LF logo
by learnformula
search
Log in
search
The Telehealth Trap: Decoding the FTC and State AGs' Coordinated Data Privacy Strike on Hims & Hers

The Telehealth Trap: Decoding the FTC and State AGs' Coordinated Data Privacy Strike on Hims & Hers

Julia Reynolds•Aug 3, 2026•
10 min read
Share
linkLinkedin iconX iconFacebook icon
TABLE OF CONTENTS
SIGN UP AND GET
10% OFF
Gift box
Sign up for our newsletter and get 10% off your next purchase!
By subscribing, I agree to LearnFormula's email marketing. I can unsubscribe anytime. See Privacy Policy.

Telehealth was supposed to democratize medicine. Instead, for a growing number of digital health platforms, it has inadvertently become a high-stakes liability trap. As highlighted in a recent Morning Docket roundup, the Federal Trade Commission (FTC), joined by a coalition of state Attorneys General, has filed a sweeping lawsuit against direct-to-consumer telehealth giant Hims & Hers. The allegation? The unauthorized sharing of sensitive consumer health information with third-party advertisers.

For corporate counsel, data privacy attorneys, and compliance officers advising the booming digital health sector, this lawsuit is not merely another headline. It represents a maturation of the FTC’s multi-year crusade against "commercial surveillance" and signals a highly coordinated, multi-jurisdictional approach to enforcing data privacy in spaces where traditional HIPAA regulations fall short. The era of "move fast and break things" in health tech is officially over, replaced by an era of aggressive regulatory scrutiny and massive financial exposure.

Key Takeaway: The FTC and state AGs are no longer treating unauthorized health data sharing via tracking pixels as a mere technical oversight. It is being prosecuted as a deceptive practice and a fundamental breach of consumer trust, requiring law firms to urgently audit their clients' marketing tech stacks.

The Anatomy of the Enforcement Action

To understand the gravity of the Hims & Hers lawsuit, legal professionals must look past the brand name and focus on the mechanics of the alleged violation. Like many direct-to-consumer (DTC) brands, telehealth companies rely heavily on performance marketing to acquire customers. This typically involves deploying tracking pixels, software development kits (SDKs), and Application Programming Interfaces (APIs) from tech giants like Meta, Google, and TikTok.

The core legal friction arises when these standard marketing tools are deployed on platforms handling sensitive information. According to regulators, when a user inputs symptoms, medication history, or treatment preferences into a telehealth intake form, and that data is quietly siphoned off to social media platforms to optimize ad targeting, it constitutes a severe privacy violation.

The Regulatory Playbook: Beyond HIPAA

A common misconception among early-stage health tech founders is that if they are not a "covered entity" under the Health Insurance Portability and Accountability Act (HIPAA), their data practices are largely unregulated. The FTC has systematically dismantled this defense using two primary weapons:

  • Section 5 of the FTC Act: Deceptive trade practices. If a privacy policy promises confidentiality but the website's backend code shares data with Meta, the FTC views this as a deceptive practice.
  • The Health Breach Notification Rule (HBNR): Historically applied to personal health records, the FTC recently finalized updates to the HBNR that explicitly sweep in health apps and telehealth providers. Crucially, the FTC now defines a "breach of security" to include not just malicious cyberattacks, but the unauthorized sharing of covered health data.
"We are witnessing a regulatory paradigm shift where marketing infrastructure is now being treated as a primary vector for data breaches. For digital health clients, the Chief Marketing Officer's tech stack is now the General Counsel's greatest liability."

The Multiplier Effect: State AG Collaboration

What makes the Hims & Hers enforcement particularly notable is the joint deployment of FTC resources alongside state Attorneys General. This coordinated strike serves multiple strategic purposes for regulators:

  1. Jurisdictional Coverage: State AGs can leverage state-specific consumer protection statutes (often referred to as "Little FTC Acts"), which sometimes offer broader definitions of deceptive practices or mandate higher statutory penalties.
  2. Resource Pooling: Complex data privacy investigations require significant forensic resources to map data flows and audit code. By teaming up, federal and state agencies can pursue larger targets more aggressively.
  3. State Privacy Laws: With comprehensive state privacy laws now active in California, Virginia, Colorado, Connecticut, and beyond, state AGs have robust, modernized frameworks to penalize the unauthorized sale or sharing of sensitive personal information.

