Skip to main content
Article

MediaBids and PartnerCentric: The Affiliate and Print Trackers in the FTC's Hims Complaint

Paragraph 77 of the FTC's complaint against Hims & Hers Health, Inc. lists the pixels allegedly placed on Hims platforms. Most names are ones a marketing team would expect: Google, Microsoft, Criteo, Pinterest, Reddit, TikTok, The Trade Desk. Two are not. MediaBids.com and PartnerCentric sit in that list because affiliate and direct-response tracking runs through the same browser and confirmation pages as everything else, though it is almost never owned by the same people.

Curve is a HIPAA-compliant conversion tracking platform that gives healthcare advertisers a single sanitized path for conversion data, so partner and affiliate programs can be measured and paid without protected health information reaching any downstream network or publisher. That matters more in affiliate marketing than anywhere else, because affiliate data does not stop at the vendor you contracted with.

The case is 3:26-cv-7871, filed in the Northern District of California in late July 2026 by the FTC with California and the Utah Division of Consumer Protection. Every statement in it is an allegation. Hims has denied the allegations, says its privacy policy makes clear that users may choose how their data is used, and intends to defend the case. Neither MediaBids nor PartnerCentric is a defendant or accused of wrongdoing. They appear as recipients, which is why they are worth writing about.

The Short Version

  • MediaBids.com and PartnerCentric are named in paragraph 77 of the FTC's July 2026 complaint among pixels allegedly placed on Hims platforms, alongside the major social, search and programmatic networks.
  • Affiliate and print-response tracking is owned by partnerships or an outside agency, and never enters the compliance review that covers Google and Meta.
  • Affiliate conversion pixels live on the order confirmation page, the highest-sensitivity page in a telehealth site, and commonly carry product and SKU parameters. In healthcare, the SKU is the condition.
  • Affiliate networks are pass-through infrastructure. What the network receives can be relayed to publishers, sub-affiliates and their media partners, none of whom appear in your contract.
  • Standard insertion orders and network terms are not business associate agreements. Most prohibit sending health information rather than taking responsibility for it.
  • Hims denies the allegations and intends to defend. No court has ruled.

What These Two Vendors Actually Do

The two sit at different ends of the direct-response spectrum, and the difference clarifies why both ended up as trackers on a website.

MediaBids operates in print and direct-response advertising, connecting advertisers with newspaper and magazine inventory and providing the measurement that makes offline placements accountable. Print cannot be tracked with a click, so the industry substitutes proxies: coupon codes, dedicated landing page URLs printed in the ad, and tracking phone numbers per publication. Each proxy eventually needs a conversion to attribute, and the conversion happens online. That is how a print vendor ends up with a pixel on a checkout page.

PartnerCentric is an affiliate program management agency. Agencies in that category run the advertiser's program on one or more networks: recruiting publishers, negotiating commission terms, handling payouts and reporting. Managing a program means administrative access to the tracking configuration, which very often means installing the tags directly.

Neither is a data broker. Both are ordinary vendors doing ordinary direct-response work, and that is the point: the FTC's theory covers every recipient of visitor Events, defined in paragraph 67 as the actions of website visitors. A print attribution pixel receiving a purchase confirmation is receiving an Event.

How Affiliate Conversion Tracking Works, and Where the Health Data Enters

The click leg

An affiliate click almost always redirects through the network's own domain before landing on your site. That redirect is where the network establishes identity: it sets a cookie, records the publisher, and appends a click identifier to the destination URL. Sub-identifier parameters, commonly labeled sid, subid or sub1 through sub5, pass through untouched and return on the conversion. Those fields are populated by the publisher and opaque to you.

The conversion leg

Conversion reporting takes one of two forms. The classic is an image pixel on the order confirmation page with parameters appended to the URL: order identifier, order value, currency, click identifier, and frequently product or SKU information so commissions can be set per product. The modern form is a server-to-server postback, where your backend calls the network's endpoint with the same fields.

Here is where healthcare diverges from retail. In e-commerce a SKU says something about taste. In telehealth the SKU is the prescription. A payload containing a product identifier for a hair loss treatment, an erectile dysfunction medication, an antidepressant or a GLP-1 contains a medication, which implies a condition, which implies a diagnosis. That inference requires no analysis. It is the literal content of the field.

