Findings
Severity assumes a health-context site with no verified mitigation (consent gating, BAA, server-side relay). Everything below is observable by any visitor’s browser — this scan used no privileged access.
F-01
Consent signals force-granted, no CMP
Critical
Consent posture
Observed
dataLayer: {"0":"consent","1":"update","2":{"ad_storage":"granted","ad_user_data":"granted","ad_personalization":"granted"}} — fired on homepage and intake page with no user interactionNo CMP globals present (checked: IAB TCF, OneTrust, Osano, CookieYes, Cookiebot, Usercentrics); no consent banner rendered18 cookies set on first load, before any interaction
What it receives. Every Google tag on the page is told the visitor consented to ad storage, ad-data use, and ad personalization.
Why it matters. Programmatic consent-granting without a user choice undermines the consent defense that pixel-litigation defendants rely on, and is the opposite of the opt-in posture strict state health-privacy laws require.
Sources: July 2026: consent defense rejected — Google & Meta in discovery over prescription pixel data · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo) · Washington My Health My Data Act — RCW 19.373, private right of action (leg.wa.gov)
F-02
Google Analytics 4 (G-3H9•••98TG)
Critical
Third-party analytics
Observed
script: googletagmanager.com/gtag/js?id=G-3H9•••98TGdataLayer config: send_page_view: true, page_title names a GLP-1 weight-loss consultation, page_location: "…/consultation?…productId=compounded-s…"cookies: _ga, _ga_•••
What it receives. IP address, full page URL and title — including the medication being sought — plus a persistent client ID on every page of the intake funnel.
Why it matters. Medication-level intent transmitted to a third party with a durable identifier is the exact fact pattern in the FTC’s GoodRx and BetterHelp actions and the 2026 prescription-pixel litigation against Google and Meta.
Sources: July 2026: consent defense rejected — Google & Meta in discovery over prescription pixel data · HHS OCR guidance on online tracking technologies (HHS.gov) · FTC & HHS joint warning to ~130 hospital systems and telehealth providers (FTC.gov)
F-03
Google Ads conversion — two accounts (AW-181•••••486, AW-182•••••662)
High
Ad conversion tracking
Observed
scripts: googletagmanager.com/gtag/js?id=AW-181•••••486 and …?id=AW-182•••••662dataLayer config for both AW accounts carries page_location including productId=compounded-semaglutidecookie: _gcl_au (Google Ads conversion linker)
What it receives. Ad-click identifiers (gclid) joined to health-intent page context and conversion events, into two separate Google Ads accounts.
Why it matters. Connects ad-platform identity to a medical consultation funnel; duplicated across two accounts (a house + agency pattern), doubling the disclosure surface.
Sources: FTC v. GoodRx — $1.5M penalty; medication lists uploaded to Facebook (FTC.gov) · July 2026: consent defense rejected — Google & Meta in discovery over prescription pixel data
F-04
Google Tag Manager via cloaked first-party loader
High
Tag manager
Observed
script: https://•••••.redacted-telehealth.com/load — a random first-party subdomain serving the tag loader (direct fetch outside a browser is refused by bot protection)Google Tag Assistant independently reports container GTM-••••••• on this sitegtm.js / gtm.dom / gtm.load events present in dataLayer
What it receives. Whatever any tag in the container is configured to collect — the roster can change at any time without a site deploy.
Why it matters. First-party cloaking of a tag container defeats ad blockers and consent tooling; in litigation and enforcement this reads as an aggravating, concealment-adjacent factor.
Sources: FTC & HHS joint warning to ~130 hospital systems and telehealth providers (FTC.gov) · HHS OCR guidance on online tracking technologies (HHS.gov)
F-05
LiveIntent identity resolution
High
Identity resolution
Observed
script: https://d-code.liadm.com/did-0014.min.jscookies: _li_dcdm_c, _li_ss, _lc2_fpi, _lc2_fpi_js
What it receives. Durable identifiers linking this browser — and, where resolvable, an email-keyed identity — into a cross-site advertising identity graph.
Why it matters. Identity resolution on a medical intake funnel attaches GLP-1 interest to a persistent cross-site profile. Sharing consumer health data with identity/ad-tech brokers is the core theory of FTC health-privacy cases and state laws like Washington’s My Health My Data Act.
Sources: FTC v. GoodRx — $1.5M penalty; medication lists uploaded to Facebook (FTC.gov) · Washington My Health My Data Act — RCW 19.373, private right of action (leg.wa.gov) · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo)
F-06
Unbranded identity script at look-alike domain (visitor-speed.com)
High
Identity resolution
Observed
script: https://b.visitor-speed.com/js/cc9•••••••.js (also calls a.visitor-speed.com)script body reads Klaviyo identity cookies (__kla_id, _kx) — an email-identity sync patterncookies: mmuid, tag_user_id, tag_session
What it receives. Visit and identity signals synced against email-marketing identity; the operating vendor is not identifiable from the domain.
Why it matters. An unbranded tracker on a generic look-alike domain is a disclosure a privacy policy almost certainly does not name accurately — a transparency failure on top of the underlying data flow.
Sources: Washington My Health My Data Act — RCW 19.373, private right of action (leg.wa.gov) · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo)
F-07
VWO
Medium
A/B testing / behavior
Observed
scripts: dev.visualwebsiteoptimizer.com/tag/12•••80.js and companion analysis/session modulescookies: _vwo_uuid, _vwo_uuid_v2, _vwo_sn, _vwo_ds, _vis_opt_s, _vis_opt_test_cookie
What it receives. Page URLs, experiment exposure, and behavior events from the intake funnel; VWO’s Insights product line adds session recording and heatmaps (recording state is not externally confirmable).
Why it matters. A third-party experimentation vendor receiving health-funnel behavior pre-consent; the recording-capable product line raises the ceiling if enabled.
Sources: CIPA website-wiretapping lawsuit tracker, 2026
F-08
Quiz telemetry into the tag layer
Medium
Intake funnel
Observed
dataLayer: {"event":"QUIZ_START"} pushed automatically on intake-page loaddataLayer: {"event":"virtual_page_view","page_path":"…/consultation?productId=compounded-semaglutide…"}
What it receives. Quiz lifecycle events are available to every tag in the tag-manager container; step URLs carry medication context.
Why it matters. The congressional inquiry into telehealth trackers centers on intake-question data reaching ad platforms. Answer-level transmission was not tested in this scan (no questions were answered); the plumbing for step-level transmission is in place.
Sources: FTC v. BetterHelp — $7.8M; intake data shared with Facebook, Snapchat, Criteo, Pinterest (FTC.gov)
F-09
Whop pixel
Low
Checkout / affiliate attribution
Observed
script: https://t.whop.tw/s.jscookies: _wuid, _wuid_link
What it receives. Visit and checkout attribution events to a third-party commerce platform.
Why it matters. Another third party receiving funnel activity; low standalone, additive in aggregate.
F-10
Third-party web chat (help-desk vendor)
Low
Third-party chat
Observed
script: https://•••••.freshdesk.com/webchat/js/widget.js
What it receives. Anything a visitor types into chat — commonly health and medication questions — plus page context.
Why it matters. Health questions in third-party chat require a vendor posture (e.g., a BAA) that cannot be verified externally; unmitigated, chat transcripts are a recurring source in health-privacy complaints.
Sources: CIPA website-wiretapping lawsuit tracker, 2026 · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo)