"Consumers seeking discreet online care for sensitive conditions found their private health information allegedly routed to advertisers, alongside deceptive billing practices, in a lawsuit filed by federal regulators."
Federal regulators have leveled serious accusations against Hims & Hers Health, a prominent direct-to-consumer telehealth company, alleging a significant breach of patient privacy and deceptive business practices. The lawsuit, filed on July 29, 2026, in federal court in San Francisco, claims the company shared sensitive health information with third-party advertising platforms despite explicit privacy assurances. This action, spearheaded by the Federal Trade Commission (FTC) with support from Utah and California, also targets the company with allegations of deceptive billing and problematic cancellation policies, raising significant concerns for consumers who turn to online platforms for discreet healthcare.
The core of the FTC’s complaint centers on the alleged use of tracking pixels, small pieces of code embedded on websites to monitor user activity and transmit that data to third parties. While a common practice across the commercial web, these pixels become a profound privacy concern when deployed on pages detailing sensitive medical conditions. According to reports by TechCrunch, Hims & Hers is accused of placing trackers from major advertising platforms including Meta (Facebook and Instagram), Snap (Snapchat), Microsoft, Pinterest, Reddit, and X (formerly Twitter). Beyond pixel tracking, the FTC further alleges that the company actively uploaded customer lists to these advertising platforms, a practice that matches known customer identities with platform user accounts.
The health conditions implicated in the complaint are those individuals often seek to manage privately online, such as erectile dysfunction, premature ejaculation, hair loss, weight management, and mental health concerns. The FTC contends that Hims & Hers marketed its services on the promise of privacy and discretion for precisely these sensitive areas, while simultaneously facilitating the undisclosed transmission of this very information to advertisers. Christopher Mufarrige, director of the FTC’s Bureau of Consumer Protection, highlighted the alleged dual nature of the company’s misconduct, stating that the complaint details "consumers unknowingly locked into recurring subscriptions" and the "disclosure of private health information without consent."
These privacy allegations are not isolated; they are presented alongside significant claims regarding the company’s financial dealings with its customers. Regulators allege that Hims & Hers advertised free initial consultations and presented intake processes that suggested no immediate payment was required. However, the complaint asserts that consumers were subsequently charged, often enrolled in recurring subscription models, particularly after a provider issued a prescription. In some instances, these charges allegedly occurred even before a consultation had taken place. Furthermore, the lawsuit claims that the company implemented convoluted and difficult cancellation procedures, leading some customers to continue paying for unwanted prescription refills.
The legal framework cited for these billing allegations includes the FTC Act and the Restore Online Shoppers’ Confidence Act (ROSCA), a 2010 statute specifically designed to regulate online negative-option billing. ROSCA mandates clear disclosure of terms, informed consent before charging consumers, and the provision of a simple and accessible cancellation mechanism.
Hims & Hers has issued a firm rebuttal to these allegations. In statements reported by BioPharma Dive and other outlets, the company has vehemently denied the claims, characterizing them as baseless. Hims & Hers asserts that its privacy policy clearly informs users about how their data may be used and expresses confidence in its legal position. However, the company has not explicitly refuted the specific factual allegations detailed in the reported statements.
This FTC action against Hims & Hers is not an isolated incident but rather part of a broader pattern of enforcement by the agency targeting the digital health sector’s data handling practices. In 2023, the FTC initiated similar lawsuits against GoodRx and BetterHelp, and previously against the telehealth startup Cerebral and alcohol recovery provider Monument. In each of these cases, the core allegation involved the transmission of consumer health data to advertising platforms through website technologies.
The industry has shown signs of responding to this regulatory pressure. Tracking data compiled by health marketing analytics firm Hedy and Hopp and reported by Bloomberg Law indicates a significant decrease in pixel deployment on hospital websites, falling from approximately 98% in 2021 to around 30% in 2025. While this data pertains to hospitals rather than direct-to-consumer telehealth services, it suggests a wider awareness and potential adjustment within the healthcare marketing landscape regarding data tracking.
A critical legal nuance that often surprises consumers is the application of HIPAA (Health Insurance Portability and Accountability Act) to telehealth platforms. Many direct-to-consumer telehealth services operate in a regulatory gray area where HIPAA’s applicability is either contested or limited. This is a primary reason why the FTC, rather than the Department of Health and Human Services (HHS) Office for Civil Rights, is the agency bringing this lawsuit. Consumers often assume that any service involving a prescription automatically falls under federal medical privacy laws, but this assumption does not reliably extend to app-based commercial health services.
For individuals who have utilized telehealth platforms, particularly those that may have shared data, there are proactive steps that can be taken. It is crucial to emphasize that no one should discontinue necessary medical treatment due to privacy concerns; the actions advised here pertain to account management and data settings, not to the safety or efficacy of prescribed medications.
Consumers are advised to review their advertising and data-sharing settings on platforms like Meta, Google, and others. These services typically provide users with the ability to review and delete off-site activity that businesses have shared, and to limit how that data influences ad targeting. These controls are usually located within account settings under labels such as "activity," "ad preferences," or "data sharing."
Additionally, a thorough review of recurring charges is recommended. Individuals enrolled in telehealth subscriptions should examine their current billing terms, identify the renewal date, and understand the cancellation process. Documenting the date and method of any cancellation request is vital for personal records and potential disputes. Consumers who believe they have been charged without explicit consent can dispute the charge with their credit card issuer and can also file a complaint with the FTC through its ReportFraud.gov portal.
Looking ahead, for future healthcare needs, it is important to differentiate between browsing a condition-specific page on a commercial health website and engaging in a direct consultation with a healthcare provider. Care delivered through a health system’s patient portal generally falls under HIPAA protections, representing a meaningful distinction for individuals who consider their medical conditions to be highly sensitive.
Several aspects of the Hims & Hers case remain unresolved. The company has not yet filed its formal legal response to the complaint, and no court has rendered a judgment on any of the allegations. The full scope of the alleged data breach, including the precise number of consumers affected and the specific data elements that were shared, as well as the ultimate remedy regulators will seek, will be determined through the litigation process. MedicalDaily will continue to monitor the case and report on the company’s response and any subsequent court rulings.
Frequently Asked Questions
What did the FTC allege?
The FTC alleged that Hims & Hers shared consumers’ sensitive health information with third-party advertising platforms despite promising privacy. Additionally, the company is accused of deceiving users regarding billing and cancellation practices.
Have the allegations been proven?
No, the allegations have not been proven. The complaint was filed on July 29, 2026, and no court has made any findings. Hims & Hers has called the claims baseless and stated its intention to defend itself.
What is a tracking pixel?
A tracking pixel is a small piece of code embedded in a web page that reports visitor activity to a third party. It becomes a health privacy issue when the tracked page reveals a medical condition.
Which platforms are named in the complaint?
Reporting on the complaint identifies Meta and Snap, along with Microsoft, Pinterest, Reddit, and X.
Does HIPAA cover telehealth apps?
Not always. Many direct-to-consumer telehealth platforms operate outside or at the edges of HIPAA regulations, which is a key reason why the FTC, rather than HHS, is bringing this action.
What can users do now?
Users are advised to review their ad and data-sharing settings on the named platforms. They should also check their telehealth subscription billing terms and cancellation processes, and document any cancellation requests.
Has the FTC pursued similar actions before?
Yes. The FTC has brought similar cases against GoodRx and BetterHelp in 2023, and against Cerebral and Monument.