Hims & Hers Lawsuit: FTC and Two States Sue Over Website Tracking Pixels
“Private.” “Secure.” “Discreet.” That is how Hims & Hers described its telehealth services to millions of customers. According to the FTC and two states, the company’s website was telling advertisers a different story.
On July 29, 2026, the Federal Trade Commission, the Utah Attorney General, and Los Angeles County Counsel (for the State of California) filed a joint complaint against Hims & Hers Health, Inc. in the U.S. District Court for the Northern District of California. The direct-to-consumer telehealth company sells prescription treatments for sexual health, hair loss, mental health, skin conditions, and weight loss. The complaint alleges that tracking technologies embedded in its website sent sensitive health information to Meta, Snap, and other advertising platforms, while the company promised customers privacy.
Hims & Hers disputes the allegations and says its privacy policy makes clear that users can choose how their data is used. Nothing has been proven in court. But the complaint itself is the lesson. It shows exactly where regulators are looking, and it is the same place most organizations are not: the client side of their own websites.
What the complaint alleges
The lawsuit combines two sets of claims. The subscription claims allege that Hims & Hers charged customers immediately after they submitted intake forms, enrolled them in auto-renewing plans without clear consent, and buried the cancellation option behind multiple navigation steps.
The privacy claims are the ones that should concern anyone who runs a website that handles sensitive data. According to the complaint, Hims & Hers:
- Marketed its services as “private,” “secure,” and “discreet”
- Embedded third-party tracking technologies on its website that automatically transmitted visitor actions (“Events”) to advertising platforms
- Shared customer information with those platforms for audience matching
- Allowed data to flow from sensitive pages, including treatment, intake, and checkout pages that reveal the health conditions or medications a visitor is interested in
Reporting on the case names Meta and Snap as recipients, with trackers from Microsoft, Pinterest, Reddit, and X also allegedly present on the site.
The regulators assert nine counts in total: three deception claims under Section 5 of the FTC Act, three violations of the Restore Online Shoppers’ Confidence Act (ROSCA), claims under California’s False Advertising Law and Unfair Competition Law, and Utah claims for privacy misrepresentation and inadequate opt-out opportunity.
Why this case is different
The FTC has been here before. GoodRx, BetterHelp, Cerebral, and Monument all faced enforcement over health data flowing to advertisers through tracking technologies. Kaiser Permanente agreed to a $47.5 million settlement after pixels on logged-in patient pages sent data to Meta, Google, and Bing. The pattern is established.
Three things make the Hims & Hers case worth your attention.
States joined the complaint. This is not just federal enforcement anymore. California and Utah filed alongside the FTC, each bringing its own consumer protection statutes. Every state privacy law adds another regulator who can bring the same fact pattern to court. If your trackers leak data, you are not facing one enforcement action. You are facing several.
HIPAA is not the hook. Hims & Hers connects consumers with providers, and much of its business sits outside traditional HIPAA coverage. It did not matter. The FTC used Section 5 deception claims, and the states used false advertising and unfair competition laws. The theory is simple: you said “private,” your website did something else. Any company that makes privacy promises can be reached this way, covered entity or not.
The website itself is the evidence. Regulators did not need a breach, a hacker, or a leaked database. The alleged violation is the ordinary, day-to-day behavior of marketing pixels on sensitive pages. Your website is publicly observable. Regulators, plaintiffs’ attorneys, and researchers can inspect your tracker behavior from the outside at any time. Many do.
The uncomfortable question: do you know what your pixels send?
Most organizations cannot answer this with confidence, and the reason is structural. Marketing adds pixels to measure campaigns. Product adds tags to analyze funnels. Agencies add their own tools. Tag managers fire scripts based on rules nobody has reviewed in years. Forgotten pixels keep collecting data long after the campaign ends.
Meanwhile, security teams focus on servers, endpoints, and networks. The client side, the code that actually runs in your visitors’ browsers, sits in a governance gap. Nobody owns it, so nobody watches it.
The Morgan Lewis health law team drew the practical takeaways from the complaint: review where advertising trackers sit on sensitive pages, identify what URLs, events, identifiers, and parameters they transmit, determine whether recipients can tie that data to identifiable individuals, and align your privacy claims with what your site actually does. And keep records of tracker configurations over time, because when a dispute comes, you will need to prove what your website was doing and when.
Read that list again. It is a continuous monitoring requirement. A one-time audit tells you what your website did on the day of the audit. Pixels change behavior after updates, tags get added weekly, and a script that was safe in January can start collecting form data in March.
How Reflectiz closes the gap
Others tell you which trackers exist on your site. Reflectiz shows you what they actually do with your visitors’ data.
