When Audience Precision Becomes Evidence: The FTC's Argument in the Hims and Hers Case
The most consequential sentence in the FTC's new complaint against Hims & Hers Health, Inc. is not about a pixel. It is paragraph 74, where the agency alleges that Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private." That is an inversion of the usual argument. Instead of starting with a network request and working forward to harm, the FTC starts with the finished audience and works backward to the promise it allegedly required breaking.
The practical lesson for healthcare advertisers is that your ad account is a written record of what you knew about your patients and when. Curve is a HIPAA-compliant conversion tracking platform that lets healthcare advertisers measure and optimize paid campaigns without sending protected health information to ad platforms, which means the audiences and conversion actions sitting inside your ad account do not double as a condition-by-condition roster of your patients.
Nothing here is proven. The case, captioned Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., Case No. 3:26-cv-7871, was filed in the U.S. District Court for the Northern District of California and is being litigated. Hims has denied the allegations, says its privacy policy makes clear that users may choose how their data is used, and intends to defend the case.
The Short Version
- Complaint paragraph 74 alleges that the specificity of Hims' advertising audiences is itself evidence that privacy promises were broken, because audiences that precise could not exist without the underlying health data.
- This reframes discovery. A regulator does not need a packet capture if the audience definition, its name, and its membership rules describe the health status of the people in it.
- Audience artifacts live inside platform account tools, they persist for years, they carry creation timestamps and the user who created them, and they are ordinary discoverable business records.
- Exclusion audiences and naming conventions are the two most commonly overlooked artifacts. Excluding "current patients" still tells the platform who the patients are.
- A pixel audit that stops at the website is half an audit. The other half is a read-only walk through every ad account your practice or agency touches.
- The fix is architectural: keep condition-level detail on your side of the wire and let the ad platform optimize on signals that do not describe a diagnosis.
What Paragraph 74 Actually Argues
Most pixel litigation over the last three years has been a plumbing argument. Plaintiffs allege that a tracker fired on a page whose URL disclosed a condition, that an event payload carried an identifier, and that the identifier let a platform connect a real person to a health interest. That argument is technical, it is contestable, and defendants have spent a great deal of money contesting it. It also depends on evidence that decays. Tag configurations change, containers get republished, and the network traffic from two years ago is gone.
Paragraph 74 does not depend on any of that. It points at an output. According to the complaint, Hims built advertising audiences with a level of specificity that, in the FTC's telling, could only have been produced from information users were told would stay private. The audience is the artifact. It sits in an account, it has a definition, and the definition is written in plain language by the advertiser.
Read the sentence closely and you can see the two-step structure of the claim. Step one is the promise, pled at paragraph 66, where the complaint quotes Hims' own published marketing: "100% online, private, and secure," treatment handled "privately," experiences described as "totally private" and "discreet." Step two is the capability. If a company can assemble a segment of people defined by a specific treatment interest, then, the FTC alleges, the promise and the capability cannot both be true. The precision is not a side detail in the pleading. It is the bridge between the marketing count and the privacy count.
Why This Is Harder to Defend Than a Payload Argument
A payload argument invites a technical rebuttal. You can argue about hashing, about whether an identifier is reasonably linkable, about whether a URL parameter was stripped by a filter. Some of those rebuttals succeed.
An audience-specificity argument closes most of those doors. The advertiser wrote the audience rule, named it, and chose the URL patterns, event names, and customer list that seeded it. There is no third-party inference to attack and no ambiguity about intent, because a segmentation rule is a statement of purpose.
It also survives the passage of time in a way that traffic evidence does not. Audience objects persist in ad platform interfaces long after they stop being used. Many advertisers have segments built by an agency that no longer works for them, referencing pages that no longer exist. Those objects still carry a name, a definition, a creation date, and in most platforms the identity of the account user who created them.
Where the Evidence Actually Lives
To understand your own exposure, enumerate the places where condition-level intent gets written down. There are seven, and most healthcare advertisers have never reviewed more than two.
