Hims Suit Tests Health Data Boundaries
Coverage from Goodwin, Benesch Law, and others

The Federal Trade Commission, joined by California and Utah, sued telehealth company Hims & Hers over alleged sharing of health-related information with advertising platforms through tracking technologies and customer-list tools.
The complaint also challenges the company’s privacy disclosures and subscription billing and cancellation practices; Hims & Hers disputes the allegations. The case highlights how consumer-protection and state privacy laws may apply to digital health services beyond the reach of HIPAA.
If you read one thing
It clearly introduces the lawsuit and explains the alleged use of advertising pixels and customer lists to share health-related data.
Best explainer
It places the Hims case in the wider legal context of consumer-health privacy protections that extend beyond HIPAA.
The evidence
It adds concrete detail on the complaint’s separate allegations about recurring charges, billing disclosures, and cancellation barriers.
Health data flows into advertising systems
The Hims & Hers case centers on allegations that tracking pixels, customer lists, and related tools sent sensitive health information to advertising platforms despite privacy assurances. The allegations remain contested and have not been adjudicated.
Digital-health oversight extends beyond HIPAA
Consumer-protection and state health-data laws are being applied to health-related information and tracking practices beyond the conventional scope of HIPAA. The Hims action and related scrutiny, including UCHealth litigation, illustrate this broader legal exposure; the claims remain unresolved.
Subscription practices are part of the enforcement case
Regulators also challenge Hims & Hers’ recurring-charge disclosures, billing practices, and barriers to cancellation, placing subscription design alongside health-data handling in the case. These remain allegations, not adjudicated findings.
more than a half-dozen
telehealth companies targeted in similar FTC cases
“The FTC has filed similar cases against more than a half-dozen telehealth companies, including BetterHelp and GoodRx. Regulators said both companies shared users’ health data with platforms such as Meta and Google without permission.”
nearly 3 million patients per year
Patients served annually by UCHealth
“The plaintiff argues that these practices violate the Electronic Communications Privacy Act and HIPAA. UCHealth serves nearly 3 million patients per year, creating the potential for a large class.”
June 2024
date of the court ruling
“In June 2024, a Texas federal judge ruled that the guidance’s position on unauthenticated users was unlawful, finding that webpage activity did not necessarily relate to an individual’s health without further indication of the visitor’s intent.”
More than 20 states
states restricting certain sharing of consumer health data with advertising partners
“More than 20 other states also restrict certain sharing of consumer health data with advertising partners.”
New articles add legal context and detail about existing allegations, but do not establish a material new development in the Hims & Hers case or its broader regulatory context.
Previously
The Federal Trade Commission, California, and Utah sued Hims & Hers over allegations that the telehealth company shared sensitive health information with advertising platforms through tracking pixels, customer-list uploads, and related technologies. The complaint also challenges subscription billing, refill disclosures, and cancellation practices. The case highlights expanding scrutiny of digital-health companies' advertising and consumer-data practices, including potential liability outside traditional HIPAA enforcement.
The current version mainly clarifies that the allegations remain unresolved; it does not materially change the story.
The story broadens from a single Hims & Hers enforcement case into a wider examination of digital-health data practices, including related litigation beyond traditional HIPAA enforcement.
