Hims Sent Health Data to TikTok, FTC Says

Hims called checkout "100% online, private, and secure." The complaint disagrees.

Share

Introduction

Meta, Snap, TikTok, Google, Microsoft, X, Pinterest, Reddit, Criteo, the Trade Desk. Those are ten of the at least fifteen advertising platforms whose tracking code was running on Hims & Hers' website, according to the FTC's complaint (¶77), reporting back what people did on their way to a prescription for erectile dysfunction, hair loss, a weight-loss shot, or an antidepressant. The complaint also quotes what those customers were reading: a "100% online, private, and secure process."

If you've ever ordered from a telehealth site for something you'd rather not see advertised back to you, your own checkout page is the surface this case is about, and Hims is not the only company whose version of it got caught. STAT News and The Markup tested 50 direct-to-consumer telehealth companies in late 2022 and found 25 of them, Hims among them, reporting cart adds and checkouts to at least one big tech platform.

Hims & Hers was named by name nearly four years before the FTC filed, and the federal investigation that opened in October 2023 ran almost three years before producing this complaint. What moved in that window was a number on the company's own balance sheet: the legal accrual for this matter went from $15 million in May, per CNBC, to roughly $60 million by June 30.

How the Data Left the Checkout Page

Two mechanisms, per the FTC. Hims uploaded lists of certain customers directly to ad platforms, which match those lists against their own user bases so an advertiser can retarget that group and buy audiences built to resemble it. Separately, Hims embedded third-party pixels on its site, small pieces of code that fire as a visitor moves through a page and report "Events" back to the platform: page viewed, form answered, item added to cart, purchase completed. The date range for this conduct is redacted in the public complaint, so nobody outside the case knows exactly when it started or whether it stopped.

The 2-0 Vote Behind the Complaint

The filing itself runs 48 pages and nine counts, brought July 29 in the Northern District of California by the FTC, the Utah Division of Consumer Protection, and the People of the State of California appearing through Los Angeles County Counsel Dawyn R. Harrison. The Commission authorized it on a 2-0 vote, which reads as consensus until you check the roster: two of five commissioner seats are filled, both by Republicans, after President Trump removed the two Democratic commissioners in March 2025 and Melissa Holyoak left in November 2025 to become interim U.S. Attorney in Utah, a co-plaintiff state in this very case.

Set against the conduct the complaint describes, the marketing: a "100% online, private, and secure process" (¶63), and health information "only accessed by the medical providers managing your care" (¶62), a claim the FTC says ran until at least late August 2023. Three of the nine counts are ROSCA claims with nothing to do with data, alleging instead that Hims charged people before they ever spoke to a provider and buried the cancel button several clicks inside an "add/remove items from order" menu. One consumer complaint the FTC quoted: "I was told that I would be able to speak with a doctor in a few days and that nothing would be charged to my card that day. Him's & Her's [sic] charged me immediately!"

25 of 50 Telehealth Sites Sent Checkout Data to Big Tech

STAT and The Markup ran their audit in October and November 2022, loading 50 telehealth sites and watching what left the browser. Trackers on 13 of the 50 captured patients' answers to medical intake questions. On half of them, a tracker told at least one big tech company when a user added an item to cart or checked out with a subscription, a group the reporters described as including "industry leaders Hims & Hers, Ro, and Thirty Madison." Thirty-five sites sent names, emails, or phone numbers to tech companies, and 49 of the 50 sent URLs or IP addresses to at least one. At least twelve of the 50 advertised themselves as HIPAA-compliant.

Hims & Hers spokesperson Scott Coriell answered that investigation by defending the industry's need to reach patients, without disputing the tracking findings.

In October 2023, less than a year after that story published, the FTC issued its Civil Investigative Demand. The company disclosed that date itself, in the Q2 10-Q, the same filing where it put a dollar figure on the exposure.

Hims Priced the Exposure at $60 Million

The Q2 2026 Form 10-Q, filed August 10, states it in a single line: "As of June 30, 2026, the Company had recorded a legal contingency accrual of approximately $60 million for this matter in accordance with ASC 450, Contingencies." The accrued-liabilities table puts legal contingencies at $62.5 million, against $0 at the end of 2025. Three months earlier, per CNBC, the number Hims had disclosed was $15 million.

