FTC Sues Hims & Hers Over Alleged Health Data Sharing With Meta and Snap

Table of Contents

FTC Sues Hims & Hers Over Alleged Health Data Sharing With Meta and Snap

The federal complaint alleges the telehealth company promised consumers a private and discreet healthcare experience while sending health-related customer information and website activity into the online advertising ecosystem.

A privacy promise is only as good as the technology operating behind it.

The Federal Trade Commission, California and Utah have sued Hims & Hers Health, alleging the telehealth company shared consumers’ sensitive health information with Meta, Snap and other advertising platforms despite telling people its services were private, secure and discreet.

The complaint does not describe a hacker breaking into a medical database. It describes something more routine and increasingly central to health privacy enforcement: customer-list uploads, advertising pixels, server-side conversion tools and website events allegedly transmitting information through the company’s own marketing infrastructure.

The lawsuit also accuses Hims & Hers of charging consumers for prescription subscriptions before they had a meaningful opportunity to review a provider’s recommendation, failing to clearly disclose refill dates and making cancellation unnecessarily difficult.

Together, the allegations present a broader regulatory warning. Privacy failures, subscription dark patterns and misleading interface design are no longer being examined as separate compliance problems. Regulators are treating them as parts of the same consumer experience.

The case was filed July 29, 2026, in the U.S. District Court for the Northern District of California. The allegations have not been proven, and the case will be decided by the court. Hims & Hers denies the claims and says it will vigorously defend itself.

What the FTC, California and Utah Allege

Hims & Hers operates direct-to-consumer telehealth platforms offering treatments for conditions that include sexual health, hair loss, skin concerns, mental health and weight management.

Consumers seeking prescription treatment generally complete an online intake process that can include dozens of questions about their medical history, treatment interests and health conditions.

According to the complaint, Hims & Hers marketed that process as private and represented that sensitive information would be accessed only by the medical providers managing the consumer’s care.

The company also allegedly promoted its service as a “100% online, private, and secure process.” Regulators contend those representations led consumers to believe that information about their medical conditions would not be disclosed to advertising companies without their consent.

The lawsuit alleges the reality was different.

Regulators claim Hims & Hers disclosed consumers’ health information through two principal advertising channels:

  • Uploading lists of selected customers to advertising platforms
  • Using tracking pixels and server-to-server advertising tools that automatically transmitted website events

The complaint specifically identifies Meta and Snap while also describing tracking technologies associated with numerous other advertising and analytics platforms.

Customer Lists Were Allegedly Uploaded to Advertising Platforms

One part of the case concerns lists of customers allegedly shared with Meta and Snap.

Advertising platforms commonly allow a company to upload identifiers associated with existing customers. The platform can attempt to match those identifiers to user accounts for advertising, audience measurement or the creation of similar audiences.

The identifiers may be hashed before transmission, but hashing does not necessarily make the activity anonymous. The point of the upload is often to match the record to an identifiable platform user.

In a healthcare setting, the selection criteria behind a customer list can reveal sensitive information even when the file does not contain a medical diagnosis field.

A list may communicate that the people included:

  • Sought treatment for a particular medical condition
  • Completed a condition-specific intake process
  • Purchased a particular medication
  • Visited a specific treatment pathway
  • Belonged to a health-related advertising audience

The FTC’s complaint alleges Hims & Hers shared certain customer lists with Meta and uploaded lists to Snap so those individuals could be matched to their social media accounts. Some details in the publicly filed complaint are redacted, but the government’s theory is clear: the identity of a customer, when combined with the treatment context, can itself constitute sensitive health information.

The Complaint Targets the Meta Pixel and Conversions API

The second alleged disclosure channel involved automated tracking technologies placed on the Hims & Hers platforms.

The complaint identifies two Meta business tools:

  • The Meta Pixel
  • Meta’s Conversions API

A browser-based pixel can collect information as a person moves through a website. A conversions application programming interface can send event information directly from the company’s server or internal systems to the advertising platform.

That distinction is important.

Removing a browser cookie or blocking one visible pixel does not necessarily stop server-side data sharing. A company may continue sending advertising events through an API even when the transfer is not readily visible in the consumer’s browser.

The complaint alleges that both Meta tools automatically tracked and disclosed certain events involving visitors to Hims & Hers websites. Regulators claim those events communicated health information to Meta.

The exact sensitivity of an event depends on what the event represents.

An event labeled only as a page view may appear ordinary in isolation. But if it occurs on a webpage devoted to erectile dysfunction, premature ejaculation, weight-loss treatment, mental health medication or another identifiable condition, the page context can disclose why the person was there.

