On 29 July 2026, the Federal Trade Commission, joined by co-plaintiffs the State of Utah and the County of Los Angeles (acting through the Los Angeles County Counsel on behalf of the People of the State of California), filed a complaint for permanent injunction and monetary relief against Hims & Hers Health, Inc. in the U.S. District Court for the Northern District of California.
The complaint has two halves, and they are more connected than they first appear.
The privacy half. Hims & Hers, which markets itself on being private and discreet, allegedly shared consumers’ health information — covering sexual wellness, mental health, weight loss, and other conditions — with third-party advertising platforms including Meta, Snap, Microsoft, Pinterest, Reddit, and X. The mechanisms alleged are the familiar pair: tracking pixels embedded in the site that captured and transmitted user actions, and customer list uploads to advertising platforms for audience matching.
The billing half. The complaint alleges Hims advertised “free” consultations and displayed “Pay $0 today” on intake forms, then charged patients and enrolled them in recurring subscriptions as soon as a provider wrote a prescription — before the patient had a chance to review or decline the treatment. It further alleges that Hims advertised monthly or quarterly refill schedules but processed refill charges approximately ten days earlier than consumers would reasonably expect, while requiring cancellation two days before that early processing date.
The claims arise under Section 5 of the FTC Act (unfair or deceptive acts or practices) and the Restore Online Shoppers’ Confidence Act (ROSCA), alongside state consumer protection claims.
The company’s shares fell sharply on the announcement. Hims & Hers has called the allegations baseless, stating that its privacy policy “makes clear” that users “may choose how their data is used,” and has said it will defend itself.
That response is worth examining closely, because it is the exact defence the FTC has spent five years dismantling.
Why the “our policy discloses it” defence does not work here
The FTC’s position across this line of cases is not that sharing data with advertisers is per se unlawful. It is that the disclosure did not match the representation the consumer actually relied on, and that for health information, buried disclosure is not disclosure at all.
Three doctrinal points do the work:
1. Net impression governs, not the fine print. Under long-standing Section 5 deception analysis, a claim is evaluated by the net impression conveyed to a reasonable consumer taking the representation as a whole. A service marketed as “private and discreet,” addressing erectile dysfunction and mental health, creates a specific net impression. A clause in a privacy policy permitting sharing with “third-party partners for marketing purposes” does not cure it. The FTC has repeatedly held that a disclaimer inconsistent with the overall message does not fix a deceptive net impression.
2. Affirmative express consent is the standard for health data. The FTC’s position, developed through GoodRx (2023), BetterHelp (2023), Premom (2023), Cerebral (2024), and Monument (2024), is that disclosing health information to advertising platforms for advertising purposes requires affirmative express consent — a separate, unavoidable, clearly-labelled choice — not a policy the consumer is deemed to have accepted by using the site. “You may choose how their data is used” describes an opt-out. The FTC’s standard is opt-in.
3. Health information is defined broadly. The FTC has consistently treated the fact of seeking treatment as health information. A consumer visiting a page about erectile dysfunction medication has disclosed a health condition regardless of whether any diagnosis code was transmitted. Pixel events named after product categories therefore carry health information even when the payload contains no clinical data.
The pixel mechanism, concretely
For compliance teams who need to find this in their own environment, here is what actually happens.
A marketing tag — Meta Pixel, Snap Pixel, Microsoft UET, Reddit Pixel, X Pixel, or a tag manager container loading any of them — is placed in the site template. It fires on page load and on configured events. What it transmits by default includes:
- The full page URL, which frequently encodes the condition or product (
/weight-loss/,/mental-health/anxiety,/ed-treatment/). - The referring URL.
- A persistent identifier — the platform’s own cookie, plus in many configurations a hashed email address supplied through advanced matching.
- Custom events the marketing team configured, often with names like
Purchase,Subscribe,CompletedIntake, or the product SKU.
Three properties make this hard to catch:
It is deployed by marketing, not engineering. Tag manager containers let marketing teams add third-party code to production without a code review, a change ticket, or a privacy review. Most organisations that find pixels on sensitive pages find them because someone in marketing added a tag to a container that applies site-wide.
Advanced matching is often on by default. Platforms offer automatic collection of email addresses and phone numbers from form fields, hashed client-side. Hashing is not de-identification when the platform holds the same hash for its own users — that is precisely how the match works.
Authenticated pages are frequently in scope. The most damaging configurations extend past the marketing site into logged-in patient portals, where the URL structure and event names describe an individual’s actual treatment.
The second mechanism — customer list uploads — is separate and often overlooked. Marketing teams export lists of customers who purchased a given product and upload them to Meta Custom Audiences or Snap Audience Match to build lookalike audiences. The list membership itself is the health disclosure: everyone on the “GLP-1 purchasers” list has disclosed a condition, and the upload transmits that fact directly, with no pixel involved.
Why HIPAA is not the operative statute — and why that is worse
A reasonable question: Hims & Hers connects patients with licensed providers who write prescriptions. Why is this an FTC case and not an OCR case?
The answer depends on covered entity status under HIPAA. A telehealth platform’s structure typically separates the technology and marketing company from the affiliated professional entities that employ the clinicians. Where the consumer-facing company positions itself as a technology platform rather than a health care provider or plan, and does not conduct standard electronic transactions, it may sit outside HIPAA’s definitions — while holding exactly the information HIPAA was written about.
The FTC has filled that gap deliberately, using three tools:
Section 5 — the general prohibition on unfair or deceptive practices, which reaches any entity in commerce regardless of sector.
The Health Breach Notification Rule (16 CFR Part 318) — which the FTC’s 2021 policy statement and 2024 final rule confirmed applies to vendors of personal health records and reaches unauthorised disclosures, not merely security breaches. Under the Rule, disclosing health information to a third party without authorisation is itself a reportable breach, carrying notification duties to individuals, the FTC, and in some cases the media, with civil penalties per violation per day. The Rule was the basis for the GoodRx and Premom actions.
