PebblePost and Programmatic Direct Mail: The Healthcare Privacy Risk the FTC Named
Of the advertising vendors listed in the Federal Trade Commission's complaint against Hims & Hers Health, Inc., one converts website browsing into physical mail delivered to a home address. PebblePost.com appears in paragraph 77 among the pixels allegedly placed on the company's platforms. PebblePost is not a defendant and is not accused of wrongdoing. But the category it represents, programmatic direct mail, deserves separate attention, because it is the one channel where a digital tracking decision produces a physical object in someone's mailbox, and because almost no healthcare compliance review has ever evaluated it as a pixel at all.
Curve is a HIPAA-compliant conversion tracking platform that keeps protected health information out of every advertising destination, including the identity-resolution vendors that convert web behavior into offline outreach. When the output of a tag is a postcard, boundary controls stop being an abstraction.
The case is Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., Case No. 3:26-cv-7871, U.S. District Court for the Northern District of California, filed in late July 2026. Nothing has been proven. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and intends to defend the case.
The Short Version
- Programmatic direct mail uses a site tag to observe onsite behavior, then triggers a printed mailpiece to a matched postal address, typically within days.
- The mechanism requires resolving an anonymous browser to a real household. Identity resolution is not a side effect here, it is the product.
- Paragraph 67 defines the shared data as "Events", meaning "the actions of website visitors on Hims' website." Those actions are what triggers the mail.
- The disclosure does not end at the vendor. A mailpiece arrives at an address shared with family, roommates or a mail room, legible to anyone who handles it.
- Direct mail is usually budgeted as offline marketing, so its tag rarely appears in a pixel inventory. That is the blind spot this article exists to close.
- Paragraph 66 alleges Hims promised care that was "100% online, private, and secure", "totally private" and "discreet". A postcard is the least discreet possible output of a browsing session.
How Programmatic Direct Mail Actually Works
The category brings the mechanics of digital retargeting to postal mail. The steps are worth spelling out, because most people picture something far more manual.
First, a JavaScript tag goes on the advertiser's website exactly as a retargeting pixel does. It observes page views and defined events: which service pages were viewed, whether a cart or intake flow was started, whether a form was abandoned.
Second, the visitor is matched to a household. This is the step with no digital analogue. The vendor operates or licenses an identity graph associating online identifiers with postal addresses, built from cooperative data, transactional records, publisher relationships and other offline sources. The match may be deterministic, using a known identifier, or probabilistic, using signals such as device, network and location. Match rates are never one hundred percent, which has consequences discussed below.
Third, a trigger rule decides whether the behavior qualifies for a mailing. The rules are ordinary automation logic: viewed a category and did not convert within a set window, abandoned a checkout, browsed repeatedly.
Fourth, the creative is composed, frequently with dynamic content reflecting what the person browsed, then printed and entered into the postal stream. A piece can arrive within days of the session that caused it. Response is then measured by matching later site visits or purchases back to the mailed household, which closes the loop and produces the attribution reporting that justifies the spend.
For a furniture retailer this is a clever, effective channel. Now replace the browsing behavior with a page about a medical condition.
Why This Is Different From Every Other Pixel on the List
The other vendors in paragraph 77 create digital exposure: an event lands in a platform, informs an audience, and affects which ads are served. The harm is real but abstract, and usually visible only to the person holding the device. Programmatic direct mail produces three distinct exposures instead of one.
The identity resolution itself. To send mail, the system must convert "a browser that viewed a condition page" into "a named person at a specific street address." That transformation is what HIPAA's de-identification concepts exist to prevent, and here it is a required workflow step rather than an accidental leak. Any argument that the tracking data was anonymous fails immediately, because the channel does not function unless the data becomes identified.
The mailpiece as a physical artifact. A postcard has no login. It arrives in a shared mailbox, gets carried inside by whoever collects the mail, and sits on a counter. If the creative references the treatment category the person browsed, the health interest is disclosed to a spouse, a parent, an adult child, a roommate or a building mail room. Consider the categories telehealth companies commonly advertise: sexual health, mental health, weight management, hair loss, fertility, substance use. These are exactly the categories where people take deliberate steps to avoid disclosure at home, and paragraph 66 alleges the promises included treating conditions "privately" and an experience that was "discreet".