The Precedent: A Pattern of Escalation

The action against Hims & Hers does not exist in a vacuum. It is the logical continuation of a regulatory roadmap the FTC has been publicly telegraphing since 2023. Legal practitioners must contextualize this latest suit within the broader enforcement landscape to accurately advise clients on risk exposure.

Target Company Year Core Allegations Regulatory Action / Penalty
GoodRx 2023 Shared users' prescription data and health conditions with Meta and Google for targeted advertising. $1.5M fine; first-ever FTC enforcement of the HBNR; permanent ban on sharing health data for ads.
BetterHelp 2023 Shared users' mental health data with third parties despite promises of strict privacy. $7.8M proposed order to refund consumers; outright ban on sharing health data for advertising.
Monument 2024 Alcohol addiction treatment platform shared user data via tracking pixels. $2.5M civil penalty; ban on disclosing health information to third-party advertisers.
Hims & Hers 2026 Unauthorized sharing of sensitive health intake data with third-party advertisers via web trackers. Pending. Coordinated FTC & State AG action seeking injunctive relief and massive civil penalties.

The Follow-On Threat: The Class Action Cascade

For defense counsel, the FTC and state AG lawsuit is often just the opening salvo. Regulatory enforcement actions provide a highly publicized roadmap for the plaintiffs' bar. When the government publishes a detailed complaint outlining exactly how a company's tracking pixels captured and transmitted data, consumer class action attorneys immediately file parallel suits.

These follow-on class actions are increasingly leveraging antiquated statutes in novel ways. For instance, plaintiffs are aggressively utilizing state wiretap laws—such as the California Invasion of Privacy Act (CIPA) and the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)—arguing that third-party tracking pixels act as illegal "wiretaps" intercepting communications between the patient and the telehealth provider. Because these statutes often carry significant statutory damages per violation, the financial exposure in these class actions can quickly dwarf the regulatory fines.

Strategic Imperatives for Legal Professionals

The Hims & Hers lawsuit serves as a definitive warning shot. Law firms representing clients in the digital health, femtech, mental health app, and telehealth spaces must proactively pivot their advisory strategies. The following steps are no longer optional best practices; they are foundational requirements for survival in the 2026 regulatory environment:

  • Conduct Deep-Dive Tech Audits: Lawyers cannot rely solely on client assurances that "we don't sell data." Counsel must engage third-party forensic technologists to audit the client's web and app architecture, identifying every tracking pixel, SDK, and API that transmits data externally.
  • Bridge the Legal-Marketing Divide: General Counsel must establish strict governance over the marketing department. No new analytics tools or advertising trackers should be deployed on consumer-facing platforms without explicit legal review and approval.
  • Revamp Consent Architecture: Ensure that privacy policies are not just legally accurate, but that the user interface genuinely obtains informed, affirmative consent before any sensitive data is collected, let alone shared. Pre-checked boxes and buried disclosures are enforcement triggers.
  • Reassess Data Minimization: Challenge clients on why they are collecting certain data points. If a piece of health information is not strictly necessary for providing the requested service, collecting it merely expands the company's attack surface.

Looking Ahead: The New Standard of Care

The coordinated FTC and state AG lawsuit against Hims & Hers marks a definitive turning point in US data privacy law. Regulators have successfully shifted the narrative: the unauthorized sharing of health data via advertising pixels is no longer viewed as an accidental byproduct of modern web design, but as a deliberate and deceptive monetization of consumer vulnerability.

For legal professionals, the mandate is clear. The defense of digital health clients requires a multidisciplinary approach that blends regulatory foresight, technical literacy, and aggressive class-action defense strategies. As the line between consumer technology and healthcare continues to blur, the firms that can effectively navigate this complex intersection will not only protect their clients from ruinous liability but will define the new standard of care in digital privacy law.