The Federal Trade Commission's (FTC) recent case against Hims & Hers underscores the agency's view of advertising technology use as a prime target for enforcement rather than a back-end implementation detail. The FTC highlights the use of pixels, server-side conversion tools, customer-list uploads, and privacy-facing marketing statements on their website, and alleges the technology did not abide by the company's privacy messaging.
On July 29, 2026, the FTC, joined by the State of California and Utah's Division of Consumer Protection, filed a complaint in the Northern District of California against Hims & Hers Health, Inc. (Hims). Hims is an online telehealth and wellness company that has grown in popularity with its offerings, especially with the provision of GLP-1 and hormones to consumers. The complaint alleges that Hims misled consumers about subscription charges, cancellation rights, and the privacy of sensitive health information. The case is in its earliest stage, and the allegations have not been adjudicated. Hims has publicly disputed the lawsuit, stating that the FTC disregarded evidence, ignored telehealth industry standards, and asserted baseless claims.
This alert focuses on the data and advertising-platform allegations, which should matter to any e-commerce or subscription business that uses third-party pixels, conversion Application Programming Interfaces (APIs), retargeting audiences, or customer-list matching to support growth. In other words, it should matter to any company that makes claims about the privacy of its customers' data. With that said, the more sensitive the information – especially for a digital health, wellness, or telehealth provider – the more likely the company is to be a target of the ire of the FTC and attorneys general.
The use of pixels to track online consumers' behavior is fast becoming its own field of litigation and liability. For more on why everyday website tracking tools are generating litigation risk, see our colleagues' recent alert, A Primer on Pixel Litigation: Understanding Why Everyday Website Tracking Tools Are Fueling Class Actions and How to Reduce Your Risk. The Hims case is a useful companion development because it shows how the same tracking technologies can become not only class action targets, but also regulatory enforcement exhibits when deployed on sensitive consumer journeys.
1. Brief Overview of the FTC Action
The complaint's allegations are broader than general privacy concerns. The FTC alleges that Hims advertised free or low-friction medical consultations, collected payment information during online intake flows, and then charged consumers and enrolled them in recurring prescription subscriptions after provider review without obtaining express informed consent. The complaint also challenges the company's refill-timing disclosures and cancellation design, including allegations that cancellation options were difficult to find and required unnecessary friction.
Those allegations matter, but the privacy claim is the sharper warning for all companies using modern marketing technology – that is to say, any company operating a website or advertising online. According to the FTC, Hims repeatedly told consumers that its platform was "100 percent online, private, and secure," that medical records and sensitive information were accessed only by medical providers managing the consumer's care, and that its services were discreet or private. The FTC alleges those statements were misleading because Hims shared sensitive health information with advertising platforms.
Hims' public response states that customers have the information they need to make informed decisions and that its privacy policy explains how customers may choose how their data is used. That dispute will be litigated and, even if Hims were to prevail, these arguments will be expensive to defend. For companies watching from the sidelines, the practical point is immediate: privacy risk now sits at the intersection of marketing copy, consumer expectations, technical implementation, vendor configuration, and legal obligations.
2. The Health Data and Advertising Platform Allegations
The FTC's complaint frames the privacy issue in familiar but important terms: what did the company promise, what did the technology do, and did consumers receive a clear disclosure before sensitive information moved to advertising platforms? Notably, while the FTC's allegations assert deceptive privacy practices, deceptive omissions, and a theory under the Restore Online Shoppers' Confidence Act pertaining to material transaction terms, the advertising tracking practices themselves are standard e-commerce activities.
The promises were not limited to the privacy policy. The FTC points to website statements, online ads, influencer content, and offline advertising (print ads, billboard, etc.). According to the FTC, the overall message was that consumers seeking treatment for personal conditions could expect privacy and discretion. Personal health information is sensitive in any context, but it is especially notable here, since Hims is alleged to have offered treatments involving sexual health, mental health, hair loss, skin health, and weight loss. However, in this context, even ordinary-sounding privacy language can carry more weight than it might in a less sensitive consumer experience.
