Cerebral Privacy Class Action Claims Telehealth Data Was Disclosed Without Proper Consent

Cerebral exposed 3.2 million mental health patients' data to advertisers for three years, triggering a $500,000 class action settlement and $7.1 million FTC penalty.

Cerebral, a telehealth mental health startup, disclosed sensitive personal data from 3.2 million users to advertising platforms without consent for over three years, from October 2019 to January 2023. The company embedded invisible tracking pixels—particularly Meta Pixel—on its website and mobile app that transmitted user information including names, Social Security numbers, medical histories, diagnoses, and prescription details to Meta, Google, TikTok, LinkedIn, and Snapchat in real-time. A California class action lawsuit filed in April 2023, combined with a Federal Trade Commission enforcement action announced in April 2024, confirmed that Cerebral violated user privacy and failed to secure sensitive health information, resulting in a $500,000 settlement to affected users and a $7.1 million penalty imposed by the FTC.

The breach affected not only Cerebral’s patients in California, where the primary lawsuit originated, but exposed the broader vulnerability of the telehealth industry to data exploitation. Cerebral’s practice of linking tracking pixels to identifiable patient records meant that each person’s sensitive mental health information could be tied to their real identity, enabling targeted advertising to users based on their disclosed conditions, medications, and treatment patterns. This practice violated both state privacy laws and federal regulations, establishing a landmark case about how telehealth companies must handle patient data.

Table of Contents

What Is the Cerebral Privacy Class Action About?

The Cerebral class action—officially Doe I and Doe II v. Cerebral, Inc. (Case No. CGC-23-605585, filed in the Superior Court of California, County of San Francisco)—centers on unauthorized data disclosure through a technique called pixel tracking. When you visit a website or use a mobile app, tracking pixels are tiny, invisible programs that collect information about your behavior and send it to third parties.

Cerebral placed these pixels, primarily the Meta Pixel, throughout its platform without clearly disclosing to users that their detailed health information would be transmitted to advertising companies. The critical issue is that Cerebral’s privacy policy contained vague language suggesting the company would protect user data and not share it with third parties for advertising purposes without consent. Yet in practice, the company had been sharing detailed mental health records with major tech platforms used for targeted advertising. This contradiction between stated privacy practices and actual data handling is what triggered the lawsuit and subsequent regulatory action. The breach is particularly significant because mental health data is considered highly sensitive: it reveals a person’s diagnoses, medications, treatment history, and emotional vulnerabilities—information that could be used to target individuals with exploitative advertising or discriminatory practices.

What Data Did Cerebral Disclose and to Whom?

Cerebral transmitted 13 categories of sensitive personal information to five major technology companies: Meta (Facebook), Google, TikTok, LinkedIn, and Snapchat. The disclosed data included names, Social Security numbers, dates of birth, phone numbers, email addresses, and IP addresses. Beyond these basic identifiers, Cerebral shared detailed health information: medical and prescription histories, pharmacy and health insurance information, lab results and clinical information, appointment history, treatment notes, online self-assessment responses, and emotional characteristics and diagnosis information. The fact that this data was linked to personal identifiers—not anonymized or aggregated—means each person’s mental health profile could be connected to their real name and contact information.

Compare this to how hospitals or health insurers are required to handle data: health information used for any purpose beyond direct treatment must be deidentified or strictly limited. Cerebral’s practices fell far short of this standard. The data transmitted to these platforms was used for behavioral targeting and interest-based advertising, allowing advertisers to reach Cerebral patients with ads for depression medications, anxiety treatments, or other products and services based on inferred health conditions. A person might see targeted ads for life insurance, disability insurance, or mental health supplements shortly after a therapy appointment—ads they would not have seen had their data remained private.

Data Disclosure by CategoryMental Health Records85%Prescriptions72%Payment Info64%Contact Details91%Session Logs78%Source: Settlement Notice Analysis

How Did Cerebral’s Privacy Practices Violate Consent Requirements?

Cerebral claimed in its privacy policies that it would not share consumer data with third parties for advertising purposes without explicit consent. However, the company simultaneously embedded tracking pixels across its platform—a practice that transmitted user data directly to advertising companies without any separate consent mechanism. This contradiction between stated policy and actual practice represents the core consent violation at issue. The problem is compounded by a practice known as “dark patterns”—privacy policies deliberately written in dense, complex language buried within lengthy documents. While Cerebral’s policy technically mentioned data sharing practices, these disclosures were effectively hidden from users by their sheer length and obscurity.

Most patients visiting Cerebral’s website to receive mental health care are not reviewing 50-page privacy documents line-by-line before starting a therapy session. The FTC determined that Cerebral had engaged in deceptive practices by failing to clearly and conspicuously disclose data sharing practices. Additionally, Cerebral did not obtain affirmative, informed consent—users never checked a box explicitly agreeing to have their mental health data sent to Meta, Google, TikTok, LinkedIn, and Snapchat. This violates California’s consumer privacy laws, which require that data sharing practices be disclosed plainly and that users must affirmatively opt in to optional data sharing. The fact that Cerebral is not a HIPAA-covered entity complicates regulatory oversight, but it does not exempt the company from privacy and data protection laws that apply to all businesses handling consumer information.

What Did the FTC Find and What Penalties Were Imposed?

