Connect with:
Saturday / August 1.

What’s Happening With All Your Therapy App Messages? — Ep 13

Annie Gilbertson
Share
Stephanie Hepburn

Stephanie Hepburn is a writer in New Orleans. She is the editor in chief of CrisisTalk. You can reach her at editor@crisisnow.com.​

From subpoenaed therapy sessions to messages being used to train AI therapy chatbots, how private are therapy apps? A conversation with Annie Gilbertson, investigative reporter and managing editor for Proof News.

Transcript

Annie Gilbertson: Talkspace is this unique telehealth provider where you can see a therapist via video chat for like 30-minute sessions, but the primary way in which patients are interacting with therapists is through asynchronous text messages. So there’s all these texting therapy logs that the company is amassing. Last I checked from their investor reports, they had amassed 140 million message exchanges that they’re keeping on hand. So you can imagine that’s a lot of very private, very sensitive information about people’s deepest, darkest thoughts.

Stephanie Hepburn: This is CrisisTalk. I’m your host, Stephanie Hepburn. Today, Annie Gilbertson joins me. She’s an investigative reporter and managing editor for Proof News, a new nonprofit newsroom examining the social impacts of AI. In today’s episode, we talk about a case she reported on a nurse practitioner who was fired by her employer when she was nine months pregnant. When she sued her employer, they subpoenaed her talks-based therapy transcripts and used them against her in court. Annie and I discuss HIPAA and how, in creating the 1996 federal law, which is intended to protect sensitive patient health data, legislators couldn’t foresee the internet of today, let alone the coming of AI. Let’s jump in.

Annie Gilbertson: I’m Annie Gilbertson, investigative reporter with Proof News, and that is a new nonprofit newsroom, and we cover artificial intelligence.

Stephanie Hepburn: Annie, you did investigative reporting on a case where Talkspace allegedly released patient transcripts. Can you tell me what happened?

Annie Gilbertson: Sure. So the case is out of Kansas, and a nurse practitioner had lost her job when she was nearly nine months pregnant. And as part of that lawsuit, she filed a pregnancy discrimination suit against her employer. It was a hospital system in Kansas. And as part of that lawsuit, her therapist was brought in as an expert witness. And the defense then subpoenaed all of her therapy records. So she was using therapy through Toxpace, which her employer provided. That’s a common way for people to receive Talkspace services is through an employer or through an insurer. And as part of the defense strategy, the employer’s lawyers subpoenaed all of her Talkspace records. So that includes all of her billing information, information about her therapist, and her transcripts with her therapist. So the important thing to know about that is that Talkspace is this unique telehealth provider where you can see a therapist via video chat for like 30-minute sessions. But the primary way in which patients are interacting with therapists is through asynchronous text messages. So there’s all these texting therapy logs that the company is amassing. And I think last I checked from their investor reports, they had amassed 140 million message exchanges that they’re keeping on hand. So you can imagine that’s a lot of very private, very sensitive information about people’s deepest, darkest thoughts.

Stephanie Hepburn: And she was speaking with a person, right? So we’ll start talking about AI soon, but she was having dialogue with an actual therapist. Did Talkspace release the transcripts themselves?

Annie Gilbertson: Yes, Talkspace maintains that they have never released transcripts, though that they are they are recording and storing them. They say that under law, they have the right to keep them private even with a subpoena. So their attorney has told me that they’re not the ones that had released it, that the data would have only at that time been accessible by the patient herself. So in this case, the nurse who sued for pregnancy discrimination. So you can imagine how this would play out in other digital avenues, say my credit card information. Like you don’t necessarily have to subpoena Chase to get my credit card information or Google to get my Gmail information. Like you could also just subpoena me and I then could log into Chase and supply that to comply with a court order.

Stephanie Hepburn: So when it comes to Talkspace, one of the issues is that they are keeping all of this. So if you could just tell me a little bit about what does HIPAA cover and then how has this case illustrated that access to all of this data and all of this information is shifting that landscape.

