The pixel promised discretion. The FTC read the payload
A fox does not need to open the henhouse to know what is inside; the scent through the gate tells the whole story. The FTC just read the same scent off a telehealth company's ad pixels.
By Katie Delaney · 2026-08-22 · 14 min read
What the FTC actually alleges about Hims & Hers#
The story broke quietly for a company that built its brand on discretion. On 29 July 2026 the Federal Trade Commission, joined by Utah and the County of Los Angeles acting for the People of California, sued Hims & Hers Health in the Northern District of California, and the complaint reads like a den someone left unswept. According to TechCrunch's review of the filing, the FTC says Hims & Hers placed pixel-sized trackers from Meta, Snap, Microsoft, Pinterest, Reddit and X on its site, and those trackers captured and shared users' health information in direct contradiction of the company's own privacy policy.
That is only half the complaint, and the quieter half is arguably the sharper one. A client alert from Shumaker, Loop & Kendrick lays out two distinct data-sharing mechanisms in the filing: automatic website tracking that transmitted user actions to advertisers as they happened, and the upload of customer lists, people identified by name and by health condition or treatment type, matched against advertiser databases so Meta and Snap could build lookalike audiences of the specifically unwell.
The same filing accuses Hims & Hers of charging consumers for prescriptions almost immediately after they submitted an intake form, before the promised consultation with a provider, and of making cancellation deliberately difficult once a subscriber tried to leave. Any healthcare marketing company reading the filing closely will notice the pattern is not one bad decision but a whole funnel built the same way.

Hims & Hers has not gone quiet on the charge. As CBS News reported, the company called the allegations baseless and said its stock fell approximately 15% the day the suit became public, a sharp market scent of how seriously investors read a privacy complaint against a telehealth brand.
Then, on 18 August, the fight went from the courtroom to cable news. Hims & Hers CEO Andrew Dudum appeared on CNBC's Squawk Box and pushed back hard, telling the network, as Investing.com reported, that "we are active disruptors" and that "it takes time for people to understand" how the company's model works. He went further still, calling the FTC's own conclusion a preference for a headline over a real agreement, which is exactly the sort of confidence a careful healthcare marketing company should read as a warning rather than reassurance.
My conversation on @SquawkCNBC covered everything from how we make accessing care more affordable to how AI is transforming healthcare, and why data is the most powerful tool we have for putting people in charge of their own health.
Read the CEO's own words against the complaint they are answering and the friction is plain: the FTC's case is precisely that Hims & Hers treated closed-loop patient data as a marketing asset to be shared outward, not just a clinical asset to be kept close. A vulpine reading of that gap is the whole point of this piece, and it applies far beyond one telehealth brand. Every healthcare marketing company running Meta and Google pixels on a symptom checker, a condition page or an intake form is one audit away from the same question the FTC is now asking Hims & Hers in open court.
Why “we didn’t mean to share it” keeps losing#
This is not a first offence for the category, and that is precisely why it matters to every healthcare marketing company reading the complaint rather than just the headline. The FTC's playbook here was written three years ago and it has not needed a rewrite since.
In February 2023 the FTC settled with GoodRx for $1.5 million, its first-ever enforcement action under the Health Breach Notification Rule. Per HIPAA Journal's coverage of the court approval, GoodRx had disclosed users' personally identifying and health condition information through third-party tracking pixels and SDKs supplied by Google, Facebook, Criteo, Branch and Twilio, while displaying a badge that falsely implied HIPAA coverage.
Four months later BetterHelp paid $7.8 million over the same basic pattern applied to therapy. According to reporting from ConsumerNotice.org, BetterHelp shared email addresses, IP addresses and health questionnaire answers with Facebook, Snapchat, Criteo and Pinterest, using the fact that someone had previously been in therapy to help those platforms build a lookalike audience for more therapy ads. Both cases predate the current suit by three years, which is exactly why no healthcare marketing company gets to call this an unfamiliar risk.
| Case | Filed / settled | Penalty | Platforms named |
|---|---|---|---|
| GoodRx | Feb 2023 | $1.5m | Google, Facebook, Criteo, Branch, Twilio |
| BetterHelp | Jul 2023 | $7.8m | Facebook, Snapchat, Criteo, Pinterest |
| Hims & Hers | Jul 2026, contested | Not yet determined | Meta, Snap, Microsoft, Pinterest, Reddit, X |
Notice what carries across all three rows and what does not. The penalty scales with harm and duration, but the defence that never scales at all is intent. GoodRx never argued it meant to leak health data; BetterHelp denied wrongdoing while paying the fine anyway. Neither “we didn't realise the pixel did that” nor “the platform's own tools did the matching” has ever been a winning defence once the FTC has the traffic logs. A healthcare marketing company that hears its own client say either sentence should treat it as the sound of a trail already being followed, not a closed matter.