Commission tiers make this structural rather than accidental. Programs pay different rates per product category, which is the exact reason the category is transmitted at all.

The confirmation page problem

Affiliate pixels are not sitewide. They sit on the one page that fires after a completed order, which in telehealth is downstream of an intake questionnaire, a clinician review and a prescription. The confirmation URL frequently contains the treatment path and the page itself often displays the medication name, which anything reading page context picks up. The same dynamic runs throughout intake, covered in telehealth intake form tracking leak points.

Print response tracking has its own version

Vanity URLs printed in a magazine ad are dedicated per publication, and in healthcare frequently per condition too, because the ad ran where the audience matches the condition. A URL created for a print campaign about hair loss carries that context in every request it generates, including to the response-tracking vendor. Condition-specific coupon codes behave the same way, and tracking phone numbers create a parallel data flow outside the pixel conversation entirely.

How Curve Handles Partner and Affiliate Conversions

Curve sits between your site and every downstream destination, including affiliate networks and response-tracking vendors. Conversion events are collected once through a first-party endpoint, sanitized on Curve's server before anything leaves, then forwarded to each configured destination. Product and SKU fields that would reveal a medication are stripped or replaced with a non-clinical value before egress, while the order identifier, value and click identifier the network needs for payout are preserved, so commissions still reconcile. Each destination is configured explicitly, so a partner receives exactly the fields you approved and nothing that happens to be on the page. A BAA is available covering Curve's processing, which affiliate contracts almost never provide.

Why Affiliate Tracking Escapes Compliance Review

Every organization we have seen with a serious pixel governance process built it around paid media: Google Ads, Meta, sometimes Microsoft and the programmatic stack, run by whoever owns those accounts and triggered when a tag goes live in that world. Affiliate sits outside all of it, for four reasons that compound.

  • Different owner. Affiliate and partnerships report through business development or revenue, not marketing operations. Whoever negotiates a commission structure does not maintain the tag manager.
  • Different budget line. Affiliate is a cost of revenue rather than media spend, so it never appears in the media plan compliance reviews.
  • Different contract path. Programs launch on insertion orders and network terms, sometimes clicked through in an interface, rather than the vendor review a new ad platform would get.
  • Different implementation path. The network or managing agency supplies the tag and often installs it directly, in many cases years ago and by an agency no longer engaged.

The result is trackers on the most sensitive page of the site that no compliance process has examined. Only a network-traffic audit finds them, which is why it must run against observed requests rather than a vendor list. Our pixel audit methodology for identifying PHI leakage and the 14-point self-assessment scorecard both start there.

Vendor of Vendor: The Part That Makes Affiliate Different

With a direct advertising platform the data flow has two ends. You send an event to Meta, and Meta has it: one recipient, one set of terms, one retention policy.

An affiliate network is not an endpoint. It is a routing layer, and routing is its entire function. When a conversion lands, the network relays it onward. Publisher postbacks fire to the publisher's own tracking system. Sub-affiliate networks relay it again. Coupon and loyalty publishers reconcile it into user-level account systems, because their model requires tying the transaction to a member account. Content publishers running paid acquisition to feed the program may then report the conversion into their own ad platform accounts, which is how a conversion reaches a social network by a path that appears nowhere in your tag manager.

Three properties of that chain matter. The publisher roster is not fixed at contract time, because programs recruit continuously. Sub-identifier fields are populated by the publisher and returned on the conversion, so a third party controls part of your payload. And you have no visibility into what a publisher does with a postback, and no privity with sub-affiliates.

For a covered entity that is a difficult posture to defend. The Security Rule expects you to know where protected health information goes and to hold agreements with the parties handling it, and a distribution chain that expands without your involvement is at odds with that. See why a signed BAA is not enough under the Security Rule, and what the Curve BAA covers.

The Contract Gap

Ask for the data protection terms in an affiliate agreement and you usually find one of three things. No addendum at all, only commissions, cookie windows and payment schedules. A general privacy clause drafted for consumer retail that references applicable law without contemplating health information. Or, most commonly, terms prohibiting the advertiser from transmitting sensitive data, which places the obligation on you and gives the network a defense rather than giving you protection.