The alleged sharing occurred through both audience tools and automated tracking. The complaint alleges that Hims shared health information with multiple social media and AdTech companies, including through customer-list uploads and matching, and that it used those social media companies' tracking pixels and APIs on its platforms. The FTC describes one of the pixel tools as website code that allows the social media company to collect and track user events, and the API that was used as a server-side tool that creates a direct connection between the advertiser's systems and the social media company's systems.
The complaint also identifies a broad array of third-party tracking technologies allegedly deployed on Hims' website, including tools used for advertising attribution, audience matching, analytics, retargeting, and customer engagement. The publicly available complaint redacts some of the most granular allegations, including specific fields, event details, and audience rules. This is interesting as it might suggest there is some sensitive information being shared. Even so, the theory is clear enough: regulators may treat event names, page context, funnel activity, identifiers, audience membership, and customer-list matching as sensitive when they reveal or imply a consumer's interest in a particular health condition or treatment.
The crux of the FTC's theory is that Hims' assurances to customers did not match its obvious marketing behaviors. The complaint against Hims belongs in the same conversation as pixel litigation because, according to the FTC, the company's privacy assurances and alleged disclosures did not match the data flows. Just as private plaintiffs often argue that website tracking tools intercept or disclose consumer interactions, here regulators are clearly signaling to businesses that, if you tell consumers their interaction with your site is private, your tracking stack must be able to withstand that statement.
3. What This Means for Your Business
The most important lesson is that your privacy policy matters. Too often we find privacy policies that are adapted from another "reputable company" but do not match the copying website's practices. We also find very sparse language that is meant to be "customer-friendly" but instead proves to be too brief to be meaningful.
It is also important to remember that the use of tracking technologies is not all unlawful. Companies need to know, in concrete terms, what their tracking tools collect, when they fire, where the data goes, who the data is shared with, and what can be inferred from the combination of page context, event labels, identifiers, and audience rules – and ensure that that their claims to customers match those website tracking activities.
These tools are often selected by marketing, implemented by product or engineering, configured by growth teams, and not reviewed by legal or compliance. They are also routinely changed as websites are updated, new targeting techniques are adopted, or new partners are identified. A privacy notice may say one thing, a campaign landing page may imply another, and a server-side event may transmit something neither team focused on when the tool went live.
Practical Takeaways
- Inventory the full tracking stack. Do not stop at cookies. Map pixels, software development kits (SDKs), conversion APIs, session replay tools, chat tools, analytics scripts, customer-list uploads, lookalike audiences, and platform integrations across websites and apps.
- Test what actually fires. Confirm when each tool activates, what events or parameters are transmitted, and whether consent or opt-out settings actually suppress the transmission. A banner does little good if sensitive events fire before the user makes a choice.
- Treat sensitive data, and the paths through which such data flows, differently. Condition-specific pages, intake flows, symptom checkers, prescription funnels, checkout pages, and account portals deserve heightened controls. In many cases, the safer approach is to remove advertising trackers from those flows or redesign events so they do not reveal the consumer's condition, treatment interest, or account status.
- Reconcile marketing language with data flows. Words like "private," "secure," "confidential," "discreet," or "provider-only access" merit special review and should be examined against actual implementation, not just against the privacy policy. Influencer scripts, landing pages, app-store copy, and paid ads can all become part of the privacy representation.
- Scrutinize deployment of personally identifiable information and specific customer data uploads and server-side APIs. These are affirmative transmissions, not passive background collection. They should have documented business justification, consent analysis, suppression rules, vendor controls, and an audit trail.
- Plan for legacy data. If sensitive data has already been transmitted to advertising platforms, consider whether deletion, suppression, or contractual remediation is available. The response plan should include preservation of configurations and logs if a demand letter, regulator inquiry, or litigation threat arrives.
Bottom Line
The Hims complaint is a reminder that privacy risk is expanding at a rapid pace. The risks are embedded in marketing strategy, website architecture, vendor configuration, and the assurances provided to earn consumer trust. Businesses that have websites using technology (hint: you all do) should be identifying exposure points and creating and implementing a governance program.
For more information, contact the authors – Scott Douglass, Vivien Peaden, and Alisa Chestler – or another member of Baker Donelson's Data Privacy and Cybersecurity, Digital Marketing, AdTech, and Consumer Privacy Compliance, or Privacy Litigation Teams.