Health Data Tracking Lawsuit: FTC and States Sue Hims & Hers

Article Content
On July 29, 2026, the Federal Trade Commission (FTC), operating alongside state regulatory authorities from California and Utah, filed a landmark federal lawsuit in the Northern District of California against direct-to-consumer telehealth giant Hims & Hers Health, Inc. The joint enforcement action alleges that the company systematically engaged in unauthorized health data tracking, harvesting patient medical inquiries and sensitive treatment metadata and transmitting them directly to major Big Tech advertising platforms—including Meta, Snap, Google, and X—via embedded code snippets and server-side pipelines. Despite explicit marketing assurances and contractual privacy policies promising complete confidentiality for discreet medical care, the complaint charges Hims & Hers with converting confidential patient interactions into algorithmic feed material for hyper-targeted social media advertising campaigns.
The regulatory action exposes a fundamental structural tension within the direct-to-consumer healthcare sector. Platforms specializing in sensitive care—such as weight loss therapies, hair restoration, erectile dysfunction, and mental health treatments—have achieved rapid commercial scale by deploying hyper-aggressive digital marketing strategies. However, when corporate growth targets rely on optimizing ad spend through real-time telemetry, user confidentiality frequently becomes collateral damage. The lawsuit against Hims & Hers not only challenges covert data disclosure mechanisms but also tackles deceptive commercial practices, including dark patterns designed to trap patients in recurring prescription subscriptions before they ever consult a medical professional.
The Technical Pipeline: Pixels, SDKs, and Metadata Extraction
At the center of the FTC’s complaint is a sophisticated digital tracking architecture designed to convert online medical intake forms into targeted advertising signals. When a user visits a telehealth platform to research sensitive medical conditions, their digital footprint is continuously monitored by embedded client-side code, including JavaScript tracking pixels, web beacons, and mobile Software Development Kits (SDKs). These tracking tools record user interactions, capturing custom “Events” such as viewing specific medication landing pages (such as compounded semaglutide or finasteride), clicking treatment buttons, or answering deeply personal diagnostic questionnaires.
To quantify ad performance and optimize Return on Ad Spend (ROAS), platforms transmit these event payloads back to Big Tech ad networks. While corporate defenders often assert that sensitive identifiers are anonymized prior to transmission using cryptographic functions such as SHA-256 hashing, regulatory findings and technical analyses reveal that hashing offers minimal protection in modern ad ecosystems. Because major advertising networks possess massive, pre-existing identity graphs populated by millions of user profile records, matching an incoming hashed email or phone digest to an existing account takes milliseconds. Consequently, a hashed data payload instantly re-identifies the user, linking their real-world identity directly to their specific medical inquiries and diagnosis requests.
Furthermore, modern tracking architectures extend beyond basic client-side pixels. To bypass browser-level privacy controls, ad-blockers, and mobile operating system tracking restrictions, digital platforms increasingly rely on server-side tracking via Conversions APIs (CAPI). Through server-to-server communication, sensitive patient metadata—including detailed questionnaire answers, cart values, treatment selections, and timestamps—is transmitted directly from internal servers to external ad platform infrastructure. This bypasses client-side script blockers entirely, creating an opaque telemetry pipeline that operates beyond the visibility or control of the end user.
The Regulatory Reckoning: Health Data Tracking Under FTC Scrutiny
The legal action against Hims & Hers represents a major escalation in the federal watchdog’s ongoing campaign against unauthorized digital health surveillance. While traditional healthcare providers are governed by the Health Insurance Portability and Accountability Act (HIPAA), direct-to-consumer telehealth platforms frequently operate in a legal gray area, asserting that they are technology platforms rather than HIPAA-covered entities. Recognizing this regulatory gap, the FTC has asserted its authority under Section 5 of the FTC Act—which prohibits unfair or deceptive acts or practices—alongside specialized privacy rules to enforce strict boundaries on health data tracking.
This action follows a sequence of high-profile enforcement precedents that have redefined the digital health landscape over recent years:
- GoodRx Enforcement (2023): The FTC issued a landmark $1.5 million civil penalty against GoodRx for utilizing tracking pixels and SDKs to transmit prescription discount inquiries and drug usage data to Facebook, Google, and Criteo without user consent, marking the first enforcement action under the FTC’s Health Breach Notification Rule (HBNR).
