Skip to main content
Article

What DTC Telehealth Brands Must Change After the FTC's Hims and Hers Lawsuit

If you run growth or marketing at a direct-to-consumer telehealth company, the practical answer is short. Three things need to be re-read this week, by the same person, in the same sitting: every tracking tag on every surface you own, every customer list you have ever uploaded to an ad platform, and every privacy claim in your own marketing copy. Those three artifacts are what the Federal Trade Commission put side by side in its complaint against Hims & Hers Health, Inc., and the theory of the case is that they contradicted each other.

The suit was filed in late July 2026 in the U.S. District Court for the Northern District of California, Case No. 3:26-cv-7871, by the FTC together with the People of the State of California acting through Los Angeles County Counsel Dawyn R. Harrison, and the Utah Division of Consumer Protection. It pleads counts under Section 5(a) of the FTC Act, Section 4 of ROSCA, California's UCL and False Advertising Law, and the Utah CSPA. Curve is a HIPAA-compliant conversion tracking platform that lets DTC telehealth brands keep measuring and optimizing paid acquisition without sending protected health information to ad platforms.

Nothing here is proven. These are allegations in a live case against a public company. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case. Read the rest of this article as risk management, not as a verdict.

What makes this filing different from the settlements that preceded it is posture. GoodRx settled in February 2023 and BetterHelp in March 2023. This one is being litigated, with civil penalties sought and two state enforcers on the caption. The question is no longer whether health-adjacent tracking draws attention. It is what your file looks like when someone reads it against your own homepage.

The Short Version

  • The FTC and two state enforcers sued a DTC telehealth company in July 2026 over tracking practices and billing practices, treating both as one pattern of conduct. The allegations are unproven and are being contested.
  • The complaint's privacy theory is built on the gap between published privacy language and what the company's advertising stack allegedly did. Paragraph 66 quotes marketing phrases including "100% online, private, and secure" and "totally private".
  • Paragraph 70 names both the Meta Pixel and the Conversions API, and describes the server-side connection accurately. Moving a tag server-side did not remove it from the pleading.
  • Paragraph 76 alleges customer list uploads to Snap for account matching. Paragraph 77 lists a long tail of other pixels, including two additional server-side vectors.
  • The remediation sequence that actually works is tag inventory, list-upload audit, intake-page review, marketing-copy review, then a sober reassessment of what your server-side setup is doing.
  • Paid acquisition is the business model for most DTC telehealth. The goal is not to stop measuring. It is to stop sending the condition.

What the Complaint Actually Alleges, in One Paragraph

The complaint defines "Events" as "the actions of website visitors on Hims' website" and alleges at paragraph 67 that those Events were shared with third-party advertising platforms. Paragraph 70 names the Meta Pixel and the Conversions API and describes the latter as operating differently to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems. Paragraph 74 alleges that the company was able to build audiences with unusual specificity only because it departed from its promises about treating conditions privately. Paragraph 76 alleges customer list uploads to Snap for matching to Snapchat accounts. Paragraph 77 lists additional pixels allegedly present, spanning search, social, programmatic, affiliate, direct mail, and podcast measurement, including Google Ads S2S and TikTok s2s. Paragraph 78 addresses knowledge, citing SEC filings since 2021 that acknowledged privacy and consumer-protection regulatory risk, and a Civil Investigative Demand issued in October 2023. The full redacted complaint is available as a PDF on ftc.gov.

Why This One Lands Differently for DTC Specifically

Health systems and clinics have been the usual defendants in pixel litigation, and their exposure is patient portals and appointment pages. DTC telehealth has a structurally worse problem. A hospital website serves many conditions, so a conversion on it tells an ad platform only that someone booked something. A single-condition DTC funnel is different. If the brand or the landing page exists to sell one category of treatment, a purchase event discloses the category by itself, with no parameters, no URL fragments, and no custom data. The event name can be perfectly generic and the disclosure still happens, because the page context supplies the meaning. That is why the audience-building allegation at paragraph 74 is the sharpest part of the privacy section. Specificity was the product.

