Skip to main content
Article

Is the Criteo Pixel Safe for Healthcare? What the FTC's Hims and Hers Complaint Alleges

The short answer is that the Criteo pixel, in a standard retargeting deployment, is not safe to run on healthcare pages that reveal a condition, a treatment interest, or a care intent. Criteo is named in the Federal Trade Commission complaint against Hims & Hers Health, Inc. as one of the advertising platforms whose pixel was allegedly placed on the company's properties. Criteo has not been accused of anything. The allegation is about what the advertiser allegedly sent, and retargeting is the use case where sending too much is hardest to avoid, because the entire product depends on knowing which specific page a specific person looked at.

Curve is a HIPAA-compliant conversion tracking platform that lets healthcare advertisers run and measure retargeting-driven campaigns without sending protected health information to Criteo or any other ad platform. That distinction matters here more than in almost any other channel, because retargeting does not just record behavior, it acts on it in public.

The case is Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., Case No. 3:26-cv-7871, filed in the U.S. District Court for the Northern District of California in late July 2026. Nothing in the complaint has been proven. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case.

The Short Version

  • Paragraph 77 of the complaint lists Criteo among the third-party pixels allegedly placed on Hims platforms, alongside Bing, Google Ads, Pinterest, Reddit, StackAdapt, The Trade Desk, PebblePost, Podsights, MediaBids, PartnerCentric and X.
  • Paragraph 67 defines the shared data as "Events", meaning "the actions of website visitors on Hims' website." Retargeting is built entirely out of exactly that raw material.
  • Retargeting is uniquely exposed in healthcare because the targeting signal, the page a person viewed, is itself the sensitive fact. There is no version of behavioral retargeting that does not transmit behavior.
  • Retargeting vendors inherit the advertiser's privacy promises. Paragraph 66 quotes Hims marketing language including "100% online, private, and secure", "totally private" and "discreet". The FTC alleges the sharing happened anyway.
  • Server-side integration does not neutralize the problem. Paragraph 70 shows the FTC described server-side transmission accurately and pled it as a violation vector regardless.
  • The fix is not to abandon retargeting. It is to stop letting page-level behavior leave your systems in identifiable form, and to send only sanitized conversion signals instead.

What the Criteo Pixel Actually Does on a Site

Criteo built its business on dynamic retargeting for commerce. The classic deployment is a single universal tag placed on every page, commonly called the OneTag, which fires a small set of standardized events: a homepage view, a category view, a product view, a basket event, and a transaction event. The product view is the important one. It does not say "this person visited the site." It says "this person viewed item X", where X maps back to a catalog entry the advertiser also supplied to Criteo through a product feed.

The catalog and the behavior are joined so the ad creative served later can display the specific item the person looked at. For a shoe retailer this is unremarkable. For a telehealth company, the catalog entries are not shoes. They are treatments, and treatments imply conditions.

Layer on the parts that are easy to forget. A page-level tag typically transmits the page URL and referrer by default, and on a healthcare site URLs are frequently self-describing: a path segment naming a condition, a query string carrying a quiz answer, a fragment identifying which intake step was reached. Retargeting also depends on persistent identification, so the tag sets or reads an identifier that survives across sessions and, where cross-device matching is enabled, across devices. The result is a durable identity attached to a record of condition-specific page views.

This is why we treat retargeting tags differently from analytics tags in a healthcare pixel audit. An analytics tag that leaks a condition creates an exposure problem. A retargeting tag that leaks a condition creates an exposure problem and then buys media against it.

The Part That Makes Retargeting Different: the Ad Is the Disclosure

Most privacy analysis of ad tech stops at the moment data leaves the browser. Retargeting has a second disclosure event that healthcare compliance reviews almost never model.

When a retargeted ad is served, it renders on a third-party website, on a shared device, sometimes on a screen someone else can see. If the creative is dynamic and reflects the specific treatment page the person viewed, the ad communicates that person's health interest to anyone within line of sight. Nothing was "breached." The system worked as designed. That is the uncomfortable part.

