What happened
On July 29, 2026, the Federal Trade Commission — joined by the State of Utah and Los Angeles County — filed suit against Hims & Hers, one of the largest direct-to-consumer telehealth companies in the country.
Two sets of allegations. First, that the company transmitted users’ sensitive health information to Meta and Snap through advertising trackers, and uploaded customer lists segmented by health condition for ad targeting — while marketing itself as “private and discreet.” Second, that it charged customers upon submitting an intake form, before any clinician had reviewed anything, and made cancellation harder than signup.
The company has called the claims baseless and says it provided substantial evidence during a nearly three-year investigation. The case is unresolved, and nothing here should be read as a finding of wrongdoing.
But the allegations describe practices that are common across the industry — which makes this worth understanding regardless of how the case ends.
Why “HIPAA protects me” is usually wrong here
This is the part that surprises most people.
HIPAA governs “covered entities” — providers, health plans, and clearinghouses — and their business associates. It’s narrower than most patients assume.
What HIPAA generally does not cover:
- Most health and wellness apps you download
- Symptom quizzes and intake funnels on marketing websites
- Data collected before you become a patient
- Advertising trackers embedded in health-related web pages
- Most direct-to-consumer supplement and wellness platforms
So the information you enter into a “find out if you’re a candidate” quiz may sit entirely outside the framework you assumed was protecting it. That gap is precisely where the FTC has been operating — using its general consumer-protection authority rather than health-privacy law.
How health data leaks without anyone intending it
Most of this isn’t malicious. It’s how modern web advertising works, applied carelessly to health.
Tracking pixels. A small piece of code from an ad platform placed on a page. It reports that a visitor viewed that page. On a shopping site that’s unremarkable. On a page about erectile dysfunction, hair loss, or mental health, the URL itself discloses a health condition.
Condition-segmented audiences. Uploading a customer list to an ad platform so you can advertise to “people who bought X.” When X is a medication, that list is health information.
URLs that describe conditions. A page address containing a diagnosis name transmits that diagnosis to every tracker on the page.
Third-party analytics with ad features enabled. Standard analytics is one thing; analytics configured for ad personalization is another.
The FTC has now brought actions on this pattern repeatedly — against GoodRx, BetterHelp, Premom, and now Hims. That’s a campaign, not a one-off.
Questions worth asking any health platform
Before you enter symptoms into an app or telehealth intake:
- Am I a patient yet, or a lead? Information entered before a clinician relationship exists is often marketing data, not medical records.
- Does the privacy policy mention advertising partners? Look specifically for “third parties,” “advertising,” “analytics,” and any named platforms.
- Is there a licensed clinician, and can I identify them? If you can’t name who is treating you, you may not be in a clinical relationship at all.
- When am I charged — before or after a clinician reviews my case? Charging at intake is one of the specific practices the FTC challenged.
- How do I cancel? If cancelling is harder than subscribing, that’s both a design choice and, per the FTC’s position, potentially a legal problem.
- What happens to my data if I don’t become a customer? Rarely answered clearly, and worth noticing when it isn’t.
What this doesn’t mean
Telehealth is not the problem. Virtual care has made healthcare accessible to people who couldn’t otherwise get it — rural patients, people with mobility limitations, anyone who can’t take half a day off for a fifteen-minute appointment. I offer virtual visits myself.
The issue isn’t the delivery method. It’s a business model where the funnel is optimized for conversion and the clinical relationship is thin — where you’re a lead first and a patient second, and where data practices are built for advertising rather than for care.
There’s a straightforward tell: can you name your clinician? In a real clinical relationship, you can.
How this practice handles it
Since it would be hollow to write this without saying what I do:
- No advertising trackers on pages about health conditions. No Meta or Snap pixels collecting what you read here.
- No condition-segmented advertising lists. I don’t build ad audiences from what patients are treated for.
- You know your clinician. It’s me — Dr. Brandon Bright, DAOM, LAc, in Tustin. Same person every visit, in person or virtually.
- Charges follow the appointment, not an intake form.
- Transparent pricing before you book.
That’s not a marketing claim so much as a description of a small practice. It’s easier to be careful with patient data when you’re not running a growth funnel.
Frequently asked questions
Is telehealth data protected by HIPAA?
Sometimes. HIPAA covers licensed providers and their business associates. Many wellness apps, symptom quizzes, and pre-patient marketing funnels fall outside it. Whether you’re protected depends on the relationship, not the technology.
Can health apps share my information with advertisers?
If they’re not HIPAA-covered entities and their privacy policy permits it, often yes. The FTC has brought multiple enforcement actions over exactly this — GoodRx, BetterHelp, Premom, and the July 2026 Hims case.
What did the FTC accuse Hims & Hers of?
Sending sensitive health information to Meta and Snap via trackers and condition-segmented customer lists while advertising itself as private, and charging customers before clinician review with a cancellation path harder than signup. The company disputes the claims; the case is unresolved.
How do I know if a health website is tracking me?
Browser privacy extensions will show which trackers load on a page. You can also read the privacy policy for named advertising partners. Neither is perfect, but both are more than most people do.
Should I stop using telehealth?
No. Ask better questions of the platforms you use — particularly whether you can identify your clinician and when you get charged.
The takeaway
The convenience of direct-to-consumer health platforms is real, and so is the tradeoff. You’re often entering sensitive information into a system designed primarily to convert you, under privacy rules narrower than you’d assume.
That doesn’t mean avoid virtual care. It means know whether you’re a patient or a lead — and if you’d rather your health information stay between you and a clinician you can name, that’s what a real practice is for.
Author: Dr. Brandon Bright, DAOM, LAc — Tustin, Orange County. Educational content; not legal or medical advice. Descriptions of the FTC action are based on public filings and reporting as of August 2026. The case is unresolved and no findings of liability have been made.
Related reading
- If Your Telehealth Company Fails, What Happens to You?
- Virtual Functional Medicine: How Telehealth Actually Works With a DAOM
- FDA 503B GLP-1 Peptides for Weight Loss & Metabolic Health: Patient Guide
- Why You Should Get Regular Acupuncture Treatments
- Who Should NOT Take Nattokinase? 7 Risks — DAOM Safety Guide 2026