Mismatch. Identity resolution is probabilistic at the margins. When a match is wrong, a mailpiece implying a health interest arrives at the wrong household or is addressed to a former resident. There is no digital equivalent, because a misdelivered impression is invisible and a misdelivered postcard is not.
How Curve Handles Offline and Identity-Resolution Destinations
Curve sits between your site and every advertising destination and sanitizes events server-side before they leave your infrastructure, so a vendor receives a conversion signal rather than a behavioral record. Condition-naming URL paths, treatment identifiers, quiz and intake parameters and form field values are removed or normalized before egress, so a destination that performs identity resolution cannot key a mailing to a clinical attribute it never received. Destinations are configured independently, letting an offline vendor be scoped far more tightly than a search platform, and every field sent to every destination is enumerable rather than inferred. Protected health information does not reach the ad platform, and Curve makes a business associate agreement available for the tracking layer, documented in what Curve's BAA coverage includes. Attribution still works, because the trigger and the measurement are built on sanitized events rather than page-level browsing history.
The Compliance Blind Spot Nobody Planned
Ask a healthcare marketing team for a list of their tracking pixels and you will get search, social, analytics, and if you are lucky the affiliate tag. Almost never the direct mail vendor, for three structural reasons.
It is budgeted as offline. Direct mail sits under a different line item, often owned by lifecycle, CRM or retention rather than digital acquisition. The review that covers "our website tracking" never reaches it, because organizationally it is not website tracking.
The word "mail" suppresses the right question. Compliance teams have a mental model for mailing lists: you have a list, you mail the list. Nobody expects the trigger to be a page view captured seconds earlier.
The vendor is invisible to the user. A person who receives a postcard cannot know a website tag caused it. There is no ad preferences page and no "why am I seeing this" disclosure, so the feedback mechanisms that surface digital tracking to consumers, and therefore to journalists and regulators, do not exist here.
Add the accumulation dynamic that paragraph 77 documents. The complaint lists Microsoft's Bing Pixel and Bing Image Pixel, Google's Ads Pixel and Ads S2S Pixel, Criteo, MediaBids.com, PartnerCentric, PebblePost.com, Pinterest, Podsights, Reddit, StackAdapt, TikTok s2s, The Trade Desk and X, with paragraph 76 separately alleging customer list uploads to Snap. No single decision created that surface. Many reasonable ones did, across years and teams. Paragraph 78 adds that Hims acknowledged privacy and consumer-protection regulatory risk in SEC filings since 2021 and received a Civil Investigative Demand in October 2023.
What to Check If You Run Programmatic Direct Mail
- Confirm whether you have this tag at all. Search your tag manager and page source for any direct mail or onboarding vendor tag, and ask lifecycle and retention teams directly, since the digital team often does not know it exists.
- Read the trigger rules in the vendor platform. This is the core question. If any trigger is defined by visits to a condition, treatment or medication page, the campaign is keyed to a health attribute. Rules are configured once and rarely revisited.
- Inspect what the tag transmits. Page URL and referrer are the standard carriers, and on a healthcare site the URL usually names the condition because search optimization requires it.
- Look at the creative logic. Dynamic creative composed from browsed content turns an internal data flow into a printed disclosure at a residential address.
- Trace the intake and form flow. Multi-step intake and eligibility quizzes leak more than any other template, a pattern covered in medical intake form tracking leak points. An abandoned-intake trigger is among the most common direct mail rules and the most sensitive.
- Check whether any customer file was uploaded for suppression or targeting. Uploading a list of existing patients so they do not receive prospecting mail is a disclosure of who your patients are, even when the intent is protective.
- Establish the contract. Determine whether a business associate agreement exists or only a commercial data agreement, and get the vendor's retention period for matched identity data.
- Test consent behavior. Verify whether the tag actually blocks before consent, and understand that a cookie banner is not a HIPAA authorization.
The Legal Framing Is Not Novel, Only Unfamiliar
Nothing here requires a new legal theory. Under Section 5(a) of the FTC Act, the question is whether representations to consumers were true. If a company tells users its service is private and discreet while a site tag causes a postcard referencing their browsing to arrive at their home, the gap between promise and practice is easy for a regulator to describe and easy for a jury to picture.
