On July 29, 2026, the Federal Trade Commission sued Hims & Hers, the telehealth company known for direct-to-consumer prescriptions for hair loss, erectile dysfunction, and other conditions patients often want to discuss privately. The FTC did not act alone. Utah and California, the latter appearing through Los Angeles County Counsel, joined the federal complaint as co-plaintiffs, putting three separate regulators behind the same filing on the same day. The complaint alleges Hims & Hers shared patients' sensitive health information, tied to specific medical conditions and treatments, with Meta, Snap, and other advertising platforms, despite marketing its service as private and discreet. It also alleges the company charged patients for prescriptions almost immediately after they submitted an online intake form, before a medical provider had reviewed or approved anything, and then made canceling the resulting subscription difficult to find. For a company whose entire pitch rests on discretion, sharing details tied to a patient's medical condition with ad networks is close to the worst version of that story a regulator could tell. For any telehealth or health-adjacent business running ad pixels on a page where a visitor discloses a health condition, this complaint reads like a preview of what "we don't share your information" needs to actually mean in a privacy policy, not just imply.

Source: Federal Trade Commission, "FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices", captured August 1, 2026.
What the FTC says Hims & Hers did
According to the complaint, filed in the U.S. District Court for the Northern District of California, Hims & Hers shared consumers' health information with advertising platforms in two ways. First, the company allegedly shared lists of customers identified by their health conditions or treatment types directly with companies like Meta and Snap for targeted ad campaigns. Second, third-party tracking technologies embedded on the Hims & Hers website automatically transmitted certain visitor actions, described in the complaint as "Events", to those same advertising companies as consumers browsed and used the site. Both mechanisms moved health-condition-linked data off Hims & Hers' own systems and into the hands of ad platforms built to profile audiences and target ads, which is the opposite of what a "private and discreet" telehealth brand promises its patients.
The complaint pairs that allegation with a separate one about billing. The FTC alleges Hims & Hers displayed "Pay $0 today" language and told consumers they would be able to consult with a provider to find the right treatment, then charged most consumers and enrolled them in a recurring subscription as soon as they submitted an intake form, without giving them a chance to review or decline the prescription first. Christopher Mufarrige, Director of the FTC's Bureau of Consumer Protection, said the case involves "the disclosure to third parties of consumers' most private health information without their consent," alongside subscriptions consumers found themselves locked into without realizing it.
Three regulators, one complaint, the same day
Figure: Number of statutes each co-plaintiff alleges Hims & Hers violated in the single federal complaint filed July 29, 2026.
The FTC's complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act, the federal law governing deceptive subscription and billing practices. Utah alleges a violation of its own Consumer Sales Practices Act. California, appearing through Los Angeles County Counsel, alleges violations of its False Advertising Law and Unfair Competition Law. Three government plaintiffs, five statutes cited between them, one company, one filing date. The Commission's vote to authorize the complaint was 2-0.
That kind of coordinated, same-day filing is worth reading correctly. It is not three separate investigations that happened to conclude at once. It is federal and state regulators treating the same underlying conduct, health data flowing to ad platforms and billing practices consumers say they never agreed to, as serious enough to pursue together rather than separately. Hims & Hers has publicly denied the allegations and said it intends to contest the case in court, so nothing here is a finding of liability. The complaint itself, and the coordinated way it was brought, is still the kind of enforcement pattern that tends to show up again in the next state's consumer protection statute or the next agency's guidance.
What this means for your privacy policy
If your business collects information that is health-adjacent, even loosely, symptoms mentioned in an intake form, conditions a customer discloses to get a product recommendation, or treatment history entered before a purchase, running standard ad pixels or conversion APIs on the pages where that information is collected creates exactly the exposure this complaint describes. A privacy policy that says data is kept private, or that vaguely mentions "third parties" without naming the advertising platforms receiving events tied to health-adjacent browsing or purchase activity, will not hold up well against a regulator reading it next to your actual tag manager configuration. Our Privacy Policy Generator builds specific third-party ad-platform disclosure language into your policy, so what you tell patients or customers about who receives their data matches what your pixels are actually sending, rather than leaving that gap for a regulator to find first.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.