NAI Issues Best Practices Guidance on Health-Related Digital Advertising
Time 2 Minute Read

On November 8, 2023, the Network Advertising Initiative (“NAI”) issued its best practices guidance (“Guidance”), which advocates for the use of demographic data for health advertising, rather than sensitive health information.

The Guidance comes after the FTC’s $1.5 million fine imposed on GoodRx for unauthorized disclosures of personal health information to third-party advertisers, and the recent enactment of laws such as Washington’s My Health My Data Act, which impose new restrictions on processing of health data.

The Guidance distinguishes between processing of “sensitive” health information (e.g., information about a consumer’s health condition, treatment, or diagnosis), which the Guidance acknowledges requires consumer consent under new privacy laws, and processing of broader demographic data such as age and gender, which does not require consumer consent.

The Guidance also indicates that population-level demographic insights may be obtained through analyzing de-identified health information, such as insurance claims or pharmaceutical prescriptions. For example, de-identified insurance claims may provide insight into which geographic regions may have increased prevalence of certain conditions over several years, which may assist pharmaceutical companies or healthcare providers to market medications and treatments to consumers in those regions. The Guidance recognizes that individual behavioral data, with enough specificity and precision, may inadvertently reveal a consumer’s health status and, that information may therefore need to be treated as sensitive health information.

The Guidance includes sections on: Demographic Audience Segment Attributes, Data Stewardship, Modeled Audience Segment Size, Data Provenance and Transparency.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page