Paragraph 66 of the complaint is worth reading with this in mind. The FTC alleges Hims published promises that its service was "100% online, private, and secure", that conditions would be treated "privately", that the experience was "totally private" and "discreet", and that these promises ran through television, radio and podcast advertising as well as the website. Paragraph 74 alleges that Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private."

Read that paragraph as a description of retargeting mechanics and it becomes a fairly precise technical claim: audience specificity is a downstream product of behavioral granularity. You cannot have one without the other. If a regulator can point at an unusually specific audience, they have implicitly pointed at the data that built it.

Retargeting Vendors Inherit Your Privacy Promises

There is a persistent belief in performance marketing that each vendor owns its own compliance posture, so choosing a reputable vendor transfers some of the risk. Under Section 5 of the FTC Act, that is close to backwards.

Section 5(a) reaches deceptive acts and practices. The deception the FTC alleges here is not committed by an ad platform. It is committed by the company that told users their care was private and then, according to the complaint, wired page-level behavior to third parties. Every platform on the paragraph 77 list becomes evidence of the gap between promise and practice. A vendor's own privacy policy and contractual assurances do not repair a promise the advertiser made to its users.

Under HIPAA the analysis lands nearby. If a covered entity or business associate discloses individually identifiable health information to an advertising vendor for marketing purposes without a valid authorization, the vendor's reputation is not the control that matters. A standard advertising data processing agreement is not a business associate agreement, and most retargeting platforms will not sign one for open-web behavioral advertising. That gap shows up repeatedly in the healthcare pixel litigation record from 2024 through 2026.

How Curve Handles Retargeting Signals

Curve sits between your website and your advertising destinations so that the raw behavioral record never becomes the thing you ship. Events are captured first-party, then sanitized server-side before egress, which means condition-revealing URL paths, query parameters, form values and catalog identifiers are stripped or replaced before anything is transmitted to a platform such as Criteo. What the destination receives is a conversion signal and the matching keys it needs to attribute that conversion, not a page-by-page account of what a person read. Destinations are configured individually, so the payload sent to a retargeting platform can be narrower than the payload sent to a search platform, and each one is reviewable. Curve makes a business associate agreement available, which is the contractual half that behavioral advertising integrations normally cannot supply.

The practical consequence for retargeting specifically: you keep bottom-of-funnel remarketing against people who took a neutral, non-condition-specific action, and you stop building audiences whose membership criterion is a diagnosis. That is a real reduction in targeting precision. It is also the trade the complaint is, in effect, arguing you were always required to make.

What to Check in a Criteo Deployment This Week

Treat this as an inventory exercise, not a theoretical one. Open the network tab on a live page and read what actually goes out.

  • Tag scope. Is the universal tag deployed site-wide by a tag manager rule that matches all pages? Site-wide is the default and it is almost always wrong for a healthcare property. Condition pages, symptom quizzes, intake flows, results pages and post-purchase confirmations should be excluded before anything else is tuned.
  • Product and catalog identifiers. If a product view event carries an ID that resolves to a specific medication or treatment in your feed, that identifier is a condition proxy. Feed hygiene is not enough, because the join happens on the platform side.
  • URL and referrer transmission. Confirm what the tag sends by default, then confirm what your own pages put in the URL. A path like a condition slug, or a query parameter carrying a quiz answer, is the single most common leak we see.
  • Identifiers and cross-device matching. Understand which persistent identifiers are set or read, whether any hashed identifier derived from an email address is passed, and whether cross-device matching is enabled.
  • Audience definitions. Read the rules of every audience segment in the account. If a segment is defined by visits to a condition page, that segment is a list of people with a health interest, built from data you sent.
  • Contract. Establish in writing whether you have a business associate agreement or only a data processing addendum. If it is the latter you have no HIPAA coverage here, and a BAA alone would not be sufficient anyway without the technical controls behind it.
  • Consent architecture. If your defense rests on a cookie banner, test whether tags actually block before consent, and understand that consent under a cookie framework is not a HIPAA authorization.

