Informational Only · Not Legal Advice · No Attorney-Client Relationship · Editorial Policy

What a Telehealth Privacy Claim Is Actually Worth: The LifeMD Numbers

Privacy claims built on website tracking behave differently from almost everything else on this site. There is no collision, no fall, no misread scan — and frequently no out-of-pocket loss at all. What there is instead is a statute that assigns a number to the violation itself, which changes how the value of a case is worked out from the first conversation.

The current example is LifeMD, Inc., the direct-to-consumer telehealth company behind the Rex MD and ShapiroMD brands. Two privacy matters have attached to it: one that ran through a Nevada court and paid $10 a head, and one still at the investigation stage in California. Set side by side, they show almost the whole economics of this claim type.

The Ordinary Damages Model Does Not Fit

In a personal injury case, damages are reconstructed from consequences: medical bills, lost earnings, future care, and the non-economic harm the injury caused. The plaintiff proves what happened to them and puts a figure on it.

A tracking-pixel claim usually has none of that. A visitor answered questions about weight loss or mental health on a website, a third-party tag allegedly reported it, and nothing observable followed — no lost job, no denied insurance, no bill. Under the ordinary model the case is worth close to nothing, because the plaintiff cannot point at a consequence.

Two features of the law keep these cases alive anyway.

Statutory damages

Some privacy statutes fix a per-violation amount that does not depend on proving loss. The California Invasion of Privacy Act — a wiretap law from the 1960s written for telephone lines, now applied by plaintiffs to third parties embedded in web pages — is the one driving most of this litigation, and it is the reason a claim with no measurable harm still has a value. The violation is the injury.

Aggregation

A per-violation figure is only interesting multiplied by a class. That arithmetic is what produces a settlement worth negotiating over, and it is also what caps the individual recovery: divide almost any realistic number by several hundred thousand people and the per-person share is small.

What the Individual Actually Receives

The LifeMD settlement is a useful calibration point, because it is finished and the figures are on the record.

In W.M.F. & Matthew Marden v. LifeMD, Inc., in Clark County, Nevada, users alleged that tracking technologies on LifeMD and RexMD websites potentially transmitted identifiable health information to third parties including Meta, Google and TikTok. Claims included alleged violations of the federal Electronic Communications Privacy Act and Nevada privacy law, plus negligence, invasion of privacy, breach of confidence and unjust enrichment. LifeMD denied wrongdoing and denied that protected information was actually disclosed; the court made no liability finding, and the settlement is not an admission.

  • Potential class: approximately 835,159 people.
  • Claimant benefit: $10 in cash or a $25 voucher valid two years.
  • Aggregate cap: none — this was not a pro rata common fund.
  • Claim deadline: September 22, 2025, passed.
  • Final approval: September 30, 2025.
  • Distribution began: January 21, 2026.
  • Attorneys’ fees and expenses: $750,000, paid separately from class benefits.
  • Class representative awards: $2,500 each, to two representatives.
  • Objections / opt-outs: none, and five exclusions.

That last line is the one to sit with. Out of roughly 835,000 potential class members, five people opted out. The rest either claimed $10 or did nothing, and by doing nothing released the claim. Whether $10 was the right price for that release is exactly the question an objector would have raised, and nobody did.

LifeMD also agreed to a non-monetary term: using a third-party consent service to strengthen consent management on its website for at least two years. Injunctive terms of that kind are routine in privacy settlements and are frequently where the practical value sits, since they change what happens to the next visitor.

Why the Non-Customer Has the Stronger Claim

The instinct in most claim types is that the more involved you were, the more you are owed. Tracking claims invert it, and the inversion is worth understanding because it decides who is in a class and who is not.

A telehealth intake runs in a fixed order: pick a topic, answer questions, then reach a screen asking you to agree to the Terms, Privacy Policy, Notice of Privacy Practices and telehealth consent, and only then create an account or pay. Everything answered before that screen was answered under no agreement. Meanwhile, advertising and analytics tags generally load with the page, well before there is any consent state to consult.

So the visitor who answered three questions and closed the tab has the cleanest version of the claim — no agreement, no arbitration clause accepted, no terms to be bound by — and is simultaneously the least likely to ever be found, because they are in no customer database and will receive no notice email.

That is precisely the group the open California review targets. Attorneys are investigating potential cases against LifeMD for alleged privacy violations in California, examining whether LifeMD, Rex MD and ShapiroMD intake questionnaires passed visitors’ answers to third-party advertising networks before those visitors accepted the terms or created an account. It is limited to California residents who started a questionnaire on or before June 14, 2026, answered at least one question, never accepted the terms, never created an account or made a purchase, and are not already represented. Because the Nevada class was built from members and purchasers, missing that claim deadline does not by itself disqualify anyone here. No complaint has been filed, no class has been certified, and nothing has been proven — the criteria and a free case review are on the LifeMD data privacy investigation page, and the panel at the end of this article has the full detail.