Almost no affiliate network offers a business associate agreement. That is not evasion, it reflects what the business is: a marketplace routing transaction data between many parties, at odds with the closed chain of custody a BAA requires. The answer is not to force a BAA onto a network that cannot honor it. It is to ensure what reaches the network is not protected health information in the first place, a design decision about the payload rather than a contract negotiation.

How This Fits the Rest of the Complaint

Paragraph 66 quotes what Hims published about privacy: "100% online, private, and secure," treating conditions "privately," "totally private," "discreet." Paragraph 74 alleges Hims was only able to create audiences with such specificity because it flouted those promises. Paragraph 70 describes Meta's server-side Conversions API accurately and pleads it as a sharing vector regardless, which matters here because affiliate postbacks are server-to-server by design. Moving from pixels to postbacks for reliability did not move a partnerships team out of scope. See why server-side tracking alone is not HIPAA compliance.

The trajectory is steep. GoodRx and BetterHelp were resolved administratively in 2023, while this matter is litigated with civil penalties sought and two states as co-plaintiffs. The broader pattern is tracked in our mid-2026 healthcare pixel settlement roundup. Hims denies the allegations and intends to defend the case.

A Practical Checklist for Partner Programs

  1. Inventory every partner, affiliate, referral and print-response relationship, including dormant ones and those run by outside agencies.
  2. Load a completed order confirmation page with network recording on and capture every outbound request, including image pixels and redirect chains.
  3. Inspect each payload field by field, looking for product name, SKU, category and any custom field a network requested.
  4. Trace server-side postbacks, which never appear in the browser. Review backend integration code and tag management server configuration.
  5. Ask each network in writing which downstream parties receive conversion data, and read the executed agreements for where the obligation sits.
  6. Decide what a partner needs to reconcile a payout. Usually an order identifier, a value and a click identifier, almost never a medication. Route what remains through a sanitized server-side path so the decision is enforced by infrastructure rather than tag configuration.

Frequently Asked Questions

Does an affiliate network count as a business associate under HIPAA?

If a covered entity discloses protected health information to it while performing a function on their behalf, the relationship raises business associate questions, and the absence of a BAA is then a problem in itself. Most networks will not sign one. The practical route is to design the conversion payload so it contains no protected health information, a technical control rather than a contractual one. Counsel should make the call for your specific structure.

Our affiliate program is run entirely by an outside agency. Are we still responsible?

The data leaves your website, from your pages, under your privacy policy. Delegating operations does not delegate the disclosure. An agency-managed program deserves closer review, not less, because the tags were installed by someone outside your organization and often years before the current team arrived.

We use server-to-server postbacks instead of pixels. Does that solve it?

No. Paragraph 70 describes server-side transmission accurately and pleads it as a sharing vector anyway, and paragraph 77 separately identifies Google Ads S2S and TikTok s2s. Postbacks change where the request originates, not what is in it. Protection comes from sanitizing the payload before it leaves your infrastructure.

What about print advertising? There is no pixel in a magazine.

The ad is not the tracking. The response mechanism is. Vanity URLs, coupon codes and tracking phone numbers resolve into digital or telephony systems that record who responded and to which condition-targeted placement. Print-response vendors need a conversion signal from your site to close the loop, which is how a print vendor ends up with a tag on a checkout page.

Can we keep the affiliate program at all?

Usually yes. Affiliate economics work on order value and order identifiers. Strip the product and category detail from the payload, hold a defensible position on what the network receives, and the program still functions. What does not work is transmitting the full retail commerce payload and assuming the network's standard terms cover you.

This article reflects the public record as of July 2026, drawn from the redacted complaint e-filed on ftc.gov. Hims & Hers denies the allegations, states that its privacy policy makes clear that users may choose how their data is used, and intends to defend the case. No court has made any finding, and no vendor in paragraph 77 is a defendant.

If your partner programs are sending conversion data you have never inspected, the fix is a single governed path rather than a dozen tag configurations. Curve sanitizes events server-side before egress, forwards only what each destination needs, and provides a BAA for its own processing, so affiliate attribution and commission reconciliation keep working without protected health information entering a distribution chain you do not control. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.