Additional parameters can make the disclosure even more revealing. These may include:

  • Page names and URLs
  • Product or treatment identifiers
  • Form actions
  • Account identifiers
  • Email addresses
  • Device and browser information
  • Purchase or conversion events
  • Information about completed intake steps

The central compliance question is not whether a tracking event looks harmless to the marketing department. It is what an outside recipient can understand when the event is combined with the page, account, campaign and user context.

The Allegations Extend Beyond Meta and Snap

Meta and Snap are the advertising platforms highlighted in the FTC’s public announcement, but the complaint describes a considerably wider tracking environment.

It alleges that Hims & Hers placed pixels associated with platforms including:

  • Microsoft
  • Google
  • Criteo
  • MediaBids
  • PartnerCentric
  • PebblePost
  • Pinterest
  • Spotify Ad Analytics
  • Reddit
  • StackAdapt
  • TikTok
  • The Trade Desk
  • X

Regulators allege many of these technologies captured and shared health information through similar event tracking, contrary to the company’s privacy assurances.

The inclusion of this broader vendor list matters.

Healthcare companies often focus their compliance reviews on the Meta Pixel because it has received the most public attention. The underlying risk is not limited to Meta.

Any advertising, analytics, session-replay, conversion-measurement or audience-building technology can create exposure when it receives information revealing a person’s medical interests, symptoms, treatments or healthcare activity.

The Company’s Privacy Claims Are Central to the Case

The FTC is not alleging only that data was transmitted.

It is alleging that the transmissions contradicted the company’s own privacy representations.

According to the complaint, Hims & Hers told consumers that their medical records and sensitive information would be accessed only by the medical providers managing their care. It also promoted the service as private, secure and discreet.

Those statements matter because Section 5 of the FTC Act prohibits unfair or deceptive acts and practices.

A company can create legal exposure when its privacy claims omit material data sharing or convey a level of confidentiality its technical systems do not provide.

A privacy notice cannot be evaluated only as a legal document. Regulators may consider the complete set of representations made through:

  • Website copy
  • Frequently asked questions
  • Intake screens
  • Advertisements
  • Influencer campaigns
  • Mobile applications
  • Consent interfaces
  • Customer support communications

The complaint alleges Hims & Hers exercised review and approval over influencer advertising that described its services as discreet. Regulators contend those statements reinforced the expectation that a consumer’s treatment information would remain confidential.

This Is Not Merely a HIPAA Question

One of the most consequential lessons from the case is that health privacy does not begin and end with the Health Insurance Portability and Accountability Act.

Consumers often assume any health-related platform is fully governed by HIPAA. Businesses may also focus their compliance analysis too narrowly on whether a particular company, provider or data flow meets HIPAA’s definitions.

The FTC complaint relies instead on broader federal and state consumer protection authority.

The FTC alleges violations of:

  • Section 5 of the FTC Act
  • The Restore Online Shoppers’ Confidence Act

California asserts claims under:

  • The California Unfair Competition Law
  • The California False Advertising Law

Utah asserts claims under:

  • The Utah Consumer Sales Practices Act

The government seeks permanent injunctive relief, monetary relief, civil penalties and other remedies.

This means a company can face substantial health privacy exposure even when regulators do not bring a HIPAA claim.

Depending on the business and data involved, additional laws may include state comprehensive privacy statutes, consumer health data laws, biometric privacy requirements, breach-notification laws and the FTC’s Health Breach Notification Rule.

The FTC Has Warned Telehealth Companies About Tracking Pixels Before

The Hims & Hers lawsuit did not arrive without warning.

In 2023, the FTC and the U.S. Department of Health and Human Services warned approximately 130 hospital systems and telehealth providers about the privacy risks created by tracking technologies such as the Meta Pixel and Google Analytics.

The agencies cautioned that these tools can collect identifiable health information as people interact with websites and mobile applications, often without their knowledge.

The FTC has also pursued several digital health companies over alleged advertising disclosures:

  • GoodRx: The company agreed to pay a $1.5 million civil penalty in the FTC’s first enforcement action under the Health Breach Notification Rule. The case involved alleged disclosures to Facebook, Google and other companies.
  • BetterHelp: The online counseling company agreed to pay $7.8 million and was prohibited from sharing sensitive health data for advertising after allegations involving Facebook, Snapchat, Criteo and Pinterest.
  • Cerebral: The telehealth company agreed to an order restricting the use and disclosure of sensitive data and requiring more than $7 million in payments over privacy and cancellation allegations.
  • Monument: The alcohol addiction treatment service agreed to restrictions prohibiting health data disclosures for advertising and requiring affirmative consent for certain other disclosures.

