Teladoc · Teladoc Privacy Policy

Freshpaint Healthcare Analytics Deployment

High severity
Share 𝕏 Share in Share 🔒 PDF

What it is

Teladoc Health runs a healthcare-specific analytics tool called Freshpaint on every page of its website, which tracks user behavior and page visits — including pages that indicate specific health conditions like diabetes, mental health, or weight management.

Consumer impact (what this means for users)

Your browsing behavior on Teladoc's website — including which condition-specific pages you visit (e.g., '/mental-health', '/glp-1', '/diabetes') — is captured by Freshpaint, which may or may not successfully prevent that health-indicative data from reaching advertising platforms depending on its configuration.

Cross-platform context

See how other platforms handle Freshpaint Healthcare Analytics Deployment and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Freshpaint is marketed as a HIPAA-compliant data pipeline designed to intercept PHI before it reaches non-covered third parties, but its presence on a healthcare site indicates that Teladoc is actively managing the risk of health data leakage to ad platforms — a risk that exists precisely because of the other tracking scripts also present on the site.

View original clause language
freshpaint.init('dcb9fb99-e4c4-4a9d-b4bc-35bcade689c0'); freshpaint.page();

Institutional analysis (Compliance & legal intelligence)

1. REGULATORY FRAMEWORK: Deployment of Freshpaint on a HIPAA-covered entity's website implicates HIPAA 45 CFR §164.514(b) (de-identification), HHS OCR December 2022 bulletin on tracking technologies and PHI, FTC Act Section 5, and CCPA/CPRA §1798.100. HHS OCR and FTC are primary enforcement authorities. 2.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • Hhs Ocr
    HHS OCR has direct enforcement authority over HIPAA-covered entities' use of tracking technologies that may result in impermissible disclosure of PHI, per its December 2022 and March 2024 guidance bulletins.
    File a complaint →
  • FTC
    The FTC has enforcement authority over unfair or deceptive health data practices under FTC Act Section 5, as demonstrated by the GoodRx enforcement action involving health data sharing with advertising platforms.
    File a complaint →

Provision details

Document information
Document
Teladoc Privacy Policy
Entity
Teladoc
Document last updated
April 29, 2026
Tracking information
First tracked
April 28, 2026
Last verified
April 28, 2026
Record ID
CA-P-003674
Document ID
CA-D-00298
Evidence Provenance
Source URL
Wayback Machine
SHA-256
b97da5aef978cf700a66fe1d90d62b255a4473451a3b418c07119c53447bafc1
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Teladoc | Document: Teladoc Privacy Policy | Record: CA-P-003674
Captured: 2026-04-28 04:57:39 UTC | SHA-256: b97da5aef978cf70…
URL: https://conductatlas.com/platform/teladoc/teladoc-privacy-policy/freshpaint-healthcare-analytics-deployment/
Accessed: May 2, 2026
Classification
Severity
High
Categories

Other provisions in this document