On July 29, 2026, the Federal Trade Commission, the Utah Division of Consumer Protection, and the People of California filed a civil consumer-protection lawsuit against Hims & Hers Health. The case concerns more than one company’s privacy policy or cancellation process. It asks what meaningful consent should look like when healthcare, online advertising, and subscription commerce occupy the same screen.
The complaint alleges that Hims disclosed sensitive health-related information through advertising and analytics technologies, enrolled and charged consumers without sufficiently clear purchasing terms, and made some subscriptions difficult to cancel. Hims denies wrongdoing and says customers receive the information needed to make informed choices.
These are allegations in a pending civil case—not findings that Hims violated the law. As of August 12, 2026, the FTC’s public case page reported no settlement, judgment, or liability finding.
That distinction matters. So does the conduct described in the complaint. Telehealth companies ask people to disclose intimate information, make potentially consequential healthcare decisions, and often authorize recurring payments in a single digital journey. Privacy, informed purchasing, and easy cancellation cannot be treated as fine print around that experience. They are part of whether the experience deserves trust.
What regulators allege happened
The lawsuit was filed in the U.S. District Court for the Northern District of California as FTC et al. v. Hims & Hers Health, Inc., No. 3:26-cv-07871. The FTC voted 2–0 to authorize the complaint, joined by Utah regulators and California acting through Los Angeles County Counsel.
The allegations fall into four broad categories.
Sensitive health-related data allegedly reached advertising platforms
According to the FTC’s announcement, Hims allegedly used tracking technologies that transmitted consumers’ health-related information and website activity to advertising or analytics companies, including Meta and Snap.
The complaint contends that these data flows could identify or reveal a person’s interest in treatment for sensitive conditions. Regulators allege that the disclosures occurred without adequate notice or informed consent, despite representations that the service protected patient privacy.
The lawsuit should not be summarized as an established finding that Hims “sold patient data.” The supplied record supports a narrower and more precise statement: regulators allege that tracking technologies transmitted sensitive health-related information and activity to advertising or analytics companies. Hims disputes the government’s account.
Even with that qualification, the allegation points to a fundamental telehealth problem. A person may reasonably understand that information entered into a medical intake will be reviewed for care. That does not necessarily mean the person expects health-related page visits or other digital activity to enter an advertising ecosystem.
Consumers allegedly were charged before a meaningful purchasing decision
The complaint also focuses on the line between requesting a medical evaluation and buying a product.
Regulators allege that consumers provided payment details while completing medical-intake forms after being told they could connect or consult with a provider to identify an appropriate treatment. According to the complaint, many consumers did not receive an actual consultation and were charged almost immediately after a provider approved a prescription.
The government contends that this gave consumers little or no opportunity to review the recommended treatment, its price, or the recurring plan before the charge occurred.
This distinction is especially important in healthcare. Submitting information for clinical review is not necessarily the same act as accepting a recommendation, approving a price, and authorizing future shipments. A well-designed process should not collapse those separate decisions into an ambiguous click.
Automatic-renewal terms allegedly were unclear
Regulators further allege that Hims failed to disclose material subscription terms clearly and conspicuously, including when initial charges and prescription refills would occur.
The federal claims cite the Restore Online Shoppers’ Confidence Act, commonly called ROSCA, as well as Section 5 of the FTC Act. ROSCA governs online “negative-option” programs—arrangements in which a consumer’s silence or failure to cancel is treated as permission for recurring charges.
Subscriptions are not inherently improper. They can be useful when people need continuity and predictable deliveries. The problem arises when a company benefits from confusion about when billing begins, how frequently it repeats, what is included, or what a consumer must do to stop it.
In healthcare, a recurring plan may also become entangled with a clinical process. That makes plain language and deliberate authorization more important, not less.
Cancellation allegedly created unnecessary obstacles
Finally, the complaint alleges that Hims made some recurring subscriptions difficult to cancel. According to a legal analysis of the case, before 2023 most consumers had to contact customer service by phone, email, or chat rather than use a straightforward online cancellation mechanism.
Regulators say those obstacles could result in another shipment and charge before a consumer completed cancellation.
A cancellation system should not become a test of persistence. If enrollment happens online, patients should reasonably expect a simple and prominent online way to stop future renewals. Companies should not depend on friction, delay, or customer fatigue to preserve revenue.
What Hims & Hers says in response
Hims has rejected the allegations and said it will vigorously defend the lawsuit. In its July 29 response, the company called the claims “baseless” and characterized the action as an attempt to generate headlines.
The company said regulators disregarded evidence it provided during an investigation lasting almost three years and ignored relevant state laws and telehealth industry standards. Hims also said customers receive the information needed to make informed decisions, its privacy policy allows them to choose how their data is used, and information shared with healthcare providers is used only to provide care.
Those statements are a material part of the dispute. The court has not yet determined which allegations have been proven, whether any law was violated, or what relief—if any—is appropriate.
The plaintiffs are requesting a permanent injunction, monetary relief or consumer redress, civil penalties, and other remedies. Those are requests, not penalties already imposed.
This is not simply a HIPAA story
It is tempting to describe every dispute involving health information as a HIPAA violation. That would be inaccurate here based on the filed claims.
The central federal theories are alleged unfair or deceptive practices under the FTC Act and alleged subscription violations under ROSCA. The complaint also invokes California’s Unfair Competition Law and False Advertising Law, along with Utah consumer-protection law.
