XOOMAR
Telehealth patient data flowing through locks and shields toward shadowy ad network nodes
CybersecurityJuly 30, 2026· 8 min read· By XOOMAR Insights Team

FTC Says Hims & Hers Fed Patient Data to Ad Giants

Share
Updated on July 30, 2026

The FTC Hims & Hers lawsuit signals that direct-to-consumer healthcare growth tactics are now being judged against the privacy expectations of a clinic, not an online store. The Federal Trade Commission says Hims & Hers shared customers’ medical and healthcare information with advertisers including Meta and Snap, while allegedly telling users a different story about privacy, according to TechCrunch.

XOOMAR Intelligence

Analyst Take

59/ 100
Moderate
3 sources analyzedLow confidenceTrend10Freshness100Source Trust90Factual Grounding91Signal Cluster20

That is the core collision here. Hims & Hers sells access to treatment for sexual wellness, mental health conditions, weight loss, and other issues. The FTC alleges the company also used website tracking tools from Meta, Snap, Microsoft, Pinterest, Reddit, X, and others that “captured and shared users’ health information,” contrary to its privacy policy.

If the allegations hold up, this case will read less like a narrow privacy dispute and more like a warning to telehealth companies: you can’t build a medical brand on trust while running the acquisition funnel like ordinary e-commerce.


Hims & Hers built a telehealth growth machine, and the FTC says patient privacy paid the price

Hims & Hers, founded in 2017 and publicly listed, built its business around fast virtual access to providers and prescription products. That model depends on removing friction: intake forms, online consultations, recurring shipments, and performance marketing that helps turn site visitors into paying customers.

The FTC says the company crossed a line by placing pixel-sized trackers on its website that allegedly sent health-related information to ad platforms. These tools typically help companies understand who visited a site and when, and measure which campaigns drove actions. In healthcare, that same machinery becomes far more sensitive because the user’s behavior can signal medical interest before a doctor ever enters the picture.

The strongest counterpoint is that tracking tools are common across consumer internet businesses and may be used for analytics or attribution, not for selling patient records in the old-fashioned sense. Hims & Hers has not explicitly denied the FTC’s claims in the TechCrunch account, but said its privacy policy “makes clear” that users “may choose how their data is used,” and that it is “confident” in its position.

“Our customers have the information they need to make informed decisions about their care and the use of our services,” Hims & Hers said, according to CBS News.

That defense matters. But it doesn’t erase the central allegation: the FTC says sensitive health information moved through advertising infrastructure without adequate consent.

The FTC Hims & Hers lawsuit turns ordinary tracking into a medical-data problem

The data at issue is not described as a full medical chart. That distinction helps Hims & Hers rhetorically, but it may not solve the legal or reputational problem.

The FTC alleges Hims & Hers used tracking technologies “offered by Meta” to monitor actions on its website, including clicks and other user behavior, and also shared lists of some customers with third parties, according to CBS News. The complaint centers on how health-related user activity can become ad-tech data.

In a sexual wellness or mental health context, inference is enough to matter. A person does not need to upload a diagnosis for a site visit, intake path, or treatment interest to reveal something deeply private. The FTC’s theory appears to treat those signals as health information when they are collected in the context of care-seeking.

A few source-backed numbers frame the stakes:

Data point Source-backed detail
Company age Hims & Hers was founded in 2017
Market reaction Shares fell nearly 15% on Wednesday, according to CBS News
FTC timeline Gizmodo reported the FTC has investigated Hims & Hers since 2023
Court venue The complaint was filed in federal court in the Northern District of California

The share move does not prove liability. It shows investors understood the case as more than a compliance nuisance.

Prior FTC cases show this is not an isolated Hims & Hers problem

The FTC Hims & Hers lawsuit fits a recent enforcement pattern against digital health companies accused of sending sensitive user data into advertising systems. TechCrunch notes prior FTC action against Cerebral, Monument, GoodRx, and BetterHelp over similar allegations involving sensitive data shared with tech giants and advertisers.

That history is important because it narrows the room for surprise. Telehealth companies have had public examples of what regulators consider dangerous: health-adtech pipelines, vague privacy assurances, and tracking tools embedded in sensitive user flows.

The Hims & Hers case also follows broader scrutiny of pixel tracking. TechCrunch previously found in 2024 that the U.S. Postal Service was sharing logged-in users’ home addresses with Meta, LinkedIn, and Snap through pixel tracking code. USPS removed the code soon after.

For XOOMAR readers following how consumer platforms collect and expose user activity, this case sits next to a broader set of questions around messaging and social data flows, including our coverage of WhatsApp Web Calling Finally Cuts the App Out of Calls and Snapchat Now Playing Turns Spotify Into Snap Map Status. The Hims & Hers case is more sensitive because the underlying activity involves care, prescriptions, and medical conditions.

Regulators, Hims & Hers, patients, and advertisers are telling different data stories

The regulator’s story is blunt: people sought help for private health issues, and Hims & Hers allegedly let third-party ad systems receive sensitive information while promising privacy.

The company’s story is narrower. Hims & Hers says customers had enough information to make informed choices and that information shared with healthcare providers is used only in providing care. It also called the FTC’s allegations “baseless,” according to Gizmodo, and said the agency “ignores established state laws and industry standards in telehealth.”

Patients likely see a different distinction. They may not care whether data moved through a pixel, a list upload, an analytics workflow, or another marketing tool. If the interaction involved hair loss, sexual wellness, weight loss, or mental health treatment, the expectation is simple: don’t let ad platforms receive signals tied to that care journey without clear permission.

