Cerebral Faces $7 Million Fine from FTC for Serious Privacy Breaches in Mental Health Startup

Published:

spot_img

FTC Orders Cerebral to Stop Using Personal Data for Advertising

Apr 16, 2024NewsroomPrivacy Breach / Regulatory Compliance

The U.S. Federal Trade Commission (FTC) has taken strict action against the mental telehealth company Cerebral for major privacy violations. The company has been ordered to pay a fine of over $7 million and is prohibited from using or disclosing personal data for advertising purposes.

The FTC found that Cerebral, along with its former CEO Kyle Robertson, misled consumers about their privacy practices and failed to honor their cancellation policies. The agency stated that the company did not clearly disclose that users’ sensitive health information would be shared with third parties for advertising purposes. Additionally, Cerebral is accused of sharing users’ data with platforms like LinkedIn, Snapchat, and TikTok without proper consent.

The company’s deceptive practices included burying data sharing practices in dense privacy policies and allowing former employees access to sensitive medical records. They also sent promotional postcards to over 6,000 patients that revealed their diagnosis and treatment information.

As a result of the FTC’s enforcement action, Cerebral has been barred from disclosing personal and health information to third parties for marketing purposes. They are also required to implement a comprehensive privacy and data security program and inform users about the FTC order on their website. Monument, another health company, also faced similar enforcement actions from the FTC for disclosing health information to third-party platforms without user consent.

The FTC’s crackdown on companies like Cerebral and Monument highlights the importance of protecting users’ privacy and reinforcing regulatory compliance in the healthcare industry. It serves as a warning to other healthcare service providers to ensure proper data handling practices and respect user privacy.

spot_img

Related articles

Recent articles

RondoDox Botnet Targets Critical React2Shell Vulnerability to Take Over IoT Devices and Web Servers

Jan 01, 2026Ravie LakshmananNetwork Security / Vulnerability Ongoing Campaign Targets IoT Devices via RondoDox Botnet Cybersecurity experts have unveiled new details surrounding a prolonged attack campaign...

Emirates 2025: 55.6 Million Passengers, New Aircraft, Starlink Launch, and 180,500 Flights Expected

Emirates Airlines: A Year of Growth and Innovation in 2025 Emirates Airlines, a prominent name in the global aviation industry, experienced remarkable growth in 2025....

ITR Not Processed by December 31, 2025? Key Risks and Essential Steps for Taxpayers

With December 31, 2025, fast approaching, countless taxpayers across India are keenly watching the status of their Income Tax Returns (ITRs) for the ongoing...

Shai-Hulud Supply Chain Attack Steals $8.5 Million from Trust Wallet Users

markdown In a significant cyberattack, Trust Wallet users experienced a loss of $8.5 million in cryptocurrency, attributed to the ongoing Shai-Hulud npm supply...