- Spotting
- Posts
- Try Not to Get Sued đ»
Try Not to Get Sued đ»
How privacy in womenâs health became the scariest part of DTC marketing â because nothing says boo like a subpoena.
If you work in DTC womenâs health and are trying to acquire customers right now, itâs hard not to feel a little paranoid. The lawsuits against Flo Health and Everly Health shook our entire category â reminding every founder, marketer, and media buyer just how fragile âprivacyâ really is in this space. Itâs made me deeply curious (borderline obsessed) with how our data moves behind the scenes, and how the rules are changing faster than most of us can keep up.
At Rescripted, our customers have started turning to us with all the same questions: Whatâs actually allowed under HIPAA? What counts as âhealth dataâ in Metaâs eyes? And how do you responsibly reach the right audience when all the old tools â pixels, lookalikes, you know the drill â are suddenly off-limits?
Enter Adam Putterman. As the co-founder of Ours Privacy (and someone whoâs lived through the same chaos from the inside), he was the perfect person to help make sense of whatâs happening â and what comes next. So I asked him to break it down for us.
đ But first: Canât find Spotting in your inbox? Check Promotions (or Spam, grrr), drag us back, then add [email protected] to your contacts and â us, so we always land right where we belong đ€
This Weekâs Signal
First of all, thank you to Abby for inviting us to chat about this. I need to get this out of my system before I end up spending our entire Thanksgiving dinner talking about pixels and HIPAA and CAC and BAAs.
Metaâs 2025 privacy changes have been (to put it lightly) a headache for anyone in healthcare marketing.
Starting in January 2025, Meta began limiting what advertisers in âsensitiveâ categories - including health and wellness - could use as campaign goals. By September, they took it even further: any audience or conversion labeled with health-related terms (think IVF, diabetes, PCOS) stopped collecting new data altogether.
If your business touches healthcare, this was borderline apocalyptic. Campaigns slowed down. Conversions broke. CAC went up - often as much as 4-5x or more. And a lot of people realized they didnât really know how their campaigns and data models with Meta worked.

