Prelude

Health companies have quietly agreed on something: that privacy is a compliance task. A box to check near the end, handed to legal, solved with a banner and a policy nobody reads.

I think it is one of the most expensive mistakes in the category. And almost no one treats it like a mistake at all.

This piece makes a single argument: in healthcare, privacy is not a legal problem. It is a product decision. Maybe the product decision. I'll break down the four places privacy actually gets decided, why the legal-first approach quietly fails, and the one test we now run on ourselves to stay honest.

Where privacy actually lives

When most teams say "privacy," they point at two things: the cookie banner and the privacy policy. Both arrive late. Both are written to be defensible, not honest. And both are downstream of decisions that were already made somewhere else.

The real decisions happen in four places. Only one of them is visible to the customer, and it is the least important one of the four:

  1. The cookie banner, which is what legal shows you.

  2. The privacy policy, which is what nobody reads.

  3. The data stack, which is what actually happens.

  4. The product, which is where it should be decided, and rarely is.

Let me take each.

Part I: The four places privacy gets decided

The banner is theater. It exists to transfer responsibility from the company to the user with a single click. "Accept all" is not consent. It is a toll booth people pay on their way to the thing they came for.

If your entire privacy posture is a banner, you have not made a privacy decision. You have made a decision to look like you made one.

2: The privacy policy (the document written to be unread)

The policy is the second artifact, and it is honest about exactly one thing: that it is written by lawyers, for lawyers, in case of lawyers. Nobody reads it because it was never meant to be read. It is insurance, not communication.

A document that exists to protect the company is not the same as a practice that protects the customer. Most companies own the first and quietly skip the second.

3: The data stack (where the real decision already got made)

This is the one that matters, and the one nobody owns.

Before a customer clicks anything, before they have agreed to a single line, the stack is already working. Scripts load. Pixels fire. Data gets handed to a dozen advertising platforms the moment a page opens. For most companies this was never a decision anyone made on purpose. It is just the default, inherited from whatever the marketing tools do out of the box.

Now sit with what that means in healthcare specifically. The page where this is happening is the page where a person is about to type the most private things about their own body. The number on the scale they have told no one. The thing they have been avoiding for two years.

The rule we set at YupMD is simple: nothing non-essential loads until someone has actually opted in. No surveillance running in the background of a moment that intimate. If that sounds obvious, I promise you it is not how most of the internet works, and not how most of healthcare works either.

4: The product (where it should live)

The decision in the data stack is a product decision wearing a marketing costume. So we treat it like one. Someone owns it. It gets designed. We decide, on purpose, what the product does in the dark, before anyone is watching and before anyone has agreed to anything.

That is the whole reframe. Privacy is not what you disclose. It is what you do when no one would ever know the difference.

Part II: Why the legal-first approach fails

1: Compliance is not trust

Compliance is the floor. It tells you what you are allowed to do without getting punished. Trust is the ceiling, and it is built by what you choose to do when the floor would have let you do worse.

You do not earn trust at the scale of someone's bloodwork by being technically compliant. You earn it by being the kind of company that does not need the fine print to behave.

2: The cost is invisible until it isn't

I want to be honest, because the legal-first path is cheaper and I felt the cost of leaving it.

When you stop tracking everything, you go partially blind. Attribution gets murky. You lose the clean line between the dollar you spent and the customer it brought in. Your dashboards start telling a softer, less certain story, and in a performance-marketing world that runs on certainty, that is genuinely uncomfortable. There are weeks I miss the data I gave up.

That cost is real today. The cost of the other path shows up later, all at once, on the worst possible day. Pick your invoice.

3: Trust is the one moat a competitor can't undercut

A symptom and a discount are generic. So is surveillance. Anyone can run the same pixels you run.

But the company people actually trust with their most intimate data has built something no competitor can price against. In this category, trust is not the marketing around the product. Trust is the product. Everything else is rented.

The test we use

Here is the one you can steal.

Imagine your user could see everything your product did in the first thirty seconds, before they agreed to a single thing. Every script. Every pixel. Every handoff to a platform they have never heard of.

Would they still sign up?

If the honest answer is no, you do not have a privacy policy problem. You have a product problem, and no banner will fix it.

Conclusion and What's Next

I do not know if the blindness is survivable forever. Maybe at scale we will need more signal than principle alone can give us, and I will have to earn it back in a way I can still defend. Ask me in a year.

But I would rather grow slower on my own data than faster on everyone's. The companies that win the next decade of healthcare will not be the ones with the best disclaimers. They will be the ones people trust with the most private thing they own. That trust gets built or lost inside decisions most teams never think of as product decisions at all.

Not a banner. A decision.

In coming weeks I'll get more tactical: how we actually gate consent without breaking the funnel, and what it costs in real numbers.

See you Mondays, Maximilian