Skip to main content
Article

Civil Penalties Change the Math: Why the Hims and Hers Case Is Not Another Settlement Story

Nearly every significant healthcare pixel matter of the past three years has reached the public as finished news. The complaint and the consent order arrive on the same morning, the payment figure is in the headline, and the story is over before it starts. The FTC's July 2026 action against Hims & Hers Health, Inc. arrived differently. It arrived as a live complaint, filed as Case No. 3:26-cv-7871 in the Northern District of California, seeking a permanent injunction, a monetary judgment, and a civil penalty judgment, with two state co-plaintiffs attached and no accompanying resolution.

Curve is a HIPAA-compliant conversion tracking platform that lets healthcare advertisers measure and optimize paid campaigns without protected health information ever reaching an ad platform, which removes the underlying factual predicate these cases are built on.

The change in posture matters more than any number will. A negotiated settlement is a priced risk. Contested litigation with penalty relief requested is an open one, and it is paired in this complaint with an allegation set specifically designed to show the company was on notice long before the filing. That combination, remedies plus a documented knowledge record, is the part worth studying.

Nothing here is proven. Every characterization below is of what the complaint alleges. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case. This article does not predict an outcome and does not estimate any figure, because doing either would be guesswork.

The Short Version

  • The complaint requests a permanent injunction, a monetary judgment, and a civil penalty judgment, three distinct forms of relief rather than a single negotiated payment.
  • Civil penalties are not automatically available on a bare deception theory. They require a statutory hook, and this complaint supplies several by pleading ROSCA and two state consumer protection statutes alongside FTC Act Section 5(a).
  • Paragraph 78 pleads knowledge: SEC filings since 2021 acknowledging privacy and consumer protection regulatory risk, and a Civil Investigative Demand the FTC issued in October 2023.
  • Knowledge allegations do not prove a violation. They remove the defense that the conduct was an oversight, which is the factor that separates a corrective matter from a punitive one.
  • Filing rather than settling means the factual record develops publicly, on a docket, over time, and becomes available to other plaintiffs.
  • For every other healthcare advertiser, the actionable lesson is about their own paper trail, not this company's.

Settlement Posture Versus Litigation Posture

When an agency and a company announce a resolution together, several things have already happened privately. The facts have been narrowed to what both sides can live with. The remedies have been negotiated. The company has weighed the cost of fighting against the cost of paying and chosen. The public sees the endpoint of a process, not the process.

A filed complaint without a resolution inverts all of that. The government has set out its theory in the form it intends to prove, not in the form the defendant accepted. The allegations are more detailed than a consent order would be, because they have to survive a motion to dismiss. And the matter now has a duration measured in years rather than a closing date.

The practical consequences for the defendant compound over that duration:

  • Discovery produces internal documents, and internal documents are where advertising and compliance decisions are actually recorded.
  • Every ruling on the docket is public and citable by private plaintiffs pursuing separate theories.
  • Disclosure obligations attach for a public company, and a contested matter is harder to characterize as immaterial than a closed one.
  • The remedies stay open. In a settlement, the number is the number. In litigation, the ceiling is set by statute rather than by negotiation.

Why Civil Penalties Require a Hook

This is the technical point most coverage skips. The FTC cannot simply attach a civil penalty to a deception claim under Section 5(a) as a matter of course. Penalty authority comes from specific statutory routes, and a complaint that wants penalties has to plead its way into one.

This complaint pleads four counts across three sovereigns: FTC Act Section 5(a) (15 U.S.C. 45(a)); Section 4 of the Restore Online Shoppers' Confidence Act (15 U.S.C. 8403); California's Unfair Competition Law (Bus. & Prof. Code 17200) and False Advertising Law (17500); and the Utah Consumer Sales Practices Act (Utah Code 13-11-4(1)).

The ROSCA count is the one that carries the clearest federal penalty mechanism, because the statute's enforcement provision directs that a violation be treated as a violation of a trade regulation rule under the FTC Act, and rule violations are the classic route to civil penalties. The state counts bring their own penalty structures, generally assessed per violation, on a track that a federal resolution does not extinguish.

The structural insight for anyone reading complaints in this space is that the billing count is not a side dish. Pleading ROSCA alongside a privacy theory is what converts a matter about data flows into a matter with federal penalty exposure. A subscription health company facing a privacy investigation should expect its checkout flow to be examined for exactly this reason.

How Curve Changes What Is Available to Plead

Enforcement theories in this area all depend on the same factual predicate: health-revealing data reached an advertising platform. Curve is built so that predicate does not exist. Events are collected first-party and sanitized on Curve's servers before anything is transmitted onward, so what reaches a platform is conversion signal rather than the identifiers, condition context, or page detail that would make the event health-revealing. Destinations are configured individually, so each network receives only what it has been explicitly configured to receive, and adding a network is a deliberate act rather than a silent widening. Curve signs a Business Associate Agreement covering the tracking layer, which places measurement inside the compliance perimeter instead of alongside it. That does not make anyone immune to an investigation, and no vendor should claim it does. It changes what an investigator finds when they look at the network traffic, which is the evidence every one of these cases is actually built on.

Paragraph 78: The Knowledge Record

The most consequential paragraph in the complaint for other companies is not one of the tracking paragraphs. It is paragraph 78, which pleads two facts about awareness.

First, that Hims acknowledged privacy and consumer protection regulatory risk in SEC filings beginning in 2021. Second, that the FTC issued the company a Civil Investigative Demand in October 2023.

Neither fact is an allegation of wrongdoing. A risk factor in an annual report is standard disclosure practice, and receiving a CID is not an accusation. But together they do specific work in the complaint's architecture. They establish a timeline in which the company is alleged to have been aware of the category of risk, aware that the agency was looking, and continuing conduct the complaint describes across paragraphs 66 through 77.