Under HIPAA, the question is whether individually identifiable health information was disclosed to a third party for marketing without valid authorization. Here identifiability is not contestable, because the vendor must identify the household to deliver the mail. That removes the argument most often advanced in digital pixel disputes.
The enforcement trajectory is clear. GoodRx settled with the FTC in February 2023 for 1.5 million dollars, and BetterHelp settled in March 2023, ultimately at 7.8 million dollars. The Hims matter, filed in July 2026, is being litigated rather than settled at filing, seeks civil penalties, and adds two state co-plaintiffs. That is escalation, not a repeat, and it sits within a pattern documented in FTC enforcement actions against virtual care advertisers, the mid-2026 settlement roundup, and the Cerebral pixel settlement.
Can Healthcare Brands Use Programmatic Direct Mail at All?
Yes, with the trigger disconnected from clinical behavior.
Mail to a geographic or demographic prospecting audience, with creative that speaks to the brand rather than to a condition someone browsed. Trigger from a neutral action such as a general account signup, not from a condition page view or an abandoned intake. Keep the creative category-neutral so a piece arriving at a shared household discloses nothing about the recipient. Send the vendor a sanitized conversion event rather than page-level browsing, so the identity resolution it performs is not attached to a health attribute. And run suppression on your side rather than by uploading a patient file, because a suppression list is a patient list with a friendlier name.
Those constraints remove the channel's sharpest targeting advantage. They also leave a channel you can defend in writing, which is the trade the current enforcement environment asks every healthcare advertiser to make.
Frequently Asked Questions
Is PebblePost HIPAA compliant?
Programmatic direct mail vendors operate under commercial advertising agreements rather than as HIPAA business associates, and the workflow depends on resolving visitors to postal identities. For a healthcare advertiser, the practical requirement is to ensure the vendor never receives data reflecting a condition, treatment or clinical interest. Start any assessment with the trigger rules in the vendor account, not with marketing materials.
Is PebblePost being sued by the FTC?
No. PebblePost.com is named in paragraph 77 as one of the pixels allegedly placed on Hims platforms. The sole defendant is Hims & Hers Health, Inc., and the allegations concern the advertiser's alleged data sharing and alleged privacy representations. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and will defend the case.
How does a website visit turn into a piece of mail?
A site tag records the visit and the events on the page, the vendor matches the visitor to a household postal address using an identity graph, a trigger rule decides the behavior qualifies, and a piece is printed and entered into the mail stream, often within days. Response is measured by matching later site visits or purchases back to the mailed household.
Does a postcard that does not mention a condition solve the problem?
It removes the household disclosure, which is meaningful and worth doing. It does not remove the underlying issue, because the vendor still received behavioral data indicating a health interest and still resolved it to an identified person. Neutral creative addresses one of the three exposures, not all of them.
Direct mail is offline. Why is it in a pixel discussion?
Because the trigger is a pixel. The mailpiece is offline, but the collection that causes it is a JavaScript tag reporting visitor behavior to a third party, the same mechanism at issue in every pixel case of the last three years. Budget category has no bearing on how a regulator characterizes the data flow.
What should we do first if we find this tag on our site?
Pause the campaigns before you start negotiating, then read the trigger rules. If any trigger references a condition, treatment or intake page, keep that campaign paused until the trigger is rebuilt on a neutral event. Fixing the trigger is faster than fixing the contract and removes more risk.
This article reflects the public record as of July 2026, drawn from the redacted complaint e-filed on ftc.gov. All allegations described are allegations only and have not been proven.
If a tag on your site can cause mail to arrive at a patient's home, it deserves the same scrutiny as your Meta and Google integrations, and it almost certainly has not received it. Curve gives healthcare advertisers one sanitized egress point to every destination, offline and identity-resolution vendors included, with a business associate agreement covering the tracking layer. See how it works at curvecompliance.com.
Keep exploring
Related articles
Pharmaceutical DTC Advertising Compliance 2026: FTC and FDA Rules for Direct-to-Consumer Health Claims
Read articleGoodRx to BetterHelp to Hims and Hers: The FTC's Health Privacy Enforcement Trajectory
Read articleStackAdapt Pixel in Healthcare Advertising: What the FTC's Hims and Hers Case Flags
Read articleStay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.