Federal and state regulators allege the telehealth company sent information about customers' medical conditions to Meta, Snap, and other advertising platforms while marketing itself as private.
What happened
The Federal Trade Commission, joined by the State of Utah and the County of Los Angeles acting on behalf of the People of California, sued Hims & Hers Health, Inc. on July 29, 2026, in the US District Court for the Northern District of California, the agency announced. The complaint alleges the San Francisco telehealth provider shared consumers' sensitive health information with third-party advertising platforms despite claiming its services keep that information private, and separately deceived users about billing and cancellation. Claims are brought under Section 5 of the FTC Act and the Restore Online Shoppers' Confidence Act, with California adding false advertising and unfair competition counts and Utah citing its Consumer Sales Practices Act. Hims & Hers prescribes treatments for conditions including erectile dysfunction, hair loss, weight loss, anxiety, and depression. The company's shares fell sharply on the day of filing.
Going deeper
Two separate disclosure mechanisms appear in the complaint. Regulators allege the company deployed third-party tracking code that automatically transmitted "Events," meaning specific actions visitors took on the Hims website, to advertising platforms, including the Meta Pixel and Meta's Conversions API, which sends data directly from a company's own servers rather than from the visitor's browser. Separately, the complaint alleges Hims uploaded lists of certain customers to those platforms, a practice that identifies people by name rather than by browsing behavior. Trackers from Snap, Microsoft, Pinterest, Reddit, and X were also placed on the site, according to TechCrunch's review of the filing. The billing allegations run on a parallel track, with regulators claiming customers were charged after completing an intake form rather than after speaking with a provider, and that cancellation required contacting customer service by phone, email, or chat until an online option arrived in April 2023.
What was said
"Hims promised a free consult and private health care. What Utahns actually got was a subscription trap and their most personal health data shipped to advertisers," said Utah Attorney General Derek Brown in a statement on the filing. The FTC's theory ties the two sets of allegations together, arguing the company could only build advertising audiences with that degree of specificity by disregarding what it had told users about keeping their conditions private. Hims & Hers called the allegations "baseless" and said it will defend itself, stating that customers have the information they need to make informed decisions about their care, as reported by CBS News.
In the know
Companies handling health data outside HIPAA's reach answer to the FTC instead, and the agency has been building that authority for several years. Its Health Breach Notification Rule covers health apps and similar technologies not regulated by HIPAA, and a 2024 update expanded the definition of a breach to include unauthorized disclosures rather than security incidents alone, the FTC explained when the revised rule took effect. Enforcement under that rule reached GoodRx in February 2023, the fertility app Premom the same year, and the mental health service BetterHelp shortly after, each involving health data flowing to advertising platforms in violation of the company's own privacy policy. The Hims complaint does not charge a Health Breach Notification Rule violation, relying instead on deception and unfair practices under the FTC Act. The distinction is procedural rather than substantive, since both routes turn on the same question of whether a company did what its privacy policy said it would.
The big picture
Nothing about this case depends on a hacker. Every disclosure at issue was configured deliberately by the company for advertising purposes, which puts it in the same category as the pixel litigation now moving through courts against hospitals and health systems. Covered entities face equivalent exposure from OCR rather than the FTC, following the December 2022 bulletin that told regulated organizations that tracking technologies that transmit protected health information to third parties can constitute a HIPAA breach. The practical lesson sits in the gap between what marketing deploys and what compliance reviews, since a pixel added to improve conversion tracking creates a disclosure regardless of which department authorized it. Organizations should inventory every tracking technology on patient-facing pages, confirm whether any transmits data tied to a condition, appointment, or provider, and check that their published privacy language matches what the site actually does.
FAQs
Is a telehealth company like Hims & Hers subject to HIPAA?
It depends on the structure. The affiliated medical groups providing care and the pharmacies filling prescriptions are typically covered entities, while the consumer-facing platform may sit outside HIPAA depending on how it handles transactions and what agreements bind it. That ambiguity is precisely why the FTC has taken an active role in this market.
What is the Restore Online Shoppers' Confidence Act?
A 2010 statute governing subscriptions that renew automatically, known as negative option features. It requires sellers to disclose material terms clearly, obtain informed consent before charging, and provide a simple cancellation mechanism. The FTC alleges Hims failed all three requirements.
How does the Conversions API differ from a tracking pixel?
A pixel runs in the visitor's browser and can be blocked by ad blockers or browser privacy settings. The Conversions API sends data server-to-server from the company's own systems, so no browser-side control interferes with it, which makes the disclosure invisible to the person whose data is moving.
Do hashed identifiers protect the people in an uploaded customer list?
Not meaningfully. Hashing converts an email address into a fixed string, but the advertising platform hashes its own user emails the same way and matches them, which is the entire purpose of the upload. The person is identified even though the raw address never changes hands.
What should a covered entity ask its marketing vendor about tracking?
Which tools are deployed on which pages, what data each transmits, whether any operate server-side, and whether a business associate agreement covers the recipient. Organizations should also ask what happens to data already transmitted, since removing a tracker going forward does nothing about disclosures that already occurred.
