Back to all articles

Is it legal to run ads inside an AI mental health chatbot?

Ads in an AI mental health chatbot are legal in 2026 if you skip data sharing and disclose sponsorship — see what triggered BetterHelp's $7.8M FTC fine.

ELContent TeamSep 23, 2026 — 8 min read
Is it legal to run ads inside an AI mental health chatbot?

Running ads inside an AI mental health chatbot is legal in the US and most markets in 2026 — the ad format isn't what regulators go after. What gets chatbot builders fined or sued is using the conversation itself to build ad profiles, sharing that data with third-party networks, or skipping disclosure that a message is sponsored.

TL;DR
  • Ads in an AI mental health chatbot are legal in 2026 if you skip behavioral targeting on chat content.
  • BetterHelp paid $7.8 million to the FTC in 2023 for sharing mental health data with advertisers without consent.
  • HIPAA usually doesn't apply to standalone chatbots, but state laws like Washington's My Health My Data Act still do.
  • Contextual ad matching that reads the current message, not a stored profile, is the lower-risk model.
  • Disclosure of sponsored content is required under the FTC Act regardless of the chatbot's health focus.
Enforcement numbers to know
$7.8M
BetterHelp FTC settlement
2023, for sharing mental health data with advertisers
$1.5M
GoodRx FTC settlement
2023, first Health Breach Notification Rule case

Why this matters

Mental health chatbots collect some of the most sensitive information a person shares, but most of them aren't run by a hospital, therapist, or insurer — the entities HIPAA actually regulates. That gap is exactly where the FTC and state legislatures moved in. If you're building or monetizing a mental health chatbot in 2026, look at how ad monetization for AI mental health support assistants is actually structured before assuming HIPAA controls the outcome, because for most apps it doesn't.

The BetterHelp and GoodRx settlements weren't about advertising being illegal. They were about health apps routing user data to ad platforms like Meta and Google without telling anyone. The question in 2026 isn't "can I show ads" — it's "what data does my ad model touch, and did the user agree to it."

Running ads in a mental health chatbot is legal under US federal law in 2026 as long as three conditions hold: the chatbot isn't a HIPAA-covered entity misusing protected health information, the ad targeting doesn't rely on health data shared without consent, and sponsored content is disclosed. Four separate legal frameworks touch this, and none of them ban the ad itself — they gate on consent and disclosure.

FrameworkApplies whenWhat it restrictsBans ads outright?
HIPAAChatbot is run by, or contracted to, a covered entity (provider, insurer, clearinghouse)Sharing protected health information without authorizationNo — requires signed authorization for that data path
FTC Act + Health Breach Notification RuleAny US-facing health app, HIPAA-covered or notUndisclosed data sharing, deceptive privacy claimsNo — penalizes non-disclosure, not the ad
State health data laws (e.g., Washington My Health My Data Act)Consumer health data collected in or from that stateSelling or sharing health data, including for advertising, without opt-in consentNo — requires consent, not a ban
GDPRAny processing of EU residents' dataTreats mental health data as "special category," requiring explicit consent for ad processingNo — consent-gated, not banned

HIPAA: does it even apply to your chatbot?

HIPAA only covers "covered entities" — health plans, healthcare providers, and clearinghouses — plus their business associates. A standalone AI mental health chatbot that isn't affiliated with a licensed provider, insurer, or clinic sits outside HIPAA entirely, even though it collects deeply personal information.

That's the trap builders fall into: no HIPAA doesn't mean no rules. It means the FTC and state law apply instead, and both have been catching up fast since 2023.

FTC rules: disclosure and data sharing are the real risk

The FTC doesn't ban advertising in health apps. It enforces against deceptive or unfair use of consumer data, using both Section 5 of the FTC Act and the Health Breach Notification Rule. BetterHelp paid $7.8 million in 2023 after sharing users' mental health details — including emails, IP addresses, and self-reported health information — with Facebook, Snapchat, Pinterest, and other ad platforms without proper consent. GoodRx paid $1.5 million the same year in the FTC's first enforcement of the Health Breach Notification Rule, for routing similar health data to advertisers without notifying users.

Neither company was fined for running ads. Both were fined for what the ad targeting was built on. Elo's contextual matcher reads the current message only and never stores a persistent user profile, which sidesteps the exact data-sharing pattern that cost BetterHelp $7.8 million.

State health data laws: the layer HIPAA misses

Washington's My Health My Data Act, effective 2023, defines "consumer health data" broadly enough to include mental health status and requires opt-in consent before that data is collected, shared, or used for advertising — regardless of whether the company is HIPAA-covered. California's Confidentiality of Medical Information Act extends similar protections to app-based health data, not just clinical records.