The Hims & Hers case extends an established enforcement pattern rather than introducing a new theory.

Privacy and Subscription Dark Patterns Appear in the Same Lawsuit

The privacy allegations are only one part of the government’s case.

The complaint also alleges Hims & Hers misled consumers about when they would be charged for prescription treatment.

According to regulators, the company promoted free consultations and told consumers they could connect with a provider to determine whether a treatment was right for them.

The lawsuit alleges that consumers were nevertheless charged and enrolled in recurring prescription subscriptions shortly after submitting an intake form, with little opportunity to review or approve the recommended treatment.

The FTC also alleges Hims & Hers did not clearly disclose when recurring refill charges would occur. Consumers could therefore miss the deadline to stop another shipment.

Cancellation was allegedly difficult as well.

Before 2023, most consumers could cancel only through customer service channels such as phone, email or chat. After online cancellation became available, the FTC alleges the cancellation button remained hidden behind an option labeled “add/remove items from order” and several additional steps.

These allegations reflect a common enforcement theme.

Regulators are increasingly examining whether companies use interface design to obtain data, consent or money through a process that consumers would not reasonably understand.

The same design choices that create a subscription dark pattern can also undermine privacy consent:

  • Important terms appear after the user has invested time in a process
  • The affirmative option is visually prominent
  • The privacy-protective or cancellation option is difficult to locate
  • Material information is fragmented across several screens
  • The company treats completion of one action as consent to several others
  • Consumers cannot easily reverse their original choice

Hims & Hers Denies the Allegations

Hims & Hers has rejected the government’s claims.

In a public statement, the company said the lawsuit disregards evidence provided during an investigation lasting nearly three years, ignores state law and telehealth industry standards, and improperly attempts to create claims.

The company characterized the action as an effort to generate headlines and said it is confident in its position.

Hims & Hers also stated that its customers receive information necessary to make informed decisions, that its privacy policy describes available data choices and that information shared with healthcare providers is used only to provide care.

The company said it has continued strengthening its systems and processes as it has grown.

These defenses will now be tested through the litigation process.

At this stage, the complaint contains allegations rather than judicial findings of liability.

What the Case Means for Telehealth and Digital Health Companies

The lawsuit should prompt immediate review across telehealth, healthcare, wellness, pharmacy, mental health and direct-to-consumer medical platforms.

The relevant question is not simply whether the company uses a Meta Pixel.

Companies should determine what every advertising and analytics tool receives, why it receives the information and whether the transfer is consistent with consumer expectations and applicable law.

Inventory Every Tracking Technology

Identify all website and mobile technologies, including:

  • Advertising pixels
  • Analytics scripts
  • Conversion APIs
  • Session-replay tools
  • Chat and customer support widgets
  • Affiliate tracking
  • Social media tags
  • Server-side tag management
  • Mobile software development kits

The review must extend beyond technologies visible in the browser.

Map the Events Being Sent

For each vendor, document:

  • The event name
  • The page or screen where it fires
  • The parameters included
  • The identifiers transmitted
  • Whether the transfer is browser-side or server-side
  • The purpose of the event
  • How the recipient may use the information

An event should be evaluated in context. A generic event fired on a condition-specific treatment page may still reveal health information.

Review Customer-List Uploads

Marketing teams should not upload customer lists to advertising platforms without understanding how those lists were selected.

Review whether an audience reveals:

  • A diagnosis
  • A treatment interest
  • A medication purchase
  • Participation in a health program
  • Use of a sensitive service

Hashing customer identifiers does not eliminate the sensitivity when the advertising platform can match the data back to an account.

Test Consent Before Tags Fire

A consent banner is not sufficient when tracking technologies activate before the consumer makes a choice.

Businesses should verify that:

  • Nonessential tracking is blocked before consent where required
  • Reject and opt-out choices are technically honored
  • Server-side events follow the same consent status
  • Consent signals reach every relevant vendor
  • Consent records are retained
  • Later tag changes do not bypass the controls

Compare Marketing Claims With Technical Reality

Review every statement describing the service as private, secure, anonymous, confidential or discreet.

Those claims should be tested against actual data flows.

The review should include website copy, advertising, influencer materials, sales scripts, FAQs and application interfaces—not only the formal privacy policy.

Review Vendor Contracts

Contracts should identify:

  • The information the vendor receives
  • The permitted purpose
  • Whether the vendor can use data for its own advertising
  • Retention restrictions
  • Deletion requirements
  • Security obligations
  • Subprocessor use
  • Consumer request support
  • Audit and monitoring rights

Calling a vendor a service provider does not make the relationship compliant when the vendor uses the information for its own commercial purposes.

