Recently, the Federal Trade Commission (FTC), joined by Utah and California, sued Hims & Hers Health, Inc., alleging the telehealth company shared its approximately 2.5 million subscribers’ health information with Meta, Snap, and other third-party advertising platforms, while publicly promising to keep that data private. In an expansive complaint, covering numerous violations of federal and state laws, the FTC and states are signaling what they believe to be the bar for collection, notice, and use of consumer online data, especially sensitive health data.
Key takeaways
- The FTC is using the FTC Act to challenge pixel-based data sharing, which is the same conduct that has driven a wave of California Invasion of Privacy Act (CIPA) and state wiretapping class actions in recent years. The FTC is also using the Restore Online Shoppers’ Confidence Act (ROSCA) to challenge deceptive billing and subscription practices. Companies are facing parallel exposure from regulators and plaintiffs over the same tracking technologies.
- The complaint also alleges violations related to custom audience uploads, billing before provider review, and hard-to-find cancellation buttons.
- The complaint’s focus on delineating HIPAA-protected data from other sensitive health data underscores the need for health-related companies to be extra vigilant about the use of consumer data collected online. As a reminder, direct-to-consumer platforms that do not bill through insurance (or collect personal data before the consumer becomes a patient) often fall outside HIPAA entirely, which is exactly why the FTC, and not HHS, brought this case.
- This is a pattern, not a one-off. GoodRx and BetterHelp settled similar claims in 2023, and a 2022 joint investigation by investigative news organizations, The Markup and STAT, found 49 of 50 direct-to-consumer telehealth platforms sharing health data with advertisers.
- Bottom line: if you collect consumer information online, use ad pixels or custom audience tools, or run a subscription model, treat this case as your call to action for auditing and revising your online data collection practices. This is especially high risk for companies that collect health or health-related information.
What the FTC alleges
According to the FTC’s complaint, Hims & Hers shared user data with Meta and Snap in two ways: by directly uploading customer lists to the platforms’ custom audience tools, which let advertisers match subscribers to named social media profiles, and by embedding tracking code that automatically sent user actions, such as completing a health intake form or checking out, to Meta’s and Snap’s ad servers in real time. The FTC alleges this happened without user consent, even as Hims & Hers told subscribers their information would stay private.
In addition, the FTC alleges Hims & Hers made cancellation unreasonably difficult. Before 2023, customers could only cancel by phone, email, or chat, and even after online cancellation was introduced, the option was buried behind an unrelated “add/remove items” menu and several additional screens. Regulators call this a “roach motel” design—easy to get in, hard to get out. It’s the same theory behind the FTC’s $2.5 billion settlement with Amazon over Prime’s enrollment and cancellation design in 2025.
Why HIPAA didn’t cover this
HIPAA only protects health records held by covered entities (including providers that bill through insurance and health plans) and their business associates. A direct-to-consumer health or telehealth company that doesn’t bill insurance may not meet that threshold at all, meaning HIPAA’s stronger protections and US Department of Health and Human Services (HHS) enforcement authority never come into play. That gap is exactly why the FTC brought this case using its consumer protection authority instead. For any organization handling sensitive data outside the insurance system, the FTC Act is often the real backstop, not HIPAA. This is the latest in a string of cases where the FTC has taken action against direct-to-consumer health companies.
- GoodRx paid a $1.5 million fine and was permanently barred from sharing prescription data with advertisers in 2023. (See FTC press release, “FTC Bars GoodRX from Sharing Health Data for Advertising,” Feb. 1, 2023.)
- BetterHelp paid $7.8 million in consumer redress for sharing mental health data with third parties, such as Facebook and Snapchat, that same year. (See FTC press release, “FTC Bans BetterHelp from Sharing Mental Health Data for Advertising,” July 14, 2023.)
- A 2022 joint investigation by The Markup and STAT found that 49 of 50 direct-to-consumer telehealth platforms were sharing sensitive health data with advertisers (The Markup & STAT, “Pixel Hunt,” December 13, 2022), and healthcare organizations have paid more than $100 million in pixel-related penalties and settlements since 2023, according to Feroot Security.
Organizations that sell health-related products or collect health-adjacent information are operating under a materially higher level of scrutiny than they were even two years ago. Regulators are treating a much broader category of information—search terms tied to symptoms or conditions, intake-form responses, prescription interests, wellness-app inputs, weight-loss and fertility-related engagement, mental-health questionnaires, and even categories inferred from browsing behavior—as sensitive health data that consumers reasonably expect to remain private. The FTC’s complaint against Hims & Hers reflects exactly that view: it treats disclosures about erectile dysfunction, hair loss, weight management, and mental health as protected sensitive information under Section 5, regardless of whether HIPAA applies. Companies well outside traditional healthcare—retailers with wellness lines, direct-to-consumer supplement brands, fitness and nutrition apps, menstrual and fertility trackers, sleep and mental-wellness platforms, and even employers running wellness programs—should assume regulators will apply the same lens to their data flows.
Beyond Hims & Hers: The broader enforcement trend
The FTC and HHS jointly warned roughly 130 hospital systems and telehealth providers about pixel-tracking risks back in July 2023 (FTC/HHS joint letter, July 20, 2023). That warning is now translating into enforcement: hospital website pixel use reportedly fell from 98% in 2021 to roughly 30% in 2025 (Christopher Brown, “Lawsuits, HHS Pressure Drive Drop in Pixel Use on Health Sites,” Bloomberg Law, Aug. 11, 2025). This trend runs on a separate but parallel track from the CIPA and wiretap class actions many companies already face—meaning the same tracking technology can now trigger exposure from both plaintiffs’ firms and regulators at once.
What you should do now
Because enforcement is now coming from multiple directions, including regulators, state attorneys general, and the plaintiffs’ bar, this is worth revisiting even if you’ve addressed tracking technology risk before. At a minimum:
- Inventory every pixel, software development kit (SDK), and custom-audience upload connected to your website or app, especially anything touching health, financial, or other sensitive data.
- Do not assume HIPAA compliance means you are covered—assess whether the FTC Act, ROSCA, state consumer protection laws, and wiretap statutes, like CIPA, also apply to your data flows.
- Match your privacy promises to what your technology actually does and obtain customer consent before customer data is shared. The FTC’s case centers on the gap between what Hims & Hers told users and what its pixels were doing behind the scenes.
- Audit your cancellation flows for dark patterns—charging before service is delivered or burying the cancel button are both now enforcement priorities.
- Review your vendor and processor agreements to ensure the appropriate controls and risk allocation are in place.
- Loop in privacy and regulatory counsel now to calibrate your risk profile before a regulator or plaintiffs’ firm does it for you.
How Nixon Peabody can help
Our Cybersecurity and Privacy Team helps clients navigate exactly this kind of overlapping exposure—auditing tracking technologies and consent flows, benchmarking billing and cancellation practices against FTC guidance, and responding to regulator inquiries or demand letters. If this case has you wondering how your organization would fare under the same scrutiny, we’re glad to help you find out.



