Overview
On July 29, 2026, the Federal Trade Commission (FTC), joined by the State of Utah and the State of California, filed a complaint in the U.S. District Court for the Northern District of California against telehealth company Hims & Hers (Hims). The complaint alleges that Hims misrepresented how it handled consumers’ health information and engaged in deceptive billing, subscription, and cancellation practices. Although these allegations have not been proven, the action is the latest in a sustained series of FTC enforcement against telehealth and digital health companies, reflecting the FTC’s continued focus on whether companies’ data practices and business operations align with their consumer-facing representations.
The Core Issue: Consumer Representations vs. Alleged Business Practices
The complaint’s central theme is one that has become familiar in FTC health-privacy enforcement: the alleged disconnect between a company’s public promises to consumers and its actual data-handling and billing practices.
The table below summarizes key representations the FTC alleges Hims made to consumers alongside the practices the complaint alleges actually occurred.
| What Hims Told Consumers | What the Complaint Alleges Actually Happened |
| Hims represented that its services maintain consumer privacy and promised to keep patients’ health information private. | Hims allegedly shared consumers’ sensitive health information about their medical conditions with third-party advertising platforms, including Meta and Snap, both by sending those platforms lists of customers and through tracking technologies that automatically transmitted website “events” (visitor activity on Hims’ platforms) to the same companies. |
| Advertisements represented that Hims offers a “free consult” allowing consumers to connect with a medical provider to find the treatment that is “right for them.” | The FTC alleges that Hims does not provide most consumers with an actual consultation with a provider and instead enrolls them in a recurring subscription, charging their payment method almost immediately after they submit an online intake form. |
| Consumers were led to believe they would not be charged unless and until a provider prescribed medication for them. | Hims collects billing information during the intake flow and, according to the complaint, enrolls consumers in subscription treatment plans and charges them shortly after intake, without clear disclosure of billing terms or adequate consent. |
| By 2023, Hims had introduced an online cancellation option for most consumers suggesting that subscriptions could be cancelled without hassle. | The complaint alleges that the cancellation option was difficult to locate and complete, requiring consumers to navigate several steps and appearing only after consumers selected “add/remove items from order.” The FTC also alleges that Hims failed to clearly disclose when subscriptions would be refilled and charged each month, making it difficult for consumers to cancel before the next billing cycle. |
A Coordinated Federal-State Enforcement Action
Notably, the FTC did not act alone. It filed the complaint jointly with the Utah Attorney General and the Los Angeles County Counsel, acting on behalf of California, continuing a broader enforcement trend of partnering with state and local regulators to pursue coordinated consumer protection, privacy, and digital health enforcement actions.
The FTC alleges that Hims’ conduct violates Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, and the Restore Online Shoppers’ Confidence Act (ROSCA), which requires companies offering automatically renewing subscriptions to clearly disclose all material subscription terms, obtain consumers’ express informed consent before charging them on a recurring basis, and provide a simple mechanism to stop recurring charges.
The state plaintiffs also assert parallel claims under their respective consumer protection statutes. Utah alleges violations of the Utah Consumer Sales Practices Act, and California alleges violations of its False Advertising Law and Unfair Competition Law.
Part of a Broader Health Privacy Enforcement Trend
The Hims & Hers action extends a multi-year FTC enforcement trend targeting telehealth and digital health companies that promise privacy but allegedly share health data with advertising platforms:
GoodRx (2023)
In the FTC’s first case under the Health Breach Notification Rule, the agency alleged that GoodRx shared users’ health conditions and prescription information with Facebook, Google, and other advertisers, contrary to its privacy policy, and used that data to target users with health-related ads. GoodRx paid a $1.5 million civil penalty and was barred from sharing health data for advertising.
BetterHelp (2023)
The FTC alleged the online counseling service disclosed users’ email addresses, IP addresses, and mental-health questionnaire answers to Facebook, Snapchat, Criteo, and Pinterest for advertising, despite promising to keep such information private. BetterHelp paid $7.8 million, which was largely refunded to consumers.
Cerebral (2024–2025)
The FTC alleged that the telehealth mental-health provider made its cancellation process needlessly complex, continued billing consumers who tried to cancel, and disclosed sensitive personal health information to advertising platforms despite marketing its services as “private, secure, and non-judgmental” and promising that data would not be shared without consent. Cerebral agreed to a $7 million order, and more than $5 million was later returned to affected consumers.
Health Breach Notification Rule Amendments (2024)
The FTC finalized changes clarifying that health apps and similar technologies not covered by HIPAA must comply with breach-notification obligations, following its GoodRx and Premom (Easy Healthcare) enforcement actions for the undisclosed sharing of health data with advertisers.
Joint FTC/HHS Guidance on Tracking Pixels (2023)
The FTC and the HHS Office for Civil Rights sent a joint letter to approximately 130 hospital systems and telehealth providers warning that online tracking technologies, such as the Meta/Facebook Pixel and Google Analytics, may impermissibly disclose consumers’ sensitive health data to third parties.
NextMed (2025)
The FTC obtained a final order against a telehealth company selling GLP-1 weight-loss programs, addressing deceptive advertising along with unfair billing and cancellation practices, including failures to obtain express informed consent before charging consumers or making recurring debits.
Collectively, these cases underscore the FTC’s continued focus on three recurring enforcement priorities involving telehealth, digital health, and health technology companies:
- the gap between consumer-facing health privacy representations and actual sharing of sensitive data with advertising platforms through customer lists and tracking pixels;
- subscription and billing practices that make it easy to sign up and hard to cancel, including compliance with ROSCA’s “click-to-cancel” and other subscription disclosure requirements; and
- increasing coordination with state attorneys general and local enforcers to bring parallel or joint actions.
Compliance Takeaways for Telehealth and Health Technology Companies
- Audit privacy policies and consumer-facing representations against actual data flows, including any use of pixels, SDKs, or other tracking technologies that transmit data to advertising platforms.
- Review agreements and configurations with advertising and analytics vendors (e.g., Meta, Snap, Google) to confirm what data is being shared, whether it constitutes health information, and whether the necessary disclosures and consents have been obtained.
- Confirm that intake, consultation, and billing disclosures clearly and conspicuously state when a consumer will be charged, for what, and on what recurring schedule, and that consumers provide express informed consent before being enrolled in a subscription.
- Evaluate cancellation flows against ROSCA’s simple-cancellation requirements to ensure that the cancellation process is at least as easy as the sign-up process.
- Assess whether the Health Breach Notification Rule applies to any product that functions as a personal health record or interacts with one, particularly if it is not otherwise covered by HIPAA.
- Prepare for the possibility of a joint federal-state inquiry or enforcement action as the FTC continues to coordinate with state attorneys general and local enforcers on health-privacy and consumer protection matters.
How Frier Levitt Can Help
The Hims action underscores that the FTC, together with an expanding roster of states, continues to treat the divide between stated privacy commitments and actual data practices as a top enforcement priority for digital health companies.
Given the potential exposure, including civil penalties, consumer refunds, and long-term injunctive obligations, telehealth and health technology companies should treat this case as an opportunity to reassess their privacy disclosures, advertising technology integrations, and subscription billing practices before becoming the subject of an investigation or enforcement action.
Contact Frier Levitt to learn how our attorneys help telehealth and health technology companies assess and strengthen their privacy, advertising technology, and subscription billing compliance programs in light of this enforcement action and the broader regulatory trends shaping the industry.