Annie Gilbertson: So when I first started reporting this, I knew I needed to get a better understanding of HIPAA for exactly these reasons. Like what does the law cover and what doesn’t it, and what is allowed to be shared and what isn’t? And I became extremely fascinated into sort of the architecture of this law and maybe even more importantly, like who this law is supposed to be working for. Is it really working for patients or is it really working for providers? So the law came into effect decades ago, and it was really about providers, you know, whether they’re primary care providers, therapists, you name it in the medical industry, are able to transfer information with insurance companies for billing purposes, right? And then how do you protect that information? So that was kind of the use case people were thinking about when this law went into effect. So once it’s anonymized, the data can be transferred and shared. And for that reason, doctors are often free to talk about individual patients, even publicly or in medical journals, as long as they don’t release that personal information. It’s no longer protected. And companies can do what they want with it. They can sell it, they can share it, they can publish it. There’s all kinds of ways in which that data can be used.

Stephanie Hepburn: And what’s interesting about that is it doesn’t mean that there isn’t any sort of identifiable information, right? So if somebody knows your story or what’s happening in your life, there are potentially ways that this is still identifiable. And when we think about it, this is a federal law that went into effect, what, in 1996 or something like that, if I remember correctly. And the concept is that it protects sensitive patient health data. But we’re thinking about a law that went into effect in 1996. A lot has changed. So when you think about that, what are the gaps and what are you seeing as the pitfalls as we enter the age of AI?

Annie Gilbertson: Yeah, I think there’s so much there. I mean, just especially because we’re just slopping off data constantly. Like you’ve probably been to the doctor yourself, Stephanie, and had them ask, like, can I record this for my AI scribe? Right. Yes. And it’s certainly one thing to like, you know, have them, you know, my knee is swollen, et cetera, et cetera. Like, okay, if you want to crunch that into your machine learning tools, go ahead. Um, but certainly therapy is at a whole other level, right? And it’s hard to imagine in the 1990s lawmakers really considering this use case and how open and available all of this data is becoming. And there’s certainly advocates in the privacy space who say that we absolutely need new data reforms in this country because of artificial intelligence. And not only because like our data is constantly being collected to train AI models. I think people are getting more of a feel for that now in 2026 than years prior, but everything we’ve ever written on the internet has been scraped and collected to train AI. And increasingly, we’re seeing that models are becoming very industry specific. So you can imagine, like a bridge, the doctor’s office scribe, is being trained on vast amounts of data from those health visits. And there’s use cases in law and in other fields as well. And same is true for mental health. There’s a huge value in collecting massive amounts of transcript data from therapy logs to train AI models for specific mental health uses. And that is exactly what Talkspace is doing here. They they’ve talked about that in their investor calls, how they’ve amassed 140 million messes exchanges and they used it to build their own proprietary AI model. They just released it actually, I believe in June. It’s called T, like a T-shirt T-E-E. And they purport that because it’s trained on mental health data, it’s safer than your general chat bots that you may be accessing online that we’ve all read so much about in terms of, you know, potential harms and encouraging suicide and things like that. And how this model would be, because it’s built specifically for mental health, could be safer. I haven’t seen any research that has tested those claims. It’s just recently out. But to circle back to your question, yes, I think we’re in a totally new era when it comes to data and privacy. And there are certainly a lot of conversations happening around what that should look like in terms of legislation.

Stephanie Hepburn: Well, and I think that’s part of it too. So if you had gone to a therapist before and there’s no record keeping where it’s just really the therapist writing down their notes, that’s a lot less accessible than talking through text to your therapist. That record is right there and much more accessible. So, you know, the company mentioned that they store text and videos and audio messages with clients. What’s happening? Are people agreeing to this in order to use Talkspace? I would assume that they would have to click agree or something like that in order for Talkspace to maintain these records.

Annie Gilbertson: Yeah, that’s that’s exactly right. I mean, with any of these services, there’s a privacy policy and it is part of just terms of use. Like you’re not going to be able to use our services unless you agree to these provisions. And for talkspace, yes, it’s laid out in their privacy policy, which is how I, as a journalist, can kind of figure out who’s using data to do what, especially in terms of AI training, is because they lay it out right in their privacy policy. Of course, this has been studied over and over again, and people do not read those privacy policies. They click through. I mean, guilty, like I definitely click through anyway to like just, I’m like, I need to get to the end of this service and use the product. So experts I talked to for that story said, you know, like this is another thing we could think about is like, could we have something that looks a little bit more like informed consent in a traditional study scenario, right? Like, so if you were like a university that was collecting data to do like some longitudinal study for people’s mental health, like the consent practice would look totally different, right? Like somebody would be walking you through how it would be used and what are the potential risks, and like they would try to do informed consent. And so that’s another thing experts talk to me about for that reporting.

