A view from DC: The FTC sues Hims over pixel tracking

Though new privacy actions under the FTC Act might be rare these days, best practices for health-related data haven’t changed.

Contributors:
Cobun Zweifel-Keegan
CIPP/US, CIPM
Managing Director, Washington D.C.
IAPP
Editor's note
A lot has happened at the U.S. Federal Trade Commission since January 2025, when the agency's leadership last changed. Most recently, the U.S. Supreme Court affirmed the Trump administration's theory that the president has the authority to terminate FTC commissioners at will, officially leaving the FTC with three vacancies in its five-commissioner structure. Two of these have been vacant, but subject to dispute, since March 2025. But even the undisputed third vacancy has been open for over eight months.
The remaining two commissioners, Chairman Andrew Ferguson and Mark Meador, have adhered closely to the administration's agenda during their tenure. In the privacy context, both have promised to focus more on violations of statutes like the Children's Online Privacy Protection Act and the Fair Credit Reporting Act than on bringing cases under the FTC's general consumer protection authority.
In accordance with these promises, over the past 18 months the FTC has announced COPPA settlements with Disney and Iconic Hearts Holdings as well as FCRA settlements with Amazon and RentGrow.
Over the same period, until this week, the FTC has announced only a single new case alleging data privacy allegations under Section 5 of the FTC Act, which prohibits unfair or deceptive trade practices. That case was a settlement in March with Humor Rainbow, the owner and operator of the app OkCupid, which alleged the company violated its own privacy promises by granting an unrelated third party access to personal information of the users of its dating app.
Privacy for me, but not for Hims
But things heated up a bit this week when the FTC announced it had filed a lawsuit, joined by the states of California and Utah, against Hims and Hers Health, a telehealth company known for its discrete prescription-by-mail services focused on common but sensitive topics like hair loss, weight loss and sexual health.
Unfortunately, the version of the complaint posted on the FTC's website includes substantial redacted claims. This makes it difficult to conclude whether there are any nuances in this case that could lead to new takeaways for privacy professionals.
What we do know makes this case look a lot like the other cases against telehealth and other online health-related companies related to the sharing of sensitive information with third parties for advertising purposes.
As the press release alleges "Hims shared its consumers' health information with advertising platforms by sharing lists of certain customers with those companies. Hims also shared consumers' health information via third-party tracking technologies that automatically shared certain 'Events' — the actions of visitors on Hims' website — with those companies."
The details about the first of these allegations are entirely redacted in the complaint, though they almost certainly describe the manual uploading of customer match lists to build meta custom audiences and the equivalent service from Snap. Since these lists revealed health information about users to the third party, the company should, at a minimum, have included clear and conspicuous disclosures.
The same is true for the use of tracking pixels as well as the use of Meta's "Conversions API," a server-side tracking infrastructure. Notably, on the pixel side, the FTC provides a long list of other trackers the company allegedly made use of, naming all the companies that host these advertising mechanisms — and thus would have received sensitive data — including Microsoft, Google, Criteo, MediaBids.com, PartnerCentric, PebblePost.com, Pinterest, Spotify, Reddit, StackAdapt, TikTok, TradeDesk and X.
I list these here to reiterate the point that the FTC's allegations are generally applicable. As the complaint explains, "As with the Meta and Snap pixels, many of these pixels captured and shared Users' health information by way of similar pixel tracking events that captured (redacted) — all of which was contrary to Hims' privacy promises."
Even with the redactions, this lawsuit clearly continues the long line of cases around telehealth and other health-related online services, including GoodRx, BetterHelp, Premom, Monument and Cerebral. Those cases went even further than clear and conspicuous notice. And it is likely the takeaway from those cases still holds: If data reveals or strongly suggests a person's health condition, treatment status, diagnosis, reproductive condition, addiction issues, mental health status or similar protected characteristic, disclosure to advertising platforms is high risk and should usually occur only with explicit, informed consent.
Marketing claims about privacy must be accurate
One interesting aspect of this complaint is its focus on the company's marketing practices, including influencer claims related to privacy and discretion about information. These claims don't explicitly mention no information will ever be shared — and, in fact, even the company's May 2023 version of its privacy policy disclosed the sharing of "sensitive information" including "health data" for advertising purposes — but the FTC suggests such claims should have been coupled with clear and conspicuous disclosures about the company's actual privacy practices so as not to be deceptive.
Up-front disclosures matter in the context of sensitive information. It is still possible to violate the FTC Act even with detailed privacy policy disclosures. Though in this case the specifics will no doubt be closely litigated. Hims' May 2023 privacy policy provides explicit details about the core practices in the FTC's complaint:
"We may provide personal data to marketing and advertising partners. For example, we may share identifying information with an advertising partner in order to deliver personalized advertising to you or for the purpose of delivering advertisements to other people with similar interests to you. This may include sensitive personal information such as health data or information about your sex life to the extent it is not Protected Health Information. For example, if you view a webpage about balding or erectile dysfunction treatments, we may provide that information to an advertising partner who will then deliver advertisements to you on different websites based on your viewing activity."
Still, the FTC alleges two counts of deceptive privacy practices. The first relates to the marketing claims explicitly or implicitly creating a material condition on which consumers relied. Customers expected "private" and "discrete" treatment from the company but they allegedly received the opposite. And the second claims the company "has failed to disclose or failed to adequately disclose that Hims shared sensitive health information provided by consumers with third-party Advertising Platforms. This fact would have been material to consumers in deciding whether to enroll in the Hims Platforms."
ROSCA is serious business
This is not the first case from Ferguson's FTC to allege major subscription billing issues under the Restore Online Shoppers' Confidence Act. It is important for companies to carefully consider the ease with which consumers can cancel subscriptions. This case also bundles classic ROSCA allegations with FTC Act charges around deceptive claims about when and how a subscription would be triggered.
If you're unsure about the takeaways here, one great place to start is your own consumer complaints. The FTC's case hinges on the fact that the company allegedly was well aware that consumers felt deceived. The patterns of complaints, some of which are redacted, allegedly reveal in stark detail how consumers feel. Any company with similar patterns of customer complaints should actively consider its sign-up and cancellation practices, or risk the ire of the FTC.
Bipartisan cooperation
Finally, the joining of this action by California and Utah adds even more claims to the mix. Though consumer privacy laws are not included — in Utah, probably because of the cure period allowed under those claims and in California, probably because privacy policy disclosures were made under the California Consumer Protection Act — each state brings its own consumer protection claims, plus some claims under professional practices requirements.
This is yet another good reminder that consumer privacy laws are built on a foundation of consumer protection laws, which as I've written before, may sometimes require practices that go beyond the basic foundational requirements of consumer privacy.
Please send feedback, updates and influencer claims to cobun@iapp.org.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Cobun Zweifel-Keegan
CIPP/US, CIPM
Managing Director, Washington D.C.
IAPP
Tags:


