Skip to main content

folkfox

Skip to main content
Skip to content
Healthcare

Telehealth advertising after the Hims & Hers complaint: the pixel is the exposure

On 29 July 2026 the FTC, joined by Utah and Los Angeles County, sued Hims & Hers in the Northern District of California, alleging that health information reached Meta and Snap through customer lists and tracking tools. For anyone buying telehealth advertising, the plumbing is the story.

Quick answerTelehealth advertising now carries risk in the pixel itself: the FTC alleges Hims & Hers shared health data with Meta and Snap, which the company disputes. Measure with consented, first-party, server-side data, and consult counsel.
Section 01

What the FTC alleges in the Hims & Hers case#

The fox does not fear the hedgerow; it fears the snare tucked inside it. For telehealth advertising, the snare is a few lines of tracking code that nobody on the marketing team wrote and everybody on the marketing team relies on.

A watchful fox in a beech wood holding a stethoscope to a tree, listening for leaks in telehealth advertising
Listening at the trunk: the pixel is where telehealth advertising leaks.

On 29 July 2026 the Federal Trade Commission, joined by Utah and by California through Los Angeles County Counsel, filed a complaint against Hims & Hers in the US District Court for the Northern District of California, according to the FTC press release of 29 July 2026. The Commission vote to authorise staff to file was 2-0. Everything below is an allegation. The FTC itself notes that it files when it has "reason to believe" a law is being broken, and that the court will decide the case.

Three things are alleged. First, the FTC alleges that Hims does not clearly disclose that it charges consumers for prescriptions almost immediately after they submit an intake form, despite telling them they can consult a medical provider to find a treatment that is right for them.

Second, the FTC alleges the company made cancelling hard, including a cancellation button that appeared only after consumers chose an option to add or remove items from an order.

Third, and the strand that matters to anyone who buys media, the FTC alleges that Hims shared consumers' health information with Meta, Snap and other third parties, both by sharing lists of certain customers and through third-party tracking technologies that passed website "Events" to those companies.

The detail on the tracking strand comes from press coverage of the complaint. TechCrunch reported that the FTC alleges the company placed pixel-sized trackers from Meta, Snap and other platforms, including Microsoft, Pinterest, Reddit and X, and that those trackers "captured and shared users' health information" contrary to the company's own privacy policy. Read that as the FTC's account, not a settled fact.

What the company says#

Hims disputes the case. The Associated Press report of 19 September 2026 reports that the company called the claims "an effort to generate headlines at our expense". TechCrunch reported that a statement on the company's website said its privacy policy makes clear that users may choose how their data is used, that it is confident in its position, and that it plans to defend against the allegations.

The company's quarterly filing adds the paper trail. The Hims & Hers Form 10-Q for the quarter ended 30 June 2026 says the FTC issued a civil investigative demand in October 2023 about the company's privacy, advertising, subscription and cancellation practices, that settlement talks were unsuccessful, and that the company had recorded a legal contingency accrual of approximately $60 million for the matter at 30 June 2026. The filing also says that amount may move materially as the litigation progresses, and that the outcome of litigation is inherently uncertain. An accrual is an accounting provision. It is not a finding.

The Hims case, and what moved around it
The case has moved from a non-public investigation in October 2023 to a public complaint in July 2026, and every allegation in it remains untested by the court.

For a healthcare marketer the moonlit truth is quieter than the headline. Nobody has to decide whether these particular allegations are right for the underlying lesson to bite: the telehealth advertising stack is a data-sharing arrangement, and regulators now read it as one. That is the working brief of healthcare marketing in 2026.

Section 02

The rulebook: which rules bite on telehealth advertising#

Telehealth advertising sits under four layers at once: the FTC Act, a breach rule, HIPAA where it applies, and platform policy. Each answers a different question, and confusing them is how good teams end up compliant on paper and exposed on the wire.

The FTC business guidance on consumer health information says the FTC Act applies to companies that collect, use or share health information whether or not they fall under HIPAA. It adds that the BetterHelp, GoodRx and Premom cases make clear that disclosing consumers' health information for advertising without their affirmative express consent may be an unfair practice. In plain terms: what your privacy policy promises and what your tags transmit have to match.

The Health Breach Notification Rule, 16 CFR Part 318#

The FTC announcement of the amended Health Breach Notification Rule explains that the rule requires vendors of personal health records and related entities not covered by HIPAA to notify individuals and the FTC of a breach of unsecured health data. The 2024 update clarified that a breach of security includes an unauthorised disclosure, not only a hack, and that for breaches involving 500 or more people the FTC must be told at the same time as individuals, no later than 60 calendar days after discovery.

