Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that health information is shared with healthcare providers for treatment and care operations, and that a broad range of personal information is disclosed to service providers supporting billing, marketing, advertising, analytics, research, shipping, data hosting, and other operational functions.
This analysis describes what Ro's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision identifies the categories of third parties receiving user data, including a broad service provider category that encompasses advertising and marketing vendors. The inclusion of marketing and advertising functions within the service provider category is relevant to assessing whether these disclosures constitute sales or shares under applicable state privacy law.
Interpretive note: Whether advertising and marketing service providers receiving health-adjacent data are subject to HIPAA business associate requirements depends on the specific data categories shared and the nature of the affiliated medical entities involved, which cannot be fully determined from the policy text alone.
Under these terms, your health information may be shared with healthcare providers, pharmacies, and a range of service providers supporting advertising, marketing, analytics, research, and other operational purposes. The policy states that service provider disclosures are for services performed on Ro's behalf, though the breadth of permitted purposes encompasses advertising and marketing functions.
Cross-platform context
See how other platforms handle Health Information Disclosure to Third-Party Providers and Service Providers and similar clauses.
Compare across platforms →Monitoring
Ro has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We disclose your information to health care providers: (i) to schedule and fulfill appointments and provide health care services as part of the Services, (ii) to whom you send messages through our Services, and (iii) for other treatment, payment or health care operations purposes, including pharmacy services, upon your request. We provide access to or disclose your information to select third parties who use the information to perform services on our behalf. They provide a variety of services to us, including billing, content/service enhancements, partner labs, sales, marketing, advertising, analytics, research, customer service, shipping and fulfillment, data hosting and storage, IT and security, fraud prevention, payment processing, and auditing, consulting, and legal services.Excerpt from Ro's Privacy Policy
REGULATORY LANDSCAPE: This provision implicates HIPAA's permitted disclosures for treatment, payment, and healthcare operations, as well as state privacy law frameworks governing service provider data sharing. The inclusion of advertising and analytics vendors in the service provider category may require evaluation against HIPAA's definition of business associates and marketing restrictions. The FTC Act applies to deceptive or unfair data sharing practices. GOVERNANCE EXPOSURE: High. The breadth of the service provider category, which includes advertising and marketing vendors alongside clinical and operational partners, creates a compliance mapping challenge. HIPAA distinguishes between treatment-related disclosures and marketing uses of protected health information, and the interaction between these categories in a telehealth context is a material compliance area. JURISDICTION FLAGS: California's CPRA requires that service providers be contractually bound to use data only for specified business purposes and prohibits them from using data for their own commercial purposes. Other state privacy laws impose analogous restrictions. The policy does not specify the contractual limitations imposed on each category of service provider. CONTRACT AND VENDOR IMPLICATIONS: Business associate agreements under HIPAA and data processing agreements under applicable state privacy laws should be in place with all service providers receiving health-related data. The breadth of the service provider category means that vendor inventory and agreement review is a significant due diligence undertaking. COMPLIANCE CONSIDERATIONS: Compliance teams should map each category of service provider to the data categories they receive, confirm that HIPAA business associate agreements cover all entities receiving protected health information, review whether marketing and advertising service providers are properly classified under applicable state privacy law, and assess whether service provider contracts limit data use to the stated business purposes.
This provision identifies the categories of third parties receiving user data, including a broad service provider category that encompasses advertising and marketing vendors. The inclusion of marketing and advertising functions within the service provider category is relevant to assessing whether these disclosures constitute sales or shares under applicable state privacy law.
Under these terms, your health information may be shared with healthcare providers, pharmacies, and a range of service providers supporting advertising, marketing, analytics, research, and other operational purposes. The policy states that service provider disclosures are for services performed on Ro's behalf, though the breadth of permitted purposes encompasses advertising and marketing functions.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ro.