The FTC also accused Hims & Hers of deceptive billing and subscription practices. The agency alleges consumers were charged before receiving services and faced cancellation friction. That matters because privacy and billing complaints reinforce the same regulatory theme: users allegedly lost control over both their sensitive information and their purchases.

Telehealth growth tactics now carry regulatory risk the ad funnel can’t hide

XOOMAR analysis: the business-model lesson is sharper than the legal complaint. Telehealth companies want the conversion discipline of consumer apps, but medical trust is not built the same way as a shopping cart.

Marketing teams want granular campaign feedback. Product teams want low-friction onboarding. Finance teams want recurring revenue. Privacy and compliance teams, if they are not empowered early, can end up reviewing a system that has already been wired into third-party tools.

That mismatch is exactly where this case bites. The same tracking stack that may be routine for apparel, food delivery, or media subscriptions becomes risky when the product category implies diagnosis, treatment intent, or prescription access. The FTC is effectively saying context changes the meaning of the data.

The counterpoint is fair: digital healthcare companies need marketing, measurement, and operational analytics. But the Hims & Hers allegations show that “everyone uses trackers” is a weak defense when the site is collecting health-related intent.

After the Hims & Hers case, the next test is whether telehealth companies remove pixels from care flows

For users, the practical lesson is uncomfortable: privacy policies may not reveal the full path of data exhaust created before a medical consultation. Sensitive searches, intake clicks, and treatment-interest signals can create risk before any formal care decision happens.

For founders and marketing teams, the likely response is not to stop advertising. It is to audit trackers, map data flows, review vendors, harden consent screens, and remove third-party pixels from pages tied to health intake or treatment interest. Less precise attribution may become the cost of operating in sensitive categories.

For compliance teams, the message is even clearer. Legal review has to happen before marketing experiments go live, not after a regulator asks for logs.

The next signal to watch is how Hims & Hers answers the complaint in court. Evidence that the company clearly disclosed data sharing, obtained meaningful consent, and limited what trackers received would weaken the FTC’s case. Evidence that health-related actions flowed to ad platforms despite privacy promises would strengthen the thesis: in telehealth, aggressive tracking can turn patient acquisition into a regulatory liability.

Impact Analysis

  • The case could set stricter expectations for how telehealth companies use ad-tracking tools around sensitive medical data.
  • It highlights the gap between healthcare privacy promises and common digital marketing practices.
  • A ruling against Hims & Hers could force direct-to-consumer health platforms to rethink growth tactics built on user tracking.
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

AI chat records leaking from a digital vault into a dark data grid with broken privacy shields and locks.Cybersecurity

Google Exposed Claude Chats Users Thought Were Private

Shared Claude chats were indexed by Google, exposing sensitive transcripts and forcing Anthropic to confront a messy privacy gap.

Jul 28, 20267 min
Hospital IT breach scene with protected medical devices, servers, shields, locks, and data streams.Cybersecurity

3.8 Million Caught in Medtronic Data Breach Fallout

Medtronic says devices stayed safe, but 3.8 million people had personal and medical data exposed through corporate IT.

Jul 3, 202611 min
Identity theft victim facing locked digital records in a dark cybersecurity data protection sceneCybersecurity

FTC Hits Amazon With $2.25M Identity Theft Fine Over Records

Amazon will pay $2.25M after the FTC said identity theft victims were denied records needed to prove fraud on fake accounts.

Jul 1, 20268 min
Departing employee silhouette near secured corporate network, illustrating offboarding data risks.Cybersecurity

Exit Gap Haunts Apple OpenAI Lawsuit Over Data Access

Apple says a former employee got back into its network after joining OpenAI. Offboarding just became a live security fight.

Jul 13, 202611 min
Shadowy attackers breach healthcare cloud systems with locks, shields, and patient data icons.Cybersecurity

Stolen Patient Data Blows Open AdaptHealth Data Breach

Attackers used contractor access to steal AdaptHealth patient and billing data from cloud systems. The patient count remains unknown.

Jul 3, 20266 min
Futuristic AI command center showing competing neural network clusters in a sleek cloud technology workspace.Technology

Microsoft AI Models Drag OpenAI Into a Margin Fight

Nadella is turning Microsoft AI models into leverage against OpenAI and Anthropic, with Azure customers and margins at stake.

Jul 30, 20268 min
Family tension over uncanny AI-generated kids books and child privacy in a modern tech-filled home.Technology

AI-Generated Children's Books Ignite Privacy Fights

Personalized AI kids' books are becoming family flashpoints over sloppy stories, creepy images, and children's privacy.

Jul 29, 20268 min
Futuristic DeFi hub with six dim blockchain links being disconnected amid cost analysis.Fintech

Aave Proposal Targets Six Chains Earning Loose Change

Aave may shut six low-revenue deployments, signaling DeFi’s multichain era has to justify its costs.

Jul 30, 20267 min
Runner with earbuds checks a music app in a futuristic tech hub with glowing audio and AI visuals.Technology

iPhone Runners Snag Spotify Running Mode as Android Waits

Spotify Running Mode turns Premium iPhone playlists into guided runs, with 25 presets and a launch that leaves many users waiting.

Jul 30, 20266 min
Cybersecurity control hub shielding small businesses from AI and security risksCybersecurity

$110M Inforcer Series C Run Crowns the MSP Security Bet

Inforcer’s $50M Series C lifts its 18-month haul to $110M, backing MSPs as the control layer for SMB AI and security risk.

Jul 30, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.