The rule moved again this month. On 9 September 2026 the FTC notice of 9 September 2026 said the Commission had rescinded its 2021 policy statement on breaches by health apps and connected devices, describing it as unnecessary because the 2024 update already covers health apps. That is the withdrawal of a guidance document, and the FTC's notice does not describe any change to the rule text. Whether a given telehealth brand counts as a covered vendor is a legal judgement worth paying for.

Meta pixel HIPAA: what a Texas court left standing#

The HIPAA layer is where the Meta pixel HIPAA question lives, and it applies only to covered entities and their business associates. The HHS Office for Civil Rights tracking technologies bulletin told regulated entities that tracking code on logged-in pages, such as a patient portal or a telehealth platform, generally has access to protected health information. It also said that IP addresses paired with visits to public pages about health conditions could trigger HIPAA.

That second point did not survive. On 20 June 2024, in American Hospital Association v. Becerra, the Northern District of Texas vacated the part of the bulletin covering that situation, and the American Hospital Association reported that HHS withdrew its notice of appeal on 29 August 2024. The HHS page, as read on 20 September 2026, still notes the vacatur and says HHS is evaluating its next steps. The practical reading: the logged-in side of the bulletin remains HHS guidance to regulated entities, the anonymous-page side is gone, and none of it protects a non-HIPAA brand from the FTC. HIPAA marketing rules bind the covered; the FTC Act binds everyone.

States add a layer. The Washington Attorney General on the My Health My Data Act describes the first US privacy law aimed at consumer health data outside HIPAA, enforceable through the state's consumer protection act and by private action. The AP notes that California, Connecticut and Maryland have passed laws protecting health information too, though it reports little enforcement so far.

Three layers of law and one of platform policy: certification sits in the last, and the pixel question runs through all four.
LayerWho it bindsWhat it coversStatus on 20 Sep 2026
FTC Act, section 5Any company handling health dataDeceptive or unfair health data practicesHims case pending; company disputes it
Health Breach Notification RulePersonal health record vendors outside HIPAABreach includes unauthorised disclosure2024 update stands; 2021 statement withdrawn
HIPAA and the HHS bulletinCovered entities and business associatesLogged-in page tracking; public-page part vacatedVacatur final; HHS evaluating next steps
Meta and Google policyAdvertisers using their toolsMeta bars health data; Google gates Rx servicesIn force; certification gates access only
  • FTC Act, section 5Any company handling health dataDeceptive or unfair health data practices Hims case pending; company disputes it
  • Health Breach Notification RulePersonal health record vendors outside HIPAABreach includes unauthorised disclosure 2024 update stands; 2021 statement withdrawn
  • HIPAA and the HHS bulletinCovered entities and business associatesLogged-in page tracking; public-page part vacated Vacatur final; HHS evaluating next steps
  • Meta and Google policyAdvertisers using their toolsMeta bars health data; Google gates Rx services In force; certification gates access only

Platform policy: Meta, Google and where certification sits#

The Meta Business Help Centre says advertisers may not use Meta Business Tools to share information about people that is not allowed under its terms, and lists information about diseases, medical conditions, medical treatments and prescription medication among the examples. It says this must not appear in URL parameters, custom event names or custom audiences, that the advertiser is ultimately responsible for what it shares, and that Meta's systems are not a substitute for the advertiser's own compliance.

On Google, the Google Ads prescription drug services policy says telemedicine providers fall under its rules on prescription drug services, that advertisers must be certified by Google to serve those ads, and that for some certifications a third-party accreditation from bodies such as LegitScript, NABP or G2 may be needed first. The LegitScript healthcare certification page says its certification is recognised by Google, Facebook, Microsoft, LinkedIn and Nextdoor, and its standards require applicants to comply with the laws on protected health information. Our own note on Google Ads healthcare policy and telemedicine covers how certification gates telehealth advertising in more detail.

Section 03

The wider trail behind telehealth advertising data sharing#

In telehealth advertising, one case is a footprint; a set of them is a trail. The Associated Press report of 19 September 2026 reports that FTC officials have filed similar cases against more than a half-dozen telehealth companies in recent years, naming online therapy provider BetterHelp and pharmacy discount service GoodRx, and that in both regulators said the companies shared users' health data with platforms such as Meta and Google without permission.

