Product

What Healthcare Marketers Should Take From the FTC's Hims & Hers Complaint

On July 29th, the FTC, along with the People of the State of California and the Utah Division of Consumer Protection, sued Hims & Hers for allegedly sharing consumers' health information with Meta, Snap, and a long list of other ad platforms while telling those same consumers the experience was "100% online, private, and secure." The complaint also alleges charging for prescription subscriptions without informed consent.

Hims has denied the allegations and intends to defend itself. Regardless of how the case shakes out, the most valuable thing here is seeing what a regulator cares about. A regulator brings an action like this maybe once every few years, and then there are years of class actions that follow. This is a peek behind the curtain of what the next few years could look like.

I asked Chris Turitzin, founder of Single Aim, to read the whole thing and tell us what his takeaways are. Chris was one of the first to survey how health companies were navigating ad trackers and HIPAA after the HHS guidance came out in 2023 and knows this space better than anyone. His read is below, and the full unredacted complaint is at the end of this post.

………………….

Chris Turitzin:

The complaint is primarily around two issues: tracker hygiene and messaging.

A 'best-practice' tracker approach is to obscure event names, send events server-side, firewall their meaning from the advertising networks, and never include additional metadata. The network receives only a user identifier and an event with no meaning such as "EVENT_jk34h", without knowing what that event represents. All Meta or Google knows at that point is "this company sent us an event that they think is worth tracking".

Nothing in the complaint invalidates that approach. The behavior being called out is more careless: naming audiences and events with their actual meaning, sharing code names meanings with Meta, and sending additional treatment/condition metadata with the event.

The second issue is what Hims told its users. The complaint states that Hims described its service as private and discreet while still sharing information with ad networks. This is avoidable by 1. Not saying these things, and 2. Being explicit about what you are sharing.

It’s worth digging into what you can practically do to address this, and we’ll cover that on the panel next week.

………………….

I'll add one thing to Chris's point. These practices aren't complicated in theory, but they're hard to sustain, because they depend on every tag, event, and destination still behaving the way someone said it would years ago. That makes this an infrastructure problem more than a policy problem.

The baseline best practices we'd recommend to any healthcare marketing team:

  • Collect consent where applicable state privacy laws require it, and keep your consent management platform current as those laws keep changing.

  • Only send the data you actually need. Nothing extra "just in case."

  • Strip, redact, hash, etc. sensitive data before sending it to third parties.

  • Rename event names, and audience names and never share what those names mean with unauthorized third-parties.

  • Set up a regular cadence to audit your data flows and messaging.

  • Make sure your messaging matches what your site actually does, whether that’s your privacy policy, your website copy, influencer’s ad copy, or a billboard.

That last one is one of the core issues in this complaint, and it's where a lot of teams are unknowingly exposed.

It's also why we built Ours Privacy the way we did. Because consent, collection, and activation live in the same system, you can answer "what are we sending, to whom, and why" in a few clicks. Our compliance reporting gives legal teams a single view of what data is being shared per destination, if it’s been anonymized and how, and if it’s being governed by consent rules. And our web scanner finds tracking pixels across your site, and scans your privacy policy pages to flag where your stated practices and actual behavior don't line up.

None of this makes you immune to scrutiny. But when someone asks what you're sharing, you have a real answer instead of a best guess, and you can make informed decisions to market with confidence.

If you’re interested in learning more about this topic and getting your questions answered, register here for our upcoming webinar, “Inside the Unredacted Hims & Hers Complaint: a conversation on what the full files reveal and what healthcare marketers need to know.

And, as promised, here is the full unredacted complaint.





Share Article

Book a Demo

Health systems and digital health companies use Ours Privacy to run essential marketing tools like Google Ads and GA4 while maintaining HIPAA compliance.

Related Articles

Newsletter

Stay up to date

Subscribe for privacy news, feature updates, events, etc.

Start the conversation

Healthcare marketers tell us every day about the challenges of flying blind, navigating compliance, and dealing with ad restrictions. Talk with one of our experts to see if Ours Privacy is the right fit for your organization.

Start the conversation

Healthcare marketers tell us every day about the challenges of flying blind, navigating compliance, and dealing with ad restrictions. Talk with one of our experts to see if Ours Privacy is the right fit for your organization.

Start the conversation

Healthcare marketers tell us every day about the challenges of flying blind, navigating compliance, and dealing with ad restrictions. Talk with one of our experts to see if Ours Privacy is the right fit for your organization.