Why documented awareness escalates exposure

There is a meaningful difference, in enforcement practice and in judicial instinct, between a company that got something wrong and a company that was told and did not change. The first calls for correction. The second invites punishment. Knowledge allegations move a matter from the first category toward the second, and they do it before anyone has litigated whether the underlying conduct was unlawful at all.

Awareness also shapes the discovery that follows. Once the government has pled notice, the internal record of what happened after that notice becomes central: what was escalated, what was assessed, what was decided, and what was deferred. Those documents exist in almost every organization, in ticket systems, in vendor questionnaires, in slide decks, and in email threads between marketing and legal.

The Uncomfortable Part: Your Own Paper Trail

The reason paragraph 78 should hold a marketing leader's attention is that most healthcare organizations already have their own version of it. Since the GoodRx and BetterHelp actions in early 2023, the sector has been saturated with warnings. Agency emails flagged pixel risk. Security questionnaires asked about third-party tags. Someone opened a ticket about removing a tracker from a condition-specific landing page. A privacy counsel memo recommended a change that never shipped because a campaign was mid-flight.

Each of those artifacts is evidence of awareness. That is not an argument for producing fewer of them, and nobody should read it that way. It is an argument for closing them. An unresolved warning is worse than no warning, because it converts a technical problem into a decision the organization made.

The practical follow-through:

  • Find the open items. Search your ticketing system, your risk register, and your vendor review files for tracking and pixel items that were raised and never closed.
  • Close them with a documented outcome. Remediated, accepted with a stated rationale, or superseded. An item with a decision attached is defensible. An item that simply went quiet is not.
  • Re-audit rather than assume. A tag removed in 2023 can return through a tag manager container, an agency template, or a new landing page builder. Our guide to identifying PHI leakage in ad tracking covers where reintroductions usually happen.
  • Include the server-side paths. Paragraph 70 of the complaint names the Meta Pixel and the Conversions API together and describes the server-side connection accurately before pleading it as a sharing vector. Paragraph 77 lists a Google Ads S2S pixel and a TikTok server-to-server integration among more than a dozen others. We have written before that server-side tracking alone is not HIPAA compliance, and this complaint is the clearest confirmation to date. Server-side done properly still helps, as our technical audit of server-side benefits explains, but only when the payload is sanitized rather than merely relocated.
  • Check that a signed BAA is doing real work. A contract is not a control. Our piece on why a BAA alone is not enough for marketing vendors covers the gap between paperwork and configuration.

What This Case Signals Without Predicting It

It would be irresponsible to forecast how this matter resolves, and this article will not. What can be said is narrower and still useful.

The government chose to litigate rather than settle a health advertising case against a public company. It requested penalty relief rather than only redress. It brought two states with it. It pled the defendant's server-side architecture accurately rather than treating the pixel as the whole story. And it pled a knowledge timeline stretching back to 2021.

Each of those choices is a signal about posture, not about outcome. Read together, they suggest an agency willing to test its theories in front of a judge rather than convert them into a negotiated figure. For companies still deciding whether to prioritize a tracking remediation project, the relevant question is not what happens to this defendant. It is what a similarly detailed complaint would look like if it were drafted about your own stack, using your own internal documents about what you knew and when.

Our running tracker of healthcare pixel settlements provides the wider context, and the penalty estimator is a way to think about magnitude in the abstract without attaching numbers to a live case.

Frequently Asked Questions

What is the difference between a monetary judgment and a civil penalty judgment?

Monetary relief is generally compensatory, directed at consumer harm, and often takes the form of refunds. A civil penalty is punitive, owed to the government, and typically assessed by reference to violations rather than to consumer losses. The Hims complaint requests both, alongside a permanent injunction. These remain requests for relief, not awards.

Why can the FTC seek penalties in this case?

Because the complaint does not rest on Section 5(a) alone. It pleads Section 4 of ROSCA, whose enforcement provision routes violations through the FTC Act's trade regulation rule framework, and it includes California and Utah state counts that carry their own penalty structures. Pleading those counts is what creates the penalty pathway.

Does receiving a Civil Investigative Demand mean a company did something wrong?

No. A CID is an investigative tool and is not itself an accusation of wrongdoing. In this complaint the October 2023 CID is pled as part of a knowledge timeline, meaning it goes to what the company is alleged to have been aware of rather than to whether any conduct was unlawful.

Should we stop documenting privacy concerns internally to avoid creating a record?

No, and that instinct causes more damage than the documents ever would. Suppressing internal risk discussion undermines the compliance function, creates its own legal problems, and does not make the underlying data flows any safer. The correct response is to resolve open items and record the resolution.

How much of this applies to a company that is not a public subscription brand?

The knowledge dynamic applies universally. A clinic does not file with the SEC, but it has emails, tickets, agency correspondence, and vendor assessments. The escalating factor is not the form the awareness took. It is whether anything changed afterward.

Is the outcome of this case predictable from the filings?

No. Complaints reflect one party's allegations and have not been tested. Hims has denied the allegations and stated it intends to defend the case. Anyone quoting a likely penalty figure for this matter is inventing it.

This article reflects the public record as of July 2026 and describes the redacted complaint as filed, available at ftc.gov. It is commentary on posture and structure, not legal advice, and not a prediction.

The cheapest position to be in when an investigator asks what your site sends to ad platforms is one where the answer is documented, narrow, and free of protected health information. Curve provides that with sanitization before egress, per-destination configuration, and a signed BAA covering the tracking layer. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.