- BetterHelp Consent Order (2023): Mental health service BetterHelp was ordered to pay $7.8 million in consumer refunds after disclosing sensitive mental health intake responses, IP addresses, and email addresses to social media networks for targeted ad retargeting despite explicit privacy promises.
- Cerebral Settlement (2024): Telehealth provider Cerebral entered into a $7 million settlement with regulators following allegations that it improperly transmitted sensitive mental health intake data and medical status details to third-party ad platforms via tracking pixels.
The regulatory message across these actions is unambiguous: commercial privacy policies that guarantee patient confidentiality while silently running third-party tracking code constitute deceptive trade practices. Advertising networks cannot be fed sensitive medical metadata under the guise of general website analytics or conversion measurement without express, affirmative consumer consent.
Subscription Traps and Deceptive Dark Patterns
In addition to data privacy violations, the complaint filed by the FTC and state regulators targets deceptive billing structures governed by the Restore Online Shoppers’ Confidence Act (ROSCA). The regulatory action reveals how telehealth growth strategies combine covert telemetry with aggressive subscription tactics, converting initial health inquiries into non-consensual, recurring financial obligations.
According to federal filings, Hims & Hers utilized misleading user flows during the onboarding process. Prospective patients were presented with intake forms displaying marketing claims such as “Pay $0 Today” or promising “Free Consultations”. However, upon submitting their credit card details to complete diagnostic questionnaires, users were immediately charged substantial amounts—ranging from $147 for maintenance prescriptions to upwards of $897 for multi-month medication bundles—prior to any medical review or interaction with a licensed healthcare provider. Patients were routinely enrolled in auto-renewing subscription plans without explicit authorization or transparent disclosures regarding recurring billing schedules.
To compound these deceptive charges, the company implemented sophisticated dark patterns designed to frustrate cancellation attempts. While enrolling in a subscription required only a few clicks, terminating the service required navigating multi-layered user interface hurdles. Cancellation controls were obscured behind misleading buttons labeled “Add/remove items from order,” completely omitting the word “cancel”. Furthermore, the platform routinely processed recurring subscription charges up to 10 days earlier than advertised refill dates, requiring consumers to cancel at least two days prior to this advance processing date—a window so narrow and unpredictable that thousands of users were locked into unwanted, non-refundable charges.
Proactive Mitigation: Reclaiming Digital Privacy in Telehealth
As regulatory enforcement works to establish structural accountability, consumers must adopt technical defenses to minimize cross-site tracking and prevent sensitive health metadata from entering commercial advertising networks. Protecting personal health data requires a multi-layered security strategy encompassing social platform audits, browser configurations, and isolated network habits:
- Audit and Restrict Social Media Ad Settings: Users should regularly review off-platform data settings within social media accounts. In Meta’s Accounts Center and Snap’s Privacy Controls, disable “Data Shown by Partners” and clear historical off-platform activity logs to prevent ad algorithms from matching uploaded customer lists or pixel telemetry with personal profiles.
- Deploy Advanced Browser-Level Blocking: Transition to privacy-centric web browsers (such as Brave or Firefox configured with Strict Tracking Protection) equipped with robust content blockers like uBlock Origin. Ensure your browser is configured to broadcast the Global Privacy Control (GPC) signal, which legally communicates an opt-out preference for data sales and targeted advertising under state privacy laws.
- Restrict In-App Webview Browsing: Avoid opening links to healthcare providers, pharmacy services, or diagnostic platforms within internal browsers embedded in social media applications (e.g., Instagram or TikTok in-app browsers). Embedded webviews frequently bypass standalone browser extensions and mobile operating system controls, enabling native scripts to log form inputs and browsing trails uninterrupted. Open sensitive links strictly in isolated, containerized browser tabs.
The joint lawsuit against Hims & Hers marks a decisive moment for the telehealth industry. As regulators enforce strict penalties for unauthorized data disclosures and predatory subscription mechanics, digital healthcare providers must fundamentally align their commercial practices with medical ethics—ensuring that patient trust and digital privacy are prioritized over algorithmic ad optimization.
Written by
TempMail Ninja
Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.


