Skip to main content
Article

The Trade Desk Pixel and Healthcare Data: Lessons From the FTC's Hims and Hers Complaint

A demand-side platform pixel is not one recipient. It is the entrance to a supply chain, and that is what makes The Trade Desk the hardest integration on a healthcare website to audit honestly. The Trade Desk is named in paragraph 77 of the Federal Trade Commission's complaint against Hims & Hers Health, Inc. as one of the third-party pixels allegedly placed on the company's platforms. The Trade Desk is not a defendant and is not accused of wrongdoing. The lesson for healthcare advertisers is structural: when you place a DSP tag, you are making a decision about a chain of downstream systems you will never directly inspect.

Curve is a HIPAA-compliant conversion tracking platform that gives healthcare advertisers a single controlled egress point, so programmatic buying platforms receive optimization signals rather than the raw record of what a patient browsed. In programmatic, control of the payload at the boundary is not a nicety. It is the only place control exists.

The case is Federal Trade Commission; The People of the State of California, acting by and through Los Angeles County Counsel Dawyn R. Harrison; and Utah Division of Consumer Protection v. Hims & Hers Health, Inc., Case No. 3:26-cv-7871, in the U.S. District Court for the Northern District of California, filed in late July 2026. Nothing has been proven. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it intends to defend the case.

The Short Version

  • The complaint lists The Trade Desk in paragraph 77 among pixels allegedly present on Hims platforms, alongside Bing, Google Ads and Google Ads S2S, Criteo, PebblePost, Pinterest, Podsights, Reddit, StackAdapt, TikTok s2s, MediaBids, PartnerCentric and X.
  • A DSP is an intermediary by design. Data entering it informs bidding executed across many exchanges, publishers and supply partners.
  • Identity resolution is the DSP's core value. That means the pixel event is joined to a durable identifier, not held as an anonymous page view.
  • Auditability collapses at the first hop. You can inspect your tag and your account. You cannot inspect the downstream systems that receive bid requests.
  • Server-side integration is not a defense. Paragraph 70 shows the FTC understood server-to-server transmission and pled it as a vector anyway.
  • The workable control is upstream: never let condition-revealing data reach the DSP, and rebuild measurement on sanitized conversion events.

What a DSP Pixel Is Doing That a Platform Pixel Is Not

A conversion pixel from a walled-garden platform has a simple job. It reports an outcome back to the same system that served the ad, and the data stays inside that system for matching and reporting. One advertiser, one platform, one loop.

A DSP works differently because it does not own inventory. It buys in real time across supply-side platforms and exchanges that connect to tens of thousands of publishers, apps and connected TV properties, and its universal tag exists to close the measurement loop across all of that heterogeneous supply. So the tag does three things at once: record that an event occurred, attach it to an identity the platform recognizes across sites and devices, and make that identity available to the bidding logic that will decide, milliseconds later on an unrelated publisher page, whether to bid on the same person.

The third step is the one healthcare teams underestimate. The value of the event is not the event. It is the ability to act on the event somewhere else. A pixel that only stored data would be inert. A DSP pixel is explicitly wired to influence real-time transactions in an open marketplace.

One Pixel, Many Downstream Recipients

Consider what happens after a conversion or audience event is recorded and the corresponding user is later eligible for targeting. When that person appears on any participating property, the supply side generates a bid request. That request is broadcast to demand partners and contains contextual and identity information: the page or app context, device and connection details, geographic signals, and whatever identifier the supply chain has for the user. Many parties see the request. Only one wins the impression. All of them received the invitation.

The advertiser's conversion event is not itself broadcast in that request, an accuracy point often overstated in privacy commentary. What is broadcast is the opportunity to bid on a user. The exposure runs the other way: the audience you built out of sensitive behavior determines which users you bid on, and bidding patterns, frequency and creative selection are observable to parties in the chain. Meanwhile the segment itself now lives in a platform that supports data onboarding, audience sharing between accounts and partners, and third-party measurement partnerships.

