Subscription Telehealth and Privacy: Why Billing and Tracking Claims Landed in One Complaint
The FTC did not file two cases against Hims & Hers Health, Inc. It filed one. Allegations about sharing sensitive health information with advertising platforms sit in the same complaint as allegations about negative-option billing under ROSCA, against the same company, over the same customer journey. That structural choice is the most important thing in the filing for anyone running a subscription health brand, because it says the agency views acquisition tactics and privacy posture as one machine rather than two departments.
Curve is a HIPAA-compliant conversion tracking platform that lets subscription healthcare advertisers measure signups, trials, and recurring revenue without sending protected health information to ad platforms, so the growth stack that drives billing does not double as a disclosure channel.
The case is Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., case number 3:26-cv-7871 in the Northern District of California, filed July 29, 2026. The counts run across Section 5(a) of the FTC Act, Section 4 of ROSCA, the California Unfair Competition Law and False Advertising Law, and the Utah Consumer Sales Practices Act. The plaintiffs seek a permanent injunction, a monetary judgment, and a civil penalty judgment.
Hims & Hers has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case. Nothing has been proven, and the description below is of what is alleged.
The Short Version
- Pixel and Conversions API allegations and ROSCA negative-option billing allegations are pled together in one complaint, not filed as separate matters.
- The unifying theory is representation. The same privacy and convenience promises used to acquire subscribers are alleged to be the promises the data practices contradicted.
- ROSCA requires clear disclosure of material terms before billing information is taken, express informed consent to the recurring charge, and a simple way to cancel.
- The two surfaces physically overlap: checkout and cancellation pages carry the billing disclosures and the tracking tags at the same time.
- A regulator examining one will see the other, because the artifacts that prove a billing claim are produced by the same stack that carries the privacy risk.
- Civil penalties and two state co-plaintiffs mark an escalation from the GoodRx and BetterHelp settlements of 2023.
What the Combination Actually Signals
Read on its own, the tracking half of the complaint is familiar. Paragraph 67 defines the allegedly shared data as "Events," meaning "the actions of website visitors on Hims' website." Paragraph 70 names both the Meta Pixel and the Conversions API. Paragraph 77 lists a long roster of other trackers said to have been placed, including Microsoft, Google, Criteo, Pinterest, Reddit, StackAdapt, The Trade Desk, and X, along with server-to-server variants for Google Ads and TikTok. Paragraph 76 describes customer list uploads to Snap for matching against Snapchat accounts.
Read on its own, the billing half is also familiar. The complaint alleges that consumers were charged for prescription subscriptions before giving meaningful consent, that refill dates were unclear, and that cancellation was made difficult.
Put them side by side and the theory becomes visible. Paragraph 66 quotes the promises: "100% online, private, and secure," conditions treated "privately," "totally private," "discreet," carried across TV, radio, and podcast advertising. Those promises did two jobs at once. They persuaded people to enter a medical funnel, and they persuaded people to hand over a card for a recurring charge. If the FTC is right that the underlying data practices contradicted them, then the same representation supports both a deception count and the consent element of a negative-option count. That is why one complaint and not two.
Paragraph 74 puts the point in the agency's own words, alleging Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private." Audience specificity is a growth output. The complaint traces it back to a privacy input. That is a growth machine argument, not a privacy argument.
How Curve Fits a Subscription Telehealth Stack
Subscription brands need more than a single lead event. They need signup, trial start, first successful charge, renewal, and churn, all tied back to campaigns with real revenue attached. Curve captures those events first-party and sanitizes them server-side before egress, so the outbound payload carries an internal identifier and a value rather than a condition, product, or prescription.
Destinations are configured individually, which matters when one brand runs Google, Meta, Microsoft, Reddit, TikTok, and Pinterest at once and each platform expects a different match key and event schema. Protected health information never reaches any of them, because removal happens on the server before the call is made rather than in a browser script that a tag edit can quietly bypass. A BAA is available, which is the entry requirement for routing patient-adjacent data through any vendor at all. The result is that renewal and lifetime value reporting stays intact while the ad platforms learn nothing clinical about the subscriber.
What ROSCA Requires, in Practical Terms
The Restore Online Shoppers' Confidence Act governs any negative-option feature sold online, which is the legal description of nearly every telehealth subscription. Three obligations do most of the work.
First, all material terms have to be disclosed clearly and conspicuously before billing information is obtained. In practice that means the price, the billing frequency, the date of the first charge and of renewals, and what happens after any introductory period, presented where a consumer will actually see them rather than behind a link or below the payment button.
Second, the seller has to obtain express informed consent to the recurring charge itself, separate from consent to the purchase generally. A checked box the user never touched, or a consent bundled into a broad terms acceptance, is the pattern regulators keep flagging.
Third, cancellation has to be simple. The practical test regulators apply is whether cancelling takes materially more effort than signing up did.
For a medical subscription there is a fourth complication that pure retail subscriptions do not have. The refill schedule is clinical, not just commercial. A charge date that maps to a dose escalation or a prescription renewal is simultaneously a billing term and a health fact, which is exactly why the two halves of this complaint are hard to keep apart.
Where the Two Surfaces Physically Touch
The convergence is not just conceptual. There are specific places in a subscription telehealth funnel where the billing surface and the tracking surface are the same pixels on the same screen.
The checkout page. This is where ROSCA disclosures must appear and where the highest-value conversion tags fire. The same DOM holds the consent language and the scripts reading the page. If the plan name in the order summary describes a treatment, every tag with auto-capture enabled can read it, and the purchase event will often carry it as a product parameter.
