Instacart · Instacart Privacy Policy

Prescription Delivery Data Handling

High severity
Share 𝕏 Share in Share 🔒 PDF

What it is

When you use Instacart to order prescription medications, the company collects health-adjacent information related to your prescription, which is handled under a separate section of the privacy policy not available on white-label retailer sites.

Consumer impact (what this means for users)

Your prescription medication order data is collected by Instacart and may be used or shared in ways that reveal sensitive health information, creating privacy risks that go beyond typical grocery shopping data.

Cross-platform context

See how other platforms handle Prescription Delivery Data Handling and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Prescription data is among the most sensitive personal information — if this data is shared with advertising partners or insufficiently protected, it could expose your health conditions to third parties without your knowledge.

View original clause language
Prescription Deliveries (Not Available on Instacart White Labels)

Institutional analysis (Compliance & legal intelligence)

(1) REGULATORY FRAMEWORK: Prescription data collection implicates potential proximity to HIPAA (45 CFR Parts 160 and 164), though Instacart as a delivery intermediary is likely not a HIPAA-covered entity. However, if Instacart receives Protected Health Information (PHI) from a covered pharmacy partner, Business Associate Agreement (BAA) obligations under HIPAA §164.502(e) may apply. The FTC Health Breach Notification Rule (16 CFR Part 318) may apply to non-HIPAA health data. State health privacy laws (e.g., Washington My Health MY Data Act) may impose additional restrictions. (2)

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC Health Breach Notification Rule and enforcement actions on non-HIPAA health data (e.g., GoodRx) give the FTC jurisdiction over how Instacart handles prescription-related consumer health data.
    File a complaint →
  • Hhs Ocr
    If Instacart is determined to function as a Business Associate of a covered pharmacy entity, HHS OCR would have jurisdiction over HIPAA compliance for prescription data handling.
    File a complaint →

Provision details

Document information
Document
Instacart Privacy Policy
Entity
Instacart
Document last updated
April 29, 2026
Tracking information
First tracked
April 18, 2026
Last verified
April 18, 2026
Record ID
CA-P-002838
Document ID
CA-D-00136
Evidence Provenance
Source URL
Wayback Machine
SHA-256
1820e1895d1605ebc16eff3b8fdeb7771e97e65214aedd6a6e598e4b96e3cb08
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Instacart | Document: Instacart Privacy Policy | Record: CA-P-002838
Captured: 2026-04-18 10:07:50 UTC | SHA-256: 1820e1895d1605eb…
URL: https://conductatlas.com/platform/instacart/instacart-privacy-policy/prescription-delivery-data-handling/
Accessed: May 2, 2026
Classification
Severity
High
Categories

Other provisions in this document