Skip to main content
Article

Podsights, Spotify Ad Analytics, and Podcast Attribution: Named in the FTC's Hims Complaint

Podcast attribution cannot work without a pixel on your most sensitive page. That is not a configuration choice, it is the method. There is no click to follow from an audio ad, so the entire technique depends on observing a visitor on the advertiser's own site and matching them backward to an impression. The conversion page, which on a telehealth site is usually the most revealing page in the funnel, becomes a mandatory instrumentation point rather than an optional one.

That is why Podsights, now Spotify Ad Analytics, is worth separating from the display and social entries in the same list. It appears in paragraph 77 of the FTC's complaint against Hims & Hers Health, Inc., filed as Podsights_iHeartMedia, among tracking technologies the agency alleges transmitted "Events," defined in paragraph 67 as "the actions of website visitors on Hims' website." None of this has been proven. Hims has denied the allegations, says its privacy policy makes clear that users may choose how their data is used, and intends to defend the case.

For healthcare advertisers who want the attribution without the exposure, Curve is a HIPAA-compliant conversion tracking platform that attributes podcast, audio and every other paid channel without sending protected health information to measurement or ad platforms.

There is a second detail that makes this entry sting more than the others. Paragraph 66 of the complaint notes that Hims' privacy promises appeared in television, radio and podcast advertising, not only on the website. The same channel that carried the promise carried the measurement tag that the FTC alleges undercut it.

The Short Version

  • Podsights, the podcast attribution product Spotify acquired in 2022 and now operates as Spotify Ad Analytics, is named in paragraph 77 of the complaint as one of the pixels allegedly present on Hims platforms.
  • Podcast attribution has no click. It matches an ad impression to a site visit using signals such as IP address and user agent within an attribution window, which means it needs a pixel on your conversion page by design.
  • Paragraph 66 alleges the privacy claims ran in podcast advertising specifically, putting the promise and the measurement in the same channel.
  • Audio media is usually bought by a media agency or a network sales team, and the attribution pixel arrives inside an insertion order rather than a technical review. Compliance is rarely in that conversation.
  • IP-based matching is household-level rather than person-level, which is worse for accuracy and no better for privacy.
  • Promo codes and vanity URLs are weaker measurement but carry a fraction of the exposure, and they are a legitimate fallback while you fix the pixel path.

What the Complaint Alleges, Briefly

The case is Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., Case No. 3:26-cv-7871, filed in the Northern District of California in late July 2026. It pleads FTC Act Section 5(a), ROSCA Section 4, California's Unfair Competition Law and False Advertising Law, and Utah's Consumer Sales Practices Act. The plaintiffs seek a permanent injunction, a monetary judgment, and a civil penalty judgment.

The privacy counts rest on a straightforward theory. Paragraph 66 sets out the promises: "100% online, private, and secure," conditions treated "privately," an experience described as "totally private" and "discreet." Paragraph 67 says sharing occurred through Events. Paragraph 74 alleges that the resulting audience specificity was only possible because those promises were flouted. Paragraph 77 lists the platforms. Paragraph 78 establishes that Hims had notice of regulatory risk, citing SEC filings from 2021 onward and a Civil Investigative Demand the FTC issued in October 2023.

The through line matters more than any individual vendor name. The FTC is not arguing that a particular pixel is illegal. It is arguing that a company said one thing to consumers and did another with their data, and that the gap between the two is a deceptive practice. This is the same theory that produced the BetterHelp settlement, escalated from a settlement posture to litigation with civil penalties and two state co-plaintiffs.

How Podcast Attribution Actually Works

Audio has no click. A listener hears a host read a code, or a dynamically inserted spot, and then does something later on a different device in a different context. Every podcast attribution product exists to close that gap, and they all close it the same way.

On the delivery side, the podcast host or ad server records the request that downloaded the episode. That request carries an IP address and a user agent string, because it is an ordinary HTTP request from a podcast app. The attribution platform receives a log of those impressions, including which ad was in which episode at what time.

On the advertiser side, a pixel on your website records the IP address and user agent of visitors, along with the page they landed on and whatever events you have configured. The attribution platform then looks for overlap. If an IP that downloaded an episode containing your ad shows up on your site within the attribution window, that visit is credited to the podcast.

Three consequences follow directly from this design, and every healthcare advertiser running audio should understand all three.

  • The pixel must be on the conversion page. An impression matched to a home page visit tells the buyer nothing about return on spend. The measurement only becomes useful at the point of purchase, signup or intake completion. That is precisely the page whose URL and context reveal the condition.
  • The match key is the household, not the person. IP-based matching cannot distinguish between people behind the same router. The listener and the site visitor may be different family members. This is a well-known accuracy limitation, and it does not reduce the privacy exposure at all, because the record that leaves your site is still tied to a specific visit to a specific page.
  • The attribution window is long. Podcast windows routinely run to thirty days, which means the platform is retaining impression logs and site-side observations long enough to join them. Data retention on the measurement vendor's side is part of your exposure whether or not you have ever asked about it.

Spotify Ad Analytics also supports server-side event delivery for advertisers who prefer not to load a browser tag. That helps only if you use the server as a place to change what you send. Our piece on why server-side tracking alone is not HIPAA compliance explains why the transport layer is not the control.