How an ordinary pixel becomes a live liability#
The uncomfortable part for any healthcare marketing company is that none of this requires a rogue actor. It requires the default setup on a website that most agencies would call standard practice, deployed on the one kind of page where standard practice stops being safe.
The clearest measure of the problem's scale comes from outside the newsroom entirely. A peer-reviewed study published in PNAS Nexus examined 1,201 large US hospitals across twelve years of archived websites, 2012 to 2023, and found that 66% of hospital-year observations carried pixel tracking of some kind. That is not a fringe habit; it is the industry default, sitting quietly beneath the surface of most healthcare digital advertising the way undergrowth sits beneath a hedgerow.
The same study puts a number on the consequence, and the number is the reason this stops being an abstract compliance worry. Hospitals with no third-party pixel carried a baseline data-breach probability of about 3%; hospitals running third-party pixels saw that risk climb by at least 1.4 percentage points, a 46% relative increase, concentrated specifically in unintended disclosure, the exact failure mode the FTC alleges against Hims & Hers. First-party pixels, tellingly, showed no such relationship: the danger is not the pixel technology itself, it is the data leaving the building.
Regulators have tried to draw a bright line around this and mostly failed to make it hold. HHS updated its own guidance on tracking technologies in March 2024, and as a Goodwin Law analysis explains, it took an expansive view: an unauthenticated visitor's IP address, sent to a tracker while they browsed a condition-specific page such as an oncology service, counts as protected health information if their reason for visiting was healthcare-related, even without a login. Popular tools including Meta Pixel and Google Analytics generally will not sign the business associate agreement that would make that sharing lawful.
A federal court later vacated part of that guidance after a challenge from the American Hospital Association, so the legal line has shifted more than once even in the past two years, which is exactly why a healthcare marketing company cannot treat this as a settled question it can check once and forget. The regulatory ground keeps moving under a topic that most media plans still treat as fixed and finished.
The practical read, laid out plainly by health-IT security specialists at Paubox, is that the FTC's authority does not stop where HIPAA stops. Consumer health apps and telehealth brands that sit outside a traditional covered entity still answer to the FTC Act's ban on deceptive practices, and the agency has now used that authority against GoodRx, BetterHelp and Hims & Hers in succession. Removing a tracker today does not undo what it already sent yesterday, so the audit has to start with what has already left the den, not just what is running now.
What Google and Meta already tell you not to do#
Here is the part that should sting most for any agency doing healthcare digital advertising in good faith: the platforms carrying this data have already published the rule you needed. Nobody had to guess.
Google's own healthcare and medicines advertising policy requires certification for prescription drug services, online pharmacies and telemedicine, restricts drug terms across ads, landing pages and keywords, and flatly bans promotion of unapproved substances and speculative treatments regardless of how the copy is worded. A healthcare marketing company running search campaigns for a telehealth client needs to be fluent in google ads healthcare policy before the first ad ever goes live, not after a complaint arrives, because certification failures and policy violations are the kind of thing Google catches quietly and regulators catch loudly.
Meta's rules cut closer to the exact mechanism named in the Hims & Hers complaint. Per Search Engine Land's breakdown of Meta's health and wellness restrictions, advertisers may not transmit data that reveals or implies a user's health condition, and Meta enforces this with a tiered restriction system: core setup features like custom audiences and advanced matching fail first, mid-funnel optimisation toward purchase or add-to-cart events is blocked next, and a full breach eventually strips access to Meta's bidding algorithms entirely.
The article's own example is almost uncomfortably close to the case at hand: tracking a purchase of a hair-loss or weight-loss product sends implied health data to Meta whether or not the advertiser meant it to. That is the precise mechanism the FTC is now litigating, dressed up as a routine conversion event.
Put the two platform policies side by side and a pattern emerges that every healthcare digital advertising team should recognise: the platforms are not hiding the boundary, they are actively fencing it off with technical restrictions, and the FTC's complaints are essentially the cases where a brand's marketing setup outran or evaded that fence. That is a survivable mistake to fix and an unsurvivable one to defend in court.
The platform already built the fence. The complaint is what happens when the campaign climbs over it anyway.
The audit a healthcare marketing company runs before the regulator does#
None of this argues for abandoning performance marketing in healthcare; it argues for treating the audit as routine rather than reactive. A good healthcare marketing company does this quietly, on a schedule, long before a subpoena forces the question.
The starting discipline is simple to state and genuinely tedious to do properly: walk every condition page, symptom checker and intake form the way a fox walks a hedgerow at dawn, patient and thorough, checking what is actually moving through the gate rather than what the tag manager documentation claims should be moving through it. Patient data privacy failures rarely begin with a bad intention; they begin with a pixel installed for one honest reason years ago that nobody has re-read since.