Connect Privacy and Subscription Reviews

Consent, billing and cancellation interfaces should be reviewed together.

A company should be able to show that consumers understood:

  • What they were purchasing
  • When they would be charged
  • Whether the purchase would renew
  • How to cancel
  • What personal information would be collected
  • Which outside parties would receive it

Why Periodic Website Audits Are No Longer Enough

Tracking environments change constantly.

A website may be reviewed and declared compliant, only for a marketing agency, product team or tag manager administrator to add another pixel days later.

Server-side events can also change without producing an obvious visual difference on the site.

Telehealth and healthcare businesses should implement continuing controls capable of detecting:

  • New trackers
  • Changed event parameters
  • Tags firing before consent
  • Unapproved vendors
  • Data sent from sensitive pages
  • Broken opt-out signals
  • Differences between stated and actual practices

A spreadsheet prepared during an annual audit cannot show what a website transmitted yesterday.

The Enforcement Message Is Bigger Than Hims & Hers

The Hims & Hers complaint is significant because it targets one of the country’s most recognizable consumer telehealth brands.

But the underlying allegations are not unique to a large public company.

The same risks exist wherever a business combines sensitive services with aggressive digital advertising.

That includes:

  • Telehealth providers
  • Online pharmacies
  • Weight-loss clinics
  • Fertility platforms
  • Mental health applications
  • Substance-use treatment services
  • Genetic testing companies
  • Symptom checkers
  • Wellness and fitness applications
  • Medical lead-generation websites

The government’s position is that ordinary advertising technology does not become harmless merely because it is common.

When the surrounding context reveals a medical condition or treatment interest, an ordinary marketing event can become sensitive health information.

Captain Compliance Helps Identify Health Data Tracking Risk

Captain Compliance helps organizations identify cookies, pixels, session-replay technologies, server-side connections and other third-party tools operating across websites and digital properties.

Our platform and privacy services can support:

  • Continuous tracking technology scanning
  • Consent management and automatic blocking
  • Consent and preference records
  • Website privacy assessments
  • Vendor and data-flow reviews
  • Consumer privacy request automation
  • Privacy notice and cookie disclosure updates
  • Documentation for regulatory inquiries

The Hims & Hers lawsuit is still at the allegation stage.

Its compliance lesson is already clear.

A company cannot promise consumers a private healthcare experience while leaving the advertising infrastructure outside the privacy review.

Frequently Asked Questions

What does the FTC allege Hims & Hers shared?

The FTC alleges Hims & Hers shared sensitive health information through selected customer lists and website events transmitted by tracking technologies. The complaint specifically identifies Meta and Snap and describes pixels associated with several additional advertising platforms.

Has Hims & Hers been found liable?

No. The complaint contains allegations, not findings of liability. Hims & Hers denies the claims and says it will defend itself in court.

What laws are involved in the lawsuit?

The FTC asserts claims under the FTC Act and the Restore Online Shoppers’ Confidence Act. California asserts unfair competition and false advertising claims, while Utah asserts claims under its Consumer Sales Practices Act.

Does the lawsuit allege a cybersecurity breach?

No traditional hacking incident is alleged. The privacy claims concern information allegedly shared through customer-list uploads, advertising pixels and conversion technologies used by the company.

Why can a website event be health information?

An event may reveal that an identifiable person visited a page, completed a form or purchased a product connected to a specific medical condition. The page and treatment context can make an otherwise ordinary event sensitive.

Does hashing an email address make a customer-list upload anonymous?

Not necessarily. Advertising platforms may use hashed identifiers specifically to match the information to an existing user account. The selection and intended matching of the list can still create privacy risk.

Is this only a HIPAA issue?

No. The government’s claims rely on federal and state consumer protection laws. Digital health companies may also be subject to state privacy laws, consumer health statutes and the FTC Health Breach Notification Rule depending on their activities.

What are the subscription allegations?

Regulators allege consumers were charged and enrolled in recurring prescription subscriptions without adequate informed consent, were not clearly told when refills would be charged and encountered unnecessary obstacles when trying to cancel.

What should telehealth companies review immediately?

Companies should inventory tracking technologies, map browser-side and server-side events, review customer-list uploads, test consent controls, examine vendor contracts and compare privacy claims with actual data transfers.

How can Captain Compliance help?

Captain Compliance can continuously scan websites for tracking technologies, support automatic blocking and consent management, document consumer choices and help organizations identify privacy risks before they become regulatory investigations or litigation. Book a demo below for a complimentary privacy audit.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.