상세 보기
건강 행태정보(Behavioral Information) 제3자 제공의 가능성과 한계 - GoodRx v. FTC 동의명령 사례 분석을 중심으로 -
- 박예준;
- 김재선
초록
Abstract This paper analyzes the regulatory framework of the U.S. Federal Trade Commission (FTC) regarding the processing of health information by non-medical digital healthcare companies, focusing on the 2023 case involving GoodRx Holdings, Inc. (hereinafter GoodRx). It aims to derive implications for our legal system. GoodRx, which provides prescription drug discounts and telemedicine services, installed information collection tools (Pixels, SDK) developed by third parties such as Google and Facebook on its website and app. This enabled the collection (tracking) of activity information generated by users during service use, and automatically shared this information with advertisers and third parties. Consequently, it collected users' health information, including medication search and purchase history, related health conditions, and pharmacy names. This data was combined with identifying information such as email addresses, phone numbers, and mobile advertising identifiers and provided to third-party advertising businesses like Facebook (Meta) and Google. This information was used to segment users who searched for or purchased specific medications, enabling the creation of targeted ads for specific drug names (e.g., ‘lisinopril claims’) or customized events. GoodRx uploaded the email addresses, phone numbers, and mobile advertising identifiers from this list to Facebook's Custom Audiences feature, using them to display ads for specific medications to those users on Facebook and Instagram. However, GoodRx stated in its privacy policy: “does not provide advertisers with any information that reveals an individual's health status or health information.” It also stated that for its telemedicine service (formerly HeyDoctor), it would obtain users' prior consent before sharing data with third parties for purposes beyond service provision. Furthermore, it displayed a HIPAA compliance badge on its website, advertising itself as if it were a healthcare provider or Business Associate directly regulated by HIPAA. However, in practice, it utilized health-related behavioral information for advertising purposes with third parties without obtaining user consent and failed to notify users of this fact. The FTC analyzed the requirements for ‘deceptive’ and ‘unfair’ acts prohibited under Section 5 of the Federal Trade Commission Act (FTCA) in this case. Regarding deceptiveness, the FTC found that GoodRx: (1) Repeatedly stated in its privacy policy that it would not share health information with third parties; (2) Stated it would obtain user consent for sharing with third parties outside the scope of service provision; (3) and that it led consumers to believe it was subject to HIPAA regulation through HIPAA compliance advertising. The FTC concluded that the average consumer would have no choice but to trust GoodRx's explanations, yet the company engaged in conduct contrary to these assurances. Next, regarding unfairness, the FTC pointed out that GoodRx combined health information with identifiers to create lists of users searching for or purchasing specific prescription drugs, using these lists for targeted advertising. Users could not reasonably expect that their disease and medication information would be provided in an identifiable form to advertising businesses while using prescription price comparison or telemedicine services, nor were they provided with a reasonable means to opt out of such sharing. Nevertheless, GoodRx failed to notify users about the third-party sharing of health information and its use for advertising purposes, nor did it offer users a choice. The FTC therefore deemed this an unfair practice posing a substantial and unavoidable risk of privacy harm to consumers. Furthermore, the FTC found GoodRx violated the HBNR by determining that GoodRx qualifies as a ‘vendor of personal health records’ as defined by the HBNR. It recognized that GoodRx failed to fulfill its notification obligations, even though it considered the unauthorized third-party sharing without consent to be a breach of security. This case is particularly significant because the FTC expanded the concept of security breach beyond external hacking or cyberattacks to include unauthorized acquisition and sharing in the form of third-party sharing without the data subject's approval. The key provisions of the FTC consent decree specified the normative standards that the platform must comply with. First, it permanently prohibits GoodRx from providing health information to third parties for advertising purposes. Health information is broadly defined to include not only an individual's past, present, or future physical or mental health status and medical service history, but also health-related behavioral information that can reasonably infer specific health conditions or medication use from actions on websites or similar platforms. Second, when providing health information to third parties for purposes other than advertising, the company is required to clearly and conspicuously disclose the scope of health information, the identity of the third party, and the purpose of disclosure on a separate screen distinct from the privacy policy and terms of service. Furthermore, it must obtain affirmative express consent from the data subject through an active, explicit action. It was emphasized that consent obtained through mere checkboxes or dark patterns is not considered valid, and the key terms of consent must be presented in a manner that is sufficiently understandable. Third, if a security breach occurs involving identifiable health information contained in Personal Health Records (PHRs), GoodRx must notify the data subjects, the FTC, and the press within 60 days. The notification must include an overview of the incident, the type of information disclosed, and the actions data subjects should take. Fourth, GoodRx must identify all third parties that have received past health information, require each third party to delete the relevant identifiable information they hold, and obtain written confirmation that the deletion has been completed. Fifth, GoodRx was required to establish and implement a comprehensive privacy program protecting the availability, confidentiality, and integrity of health information within 180 days, and subsequently undergo regular independent external evaluations. Additionally, GoodRx agreed to pay a $1.5 million civil penalty, and the consent decree was finalized as an order of the federal court. This paper examines the legal principles of the GoodRx case in light of the revision of Korea's telemedicine law. In Korea, the introduction of the so-called Telemedicine Act through the December 2025 revision of the Medical Service Act paved the way for the full-scale implementation of telemedicine. However, specific regulations regarding platform operators' collection of behavioral information have not been established, and the criteria for determining who bears legal obligations as the personal information processor during the processing of behavioral information remain ambiguous. This paper analyzes the FTC's criteria for determining deceptiveness and unfairness revealed in the GoodRx case and the logic applied to HBNR. It clearly defines health-related behavioral information as a distinct category of data. It requires the active and explicit consent of the data subject when such information is provided to third parties for advertising purposes or processed in a form that allows identification. and proposes improvements to the Personal Information Protection Act and its subordinate guidelines to make compliance obligations substantive. This aims to contribute to establishing a practical protection system for digital health information processed by non-medical institutions.
키워드
- 제목
- 건강 행태정보(Behavioral Information) 제3자 제공의 가능성과 한계 - GoodRx v. FTC 동의명령 사례 분석을 중심으로 -
- 제목 (타언어)
- Possibilities and Limitations of Third-Party Provision of Health Behavioral Information - Focusing on the Analysis of the GoodRx v. FTC Consent Decree Case -
- 저자
- 박예준; 김재선
- 발행일
- 2026-02
- 유형
- Y
- 저널명
- 토지공법연구
- 권
- 113
- 페이지
- 457 ~ 487