Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Class Action Initiated Against Telehealth Provider for Disclosure of Sensitive Information

By Kathryn Rattigan on April 27, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

A class action was filed in Fort Lauderdale, Florida this week against a national telehealth provider, MDLive Inc. (MDLive) for its mobile app’s alleged secret capture of screenshots containing sensitive patient information without restricting access to medical providers who have a legitimate need to view the information. The lawsuit was filed by Utah resident, Joan Richards, who is seeking class certification of a class that she estimates will include thousands of other MDLive users and more than $5 million damages.

In Richards’ complaint, she alleges, “Patients provide their medical information to MDLive in order to obtain health care services and reasonably expect that MDLive will use adequate security measures, including encryption and restricted permissions, to transmit patients’ medical information to treating physicians [. . .] Contrary to those expectations, MDLive fails to adequately restrict access to patient’s medical information and instead grants unnecessary and broad permissions to its employees, agents and third parties.” Richards’ complaint further alleges that MDLive programmed its app to capture an average of 60 screenshots during the first 15-minutes that the app is open on a user’s device –this is the same amount of time it takes a new user to register for an account, enter their medical history and connect with a doctor. During this timeframe, the app also prompts the user to enter sensitive information such as details about allergies, past medical procedures and behavioral health history including conditions such as obsessive compulsive disorder, bipolar disorder, schizophrenia, depression and substance abuse.

Richards’ complaint also states that MDLive sends these screenshots to TestFairy, a third-party technology company based in Tel Aviv, Israel, that works with MDLive to “insert the necessary hooks to gather information” about the user’s experiences with the app to improve the app and detect bugs. However, Richards’ concern is that TestFairy is not a health care provider and MDLive patient users have not been informed that MDLive intends to send their medical information to TestFairy in near real time.

The class action includes claims for breach of contract, intrusion upon seclusion, fraud, unjust enrichment, violation of the Utah Truth in Advertising law, and violation of the Utah Consumer Sales Practices Act.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Kathryn RattiganEmail
Show more Show less
  • Posted in:
    Class Action & Mass Torts, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo