Jul 30, 2026 · 7 min read
FTC Sues Hims & Hers Over Health Data Sent to Ads
Filed July 29, 2026 in the Northern District of California, with Utah and California alongside the FTC. Hims sold a "100% online, private, and secure process." The complaint names Meta and Snap.
Buying erectile dysfunction medication online is a purchase people make precisely because they do not want to say it out loud in a pharmacy. Hims & Hers built a business on that instinct, telling customers their medical records "are only accessed by the medical providers managing your care." The FTC spent nearly three years checking. On July 29, 2026 it sued.
Key Takeaways
- The FTC, joined by Utah and California, sued Hims & Hers on July 29, 2026 in the Northern District of California, per the agency's announcement.
- Meta and Snap are named as recipients of consumer health information, obtained through uploaded customer lists and website tracking that reported visitor "Events."
- Hims & Hers advertised a "100% online, private, and secure process," which the FTC alleges made the undisclosed sharing deceptive under Section 5 of the FTC Act.
- The complaint also alleges Restore Online Shoppers' Confidence Act violations tied to "Pay $0 today" intake forms that started recurring subscriptions.
- Plaintiffs seek a permanent injunction, monetary relief, and civil penalties; Hims & Hers denies wrongdoing and says the suit "disregards substantial evidence we provided the FTC."
What Did the FTC Actually Allege?
That Hims & Hers promised privacy and disclosed sensitive health information to advertising platforms anyway, and separately that it billed and locked in subscribers deceptively.
The privacy counts rest on a gap. On one side, public claims: a "100% online, private, and secure process," records seen only by treating clinicians. On the other, according to the complaint, two channels running to Meta and Snap. One was bulk: lists of certain customers handed over. The other was continuous: website tracking reporting "Events," meaning visitor actions, back to the same companies.
The billing counts have the same texture. Hims advertised a free consultation, showed "Pay $0 today" on intake forms, then charged patients and started a recurring subscription the moment a provider wrote a prescription. Bureau of Consumer Protection director Christopher Mufarrige called it "consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers' most private health information without their consent."
Hims & Hers denies the allegations and calls the filing "headline generation." The stock fell more than 15% intraday, its worst session since May 12, CNBC reported.
How Does a Hashed Email Turn Into a Health Disclosure?
Because a hashed email address is not anonymous data. It is a join key, and both sides already hold the same key.
A company runs each customer email through SHA-256 — the hash function standardized by NIST in FIPS 180-4 — and uploads the resulting strings. The platform hashes its own users' addresses the same way and looks for identical outputs. Same input, same hash, every time. Meta's Custom Audience terms describe the arrangement from the advertiser's side.
Nothing sensitive travels in the file, which is why the practice feels safe to the teams doing it. The sensitive part is the label on the list. Upload a file of people who bought a hair loss prescription and you have sent no diagnosis, only hashes — but the platform now knows which of its named, photographed, logged in users belong to that set. Hashing protects the transport and reveals the population.
The website channel does the same work continuously. A pixel fires an Event — page viewed, form submitted, purchase completed — and the platform ties it to whichever user it can resolve. The FTC's position throughout these cases is consistent: a page about a condition plus a resolvable identity is a health disclosure, whatever the encoding.
Where Does This Fit in the FTC's Health Privacy Record?
It is the fifth major action in a line opened three and a half years ago, and the first to arrive as a contested lawsuit rather than a negotiated order.
- GoodRx, February 2023. A $1.5 million penalty, the first enforcement of the Health Breach Notification Rule, over disclosures to Facebook and Google.
- BetterHelp, March 2023. $7.8 million in consumer refunds for sharing therapy customer data with Facebook and Snapchat.
- Premom, May 2023. A $100,000 penalty for an ovulation tracking app that shared cycle, fertility, and precise location data.
- Cerebral, April 2024. More than $7 million covering roughly 3.2 million consumers, plus a first of its kind ban on using health information for most advertising. The proposed order paired data claims with cancellation claims, the pairing that reappears now.
Penalties climbed, conduct bans arrived, and now a publicly traded company faces two state attorneys general as well. Hims & Hers has had a rough year; we covered the ShinyHunters breach of its Zendesk support tickets earlier in 2026.
What Is the FTC Asking For?
A permanent injunction, monetary relief, and civil penalties. Exact dollar figures are not specified in the reporting so far.
The STAT report on the filing notes California added Unfair Competition Law and False Advertising Law claims and Utah its Consumer Sales Practices Act claims. The remedy to watch is not financial: terms shaped like the Cerebral order would bar Hims from using health information for advertising at all, and social advertising is its growth engine.
What This Means for Your Inbox
The mechanism at the center of this case is not a telehealth mechanism. It is the standard plumbing of email marketing, applied to customers whose labels happen to be sensitive.
Your email address is the identifier that survives everything else. Clear cookies, change devices, switch browsers, and the address you typed into a checkout form still resolves to you. That is why list matching is built on it, and why platforms hash it into pixels and click tracking redirects.
Which leads to the extension the complaint does not make. If a hashed email in an uploaded list can disclose that someone treats a condition, the hashed email inside a tracking pixel discloses the same fact to the same platforms at open time, plus when you read and roughly where. Plaintiffs have noticed. The wave of CIPA and wiretapping suits over email pixels targets this exact pattern, and our guide to blocking email tracking in Gmail covers the recipient side.
Why Compliance Teams Should Move Now
Because the pixel plus customer list combination is near universal in marketing stacks, and two legal theories now aim at it at once. The FTC needs no health specific statute when a company's own copy promises privacy. State wiretap claims move faster still, because private plaintiffs drive them and California declined to close that door, as we covered in our piece on SB 690 and the surviving email pixel suits.
Here is the contrarian read. Almost every story this week led with the stock drop, but the durable lesson sits in the gap between the two disclosure channels. A misconfigured tag is a mistake, and companies defend mistakes reasonably well. A customer list upload is a deliberate file transfer, approved and named and scheduled by someone. Audit the uploads before the tags.
What Can You Do Right Now?
Four steps: two for marketing teams, two for everyone on the receiving end.
- Inventory every audience you have uploaded. Pull the list names, not the counts. If a name encodes a condition or an inferred life event, that name is the disclosure and hashing does not cure it.
- Reconcile your tag manager against your privacy policy. The FTC's theory needs only a promise and a contradicting data flow. Whichever is easier to change, change it this quarter.
- Use a separate address for anything medical. A distinct email for pharmacy, telehealth, and insurance accounts breaks the join key, so that history no longer ties to your main identity.
- Stop the open beacon from firing. Set Gmail to ask before displaying external images, or run an extension that strips tracking pixels before a message renders. Neither undoes a list upload, but both cut the ongoing signal.
The Bottom Line
The case will take years and may settle, as the FTC's case page will eventually record. The technical claim underneath needs no verdict to be useful. Hashed identifiers are not anonymity, audience names carry the meaning payloads do not, and an email address is the most durable thing most people hand over online.
Sources: FTC, FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices, Complaint for Permanent Injunction, Monetary Judgment, and Other Relief, The Record, FTC sues Hims & Hers over privacy, STAT, Hims misled consumers and violated their privacy, FTC alleges, CNBC, Hims and Hers shares fall as FTC sues over data and billing practices, FTC, Proposed Order Will Prohibit Cerebral from Using or Disclosing Sensitive Data for Advertising, and NIST, FIPS 180-4 Secure Hash Standard.