ROSCA — for the billing conduct, discussed below.
The practical consequence for compliance teams: being outside HIPAA is not a safe harbour. It substitutes a regulator with broad UDAP authority, a rule that treats unauthorised disclosure as a breach, and — increasingly — state attorneys general as co-plaintiffs. The FTC’s action against telehealth companies now includes Cerebral, Monument, GoodRx, BetterHelp, and Hims & Hers. That is not a series of one-offs; it is a sector enforcement programme.
We covered adjacent territory in our analysis of digital therapy platforms under HIPAA, 42 CFR Part 2, and FTC authority.
The ROSCA half is the part with the sharpest teeth
The billing allegations may prove more consequential than the privacy allegations, because ROSCA’s elements are concrete and the alleged facts map onto them directly.
15 U.S.C. § 8403 prohibits charging a consumer through a negative option feature in an internet transaction unless the seller:
- Clearly and conspicuously discloses all material terms of the transaction before obtaining billing information;
- Obtains the consumer’s express informed consent before charging; and
- Provides simple mechanisms to stop recurring charges.
Against each element, as alleged:
Material terms disclosed before billing information. “Free consultation” and “Pay $0 today” displayed on an intake form, where the actual arrangement is enrolment in a recurring subscription triggered by a prescription being written, is a straightforward failure of element one. The words “Pay $0 today” are, in the FTC’s framing, affirmatively misleading about the transaction the consumer is entering.
Express informed consent before charging. The allegation that patients were charged and enrolled as soon as a provider wrote a prescription, without the opportunity to review or decline the treatment, goes to the heart of element two. Consent to a consultation is not consent to a recurring charge for a medication the consumer has not yet seen prescribed.
Simple cancellation mechanism. This is the most quantifiable allegation and the most difficult to defend. Advertising a monthly refill, charging approximately ten days early, and requiring cancellation two days before that early charge produces a cancellation window that closes roughly twelve days before the date the consumer has been led to expect. A consumer who sets a calendar reminder based on the advertised schedule misses the deadline by design.
That is not a usability defect. Where the interval between the advertised date and the actual cutoff is engineered, it supports the FTC’s unfairness theory under Section 5(n) as well as the ROSCA count: substantial injury to consumers, not reasonably avoidable by them, and not outweighed by countervailing benefits.
ROSCA violations carry civil penalties under Section 5(l), currently in excess of $53,000 per violation, and each unauthorised charge is a candidate violation. For a subscription business with a large base, the arithmetic is severe.
The FTC’s Negative Option Rule — the “click-to-cancel” rule — has had a contested procedural history, but the agency’s ROSCA and Section 5 authority over these practices is independent of it and unaffected.
What compliance teams should do this week
This applies to any organisation whose website touches health, financial, or other sensitive categories — not only telehealth.
1. Inventory every third-party tag actually in production. Not the approved list. Load the site in a browser with developer tools open, filter network requests by domain, and record every external host receiving a request. Repeat on authenticated pages, on mobile web, and in the app. The gap between the approved list and the observed list is the finding.
2. Capture what each tag transmits. Read the actual request payloads and query strings. Look specifically for: page URLs encoding conditions or products, event names describing treatments, and any email, phone, or user identifier — hashed or otherwise.
3. Turn off advanced matching. Automatic form-field collection should be disabled by default on any site handling sensitive categories. Verify it is off; do not accept a settings screenshot from an agency.
4. Audit customer list uploads. Ask marketing for every audience list uploaded to any advertising platform in the last 24 months, with the segmentation criteria. Any list segmented by product, condition, or treatment is a health disclosure. This step routinely surfaces exposures the pixel audit misses.
5. Redesign URL structures. /treatment/12345 is not a health disclosure. /mental-health/anxiety-medication is. This is a one-time engineering cost that permanently reduces the sensitivity of everything downstream.
6. Implement affirmative express consent, properly. A separate, unavoidable, clearly-labelled choice specific to advertising disclosure, presented before any tag fires, with the ability to decline without losing service. Log the consent event with a timestamp. Absence of a consent record is, in practice, absence of consent.
7. Run the ROSCA arithmetic on your own subscription. Three numbers: the billing date the marketing communicates, the date the charge actually processes, and the last moment a cancellation prevents that charge. If those three are not the same day, document why — and expect to have to justify the gap. Then test the cancellation path yourself, end to end, and count the clicks.
8. Reconcile marketing claims with data practices. If the site says “private,” “confidential,” or “discreet,” those words are enforceable representations. Someone in compliance should own the list of every such claim in production copy and be able to demonstrate it is true.
Conclusion
The Hims & Hers complaint is the fifth major FTC telehealth action in three years, and the pattern across them is stable: a company that markets on discretion, tracking technology deployed by marketing without privacy review, sensitive categories transmitted to advertising platforms through page URLs and event names, and a privacy policy offered afterwards as though it were consent.
What is new here is the pairing. The FTC brought the privacy claims and the billing claims in the same complaint, with two state co-plaintiffs, in a single federal action. That combination tells you how the agency is thinking about this sector: not as a privacy problem or a billing problem, but as a business model in which the consumer’s understanding of the transaction diverges systematically from its actual terms — on what they are paying, when, and who learns what about their health.
The company’s public response — that its privacy policy makes clear users “may choose” how their data is used — is precisely the position the FTC has rejected in every one of the preceding cases. For health data, the agency’s standard is affirmative express consent obtained before the disclosure occurs. Any organisation currently relying on an opt-out buried in a policy should read that sentence as a description of its own exposure.
This article is provided for informational purposes only and does not constitute legal advice.


