Fifteen Ad Platforms Named in the FTC's Hims and Hers Complaint: The Full List and What It Means
The FTC's complaint against Hims & Hers Health, Inc., filed in late July 2026 in the Northern District of California as case number 3:26-cv-7871, names fifteen advertising companies across three paragraphs. Paragraph 70 names Meta, identifying both the Meta Pixel and the Conversions API. Paragraph 76 names Snap in connection with customer list uploads. Paragraph 77 lists the rest: Microsoft, Google, Criteo, MediaBids.com, PartnerCentric, PebblePost.com, Pinterest, Podsights, Reddit, StackAdapt, TikTok, The Trade Desk and X. This page is the complete list, grouped so you can use it as an audit checklist rather than as a news item.
Curve is a HIPAA-compliant conversion tracking platform that routes healthcare advertising conversions through one sanitized server-side path, so campaigns on any of these fifteen platforms can be measured and optimized without protected health information reaching the ad network. If you take one operational lesson from the complaint, it is that a fifteen-destination stack is not fifteen problems. It is one problem, which is that fifteen different systems each hold an independent decision about what leaves your website.
None of this is proven. The case is being litigated rather than settled, the FTC is seeking civil penalties alongside a permanent injunction, and Hims has denied the allegations, stating that its privacy policy makes clear that users may choose how their data is used and that it intends to defend the case. None of the fifteen platforms is a defendant, and none is accused of wrongdoing. They appear as alleged recipients.
The Short Version
- Fifteen advertising companies are named across paragraphs 70, 76 and 77 of the complaint, spanning social, search, programmatic, retargeting, affiliate, print, audio and direct mail.
- Paragraph 67 defines the shared data as Events, meaning the actions of website visitors on Hims' website. That definition is deliberately broad and it is what makes the list this long.
- Two entries are explicitly server-side: Google Ads S2S and TikTok s2s. Paragraph 70 separately describes Meta's Conversions API accurately and pleads it as a violation vector anyway.
- The list includes categories most healthcare compliance reviews never touch: affiliate management, print response, podcast attribution and programmatic direct mail.
- Use this as a checklist. The audit question is not which platforms you buy media on, it is which platforms receive requests from your condition and intake pages.
- Hims denies the allegations and intends to defend the case. No court has made any finding.
The Complete List, Grouped by Category
The complaint lists these as a flat roster. Grouping them shows the shape of the exposure, because each category fails a compliance review for a different reason.
Social platforms (six)
- Meta, named in paragraph 70 with both the Meta Pixel and the Conversions API. The most consequential entry in the filing, because the FTC described the server-side path correctly and pled it anyway. Covered in detail in the Meta Pixel and Conversions API in the Hims complaint.
- Snap, named in paragraph 76 for customer list uploads used to match users to Snapchat accounts. A different vector from a pixel, and one that hashing does not neutralize. See Snap pixel and customer list uploads.
- Pinterest, a platform healthcare marketers often treat as low risk because of its discovery and wellness framing. The tag behaves like any other. See the Pinterest tag and health data.
- Reddit, where healthcare advertising frequently targets condition-specific communities, which makes the targeting itself part of the record. See the Reddit pixel in healthcare marketing.
- TikTok, listed specifically as s2s, the server-to-server Events API rather than the browser pixel. See TikTok s2s and healthcare data.
- X, formerly Twitter, and in most healthcare stacks a legacy tag left behind by a paused campaign. See the X pixel and orphaned trackers.
Search platforms (two, four distinct pixels)
- Google, listed as two separate entries: the Google Ads Pixel and the Google Ads S2S Pixel. The complaint distinguishes them, which matters. See the Google Ads pixel and S2S entries.
- Microsoft, also listed twice: the Bing Pixel and the Bing Image Pixel. The second is the one nobody expects to find. See the Bing pixel and Bing Image pixel.
Programmatic and demand-side platforms (two)
- The Trade Desk, an independent demand-side platform whose universal pixel is typically installed by an agency and whose data flows into identity resolution across the open web. See The Trade Desk pixel and healthcare data.
- StackAdapt, a programmatic platform widely used in mid-market healthcare for native, display and connected TV. See StackAdapt in healthcare advertising.
Retargeting (one)
- Criteo, a retargeting network whose entire product depends on product-level browsing signals. In healthcare, product-level means condition-level. See whether the Criteo pixel is HIPAA safe.
Affiliate and print response (two)
- PartnerCentric, an affiliate program management agency.
- MediaBids.com, a print and direct-response advertising marketplace whose measurement runs through vanity URLs, coupon codes and tracking numbers that eventually need an online conversion. Both are covered in the affiliate and print trackers in the complaint.
Audio and podcast attribution (one)
- Podsights, now Spotify Ad Analytics, listed in the complaint as Podsights_iHeartMedia. Podcast attribution works by matching website visitors against podcast listening, which is a cross-medium identity join. See podcast attribution and healthcare privacy.