If your chatbot has users in Washington or California in 2026, "we're not a hospital" doesn't get you out of consent requirements. Several other states have followed with their own consumer health data statutes since 2023, and opt-in consent is now treated as the practical floor for any app touching mental health conversations.

GDPR: mental health data is "special category" data in the EU

For EU users, mental health data falls under GDPR Article 9's "special category" of personal data, alongside data on health, sexuality, and religious belief. Processing it — including feeding it into an ad matcher — requires explicit consent, not the implied consent that covers ordinary web ads. Building GDPR-compliant conversational ads means the targeting logic can't reuse conversation history without a separate, specific opt-in for that purpose.

  • Whether the chatbot is affiliated with a licensed provider, insurer, or clinic (this triggers HIPAA)
  • Whether ad targeting reads the live conversation only or builds a persistent user profile
  • Whether the ad platform shares data with third parties like Meta or Google's ad networks
  • Whether users see a clear, upfront disclosure that content is sponsored
  • Which states or countries the user base sits in — Washington, California, and the EU add consent requirements HIPAA never had
  • Whether the chatbot markets itself as a wellness tool versus a clinical or diagnostic one

Can you advertise in a mental health chatbot without violating HIPAA?

Yes, HIPAA violation risk only applies when the chatbot is a covered entity or business associate handling protected health information for treatment, payment, or operations. Most consumer-facing mental health chatbots fall outside that definition in 2026, but they still answer to the FTC and to state health data laws instead.

Yes, explicit consent is required in the EU under GDPR and in states like Washington under the My Health My Data Act whenever ad targeting uses health-related conversation content. Contextual matching — reading only the current message rather than storing a profile — cuts down how much consent infrastructure you need, and disclosing sponsored ads clearly covers most of what's left.

Is contextual advertising safer than behavioral targeting in health apps?

Yes, contextual advertising carries lower legal risk than behavioral targeting because it doesn't require building or storing a profile of the user's mental health history. Elo's SDK, for example, matches an ad to the message in front of it and discards the context after — the FTC's cases against BetterHelp and GoodRx both centered on persistent data sharing, not on a single contextual ad.

Add contextual ads without the data risk

Elo's SDK matches ads to the current message, not a stored health profile.

FAQ

Is it legal to show ads in an AI mental health chatbot?

Yes, it's legal in the US and most markets in 2026 as long as ad targeting doesn't rely on health data shared without consent and sponsored content is disclosed. The 2023 FTC settlements against BetterHelp and GoodRx targeted data sharing, not the presence of ads.

Does HIPAA cover AI mental health chatbots?

Only when the chatbot is run by, or under contract to, a HIPAA-covered entity like a licensed provider, insurer, or clearinghouse. Standalone consumer chatbots usually fall outside HIPAA entirely, even when they handle sensitive mental health conversations.

What did BetterHelp pay the FTC for sharing mental health data?

BetterHelp paid $7.8 million in a 2023 FTC settlement for sharing users' mental health information with Facebook, Snapchat, Pinterest, and other advertisers without proper consent. The case is the reference point most legal teams cite for what not to do.

Is contextual advertising legal for health chatbots under GDPR?

Yes, contextual advertising is legal under GDPR as long as it doesn't process EU users' mental health data as a persistent profile without explicit consent under Article 9. Reading the current message rather than storing history keeps the consent burden lower.

Can a free mental health chatbot use ads instead of a subscription?

Yes, ad-supported models are legal for mental health chatbots in 2026 under the same consent and disclosure rules as any other health app. The revenue model itself isn't restricted — the data handling behind it is.

Do users need to be told an ad is sponsored?

Yes, disclosure of sponsored content is required under the FTC Act regardless of whether the chatbot focuses on mental health. Clear, upfront labeling is the baseline compliance step every ad-supported chatbot needs.

What is the Washington My Health My Data Act?

It's a 2023 state law that defines consumer health data broadly enough to include mental health status and requires opt-in consent before that data is collected, shared, or used for advertising. It applies regardless of whether the company is HIPAA-covered.

One last thing

The Health Breach Notification Rule that caught GoodRx in 2023 had existed since 2009 — the FTC just never enforced it until a health app got caught quietly feeding data to advertisers. Rules that sit dormant for over a decade don't stay dormant forever, and mental health chatbots are the category regulators are watching closest heading into 2026.

You might also like