Skip to main content
Article

StackAdapt Pixel in Healthcare Advertising: What the FTC's Hims and Hers Case Flags

The StackAdapt pixel is not more dangerous than any other conversion tag. It is more often forgotten, and in healthcare that amounts to the same thing. StackAdapt appears in paragraph 77 of the Federal Trade Commission's complaint against Hims & Hers Health, Inc. among the third-party pixels allegedly placed on the company's platforms. StackAdapt is not a defendant and is not accused of any wrongdoing. What the case flags is a category problem: native and content-led advertising is bought by different teams, budgeted differently, and reviewed differently, while the tracking underneath it is identical to the tracking on your paid search landing pages.

Curve is a HIPAA-compliant conversion tracking platform that lets healthcare marketers measure native, display and content campaigns without transmitting protected health information to the ad platform. That matters most in channels nobody thinks to audit, because unreviewed tags are where pixel exposure actually accumulates.

The case is Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., Case No. 3:26-cv-7871, in the U.S. District Court for the Northern District of California, filed in late July 2026. Nothing is proven. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case.

The Short Version

  • Paragraph 77 lists StackAdapt alongside twelve other advertising vendors allegedly receiving pixel data, which is the real headline: the exposure was distributed across the whole stack, not concentrated in one platform.
  • Native advertising reads as editorial to the marketing team and as behavioral tracking to a regulator. Ad format has no bearing on what the pixel sends.
  • Content hubs are the blind spot. An article about a condition is a condition page, and it carries the same site-wide tag as everything else.
  • Native campaigns are frequently run by content, brand or agency teams outside the performance review process, so their tags never enter the pixel inventory.
  • Contextual targeting is genuinely lower risk. The conversion tracking and retargeting attached to it are not.
  • Paragraph 70 shows the FTC understood server-side transmission and pled it as a vector regardless, so a server-side native integration is not by itself a remedy.

Why Native Feels Safer Than It Is

Native advertising is designed to reduce the perceived distance between an ad and the surrounding content. A sponsored article at the bottom of a news page, an in-feed unit styled like a publisher module, a piece of long-form content about managing a condition. It reads as information rather than as a pitch.

That design goal produces a predictable organizational effect. Because native does not feel like direct response, it tends to be planned as awareness or education, funded from a content budget, and executed by people whose review checklist covers editorial accuracy, medical claims and brand safety. Those are the right checks for the creative. None of them ask what the landing page tag sends.

Meanwhile the platform-side setup is conventional. A universal tag goes on the site, conversion events get defined, retargeting audiences get built from people who engaged with the content, and predictive expansion gets enabled to scale prospecting. Each step is a data flow, and each is indifferent to whether the ad that started the session looked like a banner or an article.

We see this pattern repeatedly during a pixel audit for PHI leakage: search and social have been hardened, sometimes carefully, while a native platform tag sits site-wide and untouched, firing on every condition page the content team has ever published.

The Content Hub Problem

This is the part worth slowing down on, because it is where native advertising and healthcare privacy collide most directly.

Healthcare content marketing works. A library of educational articles about symptoms, treatment options, side effects, eligibility and cost is genuinely useful and attracts exactly the audience a clinic or telehealth brand wants. So native campaigns get pointed at those articles, because that is the content worth promoting.

Now look at what a visit to one of those pages represents. A person clicked an ad about a specific condition, landed on an article about that condition, and stayed. The page URL almost certainly names the condition, because that is what SEO requires. The referrer identifies the campaign. Scroll depth and time on page indicate genuine interest rather than a stray click. If the tag reports that URL to an ad platform, it has reported a health interest attached to a persistent identifier, with unusually high confidence.

Then the optimization loop makes it worse in a way nobody intended. The team builds a retargeting audience of engaged article readers, because that audience converts. Its membership criterion is, functionally, expressed interest in a specific medical condition. Paragraph 74 of the complaint alleges that Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private." That sentence describes an ordinary content retargeting workflow.

