Cerebral, a telehealth company that provided mental health and wellness services, shared the sensitive medical data of 3.2 million users with major tech platforms—including Meta, TikTok, Google, and Snapchat—without their knowledge or consent. The Federal Trade Commission and Department of Justice took action, resulting in a $7 million penalty and a sweeping ban on using patient data for advertising purposes. This data sharing happened through pixels, tiny tracking codes embedded on Cerebral’s website that silently transmitted information like usernames, addresses, medical histories, pharmacy records, and insurance details to third-party platforms, allowing those companies to build detailed profiles on Cerebral’s patients for targeted advertising.
The misconduct uncovered at Cerebral exposes how telehealth companies can exploit the gaps between their privacy promises and actual practices. Users who signed up for mental health treatment believed their data would remain confidential and protected under healthcare privacy laws like HIPAA—yet Cerebral’s tracking tools were exposing the most sensitive details about who sought psychiatric care, what medications they took, and where they lived. Beyond the federal action, a private class action lawsuit also settled for $500,000, and affected consumers have already received over $5 million in refunds for deceptive cancellation practices.
Table of Contents
- How Did Cerebral Share Patient Data Without Consent?
- What Were the Security Failures That Enabled This Breach?
- What Are the Settlement Amounts and Who Can Claim Compensation?
- What Are Your Rights as an Affected Cerebral User?
- What Specific Data Did Cerebral Share, and What Were the Risks?
- What Changes Did Cerebral Make After the Settlement?
- What Does the Cerebral Case Mean for Telehealth Privacy Protections?
How Did Cerebral Share Patient Data Without Consent?
Cerebral installed Meta pixels, Google Analytics, and other third-party tracking tools on its website and mobile app. These pixels automatically captured and transmitted information about every user interaction—including names, email addresses, medical histories, pharmacy information, insurance details, and IP addresses—directly to advertising platforms. A patient visiting Cerebral to schedule a therapy appointment unknowingly sent their entire medical profile to Meta’s servers, which could then use that information to create an advertising profile. The company did this without explicit user consent and with inadequate disclosures in its privacy policy.
The tracking wasn’t limited to a single third party. Cerebral’s pixels sent data to LinkedIn, TikTok, Snapchat, and Google simultaneously, creating a network where each platform received detailed health information on millions of users. Unlike typical e-commerce pixel tracking (which might monitor whether someone viewed a product), Cerebral’s pixels were transmitting protected health information—the type of data that federal law recognizes as requiring strict protection. The company’s privacy policy mentioned analytics but did not clearly explain that specific sensitive health details would be shared with these advertising platforms or that users had no meaningful option to opt out.

What Were the Security Failures That Enabled This Breach?
The ftc investigation revealed that Cerebral’s privacy and security controls were dangerously inadequate. The company failed to implement reasonable safeguards to prevent unauthorized access to sensitive health data, allowed former employees to retain access to patient records after leaving the company, and provided insufficient training to its workforce on how to handle protected health information. These weren’t one-time oversights—they represented systemic failures in the company’s approach to data security and patient privacy. One critical limitation of Cerebral’s security posture was the lack of monitoring and access controls.
After employees were terminated, their accounts remained active, allowing them to view ongoing patient records without authorization. The company also failed to establish clear data retention policies or to limit which employees could access what information. This created a situation where not only were patients’ data being routinely transmitted to external advertising platforms, but the data was also vulnerable to unauthorized access by people no longer employed by Cerebral. The FTC’s enforcement action specifically cited these security gaps as evidence of the company’s negligence in protecting some of the most sensitive information in healthcare—psychiatric and medical histories.
What Are the Settlement Amounts and Who Can Claim Compensation?
Two separate legal actions resulted in compensation for affected consumers. The Federal Trade Commission action produced a $7 million settlement that was used to fund refunds to consumers, with over $5 million already sent to more than 40,000 consumers in May 2025 for deceptive cancellation practices. If you paid for Cerebral services and had difficulty canceling your subscription or were charged after requesting to cancel, you may have been among those refunded. However, this refund program had specific eligibility requirements and claim deadlines, meaning not all consumers were automatically compensated.
In addition to the FTC settlement, a private class action lawsuit filed by Cerebral users (Doe I and Doe II v. Cerebral, Inc.) reached a settlement of $500,000 to compensate users for the unauthorized disclosure of their health information through the company’s pixel tracking. A final fairness hearing for this settlement is scheduled for March 9, 2026. The objection and exclusion deadline passed on December 23, 2025, meaning affected class members who did not exclude themselves before that date are now part of the settlement. This settlement specifically addresses the privacy violation of sharing medical and personal data with advertising platforms, not the subscription cancellation issues covered by the FTC refunds—some consumers may be eligible for compensation under both settlements if their circumstances qualify.

