Last updated: 2026-10-02
On July 29, 2026, the Federal Trade Commission, the Utah Division of Consumer Protection and the People of the State of California, acting through Los Angeles County Counsel, sued Hims & Hers Health, Inc. in the Northern District of California, No. 3:26-cv-07871. The complaint in the FTC lawsuit alleges that Hims & Hers, a telehealth company, shared consumers' health information with Meta and Snap "through at least May 2024", by uploading customer email lists and by sending Meta Pixel and Conversions API events, while advertising a "100% online, private, and secure process". These are allegations. In its 10-Q for the quarter ended June 30, 2026, Hims & Hers states that it "believes it has meritorious arguments and intends to vigorously defend against the alleged claims", and reports "a legal contingency accrual of approximately $60 million for this matter".
What does the FTC lawsuit against Hims & Hers allege?
The complaint has two parts. One concerns subscriptions: the plaintiffs allege that Hims charged consumers for prescription subscriptions after they submitted an intake form, without express informed consent, and made cancellation difficult. The other concerns privacy.
The FTC release lists the claims: the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA) for the FTC, the Utah Consumer Sales Practices Act for Utah, and California's False Advertising Law and Unfair Competition Law for California. The Commission vote to file was 2-0. The complaint names Hims & Hers Health, Inc. as the only defendant. The privacy claims are Counts I and II, FTC Act Section 5: deceptive privacy representations ("Hims' services are private"; "Hims' services are discreet") and failure to disclose "that Hims shared sensitive health information provided by consumers with third-party Advertising Platforms" (page 32). California asks for civil penalties of up to $2,500 per violation of each of its two statutes; the complaint names no total.
The complaint quotes the privacy promises it relies on. Until at least late August 2023, a question on the Hims homepage, "How does Hims ensure patient privacy?", was answered with "medical records and sensitive information are only accessed by the medical providers managing your care" (page 23). Offline advertisements described the platforms as "totally private" (page 25).
What did Hims send to Meta and Snap, according to the complaint?
The complaint alleges sharing through four channels. The figures and names below are in the unredacted version filed on August 18, 2026; the public version filed on July 29 redacted most of them.
| Channel | Recipient | What the complaint says was sent | Period and volume | Complaint |
|---|---|---|---|---|
| Customer list uploads | Meta | Email addresses of consumers who registered for, or submitted an intake form for, a named treatment, in audiences named "All Time Hims ED Purchasers", "Hers Apollo Signups" and "Lookalike (US, 6% to 7%) – PE Purchasers w LTV" | About 14 million emails, September 2020 to June 2023; Meta matched about 10 million to a Meta user ID; 90 Lookalike Audiences, March 2020 to September 2023 | ¶¶ 68–69 |
| Meta Pixel and Conversions API events | Meta | "Complete Registration" and "Purchase" events with email and IP address as parameters, plus custom parameters such as product_bucket and product_type with treatment codewords |
"approximately 8 million times" | ¶¶ 70–73 |
| Customer list uploads | Snap | Lists named "All_Time_Hers_Psych_Signups", "AllTime_RX_PEJ_06082022" and three others | Five lists with "over 1 million email addresses" | ¶ 76 |
| Other website pixels | Microsoft, Google, Criteo, MediaBids, PartnerCentric, PebblePost, Pinterest, Podsights, Reddit, StackAdapt, TikTok, The Trade Desk, X | "many of these pixels captured and shared Users' health information by way of similar pixel tracking events" | No volume given | ¶ 77 |
Source: the unredacted complaint, ECF No. 28, filed August 18, 2026.
The Meta allegations turn on codewords. According to paragraph 69, "Internal Meta marketing communications demonstrated that Meta knew what Hims' codewords meant by including the corresponding medical conditions in parentheses as follows: 'Apollo (MH),' 'Atlas (PEJ),' and 'Zeus (ED).'" The same paragraph expands the codes: "'MH' is an abbreviation for mental health, 'PEJ' is an abbreviation for premature ejaculation, and 'ED' is an abbreviation for erectile dysfunction." In the Purchase event, "M-R" in product_bucket or product_type "meant 'mental health'" (¶ 73). The complaint also lists event-based Meta audiences such as "Hers – Complete Registration – MH – 30d" (¶ 74).
Does the complaint cover the Hims and Hers apps?