Paragraph 67 defines the shared data as "Events", meaning "the actions of website visitors on Hims' website." Reading an article is an action of a website visitor. There is no editorial carve-out.

How Curve Handles Content and Native Campaigns

Curve replaces direct browser-to-platform tags with a first-party collection layer that sanitizes events server-side before anything is transmitted. For a content hub that means the condition-naming URL path, the campaign parameters carrying a treatment keyword, and any custom values describing article topic are stripped or normalized before egress, so the destination sees that a conversion occurred without seeing which article produced it. Destinations are configured independently, so a native platform can be given a narrower payload than a search platform where you may have different legal footing. Protected health information does not reach the ad platform at any point in the path, and Curve makes a business associate agreement available for the tracking layer. Attribution back to campaign and creative still works, because campaign-level context lives on your side and does not require exporting a user-level health attribute to the buying platform.

The result is that you can keep running content-led acquisition, which is often the most efficient channel a healthcare brand has, without the retargeting audience becoming a de facto patient list.

What to Check in a StackAdapt Deployment

Start from the assumption that nobody on the performance team configured this, because frequently nobody on the performance team did.

  • Find the tag first. Search your tag manager and your site templates for the universal pixel. In many organizations it was added by an agency during a campaign that ended two years ago and was never removed. A tag that outlives its campaign is pure liability with no upside.
  • Check the firing rules. Site-wide is the default. Enumerate every page template that reveals a condition, symptom, medication, quiz result or intake stage, and exclude them explicitly. Do not rely on the assumption that article pages are not sensitive.
  • Read the outbound request on an article page. Open a condition article, watch the network traffic, and look at the URL and referrer being transmitted. This single check resolves most of the question in about four minutes.
  • Inventory the audiences. List every retargeting and engagement segment in the account and read its definition. Any segment defined by visits to condition-specific content is the problem, regardless of how it is named in the interface.
  • Look at predictive and expansion features. Lookalike or audience expansion built from a seed of condition-page visitors propagates the sensitive attribute into modeling. The seed is the disclosure.
  • Check the CTV, display and video line items too. Native platforms buy across multiple formats from one account, so the tag and the audience are shared even when the media plan treats the formats separately.
  • Establish the contract. Determine whether you have a data processing agreement or a business associate agreement, and confirm who signed it. A signature does not stop a payload, so treat this as the second question rather than the first.

Contextual Targeting Is Fine. The Tracking Attached to It Might Not Be.

Native platforms market contextual targeting heavily, and for good reason. Placing an ad next to content about a topic, based on the page's content rather than the reader's history, is one of the genuinely privacy-preserving techniques available to advertisers. A healthcare brand can and should lean on it.

The mistake is to treat "we use contextual targeting" as a compliance conclusion. Contextual targeting describes how impressions are selected. It says nothing about what happens after the click. If the landing page carries a tag that reports the URL, or engaged readers are collected into a retargeting pool, the campaign is contextual on the way in and behavioral on the way out. The behavioral half is where the exposure is.

Assess the two halves separately. Targeting method and measurement method are independent decisions, and only one of them is generally safe by default. The same split shows up on other content-led platforms, which is why the guidance for medical content marketing on visual platforms and for community-based advertising compliance on Reddit lands in the same place: the format changes, the tag does not.

Why Thirteen Vendors Is the Real Finding

It is tempting to read paragraph 77 as a list and move on. The list is the argument.

The complaint identifies Microsoft's Bing Pixel and Bing Image Pixel, Google's Ads Pixel and Ads S2S Pixel, Criteo, MediaBids.com, PartnerCentric, PebblePost.com, Pinterest, Podsights, Reddit, StackAdapt, TikTok s2s, The Trade Desk and X. Paragraph 76 separately alleges that customer lists were uploaded to Snap for matching. That is not a company that made one bad integration decision. It is a company that, according to the complaint, ran a normal modern growth stack.