The second structural problem is that DTC telehealth markets on privacy. It is the category's strongest selling proposition, because discretion is why people use these services instead of walking into a clinic. Paragraph 66 alleges the promises ran through TV, radio and podcast advertising as well as the website, and every one of those claims becomes a Section 5 exhibit if the stack does not match it. Practices that would be merely risky for a generalist provider become an advertising-substantiation problem for you. Our survey of FTC enforcement against virtual care advertising traces how consistently that pattern repeats.

You Cannot Simply Stop Measuring, and Nobody Serious Is Asking You To

There is a genre of compliance advice that ends with "remove the pixels." For a company whose customer acquisition runs entirely through Meta, Google, and a handful of programmatic partners, that is a recommendation to stop growing. Blind spend is not a compliance posture, and it gets reversed within a quarter by whoever owns the revenue number.

The workable position is narrower. Ad platforms need to know that a conversion happened, roughly what it was worth, and which click it belongs to. They do not need to know what the person was treated for, who they are, or what they typed into an intake form. Nearly all the legal exposure sits in the second set and nearly all the optimization value sits in the first. Separate those two questions and remediation stops being a fight between legal and growth and becomes an engineering task.

How a Curve-Style Setup Changes the Exposure

Curve sits between your site and the ad platforms and enforces the separation described above. Events are captured first-party, then sanitized on Curve's servers before anything leaves for a destination, so identifiers and condition-revealing detail are stripped at egress rather than being trusted to a client-side configuration that any tag manager change can undo. Conversions still arrive at Meta, Google, Microsoft, and the other configured destinations with the click identifier and value needed for bidding and reporting, which is what keeps campaigns optimizing. Destinations are configured per platform, so what Google receives and what a programmatic partner receives are separate decisions rather than one global setting. Curve signs a Business Associate Agreement, which matters because the vendor holding your event stream is handling the data the complaint is about. None of that resolves a marketing-copy problem on its own, and it should not be sold as if it does. It removes the technical half of the exposure so that the remaining work is a writing and disclosure exercise you can actually finish.

The Remediation Sequence, in the Order That Works

Do these in order. Each step tells you what the next one needs to cover, and the first two produce the inventory a regulator or plaintiff's counsel would build anyway.

Step one: a real tag inventory, on every surface

Not a list of tags you believe are installed. A list of network requests actually leaving a real session. Open your funnel in a clean browser profile, record the network log from first ad click through checkout, and write down every third-party host that receives a request. Repeat on mobile web, in your app, and on any landing page a partner or agency built for you. Paragraph 77's list is instructive because it includes vendors most growth teams would not name from memory: affiliate networks, direct mail retargeting, podcast measurement, and demand-side platforms. Old campaign tags left in a container by someone who no longer works there are the most common finding. Our healthcare pixel audit walkthrough and the fourteen-point self-assessment scorecard exist to produce this. Finish with one document naming every destination, its business owner, and what it currently receives.

Step two: audit every list you have ever uploaded

This is the step teams skip, and the one with the least ambiguity in the complaint. Paragraph 76 alleges customer list uploads to Snap for matching to Snapchat accounts. A list upload is not a tag. It does not appear in a network log, it is not governed by your consent banner, and it lives in an ad account rather than your codebase.

Pull the audience list from every ad account you control and answer two questions for each. What source query built it, and does membership disclose a condition, a treatment, or a clinical status? A list called "past purchasers" on a single-category brand answers the second question by itself. Then find out who can create these lists. In most DTC companies the answer is any agency user with account access and a CSV. Until upload rights are restricted and logged, remediating tags accomplishes less than it appears to. There are workable alternatives, covered in building lookalike audiences from in-market segments rather than from patient lists.

Step three: read the intake flow the way an enforcer would

Intake concentrates the risk, because the questions are clinical and the answers are typed by the patient. Walk your own flow and note every point where an answer changes a URL, populates a data layer, fires a step event, or is echoed into a confirmation page title, then check what your tags do with each. Step-completion events are the frequent offender, because they are named after the question they follow and the question is the diagnosis. Our breakdown of the leak points in medical intake forms covers hidden fields, query-string persistence, and third-party form embeds that carry their own scripts.

Step four: read your own marketing copy as a legal promise

Paragraph 66 is a marketing-copy exhibit, not a technical one. Collect every privacy claim you make, in every channel: homepage, category pages, checkout, app store listing, TV and radio and podcast scripts, influencer briefs, and the privacy policy itself. Put them in one document next to the tag inventory from step one. Where a claim is broader than the stack, either narrow the claim or change the stack. Hunt for words like private, secure, discreet, and confidential, and treat absolutes such as "100%" and "totally" as the highest risk, because they leave no interpretive room later.

Step five: reassess server-side honestly

Many teams moved to the Conversions API and a server-side tag manager in 2023 and 2024 and logged the work as done. Paragraph 70 should end that assumption. The complaint describes the server-side connection correctly and pleads it as a sharing vector regardless, and paragraph 77 lists Google Ads S2S and TikTok s2s alongside the browser pixels.

The distinction that matters is not client versus server. It is what the payload contains when it leaves your control. A server-side endpoint forwarding the same event, identifiers, and page context is the browser pixel with a different transport. Ask engineering for a captured outbound payload from your own container and read the fields. We made this argument at length in why server-side tracking alone is not HIPAA compliance, and the filing is the clearest external confirmation of it so far.

What This Costs You in Measurement, Realistically

Expect noisier attribution while the change lands, mostly because deduplication and event naming get rebuilt at the same time. Freeze major budget shifts for two weeks after cutover and compare platform-reported conversions against backend orders daily during that window. Teams that run this as an attribution project rather than a legal one usually finish with cleaner data than they started with, because the audit surfaces duplicate events and stale conversion actions that were already distorting bidding.

Frequently Asked Questions

Does this lawsuit mean DTC telehealth companies cannot run Meta or Google ads anymore?

No. The privacy allegations concern what was allegedly shared with advertising platforms and how that squared with published privacy promises, not the act of advertising. What needs to change is the content of the data leaving your systems, and whether your public claims describe it accurately.

We already use the Conversions API instead of the browser pixel. Are we covered?

Not on that basis alone. Paragraph 70 of the complaint names both the Meta Pixel and the Conversions API, and describes the server-side connection accurately before pleading it as a sharing vector. Paragraph 77 lists Google Ads S2S and TikTok s2s as well. Server-side changes the transport, not the payload, and the payload is what the case is about.

What is the single highest-risk thing to check first?

Customer list uploads. They are invisible in a network log, usually created by people outside engineering, and a list built from purchasers of a single-condition product discloses that condition by construction. Paragraph 76 alleges this pattern with Snap.

Is a Business Associate Agreement with our tracking vendor enough?

It is necessary and not sufficient. A BAA governs how a vendor handles data you entrust to it. It says nothing about what that vendor then forwards to Meta, Google, or a programmatic partner that has signed nothing. Ask for a field-by-field description of what leaves for each destination, and treat a vague answer as an answer.

How long does a full remediation take?

For a mid-sized DTC telehealth company with an agency relationship and a few years of accumulated tags, the inventory and list audit take about a week if someone owns them full time. Intake changes and a server-side rebuild typically run three to six weeks. The copy review is fast in engineering terms and slow in approval terms, so start it in parallel on day one.

Has Hims responded to the complaint?

Yes. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has stated it intends to defend the case. The matter is being litigated and no court has ruled on any of the claims.

This article reflects the public record as of July 2026 and describes allegations that have not been proven in court. It is general information about advertising and privacy practices, not legal advice about your specific situation.

If you want to keep optimizing paid acquisition without sending protected health information to ad platforms, that is the problem Curve was built for. See how HIPAA-compliant conversion tracking works for DTC telehealth at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.