The Federal Trade Commission (FTC), State of California, and Utah Division of Consumer Protection recently filed a sweeping complaint against telemedicine company Hims & Hers Health, Inc., using federal and state consumer-protection laws to assert allegations against its direct-to-consumer telehealth business. The case is notable as regulators are not relying on a traditional health-privacy statute but rather general consumer-protection laws to challenge health-data advertising practices and aspects of Hims’s subscription model.
The regulators have focused their concerns on a central element of the direct-to-consumer telehealth industry: the marketing and sale of prescription treatments through recurring subscriptions. Significantly, the complaint highlights a developing area of privacy enforcement at the intersection of health data and digital advertising, alleging that Hims shared sensitive health information with third-party advertising platforms while making broad assurances about the privacy of its services.
Hims & Hers Complaint
Consumer Protection Claims
Hims operates a direct-to-consumer telehealth platform offering prescription treatments for conditions including sexual health, hair loss, mental health, skin conditions, and weight loss.
Hims connects consumers with contracted medical providers and partner pharmacies and sells prescription products through recurring subscriptions. Consumers seeking treatment complete an online medical intake process and provide billing information before submitting their information for medical review. As implemented by Hims, the complaint challenges several aspects of this model.
The regulators allege that Hims “caused consumers to face unwanted refill charges and made it difficult for them to cancel their subscriptions.” Specifically, they allege that Hims failed to disclose the dates when consumers would be charged, resulting in consumers paying for unwanted refills of medications.
Regulators further claim that consumers struggled to cancel subscriptions “for years” as Hims made canceling subscriptions unnecessarily difficult through unintuitive mechanisms, such as an “add/remove items from order” option. For subscription-based telehealth companies, these allegations underscore the importance of clearly communicating when recurring charges will occur and providing consumers with a readily accessible cancellation mechanism that does not require navigating unrelated account functions.
Health Data and Digital Advertising Allegations
The privacy claims focus on the alleged disconnect between the telehealth company’s representations and its use of health-related information for digital advertising. According to the complaint, Hims represented through its website and advertising that its services were “private,” “secure,” and “discreet” and that consumers’ medical records and sensitive information would be accessed only by medical providers managing their care.
But the regulators allege that Hims disclosed sensitive health information to third-party advertising platforms through tracking technologies embedded in its website, including technologies associated with several large technology and advertising companies. The challenged practices include the use of customer information for audience matching and advertising technologies that may transmit information about a consumer’s interactions with Hims’s website to third parties.
In practice, similar technologies can create heightened risk when deployed on treatment, intake, checkout, or other potentially sensitive webpages that reveal a consumer’s interest in a particular condition, treatment, or prescription product, particularly where that information is transmitted together with an identifier or other information that can be associated with an individual.
Claims and Enforcement Theories
These allegations form the basis for nine counts asserted under federal and state laws. The FTC asserts three claims alleging deceptive acts or practices under Section 5 of the FTC Act.
Count 1 alleges that Hims’s privacy representations were deceptive because Hims allegedly shared sensitive health information with advertising platforms; Count 2 alleges a deceptive omission based on Hims’s failure to disclose or adequately disclose that sharing; and Count 3 alleges deceptive intake practices. The FTC also brought three claims under the Restore Online Shoppers’ Confidence Act (ROSCA) addressing disclosures, consent, and subscription cancellation.
California and Utah extend these theories under state law. California alleges that the same conduct violated its False Advertising Law and Unfair Competition Law and invokes California constitutional and common-law privacy principles based on the alleged disclosure of health information without consent or authorization.
Utah similarly alleges privacy-related misrepresentations and omissions, including inadequate disclosure of data sharing and failure to provide consumers with a clear and conspicuous opportunity to opt out.
The overlapping claims are significant as they demonstrate how the same data practices can support multiple theories of liability.
Regulatory Considerations for Health Data and Digital Advertising
The Hims complaint reinforces that the Health Insurance Portability and Accountability Act is not the sole boundary of health-data enforcement risk. Privacy risks involving health-related information may extend beyond traditional healthcare privacy frameworks. Federal consumer-protection law can independently reach representations and omissions concerning the collection, use, and disclosure of health information. And, as the complaint demonstrates, state laws may impose additional requirements.
The state-law claims highlight the role of consumer choice in health-data advertising practices: California alleges disclosure of health information without consent or authorization, while Utah specifically alleges that Hims failed to provide a clear and conspicuous opportunity to opt out of sharing sensitive health information with advertising platforms.