- Website custom audiences built on URL rules. A rule that says "people who visited URLs containing /treatments/hair-loss in the last 180 days" is a membership list defined by a condition. The rule text is stored in the platform, readable by anyone with account access.
- Event-based audiences. The complaint at paragraph 67 defines "Events" as "the actions of website visitors on Hims' website." Audiences built on custom events inherit whatever the event name says. An event called started_ed_consult is self-describing forever.
- Customer list uploads. Paragraph 76 alleges that Hims uploaded customer lists to Snap so users could be matched to Snapchat accounts. Any uploaded list that was segmented by product line or treatment category is, functionally, a patient roster organized by condition, and the upload has a timestamp.
- Lookalike and similar-audience seeds. The seed list is the sensitive object. The modeled expansion is derivative, but the seed stays in the account and stays inspectable.
- Exclusion audiences. This is the one people miss. Excluding existing patients from prospecting campaigns is standard, sensible media practice, and it still transmits the membership of that group to the platform. Negative targeting is targeting.
- Dynamic remarketing feeds and product identifiers. If your catalog items map to treatments, the item IDs attached to remarketing events carry the same information a URL would.
- Names and naming conventions. Campaign, ad set, conversion action, and audience names, plus UTM values, are free text your team wrote. They are frequently more explicit than anything in a payload, because they were written for internal clarity rather than external eyes.
None of these require a subpoena to a platform. They are your own business records, in your own account, produced from your own systems. When a regulator or a plaintiff's firm asks for the advertising configuration, this is what gets produced. Our guide to identifying PHI leakage in ad tracking covers the site-side half of this work, and the 14-point self-assessment scorecard is a reasonable starting structure if you are running the review internally.
How a Curve-Style Setup Changes What Your Ad Account Contains
The point of a compliant tracking architecture is not to make the evidence harder to find. It is to make sure the evidence, when found, does not describe anyone's health status. Curve sits between your website and the ad platforms as a first-party layer. Events are collected on your own domain, sanitized server-side before egress, and forwarded to each configured destination with identifiers and condition-level detail removed rather than obfuscated. Protected health information does not reach Meta, Google, Microsoft, TikTok, or any other destination, because it is stripped before the request leaves your infrastructure, and a BAA is available for the layer that does the handling.
What that changes in the account is concrete. Conversion actions carry generic names rather than treatment names. Remarketing pools are built from behavior that does not encode a diagnosis. Customer list uploads, if you use them at all, are scoped so that list membership is not a statement about a condition. You still get campaign-level measurement and platform optimization, and the audit trail your ad account leaves behind stops being a document that answers the question paragraph 74 asks.
There is a related design question about how to reach the right people without condition-level segments, which we cover in more depth in building healthcare lookalike audiences without PHI. The short answer is that in-market and interest signals maintained by the platform, combined with sanitized first-party conversion feedback, do most of the work that condition-specific retargeting pools were doing, without the pools existing.
Discovery Realities Most Marketing Teams Have Never Considered
Ad accounts were built for collaboration, not litigation hygiene, and that shows up in three ways.
Change history is long and attributed
Major platforms retain account change logs recording what was modified, when, and by which user. For an audience object, that means a creation date and an editor, and in a dispute about when a company knew something, an attributed timestamp is worth more than a policy document. Paragraph 78 of the complaint alleges that Hims acknowledged privacy and consumer-protection regulatory risk in SEC filings beginning in 2021 and that the FTC issued a Civil Investigative Demand in October 2023. Timeline allegations get tested against operational records, and change history is an operational record.
Access is broad and rarely revoked
The typical healthcare advertiser has granted account access to a media agency, a creative shop, a former in-house hire, an analytics contractor, and a platform representative. Each of them can see the audience definitions, and several have exported them into slide decks. Media plans describing segments by condition are ordinary marketing deliverables that live in email and shared drives, and they are the easiest possible way for a precise audience definition to become an exhibit.
Deleting an audience does not delete the story
Removing a segment today does not remove the change log entry that created it, the agency deck that described it, or the invoice line referencing the campaign it powered. Cleanup stops ongoing exposure, but do it as documented remediation, not quiet housekeeping. If you are unsure whether an existing configuration is defensible, the sequencing in our Meta Pixel removal walkthrough is the safer order of operations.