What Are Your Rights as an Affected Cerebral User?
If you were a Cerebral user whose data was shared with Meta, TikTok, Google, Snapchat, LinkedIn, or other platforms, you had the right to object to the private class action settlement up until December 23, 2025. Objecting would have allowed you to preserve the right to sue Cerebral independently, though it would also have excluded you from receiving compensation under the settlement. For users who remained in the settlement without objecting, compensation will be distributed after the March 9, 2026 fairness hearing, assuming the court approves the settlement. The exact amount each class member receives depends on the total number of valid claims and the settlement administration costs.
Going forward, the court-approved settlement and FTC order impose strict restrictions on Cerebral. The company is now prohibited from using or disclosing sensitive health data for advertising purposes, must implement a comprehensive privacy and data security program, and faces ongoing FTC monitoring and enforcement. This means Cerebral must delete or securely manage any health data it collected and cannot transmit information like medical histories, psychiatric diagnoses, or pharmacy records to advertising platforms. However, a limitation of this order is that it applies only to Cerebral going forward—it does not compel Meta, Google, TikTok, and other platforms to delete the health data they received during the years Cerebral was tracking users. Those platforms retain the data they received, and regulatory restrictions on their use of that data remain limited.
What Specific Data Did Cerebral Share, and What Were the Risks?
Cerebral transmitted a detailed inventory of sensitive health information through its pixels. The data included names, medical histories (specifically psychiatric and mental health diagnoses), addresses, phone numbers, email addresses, IP addresses, pharmacy information, prescription histories, and health insurance details. When aggregated with other data those platforms possess, this information created a complete profile of each patient—including their location, medical conditions, medications, and economic status. For example, a patient searching for treatment for depression or anxiety would have that medical need exposed to Meta’s advertising algorithm, which could then target that individual with ads based on their mental health status.
The risks of this data sharing extend beyond targeted advertising. When health data is exposed to multiple platforms, it increases the risk of identity theft, medical fraud, insurance discrimination, and social stigma. A person whose depression diagnosis was shared with these platforms faced potential discrimination if that data was later breached or misused. Additionally, some affected consumers may have faced unexpected marketing or retargeting based on their health information—for instance, seeing ads for psychiatric medications or mental health services that made it clear their private health information had been harvested. The FTC’s enforcement action emphasized that this kind of sensitive health data sharing violates the Federal Trade Commission Act’s ban on unfair and deceptive practices, even when a company’s privacy policy technically mentions “analytics” in vague language.

What Changes Did Cerebral Make After the Settlement?
As a condition of the FTC settlement and private class action resolution, Cerebral agreed to implement a comprehensive information security and privacy program. This includes establishing clear policies for data retention, limiting employee access to patient data on a need-to-know basis, implementing technical safeguards like access controls and monitoring systems, and disabling pixels and tracking tools that transmit sensitive health information to third parties. The company must also conduct regular security audits and provide annual certifications to the FTC that it is complying with its data security obligations.
An important caveat is that Cerebral’s new obligations do not automatically undo all harm. The company has not publicly stated whether it required Meta, Google, TikTok, and Snapchat to delete the health data they received, and most privacy experts agree those platforms are unlikely to voluntarily purge such data. Users who were impacted should assume their information remains in the hands of those platforms and consider adjusting their privacy settings on those services. Additionally, Cerebral’s market position weakened significantly after the settlement, and the company has made limited public statements about its ongoing operations or future compliance efforts.
What Does the Cerebral Case Mean for Telehealth Privacy Protections?
The Cerebral enforcement action signals that the FTC is actively scrutinizing telehealth companies’ data handling practices and will pursue significant penalties against firms that misuse patient information. The $7 million fine—substantial for an enforcement action—reflected the severity of transmitting protected health information to advertising platforms and the company’s inadequate security controls. For other telehealth platforms, this case established a clear legal standard: using pixels and tracking tools to collect and transmit sensitive health data to third-party advertisers is both unfair and deceptive, regardless of whether the practice is mentioned in fine print.
Looking forward, telehealth users should recognize that privacy violations in this industry are unlikely to disappear entirely without stronger legal requirements and technological oversight. While the Cerebral settlement holds one company accountable, the broader ecosystem of pixels and tracking tools remains embedded across many healthcare websites. Regulators continue investigating similar practices at other telehealth providers, and more settlements are expected. For consumers, this case demonstrates the importance of reviewing privacy policies critically before using telehealth platforms, understanding that “analytics” can mean extensive data sharing, and considering the long-term risks of entrusting sensitive health information to digital platforms that prioritize advertising revenue alongside patient care.
You Might Also Like
- Motel 6 Guest Data Sharing ICE Class Action Settlement
- Wynn Resorts Employee Data Breach Class Action
- Tyler Technologies Ransomware Data Breach Class Action
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
