confidentiality provisions in place
This is not true.
They shared data with Facebook and Facebooks "confidentiality provisions" say "This is ours now and we will make this public". And they did in fact share the information. Which is how the watchdog found out about it.
Specifically, the FTC stated in its compliant:
...GoodRx has taken no action to limit how Advertising Platforms like Facebook, Google, and Criteo, and other third parties like Branch and Twilio, could use the personal health information it shared with them. Rather, GoodRx agreed to each of these third parties’ standard terms of service, or entered into agreements that permitted each Advertising Platform to use GoodRx users’ personal health information expansively, including for other advertising or for their own internal business purposes