Skip to main content
Article

Private, Discreet, Secure: How Marketing Copy Becomes a Legal Liability in Health Privacy Cases

The deception count in the FTC's complaint against Hims & Hers is not built from leaked data. It is built from sentences the company published about itself. Paragraph 66 quotes them directly: the service is "100% online, private, and secure," conditions are treated "privately," the experience is "totally private" and "discreet." The complaint notes those promises appeared in television, radio, and podcast advertising as well as on the website. The FTC then alleges that, contrary to those promises, sensitive health information was shared with third-party advertising platforms.

That is the whole mechanism, and it is worth sitting with. Your marketing copy sets the standard you are measured against. A competitor who says nothing about privacy has a smaller deception surface than you do, regardless of whose tracking stack is cleaner. Curve is a HIPAA-compliant conversion tracking platform that keeps protected health information from reaching ad platforms, which is what lets a healthcare marketer make privacy claims that the underlying system can actually support.

None of this is proven. Case No. 3:26-cv-7871 in the Northern District of California, brought by the FTC together with the People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison, and the Utah Division of Consumer Protection, is being litigated. Hims has denied the allegations, says its privacy policy makes clear that users may choose how their data is used, and intends to defend the case.

The Short Version

  • Under Section 5(a) of the FTC Act, a deception claim needs a representation, materiality, and a likelihood of misleading a reasonable consumer. Your own marketing supplies the first element for free.
  • Paragraph 66 of the complaint quotes four specific phrases, including absolute language such as "100%" and "totally," which leave no room for the partial truth most tracking stacks can support.
  • Spoken advertising counts. TV, radio, and podcast copy is explicitly referenced in the complaint, and it is the copy no compliance reviewer ever reads.
  • A privacy policy disclosure does not reliably cure a headline claim. Regulators evaluate the net impression a consumer takes away, not the most careful sentence on the site.
  • The practical audit is a claim-to-control mapping: for each privacy promise, name the technical control that makes it true and the person who owns that control.
  • Where no control exists, you have two honest options. Build the control, or change the words.

How a Deception Count Gets Assembled

The FTC's deception analysis is not complicated, which is part of why it is dangerous. The agency looks for a representation, express or implied, that is material to a consumer's decision and likely to mislead a consumer acting reasonably under the circumstances. Materiality is presumed for express claims about central attributes of a service. Privacy is a central attribute when you sell treatment for conditions people prefer not to discuss.

Notice what is absent from that test. There is no requirement to prove a specific consumer was harmed, no requirement to quantify damages, and no requirement to establish a breach in the security sense. The gap between the promise and the practice is the violation, which is why an enforcement theory built on marketing copy is cheaper to run than one built on forensic reconstruction of ad tech.

Paragraph 74 of the complaint shows how the two halves lock together. It alleges that Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private." The quoted word in that sentence is Hims' own. The complaint is using the company's vocabulary as the measuring stick and then arguing the operations did not meet it.

Reading the Four Phrases

Each phrase in paragraph 66 fails in a different way, and the differences are instructive if you are auditing your own copy.

"100% online, private, and secure"

The problem is the quantifier. Absolute language forecloses the qualified defense that most companies would actually want to make, which is that data handling is careful, limited, and governed. "100%" admits no exceptions, so a single unaccounted-for egress path contradicts it. Marketing writes absolutes because they convert. Legal exposure scales with them exactly as fast.

Treats conditions "privately"

This one reads as a description of the clinical experience, and consumers plausibly hear it that way. The FTC reads it as a promise about information handling. When a phrase can be read both ways, assume a regulator will adopt the reading that is harder for you to satisfy, because a reasonable consumer could too.

"Totally private"

Same absolute problem as the first, with an additional wrinkle. "Private" has no fixed technical meaning, so the claim inherits whatever meaning the consumer brings. Most consumers hear "nobody else finds out," which is a far broader commitment than any engineering team was asked to deliver.

"Discreet"

Discretion is specifically a promise about who learns something. In telehealth marketing the word usually refers to packaging and billing descriptors, but the harm alleged in pixel cases is precisely that a third party learned something, and an ad that follows someone around the internet after a hair loss consultation is the least discreet possible outcome. The word and the alleged conduct sit in direct opposition.