The practical governance question is therefore not "does the DSP leak my pixel data." It is "how many systems can, in some configuration, come into contact with an audience I defined using condition-level behavior, and can I enumerate them?" For most healthcare advertisers the honest answer to the second half is no. That is what people mean when they call DSP pixels the hardest to audit. It is not carelessness. The architecture simply has more surfaces than a single-team review can enumerate, which is why a structured pixel audit scorecard matters more here than in a walled garden.

Identity Graphs Turn a Page View Into a Person

The open programmatic ecosystem spent the last several years replacing third-party cookies with identity frameworks built on hashed and encrypted representations of stable identifiers, most commonly email addresses. The Trade Desk is publicly associated with Unified ID 2.0, an industry identity framework built on that approach. The design intent is privacy improving relative to the cookie: identifiers are hashed and encrypted, participation is meant to be consent gated, and users are meant to have a way to opt out.

For healthcare, though, the salient property is different. These frameworks make identity durable and portable. A cookie-based record of a condition page view degraded on its own. An identity-graph record does not degrade in the same way, and it can be recognized on a different browser, a different device, and in a different medium such as connected TV.

Now combine that with paragraph 74 of the complaint, which alleges that Hims "was only able to create audiences with such specificity because it flouted the promises it made to its users about treating their medical conditions 'privately' or keeping their health information private." The FTC's theory connects audience specificity to the underlying data practice. In a DSP, specificity is achieved through identity resolution. So the more capable the identity layer, the more directly it implicates the source data when a regulator works backwards from a targeting capability.

None of that makes identity frameworks illegitimate. It means that if the input to the graph is a person who read about a specific treatment, the graph has made a health inference durable across the open internet. A technical improvement in the identifier does not change the sensitivity of the attribute attached to it.

How Curve Handles Programmatic Destinations

Curve replaces the direct browser-to-DSP tag with a controlled path. Events are collected first-party on your own infrastructure, sanitized server-side so that condition-revealing URLs, query parameters, form inputs and product identifiers are removed before egress, and only then forwarded to configured destinations. Because each destination is configured separately, a programmatic platform can be sent a narrower payload than a search platform, and every field going to every destination is enumerable and reviewable rather than inferred from a network trace. Protected health information does not reach the ad platform, which means the audience the DSP can build is bounded by what you deliberately allowed rather than by what a page happened to contain. Curve makes a business associate agreement available for the tracking layer, which the DSP integration itself will not provide.

The honest trade: your programmatic audiences get less granular. You will optimize toward a qualified conversion instead of toward people who read a specific condition page. Bidding systems handle that well. Compliance reviews handle it far better.

What to Check in a Trade Desk Deployment

  • Where the universal tag fires. Site-wide deployment through a tag manager is the norm and it is the wrong default for a healthcare property. Enumerate the page templates that reveal a condition, a symptom, a medication or an intake stage, and exclude them explicitly rather than relying on a negative rule.
  • What the conversion tracker carries. Read the actual outbound request. Page URL, referrer, and any custom values passed alongside the conversion are the usual carriers. A revenue value tied to a single-treatment SKU is a condition proxy even when nothing in the payload names a condition.
  • First-party data onboarding. If any customer list, CRM segment or hashed email file has been uploaded, establish who authorized it, what the source segment was, and whether the segment definition encodes a clinical attribute. This is the highest-severity item on the list and it is usually undocumented.
  • Identity participation. Determine whether hashed identifiers derived from email addresses are being passed at any point in the flow, and under what user-facing disclosure.
  • Audience sharing and partner access. Check whether audiences are shared with agency accounts, measurement partners or other seats. Every share is another recipient with its own retention and its own contract.
  • Log-level and reporting exports. Raw log feeds and impression-level exports frequently land in a warehouse not covered by the same controls as the ad account. Follow the data to where it rests, not just where it is created.
  • Contracts and flow-downs. Confirm in writing what agreement governs the relationship and whether any obligation flows down to supply partners. The contractual question and the technical question are separate, and only one of them stops a payload.