Stephanie Hepburn: Well, and if you think about, you know, if we go back to the actual case that began your investigation, this is somebody who was having a hard time. And when you think about these buttons that you’re clicking, and this is her way to outreach a therapist and it’s provided by her employer, you’re adding a whole other element there of somebody who’s in distress and needs to get that service. And so basically the approach is if you don’t sign this, then you don’t get access, or you don’t agree to it, you don’t get access.

Annie Gilbertson: Correct. I mean, that is, I mean, that’s exactly what the privacy policy states is that if you don’t agree to these terms, please don’t use the services. And therapy is expensive and often difficult to obtain through health insurance. So increasingly we’re seeing employers and even insurance companies try to bridge the gap through offering these types of telehealth asynchronous mental health services. But if you don’t agree to sign over your data, then yeah, you wouldn’t be able to use the service. And um, I believe I don’t have it in front of me, but I believe the rules are different in Europe. So Talkspace operates in Europe and the EU has more strict privacy laws than the United States. And I believe that you can opt out there.

Stephanie Hepburn: Yeah, that’s right. In the US, we really don’t have those guardrails. And I think there’s a lot of discussion that maybe the EU has gone too far in one direction. There’s a lot of debate, but certainly the ability to opt out and you have access to a service that you need makes sense. Yeah. So privacy has been an ongoing issue with Talkspace. Can you tell me about the New York City Teenspace allegations?

Annie Gilbertson: Talkspace is a really gigantic company. And you may have heard them sort of doing those like one-off ads on podcasts and elsewhere where they were selling to individual people trying to build up a user base. And a few years ago, new leadership was brought in and they went really hard on trying to get these big contracts with insurers and then also employers, and in some cases, school districts and cities to provide mental health services to just massive amounts of people, right? And so Teen Space was part of that initiative. And um, it’s it’s actually in several places around the country, New York, North Carolina, Seattle, Baltimore County. And the idea is that, you know, teens have a lot of mental health needs and they’re on their phones constantly anyway. They’re digital natives, and maybe this could help kind of bridge the gap. And a few years ago, advocates raised concerns because they had found trackers on the sort of like intake form on the Teenspace site through New York City. So you can imagine coming to a home page and you’re putting in your name and information, and there are trackers for companies like Google or Amazon, and they’re collecting that information and using it to develop a profile to target ads at you, right? And so um, they had raised flags that this is happening on the Teen Space site in New York, and the New York ACLU wrote a letter, and it looks like they ended up having to make a bunch of changes where they had to ensure that the website was not collecting teen data and essentially giving it to advertisers.

Stephanie Hepburn: Oh my gosh.

Annie Gilbertson: Yes, exactly. And so um we actually followed up on that and checked and made sure that that that was still the case, and we also didn’t find in these later years any evidence that that was still going on. But you can imagine that would be very sensitive, right?

Stephanie Hepburn: Oh yeah. And it goes back to what happens with this data, because people again are in these scenarios where they are needing mental health support, and in this case, it’s children. And then it seems like the companies are often collecting data to sell. And so what is that line? Should they not be collecting data at all in this world of machine learning, in this world of training AI? What does that ethically look like? I’m not sure that there’s been a defined answer for that. And there are no guardrails in the United States to really protect when it comes to AI training. And certainly Talkspace is not the only company that has faced similar allegations, but it is a question that needs to be answered. And I wanted to see what your thoughts are.

Annie Gilbertson: I mean, as a journalist, like I try not to take a like a that strong of a point of view in terms of policy. I mean, I think that having covered tech over the last several years and come at this first from covering like big tech like Amazon and Google and antitrust issues and now AI, you know, certainly these companies are amassing a tremendous amount of power and pooling a tremendous amount of wealth. And that is getting built on our data. And I certainly think that there should be more policy discussions in terms of like what does an even playing field actually look like? And what is a fair playing field? And how much say should individual people and certainly minors have in terms of how their data is used and capitalized on by a gigantic corporation.

Stephanie Hepburn: In your research, have you identified AI therapy laws? You know, are there states that are banning AI therapy bots? And if not, do they have some bills on the table? Have you have you looked into that?

