Hims & Hers was sued on July 29, 2026, by the FTC, joined by Utah and California through Los Angeles County Counsel, over allegations that it shared consumers’ sensitive health data with Meta and Snap for advertising and used deceptive billing and cancellation practices. The company had already disclosed in its 2025 Annual Report that the FTC sent it a Civil Investigative Demand in October 2023 covering privacy, advertising, and cancellation practices.
The complaint contains allegations, not proven findings. But if the government’s account is accurate, the case is a direct test of whether a telehealth company can promise sensitive medical privacy on one page, then let ad-tech plumbing move that same data into marketing systems on the back end, the same basic tension that keeps surfacing in fights over Meta privacy controls, customer-data training defaults, and broader data exfiltration risks.
FTC, Utah, and California’s allegations against Hims & Hers
The core allegation is simple: government lawyers say Hims & Hers sent sensitive health-related information to Meta and Snap while telling users their information would stay private. The reporting around the case says the alleged disclosures involved data tied to users seeking treatment or information about stigmatized conditions, which is exactly the kind of data regulators have treated as especially sensitive in prior health-privacy cases.
That privacy fight is bundled with consumer-protection claims. The FTC’s announced case also alleges deceptive billing and hard-to-cancel subscriptions, making this not just a data-sharing case but a broader challenge to how the company acquired, billed, and retained customers. That matters because any eventual settlement may not isolate the privacy theory cleanly; the case appears to combine privacy and subscription-practice allegations in one package.
Hims & Hers’ own public filings show this did not come out of nowhere. In its 2025 Annual Report, the company said the FTC’s October 2023 Civil Investigative Demand sought information about “privacy, security, and advertising practices, and user cancellation issues.” That is a fairly straight line from investigation to lawsuit.
The company’s current public privacy materials are more layered than a generic app privacy page. Hims & Hers’ current privacy policy describes categories of information it collects and how information may be used, while its Notice of Privacy Practices says affiliated medical groups treat certain health information as protected health information. Those materials appear current, so some language now on the site may not match the exact disclosures the government says were live during the alleged conduct period.
The ad-tech data flows the complaint puts at issue
The technical point in cases like this is rarely an exotic hack. It is usually a tracker, SDK, or event feed doing exactly what ad systems are built to do: sending user actions to ad platforms so campaigns can be measured, optimized, and retargeted.
That is why the allegation against Hims & Hers matters beyond one company. Meta and Snap do not need a full medical chart to make a privacy problem; a browser event or app signal tied to a treatment flow can be enough. If a site or app fires events showing that a user viewed, started, or purchased care related to a specific condition, that can turn “ad measurement” into sensitive health-data disclosure very quickly.
The most detailed public facts so far appear to come from agency summaries and contemporaneous reporting, so the full complaint text should be checked once broadly available. But the basic mechanism described fits a pattern regulators have been chasing for years: health-facing companies embedding ad-tech tools that quietly transmit data outward, often in tension with consumer-facing privacy promises.
That pattern is also why “we only shared with vendors” is usually not much of a defense on its own. If the vendor is an ad platform using data for ad attribution, matching, or optimization, the privacy risk is not abstract. It is operational.
The case’s fit with recent FTC health-privacy enforcement
This is not the FTC inventing a new theory out of thin air. The agency’s privacy and security enforcement program has repeatedly used deception and unfairness law against companies that made strong privacy promises and then handled sensitive data more loosely in practice.
The closest recent analogs in the FTC’s own materials are BetterHelp and Vitagene, both summarized in the FTC’s FY 2025 Congressional Budget Justification. In that document, the FTC says BetterHelp paid $7.8 million in 2023 to settle allegations that it revealed consumers’ email addresses, IP addresses, and health questionnaire information to Facebook, Snapchat, Criteo, and Pinterest for advertising, despite privacy assurances. The same budget document says Vitagene paid $75,000 in 2023 to settle claims tied to inadequate data-security practices involving genetic and health information.
“The FTC will vigorously enforce the law against companies that use consumers’ sensitive data for advertising after promising to keep it private.”, the agency’s enforcement posture, as reflected in its privacy and security enforcement program
Hims & Hers looks more consequential than a routine telehealth complaint because it combines three pressure points at once: sensitive health data, major ad platforms, and recurring-revenue subscription mechanics. That combination turns a familiar privacy problem into a larger test of whether consumer telehealth growth has been built on systems that treated ad conversion data and patient trust as compatible when they often are not.
There is also broader scrutiny around the company in 2026. TechCrunch reported in April 2026 that Hims & Hers said its customer support system was hacked, adding separate data-security attention in the same year. That incident is distinct from the FTC case, but it underscores why telehealth data handling is under a brighter light than usual.
The next milestone is the public filing record: once the full complaint and any Hims & Hers response are broadly available on the docket, the specifics of the alleged Meta and Snap integrations, the time period, and the exact user-facing statements at issue should become easier to check line by line.
Key Takeaways
- The FTC, Utah, and California sued Hims & Hers on July 29, 2026, over alleged sharing of sensitive health data with Meta and Snap and over billing and cancellation practices.
- The case is an allegation, not a proven finding, and the fullest public details so far come from agency summaries and reporting pending wider access to the complaint text.
- The privacy theory fits a known FTC pattern: companies promise confidentiality, then ad-tech tools send health-related data to advertising platforms.
- Hims & Hers had already disclosed an FTC probe in October 2023 covering privacy, advertising, security, and user cancellation issues.
- The closest recent FTC parallels include BetterHelp and Vitagene, which the agency highlighted in its FY 2025 budget materials.
Further Reading
- FTC Privacy and Security Enforcement, FTC enforcement hub showing the agency’s privacy-deception framework and related cases.
- FTC Fiscal Year 2025 Congressional Budget Justification, FTC budget document summarizing prior health-privacy actions, including BetterHelp and Vitagene.
- Hims Privacy Policy, Current Hims & Hers privacy policy describing how it classifies and uses information.
- Medical Groups Notice of Privacy Practices | Hims, Hims notice describing treatment of protected health information by affiliated medical groups.
- Hims & Hers 2025 Annual Report, SEC filing disclosing that the FTC issued a Civil Investigative Demand in October 2023 regarding privacy, advertising, and cancellation practices.
- Telehealth giant Hims & Hers says its customer support system was hacked, Recent TechCrunch reporting that gives additional context on Hims & Hers’ data-security scrutiny in 2026.
