The FTC Just Sued Hims & Hers. Read Paragraph 70 Before Your Next Campaign Launch.
On Wednesday the Federal Trade Commission, the People of the State of California, and the Utah Division of Consumer Protection filed suit against Hims & Hers Health, Inc. in the Northern District of California. The case number is 3:26-cv-7871. The complaint runs to counts under the FTC Act, the Restore Online Shoppers' Confidence Act, California's Unfair Competition and False Advertising Laws, and the Utah Consumer Sales Practices Act.
You will read a lot of coverage this week framing it as another healthcare pixel story. It is not. Three things in this complaint are genuinely new, and one of them should change what your team does before the next campaign goes live.
For context on where we sit: Curve is a HIPAA-compliant conversion tracking platform that lets healthcare advertisers measure and optimize paid campaigns without sending protected health information to ad platforms. We have spent three years arguing that the industry's default answer to this problem does not hold up. This complaint is the clearest evidence yet that we were right, and we would genuinely rather have been wrong.
What the Government Alleges
The core theory is simple and, for anyone who has run a healthcare acquisition funnel, uncomfortably familiar. Hims told consumers its platform was, in the complaint's quotation, "100% online, private, and secure." It advertised that it treats medical conditions "privately." It described itself as "discreet" and "totally private," including in television, radio, and podcast advertising.
The FTC alleges that while making those promises, Hims shared consumers' health information with advertising platforms. The complaint calls these "Events," and defines them plainly as "the actions of website visitors on Hims' website." Not medical records. Not chart notes. The actions people took on the site.
That definition is the whole ballgame. If you have been telling yourself that your conversion events are not really health information because they are just page views and button clicks, the FTC has now written down, in a federal complaint, that it disagrees. On a site where the page is about a specific condition and the button means someone started treatment for it, the event is the disclosure.
Hims has denied the allegations and said its privacy policy makes clear that users may choose how their data is used. The company says it is confident in its position and intends to defend the case. Nothing here has been proven. But the theory of the case is now public, and the theory is what you have to plan around.
New Thing One: The FTC Named the Conversions API
This is paragraph 70, and it is the sentence healthcare marketing teams need to read.
The complaint names two Meta tools as the automated tracking technologies that allegedly disclosed health information: the Meta Pixel and the Conversions API. It goes on to describe the Conversions API as operating differently to the extent that it "creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems."
The FTC understood exactly what server-side tracking is, described it accurately, and named it as a violation vector anyway.
For three years, a large part of the healthcare marketing industry has treated server-side tracking as the compliance answer. Move the pixel off the browser, route events through your own server, and the problem is solved. It was always a weak argument. A regulator does not care which machine sent the data. It cares what data arrived and whether the person it described agreed to that.
Now the argument is not just weak. It has been pled against, by name, by the agency that brings these cases. And it is not only Meta. The complaint's list of other trackers specifically includes the "Google Ads S2S Pixel" and the "TikTok s2s Pixel." Server-to-server integrations appear in the same list as browser pixels, with no suggestion that the transport method changes anything.
If your compliance posture rests on the sentence "we moved to server-side," that posture is now materially weaker than it was last Tuesday.
New Thing Two: Fifteen Platforms, Not One
Most pixel coverage is a Meta story. This complaint is not.
Beyond Meta and Snap, the FTC alleges Hims placed pixels from at least the following platforms on its properties: Microsoft, listing both the Bing Pixel and the Bing Image Pixel; Google, listing both the Google Ads Pixel and the Google Ads S2S Pixel; Criteo; MediaBids.com; PartnerCentric; PebblePost; Pinterest; Podsights, now known as Spotify Ad Analytics; Reddit; StackAdapt; TikTok; The Trade Desk; and X, formerly Twitter.
Read that list again as an auditor rather than a marketer. How many of those would survive a review at your organization? Most healthcare marketing teams have a rigorous process for Meta, a decent one for Google, and effectively nothing for the affiliate tracker a growth contractor added in 2023, the direct mail retargeting pilot that never got switched off, or the podcast attribution tag someone pasted in to prove a sponsorship worked.
