FTC Sues Hims & Hers Over Patient Data Shared With Meta and Snap
The Federal Trade Commission filed a lawsuit Wednesday against telehealth provider Hims & Hers Health, alleging the San Francisco-based company shared sensitive patient health information with third-party advertising platforms including Snap, Meta, and others, despite public promises that it safeguarded user privacy. The complaint, joined by Utah and California, accuses Hims of violating the FTC Act through deceptive practices that funneled medical condition data—covering sexual health, mental health, and other sensitive treatments—to advertisers via customer list sharing and embedded tracking technologies on its website.
According to the FTC, Hims transmitted identifiable health information through third-party tracking pixels and analytics tools that captured user behavior on the site, while simultaneously telling consumers that "medical records and sensitive information are only accessed by the medical providers managing your care." The company's marketing materials further emphasized a "100% online, private, and secure process." The agency argues these representations "conveyed to consumers that Hims would not disclose their health information to third parties," alleging the company instead prioritized growth and revenue. Users worried about exposure from such tracking practices can run a browser fingerprint test to see how identifiable their browsing session is, or perform a DNS leak test to confirm whether their queries are being routed through their ISP unmasked.
Hims & Hers pushed back sharply, with a spokesperson calling the lawsuit an effort to "generate headlines at our expense" that "disregards substantial evidence" provided during the FTC's nearly three-year investigation and "contorts the law to try to manufacture claims." The company maintains its privacy policy adequately informs users about data handling practices. Beyond the data-sharing allegations, the FTC complaint also accuses Hims of making subscription cancellations unreasonably difficult and deceiving customers about billing—practices that mirror recurring complaints against direct-to-consumer telehealth firms operating on auto-renewal models.
The case highlights how patient intake forms on healthcare platforms can become vectors for commercial surveillance when third-party scripts are embedded without robust consent mechanisms. Individuals who have used Hims or similar telehealth services and want to understand their broader exposure can check whether their personal details appear in known aggregations using an email breach checker, or run a full privacy checkup to assess what trackers are active in their current browser. The lawsuit lands amid heightened federal scrutiny of healthcare data brokers and adtech firms, and signals that telehealth companies handling sensitive disclosures face the same regulatory exposure as traditional covered entities under HIPAA-adjacent enforcement frameworks.