Subscriptions Meet Sensitive Data: The FTC and States Sue Hims & Hers
by: Sara Chubb & Lael Bellamy
We have written before about the FTC's steady run of subscription enforcement, from Amazon and JustAnswer to Instacart and Uber. Separately, the FTC has pursued enforcement on the theory that health and sensitive data flowing to advertising platforms can violate a company's own privacy promises, in matters like GoodRx and BetterHelp. These two lines of enforcement converged with a July 29, 2026 complaint filed by the FTC, joined by Utah and California (through Los Angeles County Counsel), against telehealth provider Hims & Hers (“Hims”) in the U.S. District Court for the Northern District of California. The suit alleges both deceptive billing and cancellation practices and the sharing of consumers' sensitive health information with third-party advertising platforms.
The complaint makes several key allegations, combining three areas where regulatory enforcement is active: the telehealth industry, subscription compliance, and sensitive information disclosure via tracking technologies.
Consumers Charged Before the Promised Consultation
According to the complaint, Hims advertised that consumers could "connect" and consult with a medical provider to determine whether they needed prescription medication, and asked for billing information during intake alongside assurances that consumers would not be charged unless and until medications were prescribed. The FTC alleges that most consumers were instead charged and enrolled in a recurring subscription plan shortly after submitting the intake form, before receiving a consultation (with many allegedly never receiving a consultation at all). The FTC also alleges the company failed to clearly and conspicuously disclose when prescriptions would refill each month, making it difficult to cancel before the next billing cycle.
An Online Cancellation Path That Was Hard to Find
Before 2023, the complaint alleges, most consumers could cancel only by contacting customer service by phone, email, or chat, with additional hurdles along the way. Even after the company introduced online cancellation for most consumers in 2023, the FTC alleges the cancellation process was confusing and difficult: the cancel button appeared only after a consumer selected an option to "add/remove items from order" and navigated several further steps before the word "cancel" appeared at all.
This allegation underscores that merely having an online cancellation option is not sufficient if it is hard to find or use. Where it sits in the interface, and how many steps stand between the subscriber and the word "cancel," are critical considerations for subscription compliance.
Sharing Health Data with Ad Platforms, Two Different Ways
The complaint alleges that Hims shared consumers' health information with advertising platforms including Meta and Snap, contrary to representations of privacy and discretion in Hims’ privacy policy, website statements and influencer advertisements. The FTC describes two distinct mechanisms: sharing lists of certain customers with those platforms, and sharing information through third-party tracking technologies that automatically transmitted website "Events," meaning the actions of visitors on the site.
The Claims
The FTC alleges violations of the FTC Act (i.e., deceptive privacy practices and failure to disclose the sharing of health information with advertising platforms), and the Restore Online Shoppers' Confidence Act (ROSCA), which prohibits deceptive billing and subscription practices. Utah alleges violations of the Utah Consumer Sales Practices Act, and California alleges violations of California's False Advertising and Unfair Competition Laws. Hims has publicly disputed the allegations. Notably, the FTC did not bring a claim under the Health Breach Notification Rule, which was used in GoodRx (2023) and Easy Healthcare Corporation (Premom)(2024).
Key Takeaways
State and local enforcers are using consumer protection statutes to reach privacy conduct. No state privacy statute appears in this complaint. The state and local claims are UDAP (Unfair or Deceptive Acts or Practices) and false advertising claims, which is an important reminder that a company’s privacy and advertising practices can create exposure beyond comprehensive state privacy laws.
Nothing in the complaint suggests the core subscription model is unlawful. Instead, the allegations highlight gaps between marketing messages and actual practices. The alleged problem is that the user experience promised a consultation and no charge, and the system charged anyway and then made it hard to cancel.
Consider evaluating the following with internal stakeholders and outside counsel:
Do your privacy, subscription and enrollment flow practices match what your policies, terms, ads and online statements promise?
Have you tested your online and mobile application cancellation flow to ensure it is easy for consumers to find and navigate and allows subscribers to cancel in roughly the same number of steps as signing up?
Have you reviewed your processes, policies and operations from the consumers’ standpoint including complaints received directly and online?
Do you know what information you share with third parties? (hint: it doesn’t matter if you can’t identify an individual or device if third party adtech parties can)
Have you inventoried and tested your website and mobile app technologies for sharing with third parties including advertising, analytics and measurement vendors, which includes every tag, pixel, SDK, API and client or server-side event on your site and app?
If you have questions about subscription program design, cancellation flows, privacy and tracking technologies, or consumer health data compliance, please reach out to our team.
Originally published by InfoLawGroup LLP. If you would like to receive regular emails from us, in which we share updates and our take on current legal news, please subscribe to InfoLawGroup’s Insights HERE. This summary does not constitute legal advice.