Annie Gilbertson: Yeah, there’s actually just like uh my my colleague at Proof, Rebecca Plevin, has done some initial reporting on tracking some of this legislation. And there are several pieces of legislation across the country where people are looking specifically at mental health and at like ambient listeners in doctors’ offices. But it really feels like the public has a different palette for again being like in a doctor’s office talking about your swollen knee and being recorded versus having your therapy conversations recorded. So we’ve seen legislation in California where it hasn’t passed yet that the platforms um obtain consent before they record therapy sessions. We’ve seen in other states um laws that have passed, including in Illinois, where therapy can only be provided by a licensed therapist. And um I believe the language in California’s is a little bit looser. It’s something like therapeutic decisions can only be made by a licensed provider. So, you know, what constitutes a therapeutic decision? And I guess I also have questions of like, well, isn’t that already a law? So depending on what decision is, but but yeah, we’re seeing a ton of action around this stuff. And then of course, there’s the people trying to put in guardrails on the mainstream chatbots, right? Especially with teens and trying to put in age verification. And there’s tons of conversations about who’s liable when the chatbot kind of goes off the rails and encourages really dangerous behavior and how that affects teens. So so much happening in terms of policy discussions at the state level.

Stephanie Hepburn: So, Annie, it’s it’s interesting when you talk about these age limits. I know in the UK they have implemented age limits. And I plan to do an interview in the future with somebody who this is their area of expertise. I’ve been kind of, to be honest, reluctant to believe that this is feasible, but I’ve done a little bit of a deeper dive, and it seems like there are some ways to figure out if somebody, for example, is younger than 16. And I was listening to somebody who mentioned, well, that they’ve had an account for, you know, the past 13 years or the past 16 years, you know, that’s one way that there are some ways to verify. But I wanted to see in your research, you know, in that debate, what are you hearing? Because look, I have two teenagers and they are incredibly clever at bypassing all the things that would have barriers that would get in my way. They they seem to know all the workarounds. So I wanted to see with the people you’ve interviewed, what their thoughts are about whether that’s really viable.

Annie Gilbertson: I mean, I think that there’s widespread doubt how viable that is. And I think there’s been even studies that show that teens can quickly bypass the age verification. Yeah, I it’s just like it’s such a tough nut to crack. It’s like there’s also discussion about are there ulterior motives to even getting behind some of these ideas about age verification? Like, is it is it a little bit of a false flag for safety when there’s probably bigger reforms that are needed down the road? And also the age themselves are valuable, right? So, like if you’re tuning a model, you know, in the future, there’s a lot of discussion that as we engage with these models, they could be serving us ads and all kinds of things to influence our consumer behavior. And age is a valuable data point for that too. And the ways in which a lot of those conversations are completely accessible, like unless you’re using a paid tier for many of those mainstream chat bots, but their researchers can go in and just like look at your entire chat history to see how the model’s performing. So there’s certainly not a ton of privacy when you’re using just the free versions of these bots. But those are all conversations that are certainly happening.

Stephanie Hepburn: So when you talked to Jennifer Camras’s therapist, what were her concerns?

Annie Gilbertson: Well, first she asked not to be named just because she was worried about harm to her reputation given the exposure that her client faced. And she had agreed to testify on her patient’s behalf for her pregnancy discrimination case. So she had agreed to be involved and she was also subpoenaed. And I read through the deposition and it was like a whole day of questioning. And she just said, you know, I just was shocked at the amount of information that they had at their fingertips. And other experts I talked to who are in the therapy space also took issue with that. They said, look, like, you know, the amount of records I keep as a practitioner, like as a therapist, is is just the sort of progress note, right? And that may be like a few sentences like, we worked on coping skills, and I employed this technique for motivation for the future. Like I’m making this up, I don’t know the lingo, but they can be very vague as to sort of like what was discussed and what therapeutic intervention was deployed. And certainly not the very specific details of like, here’s how I’m feeling about my marriage and here’s how I’m feeling about my job. Like that’s not typically information that’s kept that way. So that’s what she reiterated to me was like, I was just shocked at like how much was available because of this new dynamic, new platform.

Stephanie Hepburn: And that’s really the issue, right? So Talkspace pushed back on who released the information, but the reality is what information is being stored. So when Camras went in to follow the subpoena or her attorney did, regardless of whether it was Talkspace or her who released it, you know, it’s really about going into that account and that information is all there.

