Skip to main content
Back to Our Blog
Camino Strategy Group

What the FTC Lawsuit Against Hims & Hers Means for Telehealth Companies

What the FTC Lawsuit Against Hims & Hers Means for Telehealth Companies

What the FTC Lawsuit Against Hims & Hers Means for Telehealth Companies

On July 29, 2026, the Federal Trade Commission sued Hims & Hers Health, Inc. in the U.S. District Court for the Northern District of California. The FTC did not file alone. It was joined by the State of Utah and the County of Los Angeles, acting on behalf of the People of California.

The company denies the allegations. Its statement says the lawsuit disregards evidence the company provided over a nearly three-year investigation, ignores established state telehealth law and industry standards, and contorts the law to manufacture claims. Nothing here has been proven. The stock fell as much as 16% the day it was filed.

But the shape of this complaint tells you a great deal about where enforcement in this industry is heading, and that matters whether or not Hims ultimately wins.

First, which lawsuit are we talking about

A lot of people are conflating several separate legal matters. It helps to lay them out, because the pattern only becomes visible when you see them together.

June 2025. Novo Nordisk ends its collaboration with Hims, publicly accusing the company of deceptive promotion of knockoff versions of Wegovy. The stock drops more than 33% in a day. Securities class actions follow, alleging the company misled investors.

February 2026. Hims announces a $49 compounded oral semaglutide pill. Within days, the FDA states its intent to act, citing sections 502(a) and 502(bb) of the Federal Food, Drug, and Cosmetic Act. HHS general counsel says his office referred the company to the Department of Justice. Hims pulls the product. Novo sues for patent infringement in Delaware over U.S. Patent No. 8,129,343.

March 2026. Novo voluntarily dismisses the patent suit without prejudice after the two companies announce a collaboration. Hims agrees to stop advertising compounded GLP-1 products and to carry branded Wegovy and Ozempic. Novo reserves the right to refile. That same month, FTC Chairman Andrew Ferguson creates an internal Healthcare Task Force to align the agency's competition and consumer protection work in healthcare.

July 2026. The FTC action.

Five distinct legal theories in roughly a year: securities fraud, food and drug law, patent law, and now consumer protection. Hold that thought.

What the FTC complaint actually alleges

Three buckets.

Data sharing. The FTC alleges Hims sent sensitive health information to third-party advertising platforms including Meta and Snap, through two channels. The first was tracking technology embedded on its website. The second was direct uploads of customer lists into those platforms' custom audience tools, the feature that lets a business match its own customer records against social media profiles for targeted ads. The alleged information includes the conditions people were being treated for.

The FTC's point is not simply that data moved. It is that Hims told consumers the platform was, in the complaint's words, one hundred percent online, private, and secure, and that their health information would be seen by their providers. The agency says those assurances were false or misleading.

Charging before care. The complaint alleges Hims advertised free consultations and displayed "Pay $0 today" on intake forms, then charged patients and enrolled them in recurring subscriptions as soon as a provider issued a prescription, without a meaningful opportunity to review or decline. Consumer examples in the complaint include one person charged $897 before speaking with any healthcare professional, and another charged $147 for a three-month supply of an antidepressant after indicating on an intake form that they were open to medication.

Cancellation friction. The FTC alleges refill charges were processed roughly ten days earlier than the advertised monthly or quarterly schedule would suggest, with a cancellation deadline two days before that early processing date. It also alleges the cancel button only became visible after a consumer navigated into an account section and unchecked every medication on their subscription.

The relief sought includes a permanent injunction, monetary judgment, and civil penalties. The full complaint is posted on the FTC case page.

The laws being used, and the ones that are not

This is the part most coverage skips, and it is the most important part for anyone operating in this space.

The complaint rests on two statutes. Section 5 of the FTC Act, which prohibits unfair and deceptive acts and practices. And the Restore Online Shoppers' Confidence Act, or ROSCA, which governs negative-option billing and online subscription enrollment.

Neither is a healthcare law. ROSCA was written for online subscription traps. Section 5 is a general consumer protection provision that predates the commercial internet by decades. There is no telemedicine statute being enforced here. No standard-of-care rule. No corporate practice of medicine claim. No HIPAA count.

That is not a weakness in the case. It is the design.

Reading between the lines

Every one of these actions borrowed a law written for something else

Go back to the timeline. Securities law reached the investor disclosures. The Food, Drug, and Cosmetic Act reached the product claims. Patent law reached the molecule. Consumer protection law reached the marketing and the checkout flow.

Not one of them is telehealth law, because there largely isn't any. Telemedicine in the United States is governed by a patchwork of state medical board rules, state corporate practice doctrine, and prescribing statutes, with very little that speaks directly to how a national direct-to-consumer platform behaves. So regulators are not waiting for Congress or the boards to catch up. They are reaching for whatever body of law already touches the conduct and pulling.

That is a meaningful shift for founders. The compliance question is no longer only "am I following telehealth rules." It is "which of the many general-purpose laws could someone reasonably aim at what I'm doing?" That list is long, and it includes bodies of law most digital health founders have never read.

The structure that keeps you outside HIPAA does not keep you outside the FTC

Direct-to-consumer telehealth spent a decade telling itself a convenient story: that it sits in a gap. The platform is not a covered entity under HIPAA. The professional corporation employing the clinicians is the covered entity. The platform is a management and marketing company.

Structurally, that is often correct, and it exists for real reasons. Most states have some form of corporate practice of medicine doctrine that requires a licensed professional to own the clinical entity, and the friendly PC and MSO architecture is the standard answer.