Every one of those vendors was presumably added for a defensible reason by someone doing their job. That is precisely how the exposure compounds. Nobody approves "send condition data to fifteen companies." People approve fifteen individual campaigns, each with a tag, over several years, across several teams and agencies. Paragraph 78 notes that Hims acknowledged privacy and consumer-protection regulatory risk in SEC filings since 2021 and that the FTC issued a Civil Investigative Demand in October 2023, which means the accumulation continued through a period of stated awareness.

If your organization runs native, display, search, social, affiliate and podcast advertising, the practical exercise is not to evaluate StackAdapt. It is to produce a list of every destination currently receiving events from your site and to ask, for each one, what field carries clinical meaning. Most teams cannot produce that list from memory, which is itself the finding.

Server-Side Native Integrations Are Not an Exemption

Some platforms offer server-side conversion ingestion, and some teams treat that as the compliance fix. Paragraph 70 of the complaint should settle the point. The FTC described the Conversions API accurately, noting it operates differently "to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems", and pled it as a sharing vector anyway. Paragraph 77 lists a Google Ads S2S pixel and a TikTok s2s integration as separate entries.

Server-side placement is valuable because it puts you in control of the payload. It is only protective if you then use that control to remove clinical meaning from the payload before egress. Replaying the same event from a server accomplishes nothing legally. The distinction is unpacked in server-side tracking alone is not HIPAA compliance.

A Workable Native Setup for Healthcare

Run contextual and campaign-level targeting rather than user-level condition segments. Track a small number of sanitized conversion events rather than page views. Keep article-level engagement analysis inside your own analytics environment where it is governed, and send the ad platform only what it needs to optimize bidding. Remove tags belonging to ended campaigns as part of campaign closeout, not as part of an annual review. And apply one standard across every destination, including the channels that feel editorial, an approach outlined in the 14-point pixel audit self-assessment. For regulated categories with extra scrutiny, such as weight management, the same logic is developed in GLP-1 telehealth marketing compliance.

Frequently Asked Questions

Is StackAdapt HIPAA compliant?

StackAdapt operates as an advertising platform under commercial agreements rather than as a HIPAA business associate for behavioral advertising. That places the burden on the advertiser to ensure no protected health information enters the integration. In practice, a StackAdapt deployment on a healthcare site is as compliant as the payload you allow it to send, and no more.

Is StackAdapt in trouble with the FTC?

No. StackAdapt is named in paragraph 77 of the complaint as one of the pixels allegedly placed on Hims platforms. The only defendant is Hims & Hers Health, Inc., and the claims concern the advertiser's alleged data sharing and alleged privacy representations. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it will defend the case.

Are educational articles really considered sensitive pages?

Treat them as sensitive when the URL or the content identifies a specific condition or treatment and the visit can be tied to an identifier. The legal question is not whether the page is editorial, it is whether the transmission reveals health information about an identifiable person. An article page reached through a condition-targeted ad is a strong signal by construction.

Can I keep retargeting people who read my health content?

Not on a condition-specific basis. You can retarget people who took a neutral action, and you can continue to reach similar audiences through contextual placement on relevant content. What should stop is building a user-level list whose defining attribute is interest in a particular diagnosis or medication, because that list is the thing paragraph 74 describes.

We inherited this account from an agency. Where do we start?

Start with two lists: every tag currently firing on your site, and every audience currently defined in every ad account you can access. Most teams find at least one live tag from a campaign that ended long ago and at least one audience nobody remembers creating. Fix the firing rules and delete the condition-derived audiences before you touch anything else.

This article reflects the public record as of July 2026, based on the redacted complaint e-filed on ftc.gov. Everything described is an allegation and has not been proven.

Native and content campaigns are usually the last channel to get a privacy review and the first to fire on a condition page. Curve gives healthcare advertisers one sanitized path to every destination, native platforms included, with events cleaned server-side before egress and a business associate agreement covering the tracking layer. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.