Where Curve Fits in a Claim You Can Actually Keep

The reason marketing copy becomes a liability is that the promise and the plumbing are owned by different teams who rarely read each other's work. Curve narrows that gap on the plumbing side. Events are collected first-party on your own domain, sanitized server-side so that protected health information is removed before any outbound request, and then forwarded to each ad platform destination under a configuration you control per platform. A BAA is available for the layer that handles the data, which matters because the ad platforms themselves will not sign one. Our breakdown of what BAA coverage actually includes is worth reading before you write any copy that mentions agreements.

What that buys a marketing team is narrower than "you can say anything," and that is the point. It lets you write a specific, checkable claim, such as stating that your advertising measurement does not transmit health information to ad platforms, and then point at a configuration that makes the sentence true.

The Copy Surface Nobody Audits

Website copy gets reviewed. It sits in a CMS, someone owns it, and legal has seen the homepage. The exposure lives everywhere else.

  • Voiceover and broadcast scripts. The complaint specifically notes TV, radio, and podcast advertising. A thirty-second radio spot is written by a copywriter, approved by a brand manager, recorded, and aired. In most organizations it never touches a compliance queue, and there is no archived text version to audit later, only an audio file.
  • Podcast host reads. Hosts improvise around talking points. That is what advertisers pay for. It also means the actual words broadcast to hundreds of thousands of listeners were never written down by anyone at your company. If you buy audio, keep the talking points tight and keep the recordings. The measurement side of audio has its own quirks, which we cover in podcast advertising attribution for healthcare.
  • Affiliate and partner copy. Paragraph 77 lists partners including MediaBids.com and PartnerCentric alongside the ad platforms. Affiliate networks generate enormous volumes of promotional copy that you did not write and may never see, and claims made by an affiliate on your behalf are a familiar source of liability.
  • Quiz and intake microcopy. The reassurance text next to a sensitive question, usually something like "your answers stay private," is written by a product designer optimizing completion rate. It is a privacy representation made at the exact moment a user discloses a condition.
  • Trust badges and iconography. A padlock graphic with the word secure, or a badge asserting HIPAA compliance, is a claim in visual form. Badges asserting certifications you do not hold are their own category of problem.
  • Lifecycle email, SMS, and chatbot responses. Templated once, then running for years without a re-read, and chatbot answers about data handling are often generated rather than authored.
  • Sales and support scripts. Anything a human says to reassure a hesitant prospect is a representation, whether or not it was approved.
  • App store listings and paid search ad copy. Short-form formats push writers toward absolutes, because character limits punish nuance.

The Claim-to-Control Audit

The exercise that surfaces real problems is boring and takes about a week. It works like this.

  1. Inventory every privacy claim across every surface above. Export site copy, pull two years of ad creative from platform ad libraries, collect VO scripts and host talking points from your media agency, dump email and SMS templates, and screenshot the intake flow end to end.
  2. Write each claim as a testable statement. "Totally private" becomes "no third party receives information indicating this user sought treatment for X." If a claim cannot be rewritten as something testable, that is itself the finding.
  3. Name the control for each statement. Which system enforces it? A tag configuration, an egress filter, a contract, an access policy. If the answer is a policy document rather than a mechanism, mark it.
  4. Name the owner. A control with no owner is a control that will drift. Most privacy regressions come from a well-meaning change by someone who never saw the claim.
  5. Test the control. Capture actual outbound traffic and server-side payloads. Documentation and intent are not evidence.
  6. Resolve every gap in one of two directions. Build the control, or rewrite the copy. Leaving a claim in place with a plan to fix the system later is the position that reads worst in hindsight.

One nuance on consent language. Cookie banners are frequently drafted as though consent solves the underlying question, and in a HIPAA context it usually does not, because HIPAA authorization is a different instrument with different requirements. The distinction is laid out in consent management versus HIPAA authorization, and it matters for copy because a banner implying consent was obtained for something it never covered is itself a representation.