The allegations also highlight the importance of understanding how advertising technologies operate in practice. Pixels, APIs, audience-matching tools, and similar technologies can transmit information about a user’s interaction with a website to third parties, and the legal analysis may depend on what information is collected, whether it can be associated with an identifiable consumer, and what is transmitted to third parties.
Some technologies, such as tracking pixels, may transmit information from a consumer’s browser when the consumer visits a webpage or takes a particular action, while server-side APIs may transmit similar information directly from the company’s systems to an advertising platform.
For organizations handling health-related information, reviewing these technologies should include understanding how particular webpages, tracking events, identifiers, and advertising configurations result in the collection or transmission of consumer data.
That review should identify:
- Whether advertising technologies operate on treatment, intake, checkout, or other potentially sensitive pages
- What URLs, events, identifiers, or other parameters are transmitted
- Whether recipients can associate that information with a particular consumer
Companies should also consider whether (1) advertising trackers are necessary on sensitive portions of their websites, (2) particular events or identifiers can be suppressed or limited, and (3) tracking should occur only after an appropriate consumer choice.
Privacy review should also extend beyond formal privacy policies and notices. The FTC relied on statements across Hims’s website, digital and offline advertising, influencer promotions, and descriptions of who could access consumers’ medical information.
Because a Section 5 deception analysis considers the overall impression conveyed to consumers, companies should evaluate those representations against their actual data practices. That review should include marketing and product messaging, privacy disclosures, and the technologies through which consumer information is collected and shared.
Where actual data practices cannot support broad assurances that information is “private,” “secure,” “discreet,” or accessible only to healthcare providers, companies should consider modifying the underlying data sharing, narrowing the consumer-facing representations, or providing clearer disclosure of the relevant third-party advertising use.
Litigation and Defense Considerations
The allegations in the Hims complaint remain untested, and Hims has publicly disputed the regulators’ claims. Nevertheless, the complaint is instructive as it identifies several issues that may be central to defending similar or future enforcement actions, including the meaning of consumer-facing privacy representations, the nature of the information transmitted to third parties, the adequacy of disclosures, and the remedies available for any proven violation.
For the FTC’s Section 5 claims, a central issue is likely to be what Hims’s privacy representations reasonably communicated to consumers. Under the FTC’s deception framework, the government must establish a representation, omission, or practice that is likely to mislead a reasonable consumer and is material to the consumer’s decision.
The FTC considers the overall context and “net impression” of the challenged representation rather than individual statements in isolation. Accordingly, broader descriptions of a service as “private,” “secure,” or “discreet” may present different issues than more specific statements concerning who may access particular information.
While applicable privacy policies and data practice notifications will likely be a piece of the defense, other public-facing representations will also have bearing on the suit’s resolution. The context in which consumer-facing statements appeared, and any accompanying disclosures, is likely relevant to assessing whether they were misleading.
The information actually transmitted to advertising platforms is another potentially significant issue. The Hims complaint characterizes that information as “sensitive health information,” but the complaint is heavily redacted, concealing the specific data at issue. Defending that characterization may require examining precisely what information was transmitted, whether it was linked or linkable to identifiable consumers, what a recipient could infer from it, how it was used, and how processing that data was described to consumers.
These issues underscore that early coordination between technical experts and defense counsel is key. Reconstructing historical configurations, identifying the relevant data flows, and understanding what third-party platforms actually received may materially affect both liability and litigation strategy.
For companies conducting a proactive review, preserving records of tracker configurations, consent settings, vendor changes, event definitions, and the reasons for modifying particular practices can help establish what data was transmitted at a given point in time if those practices are later challenged.
Remedies may also depend on the statutory theory asserted. While the FTC cannot obtain restitution or disgorgement for past violations under Section 13(b) of the FTC Act, it has invoked the act’s Section 19 in connection with the alleged ROSCA violations for monetary relief. Additionally, California and Utah separately seek monetary remedies and civil penalties under state law.
Looking Ahead
Digital health companies should consider coordinated legal and technical reviews of advertising and analytics practices involving health-related information.
Morgan Lewis advises digital health and life sciences companies at the intersection of healthcare regulation, privacy, advertising technology, and consumer protection. Our lawyers work together to evaluate advertising technologies and health-data practices, conduct privileged compliance and risk assessments, respond to regulatory inquiries and investigations, and defend companies when those issues develop into enforcement actions or litigation.
Because our team handles these matters from compliance counseling through investigation, trial, and appeal, we are positioned both to identify practices likely to draw regulatory scrutiny and to evaluate them critically. Keep following us at the Health Law Scan for more news, insights, and developments affecting digital health and life sciences companies.