The Pattern Across Enforcement, Not Just This Case
The precision argument did not appear from nowhere. GoodRx settled with the FTC in February 2023 for $1.5 million, and BetterHelp settled in March 2023, ultimately at $7.8 million. The Advocate Aurora pixel settlement showed the same evidentiary shape on the private-litigation side, where the configuration itself carried the story. What separates July 2026 is posture: the Hims matter is being litigated rather than settled at the outset, civil penalties are sought, and two state enforcers joined as co-plaintiffs.
The practical consequence for anyone running paid media in healthcare is that the audit surface has widened. Automated campaign types make this sharper, because signal handling is partly delegated to the platform, a topic we work through in the Performance Max audit framework. It is no longer enough to show that your site does not leak. You should be able to open every ad account your organization touches and defend every object in it by name.
A Practical Review You Can Run This Month
- List every ad account your organization or its agencies control, including dormant ones and accounts under a partner's business manager.
- In each account, export the full audience list with definitions, creation dates, and creators. Read the definitions, not just the names.
- Flag any audience whose membership rule or name would allow an outsider to infer a treatment, a diagnosis, or a medication.
- Do the same for conversion action names, custom event names, campaign and ad set names, and UTM conventions.
- Check exclusion lists and customer list uploads specifically, including historical uploads that are no longer refreshed.
- Decide remediation with counsel, document the decision, then change the architecture so the same objects do not reappear next quarter.
The last step matters most. Cleaning an account without changing how events are collected produces the same account again within two campaign cycles, because the people rebuilding it face the same performance pressure that created it the first time.
Frequently Asked Questions
Is it actually illegal to build a detailed remarketing audience in healthcare?
Building a precise audience is not itself unlawful. The FTC's theory in this complaint is narrower and, in some ways, more uncomfortable. It alleges that the specificity of the audiences is evidence that promises made to consumers about privacy were not kept, which supports the deception count under Section 5(a). The problem alleged is the gap between what the company said and what its systems did.
Can a regulator see the audiences inside my ad account?
Not by browsing. Audience definitions are ordinary business records, so they are reachable through an investigative demand or civil discovery, and they are also visible to every vendor and former employee who still has account access. Practically, treat anything in the account as producible.
Does hashing emails before uploading a customer list solve this?
Hashing addresses one risk, which is the transmission of a readable identifier. It does not address the risk paragraph 74 describes, because the sensitive fact is often the membership rule rather than the identifier. A hashed list that consists entirely of people receiving one category of treatment still communicates that category by virtue of who is on it.
What about audiences my agency built years ago?
They are still yours in every way that matters. Agency-created objects sit in accounts you own or control, they appear in change logs, and they were usually described in decks that your organization received. Include third-party-created audiences in scope for any review, and ask the agency for its own retained documentation.
If I remove condition-level audiences, will performance collapse?
Usually not, though it changes. Platform optimization has shifted heavily toward modeled delivery driven by conversion signal quality rather than manually assembled remarketing pools, so clean, well-attributed conversion events tend to matter more than segment granularity.
This article reflects the record as of July 2026 and is based on the redacted complaint as e-filed, available at ftc.gov. It is general information about advertising operations, not legal advice.
If your ad accounts currently contain audiences you would not want read aloud in a deposition, the durable fix is to stop generating them at the source. Curve gives healthcare advertisers conversion tracking and campaign measurement where protected health information never reaches the ad platform, with sanitization handled server-side and destinations configured per platform. See how it works at curvecompliance.com.
Keep exploring
Related articles
Is the Criteo Pixel Safe for Healthcare? What the FTC's Hims and Hers Complaint Alleges
Read articleGLP-1 and Weight Loss Advertising After the FTC's Hims and Hers Case
Read articleFifteen Ad Platforms Named in the FTC's Hims and Hers Complaint: The Full List and What It Means
Read articleStay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.