List every pixel, SDK and conversion API on condition-specific pages, intake forms and post-purchase confirmation screens, not just the homepage.
Check what each event actually sends: a purchase event on a weight-loss product implies a health condition even without a diagnosis field.
Cross-check every health-adjacent event against Google's healthcare policy and Meta's restricted-goods rules, not against internal assumptions about what is fine.
Treat unauthenticated visitors to a condition page as carrying the same risk as logged-in patients; regulators increasingly do.
If a vendor will not sign a business associate agreement for health-adjacent data, the tracker comes off the page, full stop, regardless of the reporting gap it leaves.
This is also where hipaa compliant marketing stops being a phrase on a slide and becomes an actual constraint on the media plan. It means accepting a smaller retargeting pool in exchange for a defensible one, and it means a healthcare marketing company occasionally telling a client that a tactic which works beautifully for a retail brand cannot be run the same way for a telehealth one. That is not caution for its own sake; GoodRx, BetterHelp and now Hims & Hers are the receipts for what happens when nobody says it out loud in time.
The FTC's own timeline on Hims & Hers is worth sitting with here, because it shows how long this kind of case actually takes to surface. Court filings referenced in the Investing.com report place the FTC's inquiry as opening years before the July 2026 suit, with settlement talks under way earlier this year before the agency chose to litigate anyway. A healthcare marketing company has that same lag working in its favour if it starts the audit now: the pixels installed today are the evidence a regulator might read in three years, and there is still time to make sure that evidence is boring.
Bring it back to the fox at the gate. The scent test is not paranoia, it is method: before the next campaign launches, ask what a stranger reading the raw event log would conclude about the person who triggered it. If the honest answer is a health condition, a diagnosis or a treatment type, that event does not belong on an open advertising platform, however small the audience or however good the intent behind it.
folkfox's paid social services and PPC work both run that check before a single dollar of a healthcare client's media spends, because the alternative is finding out the hard way, in open court, months after a campaign that felt perfectly normal at the time. Any healthcare marketing company can run the same five checks tomorrow morning, and most of the work costs nothing but attention.
Frequently asked questions#
What did the FTC allege against Hims & Hers?
The FTC alleges Hims & Hers shared consumers' health information, including condition and treatment type, with Meta, Snap and other advertising platforms through tracking pixels and customer list uploads, and separately that it charged for prescriptions before a provider consultation and made cancellation unreasonably difficult.
Why did GoodRx and BetterHelp settle with the FTC over pixel tracking?
Both companies were found to have shared sensitive health data (condition details for GoodRx, therapy questionnaire answers for BetterHelp) with advertising platforms including Meta and Google, despite promising users their data would stay private. GoodRx paid $1.5m in 2023 and BetterHelp paid $7.8m the same year.
What is a hipaa compliant marketing approach to ad pixels?
It means auditing every tracker on condition-specific and intake pages, checking what data each event actually transmits, matching that against Google's and Meta's own health-data rules, and removing any tracker whose vendor will not sign a business associate agreement for health-adjacent data.
Does patient data privacy law cover telehealth apps that are not HIPAA covered entities?
Often not directly, which is exactly why the FTC has become the main enforcer in this gap. Consumer health apps outside traditional HIPAA coverage still answer to the FTC Act's ban on deceptive practices, which is the authority behind the GoodRx, BetterHelp and Hims & Hers actions.
What does Google's healthcare advertising policy actually restrict?
Google's healthcare and medicines policy requires certification for prescription drug services, online pharmacies and telemedicine, restricts many drug-related terms in ads and keywords, and bans promotion of unapproved substances and unproven treatments outright.
How does a healthcare marketing company audit its tracking pixels?
By mapping every pixel and SDK on health-adjacent pages, reading what each event payload contains, cross-checking that against platform policy, treating unauthenticated visitors with the same care as logged-in patients, and dropping any tracker whose vendor cannot commit to the data-handling terms health information requires.
Read more on this topic#
The cheque was $15. The cost was the whole measurement stack
Five US health systems already settled Meta Pixel class actions; the cash was trivial, the remedy was not.
Read the pieceThe pixel is now the liability
An earlier FTC pixel case and an ASA ad ban, mapped to five real risks in a healthcare marketing stack.
Read the pieceThe regulator called your funnel a health record
A Dutch privacy regulator's ruling on intimate app data reaching advertisers, and what it means for consent.
Read the pieceThe $262m headline that points the wrong way
Hims and Hers' own marketing spend ratio, read correctly rather than as a scary total.
Read the piece
Ready for an honest audit of what your pixels actually see?
folkfox reads a healthcare client's tracking stack the way a regulator eventually will: page by page, condition by condition, before it becomes someone else's headline.