PebblePost is worth pausing on. It converts website behavior into physical mail. Someone browses a condition page and a postcard arrives at their home. That is a category of exposure most compliance reviews have never once considered, and it is in a federal complaint.
The list is not a scandal. It is a checklist. Print it and walk your own tag manager against it.
New Thing Three: This One Is Being Litigated, With States Attached
GoodRx settled in February 2023 for 1.5 million dollars. BetterHelp settled the following month, ultimately paying 7.8 million. Both were negotiated resolutions announced alongside the complaint.
This is a filed case seeking a permanent injunction, monetary judgment, and a civil penalty judgment. California and Utah are co-plaintiffs bringing their own state consumer protection claims, which carry their own penalties on their own track. California is appearing through Los Angeles County Counsel.
There is also a detail in paragraph 78 that matters more than its placement suggests. The FTC notes that Hims acknowledged privacy and consumer protection regulatory risk in SEC filings as far back as 2021, and that the agency issued the company a Civil Investigative Demand in October 2023. The government is building a record that the company was on notice. Knowledge is what turns a compliance gap into a penalty multiplier.
The Part Nobody Is Talking About
The privacy claims are only half the complaint. The other half is about billing: charging consumers for prescription subscriptions before they had meaningfully consented, unclear refill dates, and cancellation mechanisms the FTC alleges were deliberately difficult.
Those two halves are in one document for a reason. The FTC is describing a single growth machine. Aggressive acquisition tracking and aggressive subscription mechanics came from the same strategy, and the agency is treating them as one pattern of conduct rather than two unrelated problems.
If you run a subscription health brand, your growth tactics and your privacy posture now share a legal surface. A regulator looking at one will look at the other.
What To Actually Do This Week
Not next quarter. This week.
Inventory every tag, not just the ones you manage. Pull your tag manager, your source, and your CDP destinations. Use the fifteen-platform list above as the starting checklist. You are looking for anything nobody can name an owner for.
Stop treating server-side as the answer. Audit what your server actually sends. If your server-side setup forwards the same event, with the same identifiers, describing the same condition, you have changed the plumbing and not the disclosure. That is now the FTC's stated position.
Audit your list uploads separately. The complaint alleges Hims uploaded customer lists to Meta and to Snap for account matching. List uploads bypass every consent banner and cookie control you have. They are usually run by a different person, on a different schedule, with no review. Find yours.
Read your own marketing copy as a regulator would. The FTC built its deception count out of Hims' own words. Search your site, your ads, and your podcast scripts for "private," "secure," "confidential," and "discreet." Every one of those words is a promise you are now being measured against. Either make the promise true or stop making it.
Check what your intake form fires. The intake form is where a visitor becomes a patient. Every tracker live on that page inherits the sensitivity of what was just submitted.
The Honest Version
You do not have to choose between running paid acquisition and keeping health information out of ad platforms. That framing has always been a false one, usually offered by people selling you the idea that compliance means turning off measurement.
What you do have to do is make sure the data leaving your systems cannot describe a person and their condition at the same time. Conversions can be measured, campaigns can be optimized, and budgets can be defended without any of that being true. The architecture to do it properly exists, and it is not exotic.
The companies that get hurt over the next eighteen months will not be the ones that measured too much. They will be the ones that never checked what was leaving the building.
Curve was built for exactly this problem. If you want a second set of eyes on what your site is currently sending, and to which of those fifteen platforms, start here.
Sources
The complaint is public. Federal Trade Commission et al. v. Hims & Hers Health, Inc., No. 3:26-cv-7871 (N.D. Cal.). Paragraphs 66 through 78 cover the tracking allegations. It is worth twenty minutes of your time.
Keep exploring
Related articles
The X (Twitter) Pixel and Health Information: Named in the FTC's Hims and Hers Complaint
Read articleThe Meta Pixel and Conversions API in the FTC's Hims and Hers Case: What Healthcare Advertisers Should Learn
Read articleGoodRx to BetterHelp to Hims and Hers: The FTC's Health Privacy Enforcement Trajectory
Read articleWant to stay up to date on the latest in healthcare marketing?
Sign up for our newsletter to receive our articles directly in your inbox—covering compliance updates, platform changes, and industry insights.
We respect your privacy. Unsubscribe at any time.