not covered by HIPAA” does not mean no rules apply, but it does mean you should not infer HIPAA protections from an app's subject matter.

Protect the appointment and your own copies

HHS recommends a private setting for telehealth, using headphones when appropriate and turning on multifactor authentication when available. It also suggests reducing exposure from nearby recording devices and securing the technology used for the visit.4 These steps help protect your side of the conversation; they do not verify the platform's internal practices.

Choose a password you do not reuse for shopping or social accounts. Review lock-screen notifications if medication names or appointment details appear there. When downloading a record, decide where it will be stored and who else uses that device or account. A shared family tablet and a private phone create different practical risks.

Ask about deletion without losing needed records

Account closure, stopping marketing messages and deleting a clinical record are different requests. Ask which information can be deleted, which must be retained and which other organizations hold copies. Do not assume uninstalling an app erases the server-side account.

Before leaving a provider, obtain the records you need for continuity through the practice's approved process. Our provider switching checklist helps organize that handoff. If a privacy answer is unclear, ask for a written explanation before adding more information; a sales promise that everything is “secure” is less useful than naming the actual practice and data-sharing choices.

For an overall service comparison, combine these answers with our provider selection guide. Price, access and privacy are separate parts of the decision, and a strength in one does not establish the others.

Frequently asked questions

Does a HIPAA badge cover everything a telehealth website collects?

Not necessarily. Identify each organization and the privacy notice governing the data you provide.

Does deleting the app delete my medical record?

Do not assume so. Ask separately about account closure, retained clinical records, marketing data and copies held by other organizations.

References

  1. US Department of Health and Human Services (2023). HIPAA Rules for telehealth technology. US Department of Health and Human Services (accessed October 6, 2026). https://telehealth.hhs.gov/providers/telehealth-policy/hipaa-for-telehealth-technology
  2. US Department of Health and Human Services (2022). Protecting the Privacy and Security of Your Health Information When Using Your Personal Cell Phone or Tablet. US Department of Health and Human Services (accessed October 6, 2026). https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/cell-phone-hipaa/index.html
  3. Federal Trade Commission (2026). Mobile Health App Interactive Tool. Federal Trade Commission (accessed October 6, 2026). https://www.ftc.gov/business-guidance/resources/mobile-health-apps-interactive-tool
  4. US Department of Health and Human Services (2023). Telehealth Privacy and Security Tips for Patients. US Department of Health and Human Services (accessed October 6, 2026). https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/telehealth-privacy-security/index.html

Medical disclaimer: This content is for general educational purposes only and is not medical advice, diagnosis, or treatment. Always consult a licensed healthcare professional before starting, stopping, or changing any treatment.