Server-Side Criteo Integrations Are Not an Escape Hatch

Some teams respond to pixel risk by moving the same integration server-side, on the theory that data leaving a server rather than a browser is a different kind of event. Paragraph 70 of the complaint should end that theory. The FTC described the Conversions API accurately, noting that it operates differently "to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems", and pled it as a sharing vector anyway. Paragraph 77 separately lists a Google Ads S2S pixel and a TikTok s2s integration. The transport was understood and it did not change the analysis.

The reason is straightforward. The legal question is what information reached a third party and whether the user was told. Moving the transmission from the browser to the server changes who controls the payload, which is genuinely useful, but only if you then use that control to remove the sensitive content. If you rebuild the same event with the same condition-revealing parameters and post it from a server, you have improved your data reliability and changed nothing about your exposure. We wrote about this at length in why server-side tracking alone is not HIPAA compliance, and the Hims complaint is the clearest regulatory confirmation of that argument to date.

What You Can Still Do

None of this requires giving up performance advertising. It requires changing what the signal is made of.

Send conversion events rather than browsing events. A signal that says a qualified lead or a subscription occurred, with the matching keys required for attribution and nothing describing the clinical pathway, is enough for most bidding systems to optimize against. Keep condition-level segmentation on your side of the boundary, in your own analytics and CRM, where it is governed. Build prospecting audiences from campaign-level and content-level context rather than from individual condition-page membership, an approach we detail in building healthcare audiences from in-market segments without PHI.

Frequently Asked Questions

Is Criteo HIPAA compliant?

Criteo does not present itself as a HIPAA business associate for open-web behavioral advertising, and a standard advertising agreement is a data processing agreement rather than a business associate agreement. The practical answer is that a Criteo integration can be operated safely only if the advertiser ensures no protected health information is transmitted in the first place. Compliance here is a property of your implementation, not a certification from the vendor.

Did the FTC accuse Criteo of wrongdoing in the Hims case?

No. Criteo appears in paragraph 77 of the complaint as one of the third-party pixels allegedly placed on Hims platforms. The defendant is Hims & Hers Health, Inc. The allegations concern what the advertiser allegedly disclosed and what it allegedly promised users, not the conduct of the listed advertising platforms. Hims has denied the allegations and intends to defend the case.

Can I run retargeting for a healthcare brand at all?

Yes, with a narrower definition of the audience. Retargeting against people who visited neutral pages, or who completed a non-condition-specific action, is a very different risk profile from retargeting against people who viewed a page about a specific diagnosis or medication. The rule of thumb is that if the audience membership criterion would embarrass the person if it were printed on the ad, do not build that audience.

Does blocking the tag until consent is given solve this?

It helps and it is worth doing, but it does not fully resolve the HIPAA question. Consent captured through a cookie banner is not the same instrument as a HIPAA authorization, which has specific content requirements. It also does nothing about the data collected from users who do accept, if what you then send describes their condition.

What is the single highest-value change to make first?

Stop transmitting URLs and parameters that describe a condition. Most healthcare pixel leakage we find is not exotic. It is a page path, a query string from a symptom quiz, or a catalog identifier that maps cleanly to a treatment. Fixing the payload usually removes more risk in an afternoon than a quarter of vendor negotiations.

This article reflects the public record as of July 2026, based on the redacted complaint e-filed on ftc.gov. The full complaint is available from the FTC. The allegations described here are allegations only and have not been proven. Hims has denied them, has stated that its privacy policy makes clear that users may choose how their data is used, and has said it will defend the case.

If you are running retargeting for a healthcare brand and you are not certain what your tags are sending, that uncertainty is the finding. Curve was built to make behavioral advertising safe to operate in regulated categories by sanitizing events before they leave your infrastructure, configuring each destination separately, and backing the arrangement with a business associate agreement. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.