But the separation that keeps the platform outside HIPAA does not keep it outside the FTC. It arguably makes it easier to reach. A consumer-facing marketing entity making claims to the public is exactly what Section 5 was built for. You have effectively volunteered that the entity talking to consumers is not practicing medicine.

The FTC signaled this years ago. In the 2023 GoodRx action, the first ever enforcement of the Health Breach Notification Rule, the company paid a $1.5 million civil penalty and was permanently barred from sharing user health data with advertisers. The DOJ's announcement specifically flagged that GoodRx displayed a "HIPAA Secure" seal despite not being a covered entity and never having complied with HIPAA. Weeks later, BetterHelp agreed to pay $7.8 million over sharing email addresses, IP addresses, and health questionnaire answers with Facebook, Snapchat, Criteo, and Pinterest. Premom and Cerebral followed.

Then in July 2023 the FTC and HHS jointly warned roughly 130 hospital systems and telehealth providers about tracking technologies, stating plainly that companies not covered by HIPAA still have an obligation to protect against unauthorized disclosure of personal health information.

Hims was named in a December 2022 STAT News and Markup investigation that examined 50 direct-to-consumer telehealth platforms and found 49 of them sharing sensitive medical data with advertisers. The warning letters were the first move. This is the second.

The billing claim is a clinical question in a consumer protection costume

Look closely at what the FTC is arguing on billing. Consumers were told they would consult a provider to find a treatment that was right for them. They were charged as soon as a prescription was generated.

Framed as a disclosure claim, that is straightforward consumer protection. Framed honestly, it is a question about whether the encounter was a clinical evaluation or a checkout flow with a clinician attached to it.

No agency in this case has authority over the practice of medicine. The FTC does not need it. It can litigate the marketing description of the clinical encounter and get most of the way to the same place. If your website promises an evaluation and your architecture delivers an approval, the gap between those two things is now legally actionable even though no medical board is involved.

For anyone running an async model, that should land hard. Async intake is legitimate and widely used. But the question a regulator will ask is whether the clinical review was real and whether your marketing accurately described it.

The personalization argument moved the target

One more thread worth noticing. Hims' position on compounded GLP-1s was that its products were legal because the prescriptions were personalized in dosage, which is a real exception in compounding law.

That is a compliance argument built on a narrow exception in a statute written for individualized pharmacy practice, applied at national scale. It worked for a while. Then the FDA, a patent holder, and eventually a commercial agreement rendered it moot.

Compliance strategies that depend on a technically available exception being read generously are not durable. They are a position, not a foundation. When the incentive to challenge them gets big enough, someone finds a law that reaches you.

The co-plaintiffs are not decorative

Utah and Los Angeles County bring their own state consumer protection statutes with their own penalty structures. Their presence signals that state and local enforcers are willing to attach themselves to federal telehealth actions.

That multiplies your exposure and it multiplies the number of doors an investigation can come through. A single set of facts can now generate a federal claim, a state claim, a county claim, and a follow-on private class action, all at once.

What to do with this

The practical takeaways are unglamorous, which is usually how compliance works.

Audit everything loaded on your website and app. Every pixel, tag, analytics tool, session replay tool, and conversion event. Pay particular attention to what fires on intake pages, confirmation pages, and condition-specific landing pages, because that is where condition-level data leaks. Get a written inventory. Most companies cannot produce one, and that itself is the finding.

Stop treating intake-form language as consent. Buried authorization in a terms document is the exact posture the FTC has now challenged repeatedly. If you are disclosing health information to a third party for advertising, you need affirmative express consent, obtained separately, in plain language.

Read your own marketing the way a regulator would. If your site says private, secure, discreet, or confidential, that is a representation you must be able to defend against your actual data flows. If it promises a consultation to determine what is right for the patient, your billing sequence has to match that promise. The claim and the architecture have to tell the same story.

Map the money against the medicine. Diagram exactly when a card is charged relative to when clinical review actually happens. Then disclose that sequence plainly, on the page where it happens, not in a footer.

Make cancellation genuinely findable. If a reasonable person cannot cancel in a couple of clicks, you have a ROSCA problem regardless of what your terms say. The standard is not "technically possible." It is "as easy as signing up."

Look at your entity structure honestly. Understand which entity is making which representation to consumers, and whether your MSO is saying things about clinical care that only the PC should be saying. The structure is not just a CPOM answer. It is a map of who is exposed to what.

Assume your compliance position will be tested by someone with a commercial motive. Not just a regulator. A competitor, a patent holder, a plaintiffs' firm, a state AG, or a short seller.

The bottom line

Telehealth spent a decade arguing about which rules apply to it. That argument is effectively over, and it did not end the way the industry expected.

Regulators are not waiting for a telemedicine statute. They are using the law they already have, and it turns out the law they already have reaches quite far. If your compliance posture depends on being in a gap, the gap is closing, and it is closing from directions you are probably not watching.

How Camino helps

We build the operating layer that makes these claims defensible: tracking and pixel inventories for intake and condition pages, consent flows that stand on their own, billing sequences documented against actual clinical review, and MSO/PC boundaries that match what your marketing says. If you are a telehealth or digital health company reading this complaint and recognizing your own stack, that is the work.

Book a free 15-minute call to walk through where your exposure is.


Sources and further reading

Primary documents

Prior enforcement

Context and analysis

News coverage


This post is for general informational purposes and is not legal advice. All allegations described are allegations only and have not been proven.

Building foundations that scale | caminostrategygroup.com