Why the Server-Side Version Does Not Fix It

Programmatic teams often reach for a server-side conversion API as the compliance answer, on the theory that server-to-server transmission is categorically different. Paragraph 70 of the Hims complaint forecloses that reading. The FTC described the Conversions API accurately, observing that it operates differently "to the extent it creates a direct connection between the advertiser's server, website, app or other internal software and Meta's systems", and treated it as a sharing vector regardless. Paragraph 77 separately identifies a Google Ads S2S pixel and a TikTok s2s integration. Three server-side vectors appear in a single complaint.

The correct conclusion is not that server-side is useless. It is that server-side is a control point, not a control. Moving egress to your own infrastructure gives you the ability to inspect, filter and rewrite every field before it leaves. If you exercise that ability, your risk drops substantially. If you simply replay the browser payload from a server, you have changed the transport and kept the exposure. That distinction is developed further in server-side tracking alone is not HIPAA compliance and in the technical walkthrough of how server-side tracking improves HIPAA compliance when it is done properly.

What Good Looks Like for Programmatic in Healthcare

A defensible programmatic setup for a regulated advertiser tends to share four traits.

First, the DSP receives conversions, not journeys. One sanitized event at the point of a qualified outcome, with the identifiers needed for attribution and nothing describing the clinical path taken to get there.

Second, audiences are built from campaign and creative context rather than from condition-page membership. If a campaign is already topically targeted, the campaign itself carries the context, and you do not need to encode the sensitive attribute into a user-level segment. The same principle underlies building audiences from in-market segments without PHI.

Third, the sensitive analysis stays inside your own environment. Cohort performance by condition is a legitimate business question. It is answerable in your warehouse, with your governance, without exporting the cohort definition to a bidding platform.

Fourth, the same standard applies across every channel rather than to the loudest one. Teams that hardened Meta and left eleven other tags untouched are exactly the pattern paragraph 77 describes. A unified approach across search, social and programmatic destinations is covered in HIPAA-compliant conversion tracking setup across Google, Meta and Microsoft, and the cost of getting it wrong is visible in the anatomy of the Advocate Aurora pixel settlement.

Frequently Asked Questions

Is The Trade Desk HIPAA compliant?

The Trade Desk operates as an advertising technology provider under commercial advertising agreements, not as a HIPAA business associate for open programmatic buying. That means compliance for a healthcare advertiser depends on the advertiser ensuring protected health information never enters the integration. The question to ask internally is not whether the platform is compliant but whether your payload contains anything a regulator would characterize as health information.

Was The Trade Desk sued by the FTC?

No. The Trade Desk is referenced in paragraph 77 of the complaint as one of the pixels allegedly placed on Hims platforms. The sole defendant is Hims & Hers Health, Inc., and the claims concern the advertiser's alleged disclosures and alleged privacy representations. Hims has denied the allegations, has said its privacy policy makes clear that users may choose how their data is used, and has said it will defend the case.

Does using hashed emails make a DSP integration safe?

Hashing changes the format of an identifier, not the sensitivity of the attribute attached to it. A hashed email joined to the fact that someone viewed a page about a specific treatment is still a health inference about an identifiable person, because the whole point of the hash is that it matches consistently. Hashing is a useful security control and a poor substitute for not sending the attribute.

How would I even audit the downstream supply chain?

Realistically, you cannot audit it end to end, and any vendor claiming otherwise is overselling. The defensible posture is to make the audit unnecessary by controlling the input: if the data entering the DSP contains no health attribute, the number of downstream recipients stops being the deciding risk factor. Audit the boundary you control, then document that decision.

Can healthcare brands run connected TV and open-web programmatic at all?

Yes. Contextual and campaign-level targeting works well in these channels, and conversion measurement is achievable using sanitized events. What needs to stop is user-level segmentation built from condition-specific browsing, and the uploading of patient-derived lists into platforms that will resolve them against an identity graph.

This article reflects the public record as of July 2026, drawn from the redacted complaint e-filed on ftc.gov. All allegations described are allegations only and have not been proven in court.

If your programmatic stack was built before anyone asked what the tags were sending, the safest assumption is that it is sending the page. Curve gives healthcare advertisers one sanitized egress path to every destination, including programmatic ones, with a business associate agreement covering the tracking layer. See how it works at curvecompliance.com.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.