Programmatic direct mail (one)
- PebblePost.com, which converts online browsing behavior into physical mail sent to a home address. The most direct online-to-offline identity resolution on the list. See programmatic direct mail and healthcare privacy.
How Curve Handles a Multi-Platform Healthcare Stack
Curve replaces the direct browser-to-platform connection with a single first-party collection endpoint. Every event is captured once, sanitized on Curve's server before any outbound request is built, and then forwarded to each destination through that platform's own server-side API. Protected health information never reaches the ad platform, because the redaction happens before egress rather than inside a tag that any marketer can reconfigure. Destinations are enabled explicitly per platform, so a network receives exactly the fields you approved and nothing that happened to be present on the page, and adding a sixteenth platform means adding a destination rather than adding a new uncontrolled data flow. A BAA is available covering the collection and processing Curve performs. The structural point is that fifteen destinations become one decision, made once, enforced by infrastructure.
What the Grouping Reveals
The server-side entries are the story
Three of the fifteen are explicitly server-side or include a server-side vector: Google Ads S2S, TikTok s2s, and Meta's Conversions API as described in paragraph 70. That paragraph is worth quoting closely, because it describes the Conversions API as operating differently "to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems." The FTC understood the architecture and treated it as a sharing vector regardless.
That closes a defense many healthcare marketing teams have relied on since 2023. Moving a pixel to a server changes where the request originates, not what is in the payload. If the event still contains a click identifier, a hashed email and a URL naming a condition, going server-side improved match rates and changed nothing about the disclosure. The argument is developed in why server-side tracking alone is not HIPAA compliance and, for Meta specifically, in whether the Meta Pixel or Conversions API is HIPAA safe.
Four categories that no marketing compliance review covers
Affiliate, print response, podcast attribution and programmatic direct mail account for four of the fifteen. These are almost never in scope for a healthcare pixel review, for a consistent reason: none is owned by the paid media team. Affiliate and print sit with partnerships. Podcast attribution sits with brand. Direct mail sits with lifecycle or retention. Each has its own budget line, its own contracts, and its own tag installed by someone outside marketing operations.
A compliance process scoped to the ad accounts you log into finds zero of them. One scoped to observed network requests from your condition pages finds all of them.
Identity resolution is the through-line
Look at what the unusual entries have in common. Snap matched uploaded customer lists to Snapchat accounts. PebblePost turns browsing into a mailed piece at a home address. Podsights matches web visitors to podcast listening. The Trade Desk performs identity resolution across the open web. These are not measurement tools in the analytics sense. They are identity systems, and their value is the join between an anonymous website action and a known person.
That is exactly what paragraph 74 targets. The complaint alleges Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private." The specificity is the harm. Precision targeting on a health product requires health signal, and the FTC is pointing at the mechanism rather than at any single vendor.
Duplicate pixels from the same vendor
Google appears twice. Microsoft appears twice. Meta appears with two vectors. Internalize that during an audit: one vendor relationship frequently means several distinct data flows, added at different times by different people. Finding the Bing pixel does not mean you found the Bing Image pixel, and finding the Google Ads tag does not mean you found the server-side conversion upload running from your backend.
The Audit Checklist
Use the fifteen names as a starting inventory, not as the final list. Your stack will differ. The method is what transfers.
- Pick the right pages. Condition and treatment pages, symptom quizzes, intake forms, eligibility checkers, scheduling flows, order confirmation and patient portal login. Not the homepage. Risk concentrates where clinical context lives.
- Record actual traffic. Load each page in a clean browser profile with the network panel recording, and capture requests that fire on load, on interaction, on scroll and on form submission.
- List every third-party host. The domain identifies the vendor. Compare the resulting list against your list of active advertising relationships. The gap is your orphaned trackers.
- Read the payloads, not just the domains. Query strings, POST bodies and image pixel parameters. You are looking for URLs containing condition terms, hashed emails, click identifiers, product or SKU fields, and custom parameters someone added for optimization.
- Find the server-side flows. These never appear in the browser. Review backend integration code, tag management server containers, CRM and marketing automation connectors, and any offline conversion upload jobs.
- Check embedded tools separately. Chat widgets, scheduling iframes, landing page builders, review platforms and patient portals frequently load their own tag containers that your main audit will miss.
- Check page templates directly. Hardcoded script tags in themes and templates do not appear in any tag manager export.
- Ask the other teams. Partnerships, business development, brand and lifecycle each hold vendor relationships that marketing operations does not know about. This conversation reliably surfaces two or three names.
- Reconcile against contracts. For each recipient, identify the executed agreement and whether any health-specific data terms exist. Ad platform terms of service typically prohibit sending health information rather than accepting responsibility for it.
- Score and prioritize. A tracker on a careers page is not the tracker on an intake form. The 14-point pixel audit scorecard ranks findings, and the full audit methodology covers request-level analysis in depth.
- Decide the destination architecture before removing anything. Ripping out tags without a replacement means losing conversion measurement, which means the tags come back. Design the sanitized path first, following HIPAA-compliant conversion tracking setup.
