The Federal Trade Commission, joined by Utah and Los Angeles County on behalf of California, sued Hims and Hers on July 29, 2026, over how the telehealth company routed sensitive health data into Meta and Snap’s ad systems. It is not an isolated case. It is the third time since 2023 the FTC has gone after the same basic mechanism: a health or wellness brand feeding its customer lists and on-site behavioral events into ad platforms built for retail targeting, not medical confidentiality. For marketing leaders in regulated or adjacent categories, the pattern is now the story.
What the FTC Says Hims and Hers Did
According to the FTC’s complaint, filed in the U.S. District Court for the Northern District of California on a 2-0 commission vote, Hims and Hers charged consumers almost immediately after they submitted an online intake form, despite telling them they could consult a provider first to determine whether treatment was even appropriate. Consumers were enrolled into recurring subscription plans without clear consent. Before 2023, canceling required contacting customer service by phone, email, or chat. After the company introduced online cancellation, the FTC alleges it buried the cancel button behind multiple navigation steps, a pattern regulators have increasingly treated as a dark-pattern violation of the Restore Online Shoppers’ Confidence Act.
Layered on top of the billing allegations is the data-sharing claim that puts this case squarely in martech territory: the FTC says Hims and Hers shared consumers’ sensitive health information with Meta and Snap through two channels, uploading customer lists directly to the platforms, and running third-party tracking technology that automatically transmitted on-site user actions, described in the complaint as “Events,” back to those same platforms. One consumer quoted in the release said they were told they would speak with a doctor first and nothing would be charged that day, then were billed immediately, with no consent given to apply charges before a healthcare consultation took place.
The Third Case in a Pattern, Not the First
Regulators have been building toward this. In February 2023, the FTC brought its first-ever enforcement action under the Health Breach Notification Rule against GoodRx, which had shared user health data with Facebook, Google, and other ad companies for years despite its privacy promises. GoodRx paid a $1.5 million civil penalty and was barred from sharing health data with third parties for advertising. Weeks later, the FTC settled with BetterHelp over sharing consumers’ mental health information with Facebook and Snapchat for advertising after promising to keep it private. BetterHelp paid $7.8 million to consumers and was banned from sharing health information for advertising or retargeting.
The mechanism named in all three cases is nearly identical: a company promises privacy, then routes its own first-party customer data (an uploaded list, a pixel-fired event) into a general-purpose ad platform’s matching and lookalike-audience systems. That mechanism is not exotic. It is the standard playbook for retargeting and audience expansion across most of digital marketing. What is changing is that regulators have now decided health and health-adjacent verticals cannot use it the way retail and consumer brands do, and they are treating violations as a repeatable pattern worth suing over rather than a one-off settlement.
What This Means for the Marketing Leader
If your stack touches a regulated or sensitive category, health, mental health, financial hardship, or anything a state attorney general could plausibly frame as sensitive, the FTC’s theory here applies regardless of company size. Three things are now effectively required, not optional: consent has to be captured and verified before any data transmission occurs, not layered on afterward as a privacy policy disclosure. Server-side event integrations (the kind that fire automatically on page actions) need the same scrutiny as a manual customer list upload, because the FTC’s complaint treats them as functionally equivalent. And subscription cancellation flows are now a live enforcement surface in their own right, independent of the data-sharing allegations, under ROSCA and its state-law equivalents.
For teams outside obviously regulated categories, the read-through is about vendor diligence. Any CDP, tag manager, or ad platform integration that automatically forwards on-site behavioral events should have a documented list of what data leaves the site, to which platform, and under what consent condition. That is the same governance question identity infrastructure moving into the browser has been forcing on marketers more broadly, and it is the same enforcement posture regulators have shown on ad fraud rules in the UK: agencies are no longer treating platform-level compliance as sufficient cover for what a brand’s own tracking setup actually does.
What to Do Before the Next Case Lands
Audit every pixel and server-side event integration touching a page where a user submits health, financial, or otherwise sensitive information, and confirm the consent capture point precedes the data call, not just the privacy policy update. Treat customer list uploads to any ad platform as a data-sharing event requiring the same review as a pixel, since the FTC’s complaint draws no meaningful distinction between the two. And if your product has a subscription, test your own cancellation flow the way a regulator would: count the clicks, and compare that number to how many clicks it takes to sign up. Hims and Hers is a specific company with a specific complaint, but the enforcement mechanism now has three data points behind it, and that is what makes it a standard to build against rather than a headline to read past.
Source: Federal Trade Commission