That legal framing carries an important lesson. A health company’s responsibilities do not begin and end with whether a particular data flow falls under HIPAA. Privacy promises must accurately describe what the business and its technology actually do. Purchasing terms must be understandable. Consent must be meaningful rather than merely available somewhere in a long policy.
A platform can create serious trust problems when its public assurances and its technical data flows do not match, regardless of which particular statute ultimately applies.
Why these allegations matter across telehealth
Telehealth depends on disclosure. Before receiving care, patients may be asked about symptoms, medications, mental health, sexual health, weight, hair loss, or other personal concerns. The vulnerability is built into the service: useful evaluation requires honest information.
That creates a higher obligation for the business receiving it.
Advertising trackers can move health-related activity beyond the relationship a person thought they were entering. Unclear checkout design can make it hard to know whether someone is requesting an evaluation or authorizing a purchase. Automatic renewal can turn one confusing interaction into repeated financial harm. Cancellation barriers can leave people paying for a service they no longer want.
These concerns reinforce one another. A person who is unsure where their information went, why they were charged, or how to cancel may lose confidence not only in one company but in telehealth more broadly. That is costly for an industry whose legitimate value depends on patients trusting remote care enough to use it honestly.
Competition does not excuse these practices. In fact, responsible competition requires patients to have enough information to compare services and leave one when it no longer meets their needs. A company should succeed because people knowingly choose its care—not because the digital process obscures a charge or makes departure difficult.
What patients should be able to expect
The lawsuit offers a practical checklist for any telehealth service, regardless of how the case ends.
A clear boundary around health-related information
A company should explain what information it collects, why it collects it, who receives it, and whether any of it supports advertising or analytics. That explanation should be understandable before a patient submits sensitive information.
The questions worth asking include:
- Do advertising pixels, analytics tools, or similar trackers operate on condition, intake, checkout, or patient-portal pages?
- Can health-related page visits, form entries, identifiers, or customer lists reach advertising platforms?
- Is consent specific and understandable, or bundled into a broad acceptance screen?
- Can a person withdraw consent without losing unrelated access to care?
- Does the privacy policy match the platform’s actual technical behavior?
A policy is not a substitute for knowing where data travels.
Separate consent for evaluation, treatment, and payment
A patient should be able to tell when each important decision occurs. Requesting an evaluation, receiving a provider’s recommendation, approving that recommendation, accepting a price, and enrolling in recurring billing are distinct actions.
A trustworthy flow should display the treatment, total price, shipment schedule, and renewal terms before payment authorization. It should also make clear that an evaluation does not guarantee eligibility, a prescription, or any particular treatment.
Subscription terms that are visible before checkout
Material terms should not require searching through several screens. Before paying, a consumer should be able to answer:
- How much will I be charged today?
- Is this a one-time purchase or a recurring plan?
- When will the next charge occur?
- How frequently will refills or shipments occur?
- Can the price change?
- How do I pause or cancel?
If those answers are difficult to find, the purchasing process is not ready for informed consent.
Cancellation that is as straightforward as enrollment
People should not have to plead their case to cancel. A prominent online method, an immediate confirmation, and a clear effective date are basic consumer protections.
Patients should also know whether a cancellation stops only future billing, affects a shipment already being processed, or changes access to clinical support. Those details should be stated before a deadline passes.
The standard Gentle Health should meet
It would be easy to respond to this lawsuit with a broad promise that Gentle Health would never make the same mistakes. A promise is not enough. Privacy and subscription integrity have to be demonstrated through concrete, verifiable controls.
Our standard is that health-related information should be handled in a way that matches what patients are plainly told; evaluation should be distinct from purchase authorization; prices and renewal timing should appear before a charge; and cancellation should not depend on unnecessary friction.
Before making stronger claims about our own systems, the responsible step is to verify them. That means auditing which tracking technologies operate across condition, intake, checkout, and patient pages; confirming whether data can reach advertising platforms; checking that consent is informed and revocable; reviewing when treatment and pricing are shown; and testing cancellation from a patient’s point of view. Gentle Health regularly performs all of these audits and checks on a regular basis and strive for maximum transparency from a consumer-first perspective. As recipients of healthcare ourselves, we design everything with the customers’ privacy and best interest in mind.
It also means correcting any gap between written policy and technical reality. Compliance language cannot repair a product design that creates confusion, and a good interface cannot excuse undisclosed data flows.
That is not an accusation against Hims, whose liability remains unresolved. It is the durable lesson of the case: telehealth companies should expect their privacy promises, checkout design, billing systems, and cancellation tools to be judged together.
Trust must be designed into the service
The Hims & Hers lawsuit remains pending. Regulators have made serious allegations; Hims has firmly denied them; and no court has found the company liable.
Patients do not need to wait for a final judgment to identify the standards that matter. Sensitive information should not take unexpected routes. Medical review should not be confused with purchase authorization. Recurring charges should never be a surprise. Cancellation should be simple.
Telehealth can expand access and make care more convenient, but convenience is not just a fast intake or home delivery. It also means understanding what you are agreeing to, knowing what will happen to your information, and being able to leave without a fight.
Trust is not created by placing the word “privacy” in a policy or “cancel anytime” near a checkout button. It is created when the technology, business model, and patient-facing promises all tell the same story.
Dr. James Simmons, MD
Compounded medications are not FDA-approved. Treatment subject to medical evaluation.