GoodRx Shared Your Prescription Data With Facebook and Google
The FTC fined GoodRx $1.5M in 2023 for sharing 55M+ users' health data with advertisers without consent. Here's what happened, what was exposed, and safer alternatives that don't monetise your health data.
What Happened — The GoodRx Privacy Timeline
What GoodRx Shared Without Your Consent
How Script Unlock Is Different
How Script Unlock Protects Your Privacy
GoodRx Data Breach — Frequently Asked Questions
Was there an actual GoodRx data breach?
It was not a hacker breach — it was an unauthorised disclosure. The FTC found that from 2017 through 2020, GoodRx routinely transmitted user health information (prescription drug searches, conditions, and personal identifiers) to Facebook, Google, Criteo, and other advertising platforms via tracking pixels and SDKs — without informed user consent. In February 2023, GoodRx agreed to a $1.5M civil penalty under the FTC’s Health Breach Notification Rule and was permanently banned from sharing user health data for advertising purposes.
What data did GoodRx share with Facebook and Google?
According to the FTC complaint, GoodRx shared prescription drug names, health conditions inferred from those prescriptions, user email addresses, IP addresses, mobile advertising IDs, and unique GoodRx user IDs. This data was joined to existing Facebook and Google advertising profiles, allowing those platforms to target users with health-related ads based on their actual prescriptions.
How many people were affected by the GoodRx privacy violation?
More than 55 million GoodRx users had their prescription and health data shared with advertisers between 2017 and 2020. If you used GoodRx during that window — to search a medication, redeem a coupon, or create an account — your data was likely included.
How is ScriptUnlock different from GoodRx?
ScriptUnlock’s revenue comes from pharmacy subscriptions ($149.99/month), not from selling user data. We do not run Facebook Pixel, Google Analytics health-data integrations, or third-party advertising trackers on prescription search pages. We are HIPAA compliant, we have no PBM relationships, and you can use ScriptUnlock without creating an account — there is no persistent profile to monetise.
What should I do if I used GoodRx during the affected period?
You cannot undo the data that was shared, but you can stop new sharing: (1) clear cookies and tracking IDs in your browser and on your mobile device, (2) opt out of Facebook and Google personalised ads, (3) switch to a prescription savings tool that does not run advertising pixels — like ScriptUnlock. The FTC settlement also requires GoodRx to direct Facebook, Google, and others to delete the data they received, though enforcement of that deletion is limited.
Compare Prescription Prices Without Sharing Your Data
Script Unlock lets pharmacies compete for your prescription — without selling your health data to Facebook. Free to use. No account required.
Compare Prices Privately