US health data privacy enforcement

FTC's Hims & Hers Suit Targets a Broken Promise, Not Ad Tech Itself — That Distinction Matters

FTC, Utah, and California sue Hims & Hers for allegedly sharing sensitive health data with Meta and Snap despite promising a private service.

Three Years of Health-Data Ad-Tracking Enforcement People of Internet Research · US $7.8M BetterHelp 2023 settlement FTC fine for sharing therapy-intak… $1.5M GoodRx 2023 settlement First-ever FTC Health Breach Notif… 3 states/agencies Joint plaintiffs on Hims suit FTC, Utah, and California (via LA … ~3 years Length of FTC probe Hims says the investigation ran ne… peopleofinternet.com
Three Years of Health-Data Ad-Tracking… People of Internet Research · US $7.8M BetterHelp 2023 settlement $1.5M GoodRx 2023 settlement 3 states/agencies Joint plaintiffs on Hims suit ~3 years Length of FTC probe peopleofinternet.com

Key Takeaways

A Third Strike on Telehealth Ad Tracking

On July 29, 2026, the Federal Trade Commission — joined by Utah and Los Angeles County on behalf of California — sued Hims & Hers Health, alleging the telehealth giant shared customers' sensitive medical information with advertising platforms including Meta and Snap while marketing itself as a "100% online, private, and secure" service (FTC press release; The Record). The complaint alleges Hims disclosed both customer lists and website-visitor activity — captured via third-party tracking pixels — covering conditions like erectile dysfunction, hair loss, and mental health, categories most consumers would not expect to end up in an ad-targeting profile (Yahoo Finance/Reuters). The suit also alleges Hims charged customers for prescriptions almost immediately after an intake form, before any real provider review, and made cancellation deliberately hard (STAT News). Hims called the suit "an effort to generate headlines at our expense" and said it "disregards substantial evidence" from a nearly three-year investigation (The Record). Shares fell sharply on the news (Yahoo Finance/Reuters).

This Is Not a New Theory — It's the Third Application of One

The FTC isn't inventing a novel privacy doctrine here. It is applying the same deception theory it used against GoodRx in 2023 — the agency's first case under the Health Breach Notification Rule, which produced a $1.5 million settlement and a ban on GoodRx sharing health data for advertising after it shared prescription and condition data with Facebook, Google, and Criteo while displaying a misleading "HIPAA Secure" badge (FTC press release; HIPAA Journal) — and against BetterHelp later that year, which paid $7.8 million after sharing therapy-intake data with Facebook, Snapchat, Pinterest, and Criteo. The pattern across all three cases is identical: a company makes an affirmative privacy promise, then routes health signals through standard ad-tech pipes anyway. That consistency is worth noting before assessing whether this specific suit is proportionate.

Steelmanning the Case for Aggressive Enforcement

The strongest argument for the FTC's approach is that health data occupies a different risk tier than ordinary browsing history. A tracking pixel that reveals someone searched for running shoes carries little downside; one that reveals a customer's HIV medication, mental health treatment, or fertility history carries real risk of discrimination, insurance friction, or social harm if it leaks or is misused, and there is no opt-out once an ad platform has ingested it. Much of this data also falls outside HIPAA entirely, because intake-form answers routed to a marketing pixel never touch a HIPAA-covered transaction — leaving the FTC Act's deception and unfairness authority as the only federal backstop. Given that gap, and given that telehealth is exactly the sector where consumers are most likely to trust an explicit "private and secure" promise, regulators have a legitimate case that enforcement, not just disclosure, is warranted.

Why the Proportionate Read Still Favors the FTC's Framing — With One Caveat

Even granting that case, the FTC's approach here is the right regulatory instrument for the job. It is not banning ad tracking, requiring pre-clearance of marketing pixels, or imposing a new licensing regime on telehealth. It is enforcing a specific promise the company made and, on the FTC's telling, did not keep — a narrower and more predictable intervention than industry-wide rulemaking, and one that gives every other telehealth operator a clear, low-cost compliance path: don't claim privacy you don't deliver. That is proportionate, evidence-based regulation working as intended, and three consecutive cases (GoodRx, BetterHelp, now Hims) give the sector a genuinely predictable enforcement record rather than a surprise.

The caveat is that the complaint bundles the tracking-pixel allegations with billing and cancellation claims that are conceptually distinct — deceptive-subscription practices are a real problem, but they are not a health-privacy problem, and conflating them risks letting a strong privacy case carry weaker consumer-billing claims across the finish line, or vice versa. Courts and future defendants would benefit from the FTC keeping those theories separately pleaded and separately provable.

The Real Gap Congress Hasn't Closed

The deeper issue this case exposes is that the U.S. still has no general federal statute governing sensitive-category data outside HIPAA — leaving the FTC's Section 5 deception authority to do double duty as the country's de facto health-privacy law, one enforcement action at a time. That approach has now produced three consistent, well-reasoned cases, which is a point in its favor. But it also means the rules for an entire fast-growing industry are being written retroactively through consent decrees rather than prospectively through legislation. A narrow federal statute defining sensitive health-adjacent data and default consent requirements for its use in advertising — not a broad new privacy bureaucracy — would give telehealth companies certainty up front instead of litigation risk after the fact, without slowing the sector's growth.

Sources & Citations

  1. FTC: Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices
  2. FTC: Enforcement Action to Bar GoodRx from Sharing Health Info for Advertising
  3. The Record: FTC sues Hims & Hers
  4. STAT News: Hims misled consumers, FTC alleges
  5. Yahoo Finance/Reuters: FTC suing Hims for sending health info to Meta, Snap
  6. HIPAA Journal: Court approves FTC-GoodRx settlement