Hims & Hers Promised Privacy — Then Shared Your Health Data With Meta and Snap
Key Takeaways
- The FTC, joined by Utah and California, has sued telehealth provider Hims & Hers for sharing consumers' sensitive health information with Meta, Snap, and other third-party advertising platforms, despite publicly promising patient privacy.
- The complaint also alleges that Hims charged consumers almost immediately after they submitted an intake form — before any medical consultation — and made subscriptions deliberately difficult to cancel.
- Health data shared with advertisers included information about medical conditions, shared via customer lists and third-party tracking technologies embedded on the Hims website.
- The case is a direct example of why "we protect your privacy" in a terms of service document means very little without enforcement — and why sensitive health data in particular deserves stronger structural protection than self-regulatory promises.
The Federal Trade Commission, joined by the states of Utah and California, has filed suit against telehealth provider Hims & Hers, alleging the company shared consumers' sensitive health information with Meta, Snap, and other advertising platforms while publicly claiming to protect patient privacy, according to the FTC's press release published July 29th, 2026. The complaint was filed in the US District Court for the Northern District of California.
Hims & Hers is a San Francisco-based telehealth company offering direct-to-consumer prescription medications and online consultations for various health conditions. To use the service, consumers fill out an intake form that includes personal health information about their medical conditions and treatment needs.
The FTC alleges that Hims shared this information with advertising platforms in two ways: by providing those companies with lists of certain customers, and via third-party tracking technologies embedded on its website that automatically transmitted user actions — including the health-related steps users took on the platform — to Meta, Snap, and others.
"Consumers' most private health information" is how the FTC's Bureau of Consumer Protection director described what was shared. That framing is deliberate. Health data sits at the top of the sensitivity hierarchy for a reason: it can affect insurance, employment, relationships, and personal safety in ways that browsing history or purchase data typically don't.
When someone shares that they're seeking treatment for a specific medical condition with a telehealth provider, they're not consenting to have that information flow to the advertising infrastructure of the world's largest social media companies.
The deceptive billing complaint is separate — and also serious
The health data sharing is the most alarming part of the complaint, but the FTC's billing allegations deserve attention too, because they illustrate how companies design systems to extract value from consumers who didn't fully understand what they were agreeing to.
The FTC alleges that Hims told consumers they could consult with a medical provider before being charged for any treatment. In practice, the complaint says, most consumers were charged and enrolled in a recurring subscription almost immediately after submitting their intake form — without a consultation, and without a chance to review or approve the treatment. One consumer quoted in the complaint described being told no charge would occur before speaking with a doctor, then being charged immediately.
Cancellation was designed to be difficult. Before 2023, Hims only allowed cancellation via phone, email, or chat — with additional hurdles built in. Even after introducing online cancellation, the company allegedly hid the cancellation button behind multiple navigation steps, visible only after selecting "add/remove items from order" and working through several screens. That's not accidental UI design. That's a deliberate friction pattern built to reduce cancellation rates.
Why this keeps happening — and what it actually takes to stop it
The Hims & Hers case fits a pattern we've seen across the data broker industry, health apps, and now telehealth providers: a company builds a consumer-facing privacy promise into its marketing, collects sensitive data on the basis of that promise, and then routes that data to advertising infrastructure through mechanisms that most users don't know exist and can't meaningfully audit.
California's DROP tool — which we covered recently — exists precisely because the opt-out infrastructure for data broker relationships is so inaccessible that most people never use it.
The FTC's case against Hims is a reminder that even the nominal privacy promises companies make don't hold without enforcement. "We protect your privacy" in a terms of service document has never been a reliable guarantee. What provides actual protection is a regulator willing to file complaints, courts willing to enforce them, and structural rules that make it harder to share sensitive data without genuine consent in the first place.
The FTC filing this complaint is the system working as intended. The fact that it needed to file it — against a telehealth company whose entire value proposition depends on consumers trusting it with their most sensitive information — is a reminder of how far the default sits from where it should be. Your health data shouldn't be a currency that funds someone else's ad targeting. That should be the baseline, not the outcome of a successful federal lawsuit.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
