What the FTC Lawsuit Against Hims & Hers Means for Telehealth Companies
Updated August 4, 2026
On July 29, 2026, the Federal Trade Commission sued Hims & Hers Health, Inc. in the U.S. District Court for the Northern District of California. The FTC did not file alone. It was joined by the State of Utah and by Los Angeles County Counsel, acting on behalf of the People of California.
The company denies the allegations. Its statement says the lawsuit disregards evidence provided over a nearly three-year investigation, ignores established state telehealth law and industry standards, and contorts the law to manufacture claims. It says the company will defend itself. Nothing here has been proven. Shares fell roughly 10 percent the day it was filed.
But the shape of this complaint tells you a great deal about where enforcement in this industry is heading, and that matters whether or not Hims ultimately wins.
First, which lawsuit are we talking about
A lot of people are conflating several separate legal matters. It helps to lay them out, because the pattern only becomes visible when you see them together.
June 2025. Novo Nordisk ends its collaboration with Hims, publicly accusing the company of deceptive promotion of knockoff versions of Wegovy. The stock drops more than 33 percent in a day. Securities class actions follow, alleging the company misled investors.
February 2026. Hims announces a $49 compounded oral semaglutide pill. Within days, the FDA states its intent to act, citing sections 502(a) and 502(bb) of the Federal Food, Drug, and Cosmetic Act. HHS general counsel says his office referred the company to the Department of Justice. Hims pulls the product. Novo sues for patent infringement in Delaware over U.S. Patent No. 8,129,343.
March 2026. Novo voluntarily dismisses the patent suit without prejudice after the two companies announce a collaboration. Hims agrees to stop advertising compounded GLP-1 products and to carry branded Wegovy and Ozempic. Novo reserves the right to refile. That same month, FTC Chairman Andrew Ferguson creates an internal Healthcare Task Force to align the agency's competition and consumer protection work in healthcare.
July 2026. The FTC action.
Securities fraud, food and drug law, patent law, and now consumer protection, in roughly a year. Hold that thought.
What the FTC complaint actually alleges
Three buckets.
Data sharing
The FTC alleges Hims sent sensitive health information to third-party advertising platforms through two channels. The first was tracking technology embedded on its website. The FTC's complaint identifies pixel trackers from Meta, Snap, Microsoft, Pinterest, Reddit, and X. The second was direct uploads of customer lists into those platforms' custom audience tools, the feature that lets a business match its own customer records against social media profiles for targeted advertising. The alleged information includes the conditions people were being treated for.
The FTC's point is not simply that data moved. It is that Hims told consumers the platform was private and secure and that their health information would be seen by their providers. The agency says those assurances were false or misleading.
Charging before care
The complaint alleges Hims advertised free consultations and displayed "Pay $0 today" on intake forms, then charged patients and enrolled them in recurring subscriptions as soon as a provider issued a prescription, without a meaningful opportunity to review or decline. Consumer examples in the complaint include one person charged $897 before speaking with any healthcare professional, and another charged $147 for a three-month supply of an antidepressant after indicating on an intake form that they were open to medication. The disclosures about recurring billing, the FTC alleges, appeared in smaller and less prominent text.
Cancellation friction
Before 2023, the complaint alleges, most users had to reach customer service by phone, email, or chat to cancel. Online cancellation was later added for most customers, though not through the mobile apps. The FTC alleges the option remained buried: a consumer had to enter an account section for adding and removing medications, uncheck every prescribed medication, and only then would a cancel button appear. Clicking it did not end the subscription. The complaint alleges the consumer then had to work through roughly three to ten survey questions, each on its own screen, and reaffirm the decision. Separately, the FTC alleges refill charges were processed about ten days earlier than the advertised monthly or quarterly schedule would suggest, with a cancellation deadline two days before that early processing date.
The relief sought includes a permanent injunction, monetary judgment, and civil penalties. The full complaint is posted on the FTC case page.
The laws being used, and the ones that are not
This is the part most coverage skips, and it is the most important part for anyone operating in this space.
The federal claims rest on two statutes. Section 5 of the FTC Act, which prohibits unfair and deceptive acts and practices. And the Restore Online Shoppers' Confidence Act, or ROSCA, which governs negative-option billing and online subscription enrollment. The state claims run under the Utah Consumer Sales Practices Act and California's False Advertising and Unfair Competition Laws.
| Claim | Statute used | What it is not |
|---|---|---|
| Deceptive privacy assurances | FTC Act Section 5 | Not HIPAA |
| Subscription enrollment and cancellation | ROSCA | Not a telehealth statute |
| State consumer claims | Utah CSPA; CA FAL and UCL | Not standard of care |
Not one of those is a healthcare law. ROSCA was written for online subscription traps. Section 5 is a general consumer protection provision that predates the internet by decades.
There is no telemedicine statute being enforced here. No standard-of-care rule. No corporate practice of medicine claim. No HIPAA count.
That is not an accident, and it is not a weakness in the case. It is the strategy.
For years, direct-to-consumer telehealth operated on a premise that was rarely said out loud but shaped everything: this is a new category, the rules were not written for us, and until someone writes them we are working in open space. That argument is effectively over, and it did not end the way the industry expected. Regulators did not wait for a telemedicine statute. They reached for the law they already had, and the law they already had reaches quite far.
The structure that keeps you out of HIPAA is what puts you in front of the FTC
Most states have some form of corporate practice of medicine doctrine requiring a licensed professional to own the clinical entity. The friendly PC and MSO architecture is the standard answer. The PC employs the clinicians and holds the medical records. The MSO does marketing, technology, billing support, and everything else.
