Sample report · real scan, target de-identified
Reply Media · Compliant Analytics

Tracking Exposure Scan

redacted-telehealth.com
Property
DTC telehealth company (de-identified) — Cash-pay GLP-1 telehealth
Scanned
2026-08-26
Pages examined
/ (homepage)
/…/consultation?productId=compounded-semaglutide (intake landing — loaded only; no questions answered)
Method
Runtime inspection in a fresh browser profile: script census of the rendered DOM, JS tracker globals, cookie jar, and the Google dataLayer. No forms were submitted and no intake questions were answered. This is a real scan of a live telehealth website; identifying details are withheld in this public sample.
2Critical
4High
2Medium
2Low

This site runs a full ad-tech stack directly on its medical intake funnel with no consent management: ad consent is force-granted in code, Google receives medication-level intent in page URLs and titles, two identity-resolution vendors are present, and 18 tracking cookies are set before any user interaction. This is the exposure profile at the center of current FTC enforcement and healthcare pixel litigation.

Three findings that matter most

Findings

Severity assumes a health-context site with no verified mitigation (consent gating, BAA, server-side relay). Everything below is observable by any visitor’s browser — this scan used no privileged access.

F-01

Consent signals force-granted, no CMP

Critical Consent posture
Observed
dataLayer: {"0":"consent","1":"update","2":{"ad_storage":"granted","ad_user_data":"granted","ad_personalization":"granted"}} — fired on homepage and intake page with no user interactionNo CMP globals present (checked: IAB TCF, OneTrust, Osano, CookieYes, Cookiebot, Usercentrics); no consent banner rendered18 cookies set on first load, before any interaction

What it receives. Every Google tag on the page is told the visitor consented to ad storage, ad-data use, and ad personalization.

Why it matters. Programmatic consent-granting without a user choice undermines the consent defense that pixel-litigation defendants rely on, and is the opposite of the opt-in posture strict state health-privacy laws require.

Sources: July 2026: consent defense rejected — Google & Meta in discovery over prescription pixel data · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo) · Washington My Health My Data Act — RCW 19.373, private right of action (leg.wa.gov)

F-02

Google Analytics 4 (G-3H9•••98TG)

Critical Third-party analytics
Observed
script: googletagmanager.com/gtag/js?id=G-3H9•••98TGdataLayer config: send_page_view: true, page_title names a GLP-1 weight-loss consultation, page_location: "…/consultation?…productId=compounded-s…"cookies: _ga, _ga_•••

What it receives. IP address, full page URL and title — including the medication being sought — plus a persistent client ID on every page of the intake funnel.

Why it matters. Medication-level intent transmitted to a third party with a durable identifier is the exact fact pattern in the FTC’s GoodRx and BetterHelp actions and the 2026 prescription-pixel litigation against Google and Meta.

Sources: July 2026: consent defense rejected — Google & Meta in discovery over prescription pixel data · HHS OCR guidance on online tracking technologies (HHS.gov) · FTC & HHS joint warning to ~130 hospital systems and telehealth providers (FTC.gov)

F-03

Google Ads conversion — two accounts (AW-181•••••486, AW-182•••••662)

High Ad conversion tracking
Observed
scripts: googletagmanager.com/gtag/js?id=AW-181•••••486 and …?id=AW-182•••••662dataLayer config for both AW accounts carries page_location including productId=compounded-semaglutidecookie: _gcl_au (Google Ads conversion linker)

What it receives. Ad-click identifiers (gclid) joined to health-intent page context and conversion events, into two separate Google Ads accounts.

Why it matters. Connects ad-platform identity to a medical consultation funnel; duplicated across two accounts (a house + agency pattern), doubling the disclosure surface.

Sources: FTC v. GoodRx — $1.5M penalty; medication lists uploaded to Facebook (FTC.gov) · July 2026: consent defense rejected — Google & Meta in discovery over prescription pixel data

F-04

Google Tag Manager via cloaked first-party loader

High Tag manager
Observed
script: https://•••••.redacted-telehealth.com/load — a random first-party subdomain serving the tag loader (direct fetch outside a browser is refused by bot protection)Google Tag Assistant independently reports container GTM-••••••• on this sitegtm.js / gtm.dom / gtm.load events present in dataLayer

What it receives. Whatever any tag in the container is configured to collect — the roster can change at any time without a site deploy.

Why it matters. First-party cloaking of a tag container defeats ad blockers and consent tooling; in litigation and enforcement this reads as an aggravating, concealment-adjacent factor.

Sources: FTC & HHS joint warning to ~130 hospital systems and telehealth providers (FTC.gov) · HHS OCR guidance on online tracking technologies (HHS.gov)

F-05

LiveIntent identity resolution

High Identity resolution
Observed
script: https://d-code.liadm.com/did-0014.min.jscookies: _li_dcdm_c, _li_ss, _lc2_fpi, _lc2_fpi_js

What it receives. Durable identifiers linking this browser — and, where resolvable, an email-keyed identity — into a cross-site advertising identity graph.

Why it matters. Identity resolution on a medical intake funnel attaches GLP-1 interest to a persistent cross-site profile. Sharing consumer health data with identity/ad-tech brokers is the core theory of FTC health-privacy cases and state laws like Washington’s My Health My Data Act.