The FTC's own announcements carry the numbers. In February 2023 the FTC GoodRx announcement described a proposed order under which GoodRx would pay a $1.5 million civil penalty, the first action under the Health Breach Notification Rule. In March 2023 the FTC BetterHelp announcement described a proposed order requiring $7.8 million to be paid to consumers, and a ban on sharing health data for advertising. Both were proposed orders resolving FTC allegations, and the numbers describe those resolutions, not the Hims matter.

Why does the pattern keep repeating? The AP puts part of the answer in the law. It reports that HIPAA generally applies to medical offices, hospitals and insurers rather than to telehealth companies selling prescriptions, counselling or DNA tests, and quotes a Consumer Reports technology policy director saying there is no clear federal law saying not to do this, just soft law and settled FTC cases many companies may not know about. Whether HIPAA reaches a particular brand depends on facts, so that is a question for counsel, not for a blog.

The same AP piece cites a Yale-led analysis of nearly 50 telehealth companies selling GLP-1 drugs, which found that fewer than a third required a real-time video or audio consultation. That is about clinical process, not advertising, but it shows why regulators study the intake form: sales flow, medical questionnaire and tracking code all meet there.

Two measured pictures of the tracker thicket#

Two dated studies show how normal telehealth advertising tracking was before the current case. They describe the web at the time they were done, not any company today, and neither is about the Hims allegations.

The first is peer-reviewed. A census of US non-federal acute care hospital websites in Health Affairs census of hospital websites (Friedman et al., April 2023) found third-party tracking on 98.6 percent of them, including transfers to large technology companies, social media companies, advertising firms and data brokers.

Almost every hospital site in the census sent visitor data to third parties, so tracking was the default state of the health web, not an exotic leak.98.6% of US hospital websites carriedthird-party tracking (Health Affairs, April 2023)
Almost every hospital site in the census sent visitor data to third parties, so tracking was the default state of the health web, not an exotic leak.
ItemValue
98.6% of US hospital websites carried98.6% of US hospital websites carried
third-party tracking (Health Affairs, April 2023)third-party tracking (Health Affairs, April 2023)
Almost every hospital site in the census sent visitor data to third parties, so tracking was the default state of the health web, not an exotic leak.

The second speaks to telehealth directly. In December 2022 The Markup and STAT investigation of December 2022 audited 50 direct-to-consumer telehealth websites. On 13 of the 50 they documented at least one tracker that collected patients' answers to medical intake questions, and trackers on 25 sites told a large platform that a user had added an item such as a prescription to a cart or checked out with a subscription. On 35 sites, trackers sent individually identifying information such as names, email addresses and phone numbers.

How deep the trackers went, 50 telehealth sites audited in December 2022
Data shared via trackers
49 of 50
Identity details sent
35 of 50
Cart or checkout events
25 of 50
Intake answers collected
13 of 50
Trackers reached the intake questions on 13 of 50 telehealth sites and the cart or checkout on 25, so the depth of the leak is the story, not just its presence.

The 49 comes from the investigation's own headline. The narrower counts are the ones a media buyer should study, because they map onto the funnel: page view, sign-up, cart, intake. The deeper the tag sits, the more it knows.

Section 04

Certification is table stakes; the pixel is the exposure#

Here is the folkfox view, and it is an opinion, not a legal one. Certification with LegitScript or Google decides whether your ad account is allowed into the wood. It says nothing about what your tags whisper once you are inside. Every certified telehealth brand can run the same pixel, so in telehealth advertising certification cannot be a moat. It is the price of the ticket.

The exposure lives in the plumbing, and the plumbing belongs to marketing. In the complaint as the FTC describes it, health information travelled through two channels: customer lists shared with ad platforms, and website events sent by tracking technologies. Both are things a growth team sets up in an afternoon and forgets for years. So in telehealth advertising the audience upload is as much in the frame as the pixel, and any custom audience built from a condition or a prescription belongs on the audit list.

Certification opens the ad account. It does not close the pixel.
folkfox, on telehealth advertising after the Hims complaint

There is a real trade-off in telehealth advertising, and we will not pretend otherwise. Ad platforms optimise on the signals they receive, so a leaner data feed can mean weaker optimisation and a pricier prowl for new patients. We cannot put a number on that cost for your account. What we can say is that the alternative cost, a regulator reading your data flows the way the FTC has read this company's, is uncapped and public.