Why California Changes the Arithmetic

Claims of this type cluster in California for reasons that are entirely about the statute book.

  • CIPA supplies statutory damages, so a claim survives the absence of measurable loss.
  • The CCPA, as amended by the CPRA, classifies health information — and inferences drawn about health — as sensitive personal information, with rights attached to how it is shared.
  • The Confidentiality of Medical Information Act reaches medical information held outside the traditional HIPAA perimeter.
  • The unfair competition law supplies a general vehicle.

None of these has been applied to LifeMD by any court. They explain why an investigation would be drawn along a state line rather than nationwide.

The countervailing factor is time. California privacy claims of this kind can carry short limitation periods, and a statute of limitations runs whether or not a complaint has been filed. An investigation with no deadline and no claim form can still be time-barred while everyone waits for one.

What Evidence Looks Like Here

The proof problem is unusual: the strongest evidence is technical and sits with the defendant, while the plaintiff-side evidence is mostly about establishing that a particular person was on a particular page at a particular time.

  • Browser history with dates, and any bookmark.
  • Marketing follow-up. An abandoned-cart or “finish your visit” email is often the cleanest available proof that an intake was started — the retargeting is the receipt.
  • Retargeted advertising seen afterwards for the same service.
  • Which topic was started and roughly how far the questionnaire went.
  • Location at the time — state residency and physical presence are both threshold facts where the statute is state-specific.
  • Whether consent was ever given or an account created. Here the absence is the qualifying fact, so accuracy matters more than usual.

Approximate dates described as approximate are more useful to a reviewing attorney than a confident guess. The same rule applies to any claim — see our guide to what evidence proves damages.

Two Things People Merge That Should Stay Apart

LifeMD is also the subject of unrelated reporting that has nothing to do with privacy. In July 2026 the health-news outlet STAT reported that former employees said clinicians were pushed to review GLP-1 weight-loss cases at roughly two minutes each. LifeMD strenuously denies it. There is no patient class action over prescribing, no certified class and no claim form, and the two lawsuits behind part of that reporting are employment disputes brought by former executives. It is a separate subject with a separate posture, covered on our sister site at Did LifeMD Rush GLP-1 Prescriptions? What Ex-Workers Say.

And a patient who says a GLP-1 drug physically injured them is in a third posture again: that is an individual product-liability claim against the manufacturer, not a privacy claim against a telehealth prescriber, and it is valued the ordinary way — on medical evidence and documented consequences.

Frequently Asked Questions

How much is a telehealth privacy claim worth per person?

Usually very little individually. The LifeMD settlement paid a timely, valid claimant $10 in cash or a $25 voucher across a potential class of roughly 835,159 people. These claims derive their value from statutory damages multiplied across a class, which is also what keeps the individual share small.

Do I need to prove I lost money?

Not under a statute that supplies statutory damages. The California Invasion of Privacy Act assigns a figure to the violation itself, which is why claims survive where no financial loss can be shown. A claim brought only under negligence would face the opposite problem.

I never created an account. Am I excluded?

Not necessarily, and it can be the reverse. The open California review is aimed specifically at people who started a LifeMD, Rex MD or ShapiroMD intake questionnaire, answered at least one question, and never accepted the terms, created an account or made a purchase. Answering before any agreement existed is the qualifying fact, not a disqualifier.

Is the LifeMD settlement still accepting claims?

No. Claims, exclusions and objections closed September 22, 2025, final approval was entered September 30, 2025, and distribution to timely, valid claimants began January 21, 2026.

Is there a deadline for the California investigation?

There is no claim form and no court deadline, because no complaint has been filed and no class has been certified. Statutes of limitations run independently of any filing, though, and California privacy claims of this kind can carry short deadlines.

Has LifeMD been found liable for anything?

No. The Nevada settlement was reached with no admission of liability and the court made no finding. Nothing in the open California investigation has been proven, and no complaint has been filed on it.


This article is general information about how a category of claim is valued. It is not legal advice, it does not create an attorney-client relationship, and it does not describe any outcome you should expect. LawyerDamages is not a law firm and is not affiliated with LifeMD, Inc., Rex MD or ShapiroMD. Prior results do not guarantee a similar outcome. Speak with a licensed attorney about your own situation.

We use essential cookies to make this site work and remember your preferences. We do not use advertising or analytics cookies. Privacy Policy.