Sources: FTC v. GoodRx — $1.5M penalty; medication lists uploaded to Facebook (FTC.gov) · Washington My Health My Data Act — RCW 19.373, private right of action (leg.wa.gov) · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo)

F-06

Unbranded identity script at look-alike domain (visitor-speed.com)

High Identity resolution
Observed
script: https://b.visitor-speed.com/js/cc9•••••••.js (also calls a.visitor-speed.com)script body reads Klaviyo identity cookies (__kla_id, _kx) — an email-identity sync patterncookies: mmuid, tag_user_id, tag_session

What it receives. Visit and identity signals synced against email-marketing identity; the operating vendor is not identifiable from the domain.

Why it matters. An unbranded tracker on a generic look-alike domain is a disclosure a privacy policy almost certainly does not name accurately — a transparency failure on top of the underlying data flow.

Sources: Washington My Health My Data Act — RCW 19.373, private right of action (leg.wa.gov) · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo)

F-07

VWO

Medium A/B testing / behavior
Observed
scripts: dev.visualwebsiteoptimizer.com/tag/12•••80.js and companion analysis/session modulescookies: _vwo_uuid, _vwo_uuid_v2, _vwo_sn, _vwo_ds, _vis_opt_s, _vis_opt_test_cookie

What it receives. Page URLs, experiment exposure, and behavior events from the intake funnel; VWO’s Insights product line adds session recording and heatmaps (recording state is not externally confirmable).

Why it matters. A third-party experimentation vendor receiving health-funnel behavior pre-consent; the recording-capable product line raises the ceiling if enabled.

Sources: CIPA website-wiretapping lawsuit tracker, 2026

F-08

Quiz telemetry into the tag layer

Medium Intake funnel
Observed
dataLayer: {"event":"QUIZ_START"} pushed automatically on intake-page loaddataLayer: {"event":"virtual_page_view","page_path":"…/consultation?productId=compounded-semaglutide…"}

What it receives. Quiz lifecycle events are available to every tag in the tag-manager container; step URLs carry medication context.

Why it matters. The congressional inquiry into telehealth trackers centers on intake-question data reaching ad platforms. Answer-level transmission was not tested in this scan (no questions were answered); the plumbing for step-level transmission is in place.

Sources: FTC v. BetterHelp — $7.8M; intake data shared with Facebook, Snapchat, Criteo, Pinterest (FTC.gov)

F-09

Whop pixel

Low Checkout / affiliate attribution
Observed
script: https://t.whop.tw/s.jscookies: _wuid, _wuid_link

What it receives. Visit and checkout attribution events to a third-party commerce platform.

Why it matters. Another third party receiving funnel activity; low standalone, additive in aggregate.

F-10

Third-party web chat (help-desk vendor)

Low Third-party chat
Observed
script: https://•••••.freshdesk.com/webchat/js/widget.js

What it receives. Anything a visitor types into chat — commonly health and medication questions — plus page context.

Why it matters. Health questions in third-party chat require a vendor posture (e.g., a BAA) that cannot be verified externally; unmitigated, chat transcripts are a recurring source in health-privacy complaints.

Sources: CIPA website-wiretapping lawsuit tracker, 2026 · California CMIA §56.06 — consumer health software deemed a “provider of health care” (leginfo)

Side by side: what a compliant setup looks like

The same scan, run the same day, against a HIPAA-conscious build we operate for a Medicare telehealth practice (name available on request). It meets the stricter covered-entity bar — and still measures everything.

redacted-telehealth.comcompliant reference build compliant baseline
Client-side ad pixelsGA4 + two Google Ads tags via GTMNone — conversions relayed server-side, limited to lead/booked events
Consent postureForce-granted in code; no CMPConsent Mode default: denied stub + opt-in gate; choice logged server-side
Identity resolutionLiveIntent + unbranded look-alike-domain scriptNone
Session-replay-capable vendorsVWO (Insights line)None
AnalyticsGA4 (third party)Self-hosted, first-party, cookieless
ChatHelp-desk chat (BAA unverifiable)CRM chat under a signed BAA with the HIPAA add-on
Tag managerGTM behind a cloaked first-party loaderNone — every script ships through code review
Tracking cookies before consent180 third-party ad or identity cookies
Marketing measurementFullFull — first-party event ledger + server-side conversion relay

The legal backdrop

The fix — without going dark on marketing

  1. Inventory and remove. Strip ad pixels, identity-resolution scripts, and any vendor without a signed BAA from the client side. This report is the inventory.
  2. Replace analytics. First-party, self-hosted, cookieless analytics — the operator keeps full behavioral insight; no third party receives it.
  3. Move conversions server-side. A server-side relay sends ad platforms only a minimal, approved event set (lead, booking) with no health context — campaigns keep optimizing without health data leaving the stack.
  4. Gate what remains. Anything left that touches an outside vendor sits behind real opt-in consent, with the choice logged server-side as a record.
  5. Paper it. BAAs with every vendor that handles identifiable data, and a privacy policy that matches the actual data flows on the wire.

Measurement survives all five steps: first-party click-ID capture plus a server-side event ledger preserves campaign attribution end to end.