Why This Case Is an Escalation, Not a Repetition
GoodRx settled with the FTC in February 2023 for $1.5 million. BetterHelp settled in March 2023 at ultimately $7.8 million. Both were administrative resolutions with a single federal plaintiff. Hims & Hers in July 2026 differs on four dimensions: it is being litigated in federal district court, civil penalties are sought alongside a permanent injunction and monetary judgment, two states joined as co-plaintiffs, and the counts span the FTC Act Section 5(a), ROSCA Section 4, California's Unfair Competition Law and False Advertising Law, and the Utah Consumer Sales Practices Act.
Paragraph 78 addresses knowledge directly, noting SEC filings since 2021 acknowledging privacy and consumer-protection regulatory risk and a Civil Investigative Demand issued in October 2023. The complaint also folds in a billing theory, alleging charges for prescription subscriptions before meaningful consent, unclear refill dates and cancellation mechanisms alleged to be difficult. The FTC is treating privacy and billing as one pattern of conduct, which is a meaningful framing choice.
Paragraph 66 anchors the whole thing in marketing copy: "100% online, private, and secure," treating conditions "privately," "totally private," "discreet," with the complaint noting the promises ran in television, radio and podcast advertising as well as online. The gap between what the site promised and what the site transmitted is the theory of the case. For where this sits in the broader enforcement pattern, see our healthcare pixel lawsuit and settlement tracker, the mid-2026 settlement roundup, and prior telehealth matters including the Cerebral settlement and the BetterHelp settlement. Hims denies the allegations, says its privacy policy makes clear that users may choose how their data is used, and intends to defend the case.
Frequently Asked Questions
What are all fifteen platforms named in the FTC complaint against Hims and Hers?
Across paragraphs 70, 76 and 77: Meta (Pixel and Conversions API), Snap, Microsoft (Bing Pixel and Bing Image Pixel), Google (Google Ads Pixel and Google Ads S2S Pixel), Criteo, MediaBids.com, PartnerCentric, PebblePost.com, Pinterest, Podsights (now Spotify Ad Analytics, listed as Podsights_iHeartMedia), Reddit, StackAdapt, TikTok (s2s), The Trade Desk and X (formerly Twitter). Paragraph 77 introduces its list as the other pixels beyond Meta and Snap.
Are these platforms being sued?
No. Hims & Hers Health, Inc. is the sole defendant. The platforms are named as alleged recipients of visitor Events, not as parties, and none is accused of wrongdoing in the complaint.
Does using a server-side integration protect a healthcare advertiser?
Not on its own. Paragraph 70 describes Meta's server-side Conversions API accurately and pleads it as a sharing vector anyway, and paragraph 77 lists Google Ads S2S and TikTok s2s separately. Server-side changes where the request originates, not what is in it. Protection comes from sanitizing the event before egress so that no protected health information is in the payload regardless of transport.
Which of these platforms is riskiest for a healthcare advertiser?
The framing is wrong in a useful way. Risk does not attach to the platform, it attaches to the page the tag sits on and the fields in the payload. A tag on a corporate blog is close to harmless. The same tag on a GLP-1 eligibility quiz is a different matter. Rank your pages first, then look at which vendors receive requests from the top of that list.
How do I know if my own site has trackers I do not know about?
Audit observed network traffic on your clinical pages rather than auditing your list of ad accounts. The two lists differ, usually substantially. Then separately review backend code and tag management server configuration for server-side flows, which never appear in a browser at all.
Can healthcare companies advertise on these platforms at all?
Yes. Nothing in the complaint suggests healthcare advertising is unlawful. The allegation concerns what was transmitted about specific visitors and specific conditions, against published privacy promises. Advertisers who send campaign-level conversion signal without protected health information can run on all fifteen. That is a design problem, and it is solvable.
Does an ad platform's terms of service cover us?
Generally the opposite. Most major ad platform terms prohibit advertisers from sending sensitive or health information, which places the obligation on you and gives the platform a defense. A BAA is a different instrument, and the major ad networks do not offer one for their advertising products. See why a BAA alone is not enough under the Security Rule.
This article reflects the public record as of July 2026, based on the redacted complaint e-filed on ftc.gov. Everything described here is an allegation. Hims & Hers has denied the allegations, states that its privacy policy makes clear that users may choose how their data is used, and intends to defend the case. No court has made any finding on any count.
If your audit turns up more destinations than you expected, the answer is not fifteen separate remediation projects. Curve gives healthcare advertisers one collection endpoint, server-side sanitization before egress, explicitly configured destinations per platform, and a BAA covering its own processing, so conversion measurement keeps working across your whole stack without protected health information leaving your infrastructure. See how it works at curvecompliance.com.
Keep exploring
Related articles
The Meta Pixel and Conversions API in the FTC's Hims and Hers Case: What Healthcare Advertisers Should Learn
Read articleThe X (Twitter) Pixel and Health Information: Named in the FTC's Hims and Hers Complaint
Read articleThe Reddit Pixel in Healthcare Marketing: What the FTC's Hims and Hers Complaint Shows
Read articleStay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.