Why Timing Makes Copy Worse

Paragraph 78 of the complaint addresses knowledge. It alleges that Hims acknowledged privacy and consumer-protection regulatory risk in SEC filings beginning in 2021, and that the FTC issued the company a Civil Investigative Demand in October 2023. In a deception case, dates like those change the character of the claim. Copy published before anyone in the industry understood pixel risk reads as negligence. The same copy still running after a regulator has asked you formal questions reads differently.

The operational implication is that a privacy claim is not a one-time approval. It is a standing commitment that has to be re-verified whenever the system underneath it changes, and every tag deployment, vendor addition, and agency handoff is such a change. That is the pattern across the enforcement line, from GoodRx settling in February 2023 for $1.5 million to BetterHelp settling in March 2023 at ultimately $7.8 million. Both turned substantially on the distance between published assurances and operational reality, a point we unpack in the BetterHelp settlement lessons. The Hims filing escalates that pattern, with civil penalties sought and two state enforcers as co-plaintiffs. The wider trajectory is tracked in FTC telehealth enforcement actions.

Copy That Holds Up

Being careful does not require being vague or defensive. A few patterns survive scrutiny better than others.

  • Prefer specific to absolute. "We do not send information about your treatment to advertising platforms" beats "totally private," because it is narrow enough to be true and concrete enough to reassure.
  • Describe mechanisms, not feelings. "Shipped in unmarked packaging" is verifiable. "Discreet" invites the reader to fill in a broader meaning.
  • Keep claims where the control lives. If shipping is discreet but ad measurement is not, do not let a shipping claim sit in a headline a reader will apply to everything.
  • Avoid asserting certifications or determinations you do not hold, including audit standards and formal de-identification determinations.
  • Scrutinize spoken and partner copy the way you scrutinize the homepage. That is where quotable absolutes survive.

The commercial fear is that careful copy converts worse. In categories with real stigma, the opposite is often true, because the audience is skeptical and reads closely. Specific claims signal that someone thought about the problem. The rules around those categories are tightening independently, which we cover in GLP-1 telehealth marketing compliance.

Frequently Asked Questions

Can my privacy policy fix an overstated marketing claim?

Generally not on its own. The FTC evaluates the net impression a reasonable consumer takes from an advertisement, and a qualification buried in a policy document that most users never open is unlikely to cure a prominent headline claim. Disclosures work best when they are clear, close to the claim, and hard to miss.

Do radio and podcast ads really create the same exposure as web copy?

Yes. The medium does not change the analysis, and the complaint against Hims specifically references television, radio, and podcast advertising when quoting the privacy promises at paragraph 66. Audio is riskier in practice because scripts are rarely archived and host reads deviate from the approved text.

What if an affiliate makes a privacy claim we never approved?

Advertisers have historically been held responsible for claims made by affiliates promoting their products, particularly where the advertiser controls the program and its incentives. Contractual prohibitions help, but they work only alongside actual monitoring of what partners publish.

Is the word "secure" safe to use?

It is usable when it refers to something specific and true, such as encryption in transit or access controls. It becomes a problem standing alone as a general assurance, because consumers hear a comprehensive statement about who can learn what, which is a much larger claim than any security control delivers.

How often should we re-audit our privacy claims?

Tie the review to system change rather than the calendar. Any new advertising destination, tag manager change, vendor addition, agency transition, or site redesign can invalidate a standing claim. A quarterly sweep plus a change-triggered check suits most teams.

Does this complaint mean healthcare companies should stop advertising privacy?

No. Privacy is a genuine differentiator in stigmatized categories. The lesson is that a claim needs a mechanism behind it, and that absolute phrasing removes your ability to defend a partial truth.

This article reflects the record as of July 2026 and is based on the redacted complaint as e-filed, available at ftc.gov. It is general information for marketing and compliance teams, not legal advice.

If your site says private and your tracking stack cannot support the word, the durable fix is to change the stack rather than the sentence. Curve gives healthcare advertisers conversion tracking and campaign measurement where protected health information never reaches the ad platform, with server-side sanitization before egress, per-destination configuration, and a BAA for the processing layer. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.