logo

Mental health company Cerebral failed to protect sensitive personal data, must pay $7 million

ID: 9f0e7808-db39-5349-88cb-671bb4a109b5

STIX ID: report--9f0e7808-db39-5349-88cb-671bb4a109b5

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-04-18

Date Updated: 2026-04-28

...
...

The report details a privacy breach at telehealth provider Cerebral after the company deployed invisible tracking pixels that allegedly sent sensitive personal and health information for about 3.2 million consumers to third-party advertisers; the FTC reached a settlement imposing restrictions on data use, refunds to affected customers, and civil penalties. The article lists the types of exposed data (including PHI such as treatment details and self-assessment responses), links to regulatory notices, and offers practical post-breach advice for individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.