Annie Gilbertson: Yeah, it’s all there. It’s all kept. I mean, they talk space lays that out also in their, I don’t know if it’s in their term of service or in their privacy language, but essentially that there are inherent risks of exposure with any data that is being kept to. Go back to the credit card example. Like I had to go replace my credit card a couple of weeks ago because of course my number got swiped again. Like, I don’t know how people get this, but like it seems every couple of years I’m having to replace it. So there’s just inherent risks with keeping any kind of data. And of course, the company would say that they are they’re following, you know, the industry standard practices for keeping data protected and safe. But as we’re learning now with these new AI models, too, like a lot of our cybersecurity defense mechanisms are showing new vulnerabilities. And I think like the other point to this too, like it is about the data being kept, but it’s also about how people’s data is being used and whether or not they really have consent over how their data is being used. And certainly like the amount of information that you and I have put into the digital ecosystem that has been vacuumed up to train AI models is like stunning. Like, like I know you’ve published books, like your books may be in there. Like I’ve certainly published numerous articles that have been sucked up into AI and now it’s videos. And if you’re posting pictures of your kids on Instagram and you don’t have a private account, like those very well may being used to train AI models. So it’s just kind of incredible to the extent that our information is exposed to being scraped and then being monetized by these gigantic companies.

Stephanie Hepburn: Right. And I think your point is right on to say, then what? You know, not only is this data being amassed, but how is it being used? And I think that is so critical. And there needs to be a deeper dive in terms of what that looks like, but also what can be done to protect individuals. There’s a company onus, but there’s also what can we do for ourselves and in your investigations? If you delete your Talkspace account, what happens to your data?

Annie Gilbertson: Oh, that’s a good question. I think I read that you can ask for your information to be deleted. I believe that is California state law. California’s often, and New York as well, but they’re often on the forefront of stricter privacy and data protections and stricter rules on the tech platforms. So if they set a standard, it’s often easier to comply, you know, if you just like have it available for everyone, not just in the state of California. So yes, you can request that it’s deleted. I don’t know that you yourself can go in and like, you know, empty your inbox, right? And I don’t know.

Stephanie Hepburn: Well, thank you so much, Annie. Do you have any final thoughts? Like, what are you working on now in the space?

Annie Gilbertson: Oh, I I do. So if there are any talk space or other types of telehealth therapists or other people in the mental health space that are encountering AI or that are using AI as part of their practice or their employer is starting to roll out AI, like we’re so interested in this space. I just don’t think that there’s enough coverage happening in terms of the Venn diagram that is artificial intelligence and mental health. And so I would love to hear from you. You can find me at proofnews.org. If any of your listeners also are interested in following up on more mental health and AI, but also other AI and work coverage, like, you know, we have a newsletter. So I’ll just I’ll plug that too. You can find that on our website at proofnews.org. I’ll also put that in the show notes.

Stephanie Hepburn: Well, thank you so much, Annie. Thanks, Stephanie.

Annie Gilbertson: Thank you for talking to me. I really appreciate it. Thanks, Stephanie.

Stephanie Hepburn: That was Annie Gilbertson. She’s an investigative reporter and managing editor for Proof News, a nonprofit newsroom examining the social impacts of AI. I’ll include her contact information in the show notes. If you enjoyed this episode, please subscribe and leave us a review wherever you listen to the podcast. It helps others find the show. Thanks for listening. I’m your host and producer. Our associate producers are Rin Koenig, Audio Engineering by Chris Mann. Music is Vinyl Couch by Blue Dot Sessions.


References

Woman’s Talkspace Therapy App Sessions Exposed in Court

Annie Gilberton: annie@proofnews.org

Where to listen to and follow ‘CrisisTalk’

Apple | Spotify | Amazon | iHeartYouTube

We want to hear from you

Have you turned to an AI chatbot to discuss an interpersonal or mental health issue? Work at an AI company? Are you a researcher studying AI and mental health? We want to hear from you. Reach us at editor@crisisnow.com

Credits

“CrisisTalk” is hosted and produced by Stephanie Hepburn. Our associate producer is Rin Koenig. Audio engineering by Chris Mann. Music is Vinyl Couch by Blue Dot Sessions.

Discover more from CrisisTalk

Subscribe now to keep reading and get access to the full archive.

Continue reading