The same note confirms the October 2023 demand, says the company "engaged in good faith settlement negotiations with the FTC, but these negotiations were unsuccessful," and discloses a follow-on class action, Doe v. Hims & Hers Health, Inc., filed in the same court after the FTC's suit under the federal wiretap statute and two California privacy laws.

Hims disputes all of it. The company's statement calls the case "an effort to generate headlines at our expense" and promises to "vigorously defend." It never says the data stayed put, only that the privacy policy "makes clear that they may choose how their data is used," which argues about the disclosure rather than the pipeline. CEO Andrew Dudum went further on CNBC's "Squawk Box" on August 18, telling Andrew Ross Sorkin the agency "wanted more of a headline than a real agreement here." Bloomberg put the stock's same-day drop on July 29 at about 15%, to $25.00. It closed at $31.10 on August 19, up 13.55% on the day, above where it traded before the lawsuit existed.

Who Benefits

Hims & Hers first, and the benefit is growth rather than profit. A list of customers already buying finasteride is worth more to an advertiser than a list of men aged 25 to 45, because the platform can match it and then sell an audience built to look like it. That is the entire function of the custom-audience tools these lists get uploaded to. The complaint puts the motive in plain language at ¶7: Hims "opted to grow the company and increase its revenue streams" with platforms such as Meta and Snap. The Q2 numbers show what growth looked like while the investigation ran: 2.891 million subscribers, up 19% year over year, U.S. revenue up 16% to $621.8 million, monthly revenue per average subscriber up 21% to $92. That 21% is the figure I keep coming back to, because it means the company was pulling more out of each customer in the third year of a federal investigation into how it got them. None of it reached the bottom line. Hims lost $86.3 million in the quarter and its gross margin fell from 76% to 64%.

Meta and Snap sit at the other end of the pipe, and neither is a defendant here. What they get is inventory that prices higher. An ad served to someone the system knows is shopping for a weight-loss prescription is worth more than an ad served to a stranger, and the platforms' defense against ingesting that kind of data is asking advertisers not to send it. Meta told New York regulators in 2021 that its filtering was "not yet operating with complete accuracy." When STAT and The Markup brought specific findings to Snap, Google, and Pinterest, those companies took remedial action after being shown the data. That kind of self-policing catches what a reporter brings them, and more data flowing in is good for their ad business.

GoodRx, BetterHelp, and the HIPAA Gap

This is the FTC's third run at the same conduct. GoodRx paid a $1.5 million civil penalty in February 2023. BetterHelp was ordered to pay $7.8 million that July, and roughly 800,000 people began receiving refund notices in May 2024. Both cases turned on health data moving to ad platforms through pixels, contrary to what the company had promised in public.

The legal theory shifted this time. GoodRx was the FTC's first-ever action under the Health Breach Notification Rule, but the Hims complaint skips that rule entirely and runs instead on FTC Act §5, ROSCA, and California and Utah statutes. Venable's client alert flagged the omission on August 10, noting the contrast with Biden-era enforcement of similar practices; the theory the agency did choose never requires proving a breach.

Underneath all three cases is a gap Congress hasn't closed. HIPAA covers the provider group, and generally not the telehealth company's marketing website, which is where the checkout page lives and where the pixels fire. The part I find hard to get past: "private" on a direct-to-consumer health site is a marketing word, not a HIPAA obligation, because these companies structure themselves as something other than the "covered entity" HIPAA actually regulates. Ro and Thirty Madison were named in the same 2022 audit and, as far as the public record shows, face no comparable federal action.

The Bottom Line

The $60 million on the balance sheet is the company's own estimate, and the 10-Q warns it "may decrease or increase materially in future periods." What isn't priced into it is the injunction. The plaintiffs are asking the court to permanently bar the conduct and to impose civil penalties of up to $2,500 per violation under two separate California statutes, and an order like that would be the first of its kind imposed by a court rather than negotiated, as the GoodRx and BetterHelp orders were.

The market isn't treating that as the risk. Three weeks after the filing the stock closed above its pre-lawsuit level, and the accrual reads as a rounding error against a company that booked $753 million in revenue last quarter, a figure that includes the international business it acquired in June. The open question is whether the accrual and a court fight register to the other 24 companies the 2022 audit caught as a penalty, or as the going rate for the same growth.