What the FTC Says Hims & Hers Actually Did
The FTC’s complaint, filed July 29, 2026 and joined by the California Attorney General and Utah’s Division of Consumer Protection, centers on a specific contradiction: what Hims & Hers told customers about their data versus what the company allegedly did with it. According to the complaint, the company represented across its homepage, advertisements, and paid influencer endorsements that customer health data would be shared “only with the consumers’ medical providers”, marketing its telehealth service as “private” and “secure.”
TechCrunch reports the company placed pixel-sized tracking code from Meta, Snap, Microsoft, Pinterest, Reddit, and X directly on its website, with these trackers capturing and transmitting user health information to each platform in real time — contrary to the company’s own stated privacy policy. CBS News reports Hims & Hers used Meta’s tools specifically to monitor website activity and shared customer lists with advertising platforms for targeting purposes, a technique that lets an advertiser match a health-service customer against Meta’s or Snap’s existing user profile to build precisely targeted ad audiences.
FTC Bureau of Consumer Protection Director Christopher Mufarrige framed the core violation: “Hims was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions ‘privately’ or keeping their health information private.” That statement gets at the legal theory driving the case — not that data-sharing with advertisers is inherently illegal, but that doing so while explicitly promising customers the opposite constitutes deception.
The Billing and Cancellation Allegations Round Out the Complaint
Data-sharing is not the only allegation. TechCrunch reports the complaint also targets Hims & Hers’ billing and cancellation practices, alleging the company engaged in deceptive billing by failing to clearly disclose when consumers would be charged for prescriptions, and separately created cancellation policies that made it difficult for subscribers to cancel — allegations CBS News confirms center on unclear charge timing and cancellation friction, issues the FTC treats as violations of federal consumer protection law independent of the privacy claims.
On the legal mechanics, Venable’s analysis of the complaint notes the FTC is relying on Section 5 of the FTC Act — the agency’s core authority against “unfair or deceptive acts or practices” — alongside California and Utah’s own state-level unfair-and-deceptive-practices statutes and California’s state constitutional privacy protections. Notably, Venable’s analysis points out the complaint does NOT invoke the FTC’s Health Breach Notification Rule, a tool the agency used more aggressively under the prior administration — a legal-strategy detail suggesting the current FTC is building this case on general deception authority rather than health-specific breach-notification rules.
Hims & Hers has pushed back publicly. CBS News reports the company called the allegations “baseless”, stating its privacy policy allows customers to control how their data is used, while TechCrunch reports the company said its privacy policy “makes clear” that users “may choose how their data is used” and expressed confidence it would prevail in defending against the allegations.
Advertisement
Why This Case Matters Beyond One Telehealth Company
The market reacted immediately: CBS News reports Hims & Hers shares fell nearly 15% the day the lawsuit became public, a sharp single-day move that reflects how directly health-data privacy exposure now translates into investor risk for telehealth companies, whose entire business model depends on customers trusting a service with medically and personally sensitive information. Telehealth exploded as a category over the past several years precisely because customers were willing to discuss sensitive conditions — hair loss, weight management, sexual health — through a screen rather than in person, on the implicit promise that doing so carried more privacy than an in-person visit that shows up in a shared electronic health record. A regulatory finding that a major platform violated that specific promise threatens the trust premium the entire telehealth sector has been selling.
The case also lands at a moment when tracking-pixel litigation has become one of the most active areas of privacy enforcement across healthcare-adjacent industries, precisely because pixels are technically easy to detect (researchers and regulators can find them by inspecting a website’s network traffic) and factually straightforward to compare against a company’s stated privacy promises — making pixel-based health-data cases some of the more provable privacy violations regulators currently pursue, compared to harder-to-establish claims about internal data handling practices.
What This Means for Telehealth and Health-Adjacent Companies
1. Audit every tracking pixel and SDK against your actual privacy policy language, not just industry norms
If your privacy policy promises data stays “private” or is shared “only with medical providers,” any Meta Pixel, Snap tracker, or similar tool feeding user behavior data to an ad platform is a direct, provable contradiction — the exact fact pattern the FTC used here. This is a mechanical compliance check any company can run today, not a theoretical risk.
2. Treat marketing claims and technical implementation as one unified compliance surface
The FTC’s complaint spans homepage copy, paid advertising claims, and influencer endorsements alongside the technical tracking implementation — meaning legal and marketing teams cannot treat privacy promises as a marketing-department concern separate from what the engineering team actually ships. Any company making “private” or “secure” claims needs those claims reviewed against actual data flows, not just against what the privacy policy legally permits.
3. Expect state attorneys general to keep pairing with the FTC on health-data cases
With California and Utah both joining this action using their own state unfair-and-deceptive-practices authority, companies should expect state AGs to increasingly co-file alongside the FTC on health-privacy cases rather than states acting alone or deferring entirely to federal enforcement — meaning compliance reviews need to account for each relevant state’s own unfair-and-deceptive-practices standards, not just federal FTC Act Section 5 requirements.
The Regulatory Signal Behind the Case
What makes this case notable beyond its facts is the enforcement pathway the FTC chose: general deception authority under Section 5, not the health-specific Breach Notification Rule the agency leaned on more heavily in recent years. That choice suggests the current FTC is building health-privacy cases on the same foundational theory it uses across all consumer protection — promises made publicly must match practices implemented technically — rather than relying on health-sector-specific tools that could be narrowed or challenged more easily. For telehealth and any company handling sensitive personal data under a “private” or “secure” marketing promise, that’s arguably a broader and more durable enforcement theory than a health-specific rule would be, since it applies the same scrutiny regulators already bring to any company’s privacy claims, medical or otherwise.
Frequently Asked Questions
What exactly is the FTC alleging against Hims & Hers?
The FTC alleges Hims & Hers shared sensitive customer health information with third-party advertising platforms — TechCrunch identifies these as Meta, Snap, Microsoft, Pinterest, Reddit, and X — despite publicly promising the data would stay private and be shared only with medical providers, alongside separate allegations of deceptive billing and difficult subscription cancellation.
Which states joined the FTC in this lawsuit?
Venable’s legal analysis identifies the California Attorney General and Utah’s Division of Consumer Protection as co-plaintiffs alongside the FTC, each relying on their own state unfair-and-deceptive-practices statutes in addition to the FTC’s Section 5 authority.
How did the market react to the lawsuit?
CBS News reports Hims & Hers shares fell nearly 15% the day the lawsuit became public on July 29-30, 2026, reflecting investor concern about the reputational and financial exposure of a health-data privacy case against a telehealth company whose business model depends on customer trust with sensitive information.
Sources & Further Reading
- FTC Sues Hims & Hers for Allegedly Sharing Patients’ Medical Data With Advertisers Meta and Snap — TechCrunch
- FTC Sues Hims & Hers, Alleging It Shared People’s Health Data With Meta and Snap — CBS News
- FTC and States Take Action Against Hims & Hers: Key Privacy Takeaways for Consumer Health Data Sharing — Venable LLP













