← Back to Feed

Hims & Hers sued over alleged health data privacy failures

July 30, 2026 · Malwarebytes · Severity: MEDIUM

The U.S. Federal Trade Commission (FTC), alongside Utah and California, has filed a lawsuit against telehealth provider Hims & Hers, alleging the company shared consumers’ sensitive health data with third-party advertising platforms like Meta and Snap despite promising robust privacy protections. Hims & Hers, a digital health platform offering online consultations, prescription medications, and personal care products, is also accused of deceptive billing practices, including charging users before consultations and making subscription cancellations unnecessarily difficult. The FTC claims that consumers were often enrolled in recurring prescription subscriptions shortly after submitting intake forms, often without consulting a medical provider, and that cancellation options were hidden behind confusing steps even after an online option was introduced. This lawsuit underscores broader issues in consumer privacy and cybersecurity, particularly in health-related services. It highlights the gap between privacy policies and actual practices, as companies may integrate third-party advertising SDKs that leak sensitive data. Additionally, the case exemplifies the use of "dark patterns," such as hard-to-find cancellation flows, which manipulate users into retaining services. The FTC’s action signals growing regulatory scrutiny over how health-related services handle sensitive data, emphasizing the need for transparency and accountability. For consumers, this case serves as a reminder that "health tech" does not inherently prioritize privacy, urging vigilance in understanding privacy policies and limiting the sharing of sensitive information.

The US Federal Trade Commission (FTC), together with Utah and California, has filed a lawsuit against telehealth provider Hims & Hers.

The FTC alleges that the company shared consumers’ sensitive health information with third‑party advertising platforms despite promising strong privacy protections.

Hims & Hers is a telehealth and digital health platform that connects users with licensed medical providers for online consultations, prescription medications, and personal care products.

The complaint also accuses Hims & Hers of deceptive billing and subscription practices that made it hard for users to avoid charges or cancel subscriptions.

According to the FTC’s complaint, filed in federal court in California, Hims & Hers:

  • Shared sensitive health data, including details about medical conditions, with ad platforms such as Meta and Snap despite privacy promises.
  • Charged before consultations. The company promised users they could consult a medical provider before being charged, but the FTC says many consumers were enrolled in recurring prescription subscriptions shortly after they submitted an intake form, often without first having a consultation.
  • Made cancellation difficult. Before 2023, cancellation reportedly required contacting customer service by phone, email, or chat. Even after an online cancellation option appeared, the FTC alleges the button was hidden behind multiple steps and confusing options.

From a cybersecurity and privacy research perspective, this isn’t just about a single telehealth brand. It highlights three broader trends we see repeatedly in consumer programs:

Privacy policies versus reality. A company can market itself as privacy‑focused while still integrating third‑party advertising and analytics software development kits (SDKs) that leak sensitive information. This becomes especially concerning when health‑related events are linked to user accounts or tracking cookies.

Friction as a feature. Hard‑to‑find cancellation flows and unclear billing practices are examples of “dark patterns” that nudge users into paying for services they might not have chosen given all relevant information.

Regulatory pressure is growing. Health‑related services are under increasing scrutiny, especially when they handle sensitive data and combine it with advertising platforms.

The court will ultimately decide whether Hims & Hers violated the law, but the FTC’s action sends a clear signal: regulators are paying close attention to how health‑related services collect, use, and share sensitive data.

For anyone who values online privacy, the Hims & Hers case is a reminder that “health tech” does not automatically mean “privacy first.”

How to stay safe

More often than not, the privacy loopholes are hidden in the privacy policy somewhere.

Pro tip: one thing AI is good at is reading between the lines. Ask an AI chatbot to summarize a privacy policy and identify when your information may be shared with third parties. AI makes it much easier to understand lengthy privacy policies without reading every word yourself. If companies fail to follow their own privacy policies, regulators and consumers can hold them accountable.

Other than that:

  • Don’t share sensitive information unless it’s genuinely needed to provide the service.
  • Use strong, unique passwords and multifactor authentication (MFA). Even if a company is compliant, breaches happen. Unique passwords and two‑factor authentication limit the damage if your account details are exposed.
  • Check your browser and app permissions. Disable unnecessary tracking features where possible, and consider privacy‑focused browser settings or extensions that limit third‑party cookies and trackers.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

Key Takeaways

  • FTC lawsuit alleges Hims & Hers shared health data with ad platforms.
  • Company promised privacy but shared medical conditions with Meta and Snap.
  • Deceptive billing practices made cancellation difficult for consumers.
☕ Buy a Coffee