Will Smith in Independence Day = all of us womenâs health marketers.
It was one of the biggest privacy shake-ups since Appleâs iOS 14 update - except this time, it wasnât about cookies. It was about liability and who is allowed to have access to sensitive health data (TLDR: the answer is â only companies that are themselves HIPAA compliant and have a signed BAA).
What Weâre Missing
The story didnât start this year. It started back in 2022, when investigative reporters found Metaâs Pixel quietly collecting sensitive data from hospital websites - in some cases, even from inside patient portals.
That discovery triggered a wave of lawsuits, FTC scrutiny, and new HHS guidance warning that sensitive health information cannot - under any circumstances - be shared with platforms that do not have a signed BAA in place with you (e.g., Meta, Google, Reddit, GA4, and nearly every other platform that a modern marketer requires to do their job).
By early 2025, Meta had a choice: clean up or keep paying lawyers. They chose both. Meta continues to fight many of the initial lawsuits, but also has made sweeping changes to the types of data it will accept and allow healthcare marketers to use.
Even more importantly though, in trying to protect consumers, these platforms accidentally broke the bridge between health brands and the audiences that actually need them.
And thatâs a real problem. While the U.S. healthcare system continues to crumble, consumer health has exploded - fertility startups, telehealth platforms, womenâs wellness brands. The demand is there. But if compliant performance channels disappear, the right products canât find the right people.
Metaâs new rules do protect privacy. But theyâve also made it harder for someone dealing with fertility challenges, menopause, or postpartum anxiety to stumble onto the brand that could actually help them.
What Weâre Seeing
We didnât start as a privacy company. We started as a digital telehealth company called Ours focused on couples. Like many of you reading this, we were trying to solve a very specific, very important part of peopleâs health and wellness - their relationship health, e.g., premarital counseling, couples therapy, etc.
A lot of couples donât go searching for help. So awareness-based channels like Meta were critical for our company. As we transitioned from word-of-mouth + coaching to scalable growth + therapy, we hit the same wall everyone else did.
We were running pixel-less to stay compliant and had no visibility into what was working and - even worse - no campaign optimizations. Campaign costs were skyrocketing, attribution fell apart, and every change started to feel like guesswork.
So we built our own solution: a HIPAA-compliant, BAA-backed, server-side infrastructure that allowed us to keep marketing without risking compliance. The setup was compliant by default and let us anonymize sensitive data before sending anything to third parties like Google or Meta.
Soon, other healthcare companies started reaching out, asking how we were managing these challenges. After answering that question over and over again, we realized the entire industry needed this solution.
So we launched Ours Privacy - a healthcare privacy platform designed for healthcare marketers who want to grow responsibly (but also effectively).
Today, weâre focused on building the healthcare marketing engine - a platform that brings together everything teams need to grow responsibly. Beyond HIPAA-compliant data management, weâre expanding into tools for consent, maps, video, translation, and session replays, all designed to work together seamlessly. The goal is simple: give healthcare organizations a single, compliant way to manage their digital presence and understand their data without juggling multiple vendors or contracts.
What It Means
But back to youâŠhereâs some practical advice for Meta:
1. First, see if youâre restricted.
You probably already know. But if not, itâs worth checking ASAP. Weâve seen several brands come to us - unrelated to Meta restrictions - complaining of high CAC. It turned out their campaigns were being restricted and they hadnât seen the notification that theyâd been tagged as a health and wellness brand - in these cases, campaigns appear to be working, but the algorithms have stopped optimizing.
You can check your restriction here: Events Manager > Select your pixel > Settings tab > "Manage data source categories" section > Manage. If you see âcare portalâ you are fully restricted. Any other labels mean you are partially restricted.
2. Make a plan.
Start by defining your own health data / privacy framework (focus on HIPAA, the recent HHS guidance, and state privacy laws). The entire ad ecosystem is shifting towards similar guidance (LinkedIn also disabled their pixel and standard events for health companies and we expect more to follow) and now is the time to get ahead of it.
Itâs worth noting that Meta and other platforms are not only restricting companies that need to follow HIPAA - theyâre restricting a much wider sector across health & wellness, regardless of covered entity status.
3. Transition off of pixels.
Practically, the days of pixels and standard events are behind us. Start to onboard conversion APIs and obfuscated custom events with PHI redaction.
Lastly, donât fall for any fear mongering. This stuff is important and critical. But itâs solvable. Weâve seen countless brands end up with better performance after doing this work.

Pixels â cookies⊠but who can resist a Cookie Monster meme.
Adam said it best: this is solvable. The privacy reckoning sweeping healthcare marketing isnât the end of consumer health â itâs a chance to rebuild trust the right way. For womenâs health brands, that matters more than ever.
Because while privacy laws evolve, one thing wonât change: people still need to find the right information, products, and care. The goal isnât to stop marketing â itâs to do it responsibly.
Huge thanks to Adam and the Ours Privacy team for helping us unpack whatâs really happening behind the curtain. If this conversation has you rethinking your own data practices, youâre not alone â and weâll keep digging into it right here on Spotting.
(And for anyone curious about Ours Privacy, Adamâs offering 10% off when you mention Rescripted.)
With more signal and less noise, Spotting is your weekly lens on whatâs next in womenâs health â and why it matters. See you right here next time, in your inbox. (And if a friend forwarded this to you, you can subscribe to get your own copy.)
With hugs, science & freedom,
Abby
P.S. Whether this hits or misses for you, Iâd love to hear your thoughts â just hit reply. Thanks for being here đ€

Reaching 20M women monthly and partnering with trusted brands like Pfizer, Kotex, BetterHelp, and Noom, Rescripted is the leading media platform for all women and their health, from first period to last period.