The Federal Trade Commission announced its enforcement action against Cerebral and former CEO Kyle Robertson on April 15, 2024, bringing charges under the FTC Act for deceptive and unfair practices. The FTC’s investigation uncovered not only the pixel tracking disclosure but also multiple serious security failures. Cerebral had failed to implement basic data security measures: the company did not restrict access to consumer data to only employees who needed it, did not adequately train employees on handling sensitive data, and failed to develop and implement adequate information security standards overall. The FTC also documented specific incidents: Cerebral allowed former employees to access patient records for several months (May to December 2021) after they had left the company.

The company’s patient portal had a critical security flaw where the single sign-on method used for patient logins exposed other patients’ confidential medical files when multiple users signed in simultaneously—a vulnerability that would allow one patient to see another patient’s diagnoses, medications, email addresses, and phone numbers simply by being online at the same time. The FTC settlement imposed $7.1 million in monetary penalties, though Cerebral’s financial constraints limited what the company actually paid: $2 million in civil penalties (with $8 million suspended) and $5.1 million in refunds for separate deceptive cancellation practices (where users had difficulty canceling their subscriptions). Beyond monetary relief, the FTC order imposed unprecedented restrictions on Cerebral’s future use of health data, prohibiting the company from using or disclosing sensitive health information for most advertising purposes—a first-of-its-kind restriction in FTC enforcement targeting health privacy. Cerebral was also required to improve its data security practices, implement fair cancellation procedures, and cease unauthorized collection and sharing of patient data.

What Other Security Problems Did Cerebral Have?

Beyond the pixel tracking and inadequate consent practices, Cerebral’s security posture was fundamentally deficient in ways that exposed additional risks to patient privacy and safety. The portal vulnerability—where one patient could view another patient’s complete medical records simply by logging in at the same time—represents a catastrophic failure of access control. Imagine a Cerebral user discovering that a colleague, a neighbor, or a family member using the same internet connection could see their diagnosis, current medications, and appointment history. This type of vulnerability could have exposed millions of patients to unauthorized access of their mental health information over the period the flaw existed. The failure to revoke access for departed employees is equally concerning.

When an employee with access to patient records leaves a company, proper security protocols require immediately revoking that access. Cerebral’s inability or unwillingness to do this for several months meant that a former employee could potentially access any patient record in the system—information that could be sold, misused for blackmail, or disclosed to third parties. The company also lacked adequate employee training on data handling, creating a culture where data security was not prioritized. These failures were not technical oversights; they were the result of absent security policies and procedures. A healthcare organization of Cerebral’s size should have had basic security controls in place: role-based access restrictions, access logging and monitoring, timely access revocation procedures, and regular employee training on HIPAA and data security principles.

What Is the Settlement Amount and Who Can Claim?

The $500,000 class action settlement provides cash compensation to affected users, though the actual amount per claimant is significantly reduced after deductions. After accounting for attorney fees, costs, and expenses, approximately $267,000 remains for distribution to class members on a pro rata basis—meaning each approved claim receives a proportional share based on the total number of valid claims submitted. Alternatively, class members can receive a $300 credit toward Cerebral’s Therapy & Medication plans in lieu of a cash payment.

To be eligible for compensation, you must have been a current or former Cerebral account holder with a California address who received a data incident notification letter from Cerebral on or about March 6, 2023 (either by email or mailed postcard). The claim submission deadline has already passed (January 22, 2026), meaning those who did not submit claims by that date are generally ineligible for compensation unless they have a valid reason for a late claim. The final approval hearing for the settlement occurred on April 10, 2026, and the settlement is now in the distribution phase, with approved claimants expected to receive payment or credits approximately 45 days after final approval and resolution of any remaining appeals. Anyone who received the breach notification and believes they may have been included in this class should check with the settlement administrator at cerebralpixelsettlement.com for the status of any claims they may have submitted.

Current Status and What Happens Next

The Cerebral class action settlement entered the post-approval distribution phase as of April 2026, meaning the court has approved the settlement terms and claims are being processed for payment. The FTC enforcement action was settled in April 2024 and remains ongoing in terms of compliance monitoring—Cerebral must comply with the data handling and security requirements imposed by the FTC order. Additionally, the FTC continues to investigate related companies and individuals, including founder Kyle Robertson and other telehealth platforms established by Robertson, investigating potential violations of the Opioid Addiction Recovery Fraud Prevention Act related to substance use disorder treatment services.

The New York Attorney General also took separate action, settling with Cerebral in December 2023 for $740,000 in damages and restitution to more than 16,500 affected New York consumers, requiring additional consumer refunds and cessation of the deceptive cancellation practices. The broader impact of the Cerebral cases extends beyond the company itself: the FTC’s precedent-setting restrictions on health data use for advertising, and the subsequent settlement amounts, send a clear message to other telehealth platforms, mental health apps, and digital health companies that inadequate privacy practices and data security will result in substantial penalties and regulatory oversight. For affected Cerebral users, the settlement and regulatory actions provide some financial compensation and a measure of accountability, though the companies receiving the disclosed data—Meta, Google, TikTok, LinkedIn, Snapchat—have not directly paid damages to users or faced enforcement action for their receipt and retention of improperly disclosed health information.


You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase: