Skip to main content
Article

GoodRx to BetterHelp to Hims and Hers: The FTC's Health Privacy Enforcement Trajectory

The Federal Trade Commission has brought three landmark health-data advertising actions in a little over three years, and each one asked more of the defendant than the last. GoodRx resolved in February 2023 with a $1.5 million payment. BetterHelp resolved a month later, in March 2023, with $7.8 million directed to affected consumers. In July 2026 the FTC did something different with Hims & Hers Health, Inc.: instead of announcing a negotiated settlement, it filed a complaint in federal court, brought two state co-plaintiffs with it, and asked for a civil penalty judgment on top of an injunction and monetary relief.

Curve is a HIPAA-compliant conversion tracking platform that lets healthcare advertisers run and measure paid campaigns without sending protected health information to ad platforms, which is the specific failure mode all three of these actions describe.

Read as a sequence, the three matters are not repetition. They are escalation along three separate axes: the legal theory, the technical conduct the government is willing to describe, and the posture in which the government is willing to fight. This article traces that line and explains what the shape of it suggests about the next action, whoever the defendant turns out to be.

Everything about the Hims & Hers case described here is an allegation. Nothing has been proven. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case.

The Short Version

  • GoodRx (February 2023) established that health data shared with ad platforms is an FTC problem even when no traditional data breach occurred, and it ended in a $1.5 million payment.
  • BetterHelp (March 2023) established that promises of privacy in marketing copy are enforceable representations, and it directed $7.8 million to affected consumers.
  • Hims & Hers (July 2026, Case No. 3:26-cv-7871, Northern District of California) is being litigated rather than settled, with the FTC seeking a permanent injunction, a monetary judgment, and a civil penalty judgment.
  • California, acting through Los Angeles County Counsel, and the Utah Division of Consumer Protection filed alongside the FTC with their own state-law counts.
  • The Hims complaint names the Meta Conversions API and two other server-to-server integrations by name, which closes the argument that moving tracking to the server resolves the exposure.
  • The complaint also pleads a Restore Online Shoppers' Confidence Act count about subscription billing, which means privacy and billing conduct are being treated as one pattern.

Action One: GoodRx, February 2023

The first of the three actions mattered less for its dollar figure than for the fact that it existed at all. Before GoodRx, the common working assumption inside healthcare marketing teams was that a regulator would only take interest if data was stolen. GoodRx involved no theft. It involved a company sending information about consumers and their prescriptions to advertising platforms in the ordinary course of running ad campaigns.

The FTC treated that routine advertising plumbing as the harm itself. That is the piece worth carrying forward. The agency did not need an intruder, a ransom note, or a stolen laptop. It needed only the flow of health-adjacent information to a third party that the consumer did not know about and would not have expected.

The $1.5 million figure was modest by enforcement standards, and it was widely read at the time as a warning shot rather than a punishment. Read against what followed, that interpretation looks correct. The number was small, but the theory it established was the load-bearing part.

What GoodRx changed for marketers

After GoodRx, the risk conversation stopped being about security controls and started being about egress. The question was no longer whether your database was locked down. It was where your pixel, your tag manager, and your ad platform integrations sent data, and whether any of that data described a person's health. Every serious PHI leakage audit performed since exists because of the category of problem GoodRx defined.

Action Two: BetterHelp, March 2023

BetterHelp landed weeks later and added the second axis. Where GoodRx was about the data flow, BetterHelp was about the gap between the flow and what the company had told people. BetterHelp had made privacy assurances to prospective users at exactly the moment those users were disclosing mental health information, and the FTC treated those assurances as commitments that could be enforced.

The $7.8 million was directed to consumers as refunds, which is a different remedy shape from a penalty, and it carried a different message: the harm was framed as something consumers had paid for and not received. We covered that matter in depth in our breakdown of the $7.8 million BetterHelp settlement and what it means for therapy practices, so this article will not retell it. The relevant point for the trajectory is narrow: BetterHelp made marketing copy legally operative. Every reassuring phrase on a landing page became a representation the government could measure your data flows against.

A third data point from the same period reinforces the pattern. The Cerebral matter, another telehealth pixel settlement from the same enforcement wave, showed that the same theory travels to any virtual care company running performance marketing at scale.

How Curve Handles the Failure Mode These Cases Describe

All three actions describe the same mechanical problem: an event fires on a healthcare website, that event carries information about who the person is and what condition brought them there, and it is transmitted to an advertising platform. Curve is built so that transmission never contains protected health information in the first place. Events are captured first-party and sanitized on Curve's servers before anything leaves for a destination, so identifiers and condition-revealing context are stripped rather than forwarded. Destinations are configured per platform, which means the same sanitized event can be shaped for Meta, Google, Microsoft, or another network without each platform receiving raw page context. Curve signs a Business Associate Agreement, so the tracking layer sits inside the covered entity's compliance perimeter instead of outside it. The advertiser still gets conversion signal for optimization and reporting. The ad platform simply never gets the part that would make a complaint like this one possible.

Action Three: Hims and Hers, July 2026

The third action breaks the pattern of the first two in four specific ways.

It is being litigated, not announced as a settlement

GoodRx and BetterHelp were both revealed to the public as resolved matters. The complaint and the consent order arrived together. The Hims complaint arrived alone. A filed, contested complaint means the government expects to prove its case, and it means the factual allegations in the document will be tested rather than absorbed into a negotiated order.

It seeks a civil penalty judgment

The relief requested includes a permanent injunction, a monetary judgment, and a civil penalty judgment. Asking a court for penalties in a contested posture is a different exercise from negotiating a payment figure, and it changes what the defendant is exposed to if the case goes badly.

Two states are attached

The caption reads Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc. California brings claims under its Unfair Competition Law and False Advertising Law. Utah brings a Consumer Sales Practices Act claim. Those are independent state causes of action riding alongside the federal counts, which is a structure neither earlier action had.

It describes server-side tracking accurately and pleads it anyway

This is the part that should change engineering roadmaps. Paragraph 70 of the complaint names the Meta Pixel and the Conversions API together, and it describes the Conversions API as operating differently to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems. The government understood the architecture and alleged it as a violation vector regardless. Paragraph 77 lists further integrations including a Google Ads S2S pixel and a TikTok server-to-server integration, alongside Bing, Criteo, Pinterest, Reddit, StackAdapt, The Trade Desk, X, Podsights, MediaBids, PartnerCentric and PebblePost. Paragraph 76 separately alleges customer list uploads to Snap for account matching.

If your compliance plan was to move the pixel to the server, this complaint is the end of that plan. We have argued for a long time that server-side tracking alone is not HIPAA compliance, and that the honest answer to whether the Meta Pixel or the Conversions API is safe for a health advertiser depends entirely on what you put in the payload. A complaint that pleads both vectors in the same paragraph settles the point.

The Trajectory, Stated Plainly

Three actions, three additions:

  • GoodRx added the theory. Sharing health-adjacent data with ad platforms is actionable without a breach.
  • BetterHelp added the representation. Your privacy marketing is a promise the government will hold you to. Paragraph 66 of the Hims complaint follows this template exactly, quoting published phrases including "100% online, private, and secure", treatment of conditions "privately", "totally private" and "discreet", and noting the promises ran in TV, radio and podcast advertising as well.
  • Hims added the posture and the technical scope. Litigation instead of settlement, penalties instead of refunds, states instead of the FTC alone, and a defendant-side architecture that the complaint describes with precision.

Paragraph 74 of the Hims complaint ties the two halves together with a sentence worth reading twice: the complaint alleges Hims was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions privately. That is BetterHelp's representation theory applied to audience-building precision. The better your targeting was, the more the complaint says it proves.

What the shape suggests about what comes next

Nothing here predicts the outcome of this case, and no one should try. But the direction of travel across the three matters is legible. The FTC has moved from establishing a theory, to enforcing marketing promises against data flows, to contesting a case in court with penalty exposure and state partners. Each step raised the ceiling on what a health advertising matter can cost and lowered the amount of technical ignorance a defendant can rely on. Our running tracker of healthcare pixel settlements from 2024 through 2026 shows the same slope across the wider docket, not just in these three headline matters.

For a marketing team, the operational takeaway is unglamorous. Inventory every destination that receives event data, including the server-side ones, including the offline list uploads, and including the partners you inherited from an agency. Then check what each one actually receives. A 14-point self-assessment takes an afternoon and answers the only question these three actions have ever really asked.

Frequently Asked Questions

Is the Hims and Hers case the same kind of matter as GoodRx and BetterHelp?

It shares the underlying theory but not the posture. GoodRx and BetterHelp were announced as resolved settlements. Hims & Hers was filed as a contested complaint in the Northern District of California, Case No. 3:26-cv-7871, with a permanent injunction, a monetary judgment, and a civil penalty judgment all requested. Hims has denied the allegations and said it intends to defend the case.

Did the FTC really say the Conversions API was a problem, not just the pixel?

According to the complaint, yes. Paragraph 70 names the Meta Pixel and the Conversions API together and describes the server-side connection accurately before pleading it as a sharing vector. Paragraph 77 lists additional server-to-server integrations including Google Ads S2S and TikTok s2s. These remain allegations that have not been proven.

Does a smaller healthcare practice need to care about a case against a public company?

The legal theory does not scale with company size. GoodRx, BetterHelp and Cerebral covered very different business models, and the common element was event data describing health conditions reaching advertising platforms. A single clinic running a Meta campaign on a condition-specific landing page has the same exposure shape, with less legal budget.

If we already removed the Meta Pixel, are we finished?

Not necessarily. The Hims complaint alleges more than a dozen distinct integrations, including search, retargeting, podcast measurement, direct mail, affiliate and demand-side platforms, plus customer list uploads. Removing one tag while leaving the others in place addresses one line item on a long list. Our guide to removing the Meta Pixel from a healthcare site covers what to check afterward.

Can we keep running paid acquisition at all in this environment?

Yes, and the three actions do not say otherwise. None of them allege that healthcare advertising is unlawful. They allege that specific data was sent to specific platforms in a way consumers were not told about. A compliant conversion tracking setup across Google, Meta and Microsoft keeps the optimization signal while removing the payload that creates the exposure.

This article reflects the public record as of July 2026. The Hims & Hers complaint is available in redacted form at ftc.gov, and every characterization of it above is an allegation the company has denied and intends to contest.

If you are running paid campaigns for a healthcare brand and cannot say with certainty what leaves your site for each ad platform, that uncertainty is the finding. Curve was built to remove it, with sanitization before egress, per-destination configuration, and a signed BAA covering the tracking layer. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.