That is why our position on telehealth advertising is a growth model, not a retreat. First-party data you own, server-side collection you control, consent captured before any tag fires, and a hard minimum on what each vendor receives. Brands that build this well will outfox rivals still hiding behind a certificate, because their measurement will survive the next complaint, the next browser change and the next platform policy tweak. The wider shape of this argument, that regulated health brands win on proof rather than reach, runs through our pieces on the CMS ACCESS model and on telehealth rulings from the UK advertising regulator.

Section 05

What you can still measure, and how#

A healthy telehealth advertising programme keeps a great deal of signal without sending a diagnosis anywhere. The trick is to decide what each system needs to know and to stop there. Nothing in this section is legal advice; take the plan to counsel before you change tags.

A minimum-data measurement stack, in order
Map every flow

List each pixel, SDK, tag manager container and audience upload, and what each one sends. You cannot minimise what you have not found.

Strip the context

Remove condition, treatment and medication words from URLs, event names and parameters, which Meta names as places prohibited information must not appear.

Consent first

Fire no advertising tag before affirmative consent, and write the consent so it matches what actually happens.

Collect server-side

Route events through a server container on your own domain, then forward only the coarse events you have approved.

Measure in the den

Join ad clicks to sign-ups in your own first-party database, and use holdout and geo tests rather than platform-side conversion tracking.

Server-side collection is a control point, not a loophole. The Google Tag Manager server-side documentation says a server container runs on a server you control, that only you have access to the data there until you choose to send it elsewhere, and that you decide how the data is shaped and where it is routed. That control is the point: what you forward from the server is still what you disclose.

So what stays measurable? Almost everything a media plan needs. Sessions and sign-ups by channel and campaign, recorded in your own analytics on your own domain. Cost per lead by campaign, with the click identifier stored in your CRM rather than shipped to a platform. Subscription retention, refill rates and support contacts, analysed in your own warehouse. Incrementality through holdout regions or paused audiences, which needs volume totals rather than personal data. If you still send a conversion signal back to a platform, keep it coarse, something like a lead event with no condition, no product, no URL path, and get counsel's sign-off on the payload.

If you run paid search or paid social for a telehealth brand, the practical first move is an audit. Our PPC and paid social teams treat the tag inventory as step one of every healthcare account, before creative, before bids. Comparing your current telehealth advertising stack against the table above is a two-hour job that can save a two-year problem. If you want a second pair of eyes on the trail, start the conversation.

Questions

Frequently asked questions#

What is telehealth advertising?

Telehealth advertising is paid and organic promotion of remote care and prescription services, across search, social and display. It sits under health-specific rules on claims, on prescription drug services and on data, and platforms such as Google gate parts of it behind certification.

What are the privacy concerns associated with telehealth?

The main concern is that intake answers, cart events and identifying details can pass to advertising platforms through tracking code or customer lists, often without the person expecting it. Regulators, including the FTC in its Hims & Hers complaint, treat undisclosed sharing of health information as a consumer protection issue.

What has Hims & Hers said about the FTC case?

The company disputes it. It has said the lawsuit is an effort to generate headlines, that its privacy policy makes clear customers may choose how their data is used, and that it will defend itself vigorously. The FTC's claims are allegations that a court has yet to decide.

Does HIPAA marketing law cover a direct-to-consumer telehealth brand?

It depends on facts. HIPAA marketing rules apply to covered entities and their business associates, and the AP reports that HIPAA generally does not reach many telehealth companies. The FTC Act and state health privacy laws can still apply, so ask counsel where your brand sits.

What does HIPAA compliant marketing look like for a telehealth brand?

In practice it means minimum data, informed consent and no health context in ad tags, with vendor contracts to match. Where HIPAA applies, that includes authorisations and business associate agreements. Where it does not, the same discipline still answers the FTC and state laws. Have counsel confirm the design.

Is the Meta pixel HIPAA compliant?

There is no blanket answer. For HIPAA covered entities, tracking code on logged-in pages generally has access to protected health information, per HHS guidance, and Meta's own terms prohibit sending health information. Whether a given setup is lawful depends on the data sent and on the entity. Consult counsel.

Is LegitScript certification enough to advertise telehealth on Google and Meta?

No. Certification, or Google's own, gates access to prescription drug advertising, and LegitScript says its standards require compliance with privacy law. It does not audit or excuse what your tracking sends. Data flows still need their own review.

Keep reading

Read more on this topic#

Want telehealth advertising that survives a regulator's read?

folkfox audits healthcare ad stacks, maps every tag and audience, and builds consented, first-party measurement that keeps growth honest.

Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.