The complaint's definitions include the apps. Paragraph 17 defines the "Hims Platform" as "the Hims website and app" and the "Hers Platform" as "the Hers website and app". Paragraph 70 alleges that Hims placed the Meta Pixel and Conversions API "on the Hims Platforms to track consumers", and describes the Conversions API as a "direct connection between the advertiser's server, website, app or other internal software and Meta's systems".
The complaint's factual examples describe the website. Paragraph 67 defines the shared "Events" as "the actions of website visitors on Hims' website", and paragraph 77 lists pixels "on its website". The complaint names no mobile SDK (the Facebook SDK, the Snap SDK or another) and gives no app event names. The apps appear in the subscription allegations: a self-serve in-app cancellation feature was introduced "in or around May 2023" and removed (¶ 58), and Hims delayed its launch "to January 2024" (¶ 59). What the apps sent to Meta or Snap is outside the public record of this case.
Where does the case stand?
From the CourtListener docket and PacerMonitor's copy of the PACER docket, both checked on October 2, 2026:
- Hims moved to permanently seal portions of the complaint. On August 17, 2026, Judge Vince Chhabria denied the sealing motions and ordered Hims to show cause. On August 24 he lifted the order: "If Hims files another sealing request that is remotely this overbroad, sanctions will issue" (ECF No. 32).
- The FTC filed the unredacted complaint on August 18, 2026 (ECF No. 28). The FTC case page posts it under August 31, 2026. It is the same complaint with the redactions removed, still signed July 29, 2026; the docket lists no amended complaint.
- Hims waived service, and its answer was first due on September 28, 2026. On September 10, 2026, Judge Chhabria granted a stipulated schedule for responding to the complaint (ECF No. 43): a motion to dismiss is due by October 22, 2026, responses by November 25, replies by December 17, and the motion hearing is set for January 7, 2027. The docket text of the order adds: "The Court does not anticipate granting any further extensions." The order is available as docket text only; its six pages were not reviewed.
- The initial case management conference is set for October 30, 2026. On October 1, 2026, Hims filed an administrative motion to continue it, with responses due by October 5 (ECF No. 49).
A private putative class action, Doe v. Hims & Hers Health, Inc., No. 3:26-cv-07941, was filed in the same court on July 30, 2026, and on September 16, 2026, Judge Chhabria related it to the FTC case (ECF No. 44). The company's 10-Q describes it as "asserting claims arising from substantially the same underlying facts alleged in the FTC action, including claims under the Electronic Communications Privacy Act, the California Invasion of Privacy Act, the California Confidentiality of Medical Information Act". The Doe complaint itself is not available on CourtListener, so this post relies on the company's description. On September 30, 2026, the judge related a third case, Holbrook v. Hims & Hers Health, Inc., No. 3:26-cv-10668, filed on September 18, 2026 (ECF No. 48); its complaint was not reviewed for this post. California's SB 690, signed on September 30, 2026 and operative on January 1, 2027, amends CIPA's private right of action; the post on SB 690 covers which CIPA claims remain.
What a CanITrustThat scan shows for a telehealth app
The Hims app on Android is com.himshers.hims and the Hers app is com.himshers.hers. This post covers the complaint and what a scan of a telehealth app records; it reports no scan results for these two apps.
Meta's App Events reference lists Complete Registration (EVENT_NAME_COMPLETED_REGISTRATION) and Purchase (EVENT_NAME_PURCHASED) among the standard events of the Facebook SDK for Android, the same two standard event names the complaint describes for the website. Custom parameters such as a treatment code are added by the app developer. Meta's Conversions API page states that a direct integration connects "an advertiser's server and Meta's Conversions API endpoint". Server events are sent from the advertiser's servers, so a capture on a test phone records the SDK traffic from the device and excludes server-to-server events.
When I scan an app, the static pass lists the SDKs found in the binary (Facebook, Snap, TikTok, Google and others) and the permissions and consent flow, with the file and line for each finding. Presence in the binary shows the code is in the app; only the traffic capture shows what was sent. The dynamic pass records the traffic on a test device during registration and an intake flow: which host received which event name and parameters, with email hashes and treatment codes where present, and whether each request was sent before or after consent. What a scan checks and the limits of a scan are on the methodology page. The post on the Rodriguez v. Google verdict covers a jury case decided on SDK data from apps.
I run these investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.