The Reflectiz Privacy Hub continuously monitors your website from the outside, exactly the way a regulator or researcher would look at it, and answers the questions the Hims & Hers complaint raises:
- Full tracker inventory. Every pixel, tag, and third-party script on every page, including the ones added through tag managers and fourth parties nobody approved.
- Data flow mapping. What each tracker collects and where it sends it, down to the URLs, events, and parameters. You see health-context data leaving a checkout page before the FTC does.
- Sensitive page coverage. Alerts when a tracker appears on pages where it should never run: intake forms, symptom checkers, checkout flows, patient portals.
- Consent validation. Whether trackers actually respect user choices, or fire before consent, which is where privacy-policy claims and reality drift apart.
- Evidence trail. A historical record of tracker configurations and changes, so you can document what ran on your site and when.
Because Reflectiz is agentless, there is no code to install and no impact on site performance. You get the outside-in view of your website that regulators already have, before they use it.
What to do this week
- Inventory every tracking technology on your site, including everything loaded through tag managers.
- Map your sensitive pages: anywhere a URL, button click, or form field reveals a health condition, a financial situation, or another sensitive fact about the visitor.
- Check what fires on those pages and what it transmits.
- Compare the result against your privacy policy and marketing claims. If your site says “private,” verify that the network traffic agrees.
- Set up continuous monitoring and keep the records. Point-in-time audits do not survive contact with weekly tag changes.
The Hims & Hers case will take years to resolve. Your exposure will not wait that long. Book a demo to see what your website is telling advertisers about your visitors.
FAQs
What is the FTC lawsuit against Hims & Hers about?
On July 29, 2026, the Federal Trade Commission, the Utah Attorney General, and Los Angeles County Counsel filed a joint complaint against Hims & Hers Health, Inc. in the U.S. District Court for the Northern District of California. Regulators allege the telehealth company marketed its services as private, secure, and discreet while third-party tracking technologies on its website transmitted sensitive health information to advertising platforms. The complaint also alleges deceptive subscription and cancellation practices. Hims & Hers disputes the allegations, and the claims remain untested in court.
Did Hims & Hers break HIPAA?
No. The complaint does not rely on HIPAA. Regulators used Section 5 of the FTC Act for deception, the Restore Online Shoppers’ Confidence Act for the subscription claims, and state consumer protection statutes in California and Utah. That matters for any company that assumes it sits outside these rules. If you tell visitors their data is private and your website behaves differently, consumer protection law reaches you whether or not you are a HIPAA covered entity.
How do tracking pixels leak sensitive health data?
A tracking pixel is a small piece of third-party code that fires when someone loads a page or takes an action, then reports back to the advertising platform that placed it. On an ordinary product page that is routine analytics. On a treatment page, an intake form, or a checkout flow, the URL, button click, or form field itself reveals the condition or medication the visitor is interested in. The platform receives that event alongside identifiers that can tie it to a real person, which turns a marketing tag into a health data disclosure.
Which advertising platforms allegedly received Hims & Hers customer data?
The FTC complaint names Meta and Snap. Reporting on the case indicates trackers from Microsoft, Pinterest, Reddit, and X were also present on the website. Regulators allege data reached these platforms in two ways: customer lists shared directly for audience matching, and third-party tracking technologies embedded in the site that automatically transmitted visitor actions, described in the complaint as Events.
What have other companies paid for sharing health data with advertisers?
The FTC fined GoodRx $1.5 million in February 2023 and BetterHelp $7.8 million in March 2023, both over health data shared with advertising platforms. Kaiser Permanente agreed to pay up to $47.5 million to settle web tracker litigation. Cerebral and Monument faced similar actions. The Hims & Hers case adds state regulators to that pattern, so one tracker configuration can now trigger federal and multiple state claims at the same time.
How do you find out what your website's trackers actually send?
You inspect them continuously from the outside, the way a regulator or researcher would. That means a full inventory of every pixel, tag, and third-party script across your pages, a map of what each one collects and where it sends it, alerts when a tracker appears on a sensitive page such as an intake form or checkout flow, validation that trackers respect consent choices, and a historical record of tracker configurations you can use as evidence. Reflectiz does this agentlessly, with no code to install, so you find a leaking tracker before a regulator does.
Subscribe to our newsletter
Stay updated with the latest news, articles, and insights from Reflectiz.
AI Has Changed The Web.
Are You Ready for What’s Next?
Third-party code shifts by the hour. Supply-chain compromises strike without warning. AI-driven web attacks now evolve faster than traditional security can ever keep up.
Reflectiz delivers the continuous, real-time visibility needed to expose the risks traditional tools miss entirely.
Zero code changes. Zero access to your data. Ultimate peace of mind.