That separation is often described as keeping the consumer-facing entity outside HIPAA. Fine. But outside HIPAA is not outside the FTC. It arguably makes the entity easier to reach. A consumer-facing marketing company making claims to the public is precisely what Section 5 was built for. You have effectively volunteered that the entity talking to consumers is not practicing medicine.
The FTC signaled this years ago. In the 2023 GoodRx action, the first ever enforcement of the Health Breach Notification Rule, the company paid a $1.5 million civil penalty and was permanently barred from sharing user health data with advertisers. The DOJ's announcement specifically flagged that GoodRx displayed a "HIPAA Secure" seal despite not being a covered entity and never having complied with HIPAA. Weeks later, BetterHelp agreed to pay $7.8 million over sharing email addresses, IP addresses, and health questionnaire answers with advertising platforms. Premom and Cerebral followed.
Then in July 2023 the FTC and HHS jointly warned roughly 130 hospital systems and telehealth providers about tracking technologies, stating plainly that companies not covered by HIPAA still have an obligation to protect against unauthorized disclosure of personal health information.
Hims was named in a December 2022 STAT News and Markup investigation that examined 50 direct-to-consumer telehealth platforms and found the overwhelming majority sharing sensitive medical data with advertisers. The warning letters were the first move. This is the second.
The billing claim is a clinical question in a consumer protection costume
Look closely at what the FTC is arguing on billing. Consumers were told they would consult a provider to find a treatment that was right for them. They were charged as soon as a prescription was generated.
Framed as a disclosure claim, that is straightforward consumer protection. Framed honestly, it is a question about whether the encounter was a clinical evaluation or a checkout flow with a clinician attached to it.
No agency in this case has authority over the practice of medicine. The FTC does not need it. If your intake flow was designed by a growth team and reviewed by a clinical team afterward, this is the paragraph to sit with.
And the FTC is not the only regulator reaching into structure
Two months before the FTC filed, California Attorney General Rob Bonta announced a $4.5 million settlement with Carbon Health, requiring a full restructuring of its friendly PC arrangement and attaching a $100,000 penalty to a co-founder personally. That action came alongside an amicus brief in a CPOM appeal and a settlement with Aspen Dental, all in the space of four months.
Put the two together. The FTC is using consumer protection law to reach the marketing entity. State attorneys general are using corporate practice doctrine to reach the structure itself. Those are different agencies, different statutes, and different theories, converging on the same set of companies from opposite ends.
The gap is closing, and it is closing from directions most operators are not watching.
What to actually audit this week
If you run a DTC telehealth business, five things:
- Every pixel and tag on every page, including intake. Know what each one sends and when it fires. "Marketing installed it" is not an answer.
- Every custom audience upload you have ever done. What list, from what source, matched against what.
- Your privacy policy against your actual data flows. The deception claim is about the gap between the two, not about the data movement alone.
- Your intake-to-charge sequence. When exactly does the card get charged relative to the clinical decision, and what does the consumer see at that moment?
- Your cancellation flow, timed with a stopwatch. Count the clicks. Count the screens. Try it on mobile. If it takes longer to cancel than to sign up, you have a ROSCA problem.
Where this goes next
Nothing has been decided. Hims has said it will defend itself vigorously, and it has real arguments. The company's next earnings report is scheduled for August 10, which is the next date on the calendar worth watching.
But the outcome of this particular case matters less than the template it represents. If the industry's compliance posture depends on being in a gap, the gap is closing.
How Camino helps
We build and run the operating layer that makes these audits routine instead of reactive: MSO and PC structure that holds up under state review, documented intake-to-charge and cancellation flows, vendor and pixel due diligence with approvals, and quarterly attestations so the compliance record already exists when a regulator or investor asks for it.
Start your project or see what we do.
Sources and further reading
Primary documents
- FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices, Federal Trade Commission, July 29, 2026
- FTC case page, FTC et al. v. Hims & Hers Health, Inc. (N.D. Cal.), ftc.gov
- Hims & Hers Responds to FTC Lawsuit, company statement
- Section 5 of the FTC Act, 15 U.S.C. § 45
- Attorney General Bonta Announces First-of-Its-Kind Settlement with Carbon Health, California Department of Justice, June 26, 2026
Prior enforcement
- FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising
- DOJ announcement of the GoodRx consent order
- FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising
- FTC and HHS Warn Hospital Systems and Telehealth Providers About Privacy and Security Risks from Online Tracking
Context and analysis
- FTC Launches Healthcare Task Force, Troutman Pepper
- FTC and States Sue Hims & Hers Over Deceptive Health Data Sharing and Subscription Billing Practices, National Law Review
- Why Hims & Hers Is Embroiled in Yet Another Controversy, This Time with the FTC, MedCity News
News coverage
- Hims and Hers shares fall as FTC sues company over data, billing practices, CNBC
- FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers, TechCrunch
- FTC sues Hims & Hers for sharing health data with Big Tech, The Register
- FTC Claims Hims & Hers Charged Patients Without Consent And Shared Health Data With Big Tech, Forbes
- The FTC is suing the popular telehealth company Hims & Hers, NPR
This post is for general informational purposes and is not legal advice. All allegations described are allegations only and have not been proven. The Carbon Health settlement referenced above was a proposed resolution subject to court approval, entered without admission of liability.