What a Curve-Style Setup Does Differently for Audio

Curve receives conversion events first-party from your own site, sanitizes them on the server before anything leaves, and then delivers a cleaned payload to each configured destination. For an audio measurement destination that means the platform gets the timing and the conversion signal it needs to attribute the impression, without the condition-bearing URL path, the intake responses, or direct identifiers riding along. Destinations are configured individually, so what Spotify Ad Analytics receives can be narrower than what a search platform receives, and neither one gets the raw event. Curve signs a business associate agreement, which measurement and ad platforms do not offer, so the sanitization has to happen before the handoff rather than being papered over afterward. If you are planning audio campaigns from scratch, our guide to Spotify podcast advertising and HIPAA audio attribution covers the campaign-side decisions that pair with this.

The Ad Read Is Also the Privacy Promise

Paragraph 66 is the part of this complaint that podcast advertisers should read twice. The FTC did not confine itself to the website. It alleges the privacy claims appeared in television, radio and podcast advertising, which puts host-read copy squarely inside the deception theory.

Direct-response audio copy in the health category almost always leans on discretion. The whole selling proposition of telehealth for a stigmatized condition is that you do not have to sit in a waiting room. Words like private, discreet and confidential are not decoration in an audio script. They are the offer. That makes them representations, and representations that a regulator can measure your conduct against.

The practical implication is uncomfortable but simple. If your host-read script promises privacy, and the same campaign is measured by a pixel that reports condition-specific conversions to a third party, the FTC's theory says those two facts sit in tension. Reviewing audio scripts for privacy claims is a compliance task, not a brand task, and most organizations have never routed them that way. Our overview of FTC telehealth enforcement actions covers how consistently the agency reaches for advertising copy in these cases.

Why Audio Buyers Rarely Involve Compliance

There is a procurement reason this specific pixel gets missed, and it is worth naming because it is fixable.

Web pixels usually arrive through a marketing operations person who has at least seen a tag manager. Audio attribution pixels arrive differently. A media agency or a podcast network sells the buy, the insertion order includes measurement, and a paragraph in that document asks the advertiser to place a pixel so the campaign can be attributed. The task then goes to whoever can edit the site, often as a one-line request with no context about what the pixel collects or which pages it needs to be on. In many organizations the answer to "where should this go" is "everywhere," because that is the least effortful implementation and it maximizes match rates.

Nobody in that chain is behaving badly. The media buyer is buying media, the network is proving value, and the developer is completing a ticket. But no one in the chain owns the question of whether a request from a page named after a medical condition should be leaving the building. This is exactly the class of tag our PHI leakage audit walkthrough is designed to surface, because it never appears in the tracking documentation that marketing maintains.

What to Check This Week

  1. Search your site and tag manager for audio measurement tags. Look for Podsights and Spotify Ad Analytics tags, plus any network-specific pixels from podcast sellers. Check both the container and the page source, because these are frequently hardcoded rather than containerized.
  2. Determine which pages they fire on. If the answer is all pages, you are sending a request from every condition page you operate. Narrow it to what the measurement actually requires.
  3. Read the outbound payload from your confirmation page. Open the network panel, complete a test conversion, and look at what leaves. Page URL, referrer and any event parameters are the fields to scrutinize.
  4. Pull every insertion order signed in the last two years. Measurement obligations are contractual. Find out what you agreed to place, and whether it was ever removed when the flight ended. Expired campaigns leave live pixels behind more often than anyone expects.
  5. Ask the vendor about retention. Attribution windows imply storage. You should be able to state, in writing, how long a measurement partner keeps site-side observations tied to your domain.
  6. Review the scripts. Every host-read and produced spot currently in rotation, checked for privacy and confidentiality claims. Then check whether your tracking configuration is consistent with them.

Frequently Asked Questions

Is Podsights the same thing as Spotify Ad Analytics?

Yes. Spotify acquired Podsights in 2022 and the product now operates as Spotify Ad Analytics. The FTC complaint uses the older name, listing it as Podsights_iHeartMedia in paragraph 77, which suggests the integration ran in connection with iHeartMedia podcast inventory. Advertisers who signed a Podsights insertion order years ago may have the tag on their site under a name they no longer recognize.

Can a podcast attribution pixel see medical information?

It can see the pages a visitor loads on your site and whatever event data you configure. On a telehealth site the page path frequently names the condition, which means a plain page view can communicate a treatment interest without any special payload. The complaint's definition of Events in paragraph 67 covers exactly this: actions of website visitors, not medical records.

Do we have to stop advertising on podcasts?

No. Audio is a legitimate and effective channel for telehealth, and nothing in the complaint suggests otherwise. The question is how the campaign is measured. You can keep the media and change the measurement, either by routing events through a compliant layer that sanitizes before egress or, as a temporary step, by falling back to promo codes and vanity URLs while the pixel path is fixed. Our audio campaign compliance guide goes through the tradeoffs.

Does a business associate agreement with the podcast network solve this?

Podcast networks and audio measurement platforms do not sign business associate agreements with advertisers, and the FTC Act theory in this complaint does not depend on HIPAA at all. Section 5 deception is about the gap between what you told consumers and what you did. A contract with your vendor does not close that gap if your public promises still say the experience is private.

Is server-side delivery to Spotify Ad Analytics safer than the browser pixel?

Only if you use the server step to remove things. Paragraph 70 of the complaint describes Meta's server-side Conversions API accurately and pleads it as a sharing vector regardless, and paragraph 77 names two more server-side integrations. The FTC is looking at what arrived at the platform, not how it traveled.

This article reflects the public record as of July 2026 and describes allegations in a complaint that has not been adjudicated. The filing is available as the redacted e-filed complaint on ftc.gov.

If you buy podcast media for a healthcare brand and cannot say today which pages your attribution pixel fires on, start there. Curve gives healthcare advertisers audio and web attribution that keeps working while protected health information stays on your side of the line, with a business associate agreement in place. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.