The cancellation and retention flow. Retention pages tend to be heavily instrumented, because product teams want to know which save offer works. They also tend to encode the plan, and therefore the condition, in the URL. A cancellation funnel is the page a regulator will most want to see and one of the least reviewed pages for tracking hygiene in most companies.
The intake step immediately before payment. Medical intake and card capture usually sit back to back, which is what turns an ordinary conversion event into a disclosure. That specific mechanism is worth understanding in detail, and we walk through it in where telehealth intake funnels leak health information.
The evidence itself. Session recordings are the clearest way to prove what a cancellation flow looked like on a given date, which makes them valuable to an investigator and risky to retain unmasked. Analytics logs, tag manager version history, and creative archives serve the same dual role. The material that answers a billing question is produced by the stack that carries the privacy exposure.
The org chart. In most subscription health companies, one growth team owns trial-to-paid conversion rate, the checkout experience, and the pixel configuration. The incentives that produce an aggressive checkout are the same incentives that produce aggressive measurement. Regulators are describing that team, not two unrelated failures.
Why This Is an Escalation
The precedent line matters for calibration. GoodRx settled with the FTC in February 2023 for $1.5 million. BetterHelp settled in March 2023, ultimately at $7.8 million. Both were resolved administratively, and both were framed around health data sharing. Our breakdown of the BetterHelp settlement covers what that order actually required.
July 2026 is different in three ways. The matter is being litigated rather than settled at announcement. Civil penalties are sought, which requires a knowledge theory, and paragraph 78 supplies one: SEC filings acknowledging privacy and consumer-protection regulatory risk since 2021, plus a Civil Investigative Demand issued to the company in October 2023. And two states are co-plaintiffs, bringing state consumer protection statutes alongside the federal counts.
That last point is easy to underweight. State claims mean state remedies, state penalty structures, and enforcement staff whose interest does not end when the federal matter does. For a national telehealth brand, the practical exposure is not one regulator but a template that other state attorneys general can read and reuse. The broader pattern across recent matters is tracked in our mid-2026 roundup of healthcare pixel settlements, and the telehealth-specific enforcement history sits in FTC enforcement actions against virtual care advertisers.
What Subscription Health Brands Should Do This Quarter
- Review checkout and cancellation as one artifact, with legal, growth, and engineering in the same room, rather than as a billing review and a separate tracking review.
- Capture what your checkout actually renders today, including the disclosure text, its position relative to the payment button, and the full list of scripts loaded on that page.
- Time your own cancellation flow and compare it against your signup flow. If cancelling takes more steps, that gap is the allegation.
- Strip plan names that describe a condition or medication from URLs, order summaries, and purchase event parameters, replacing them with internal identifiers.
- Check what session replay and heatmap tools record on checkout and cancellation pages, since those recordings are both your best evidence and a live exposure.
- Reconcile your marketing claims against your data flows line by line. Every privacy adjective in an ad script is a representation someone can test against a network capture.
- Give one named person ownership of the seam. In most companies nobody currently owns both halves, which is precisely why they diverge.
Brands advertising weight-loss subscriptions have an additional layer here, since the same funnel attracts platform-level ad policy scrutiny on top of everything else. That interaction is covered in GLP-1 telehealth marketing compliance.
Frequently Asked Questions
Why did the FTC combine privacy and billing claims in one complaint instead of filing separately?
Because the alleged conduct shares a factual core. The privacy promises quoted at paragraph 66 are the same representations that consumers relied on when subscribing, so they support both a deception theory and the consent element of the negative-option claims. Pleading them together also lets the agency describe a single course of conduct rather than isolated lapses.
Does a ROSCA problem create HIPAA exposure, or the other way around?
Neither directly, since they are different statutes with different regulators and different tests. What connects them in practice is scrutiny and evidence. An investigation that starts with a cancellation complaint will pull the checkout page, the tag configuration, and the session recordings, and anything found there is available for a different theory.
Can a subscription telehealth brand still track purchase events and revenue?
Yes. Purchase value, subscription start, and renewal are ordinary commercial signals, and platforms need them to optimize. The requirement is that the event carries an internal identifier and a value rather than a plan name, condition, or medication, and that the page it fires on does not encode the treatment in the URL or title.
What does the complaint actually say about server-side tracking?
Paragraph 70 describes the Meta Conversions API as operating differently "to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems," and pleads it as a sharing vector regardless. Paragraph 77 lists further server-to-server vectors for Google Ads and TikTok. The architecture was understood and did not function as a defense in the pleading.
Is Hims & Hers contesting this?
Yes. The company has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case. The complaint is a set of unproven claims, and the docket is where any of it gets decided. The filing itself is available as the redacted e-filed complaint on ftc.gov.
This article reflects the public record as of July 2026 and describes allegations that have not been proven.
If your subscription health funnel was built by a growth team optimizing for trial-to-paid conversion, the tracking layer probably grew the same way, and the two now share one legal surface. Curve exists to remove one side of that risk: sanitized, server-side conversion and subscription tracking with a BAA, configured per destination, so your revenue reporting stays complete while patient information stays out of ad platforms. See how it works at curvecompliance.com.
Keep exploring
Related articles
MediaBids and PartnerCentric: The Affiliate and Print Trackers in the FTC's Hims Complaint
Read articleThe Reddit Pixel in Healthcare Marketing: What the FTC's Hims and Hers Complaint Shows
Read articlePebblePost and Programmatic Direct Mail: The Healthcare Privacy Risk the FTC Named
Read articleStay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.