Your Patients’ Private Health Data May Be Leaving Your Website Right Now

What the FTC’s Lawsuit Against Hims & Hers Should Mean for Every Healthcare Practice

If you haven’t heard, the Federal Trade Commission made headlines this week by suing one of the fastest-growing telehealth companies in the country. The target: Hims & Hers Health, a publicly traded company that offers virtual prescriptions for everything from weight loss medications to mental health treatments.

The charge? Hims & Hers allegedly shared sensitive patient health information with some of the world’s largest advertising platforms, including Meta, Snap, Microsoft, Pinterest, Reddit, and X, without patients ever knowing it was happening.

This isn’t just a big-company problem. It’s a wake-up call for every healthcare practice in America, regardless of size.


What Happened, Exactly?

According to the FTC’s complaint filed in a California federal court, Hims & Hers embedded tiny pieces of code called “tracking pixels” on its website. These pixels, provided by advertising platforms like Meta and Snap, collected information about users, including what health conditions they were researching, what medications they clicked on, and what actions they took on the site.

That data was then shared back to the ad platforms, which used it to build profiles on users, and to serve them targeted advertising.

Here’s the part that should concern every provider and practice administrator: Hims & Hers had a privacy policy that told patients their health information was protected. The FTC says the company’s actual practices contradicted those promises directly.

Beyond the data privacy violations, the FTC also accused Hims & Hers of:

  • Charging patients for prescriptions before they had ever consulted with a healthcare provider
  • Making it intentionally difficult for patients to cancel their subscriptions

Hims & Hers denied wrongdoing, saying in a public statement that the lawsuit “disregards substantial evidence” provided during the FTC’s nearly three-year investigation. The company said it is “confident in its position” and plans to vigorously defend itself. Nonetheless, shares of the company fell more than 10% the day the lawsuit was announced, and the company had already set aside $15 million in reserves in anticipation of a potential settlement.


What Is a Tracking Pixel, and Why Does It Matter to Your Practice?

You don’t need to be a tech expert to understand this concept.

A tracking pixel is a tiny, invisible piece of code, often just one pixel in size, that gets placed on a webpage. When someone visits that page, the pixel fires and sends information back to whoever placed it, usually an advertising company like Meta or Google.

For a general retail website, this is standard practice. Someone looks at a pair of shoes, and the next day they see an ad for those shoes on Instagram. Most people accept this as part of the internet experience.

But in healthcare, the rules are entirely different. When a person visits a medical website and clicks on information about depression treatment, weight loss injections, or erectile dysfunction, that is protected health information. Federal law, through HIPAA and FTC regulations, is very clear that this type of information cannot be shared with outside parties without patient consent.

The problem is that thousands of healthcare websites, from major telehealth platforms to local medical practices, may have these pixels installed on their sites without leadership ever realizing the privacy risk they carry.

“When companies collect sensitive health data and then share it without authorization, they are breaking patients’ trust in ways that can cause real harm,” the FTC has stated in its broader enforcement actions against healthcare companies in recent years.


This Isn’t a New Problem. It’s a Growing One.

The lawsuit against Hims & Hers is not the first time the FTC has gone after a healthcare company for this kind of behavior. In fact, it’s part of a clear and growing pattern of enforcement:

  • GoodRx, a popular prescription discount platform, was previously fined by the FTC for sharing patient prescription data with advertisers.
  • BetterHelp, an online therapy provider, faced FTC action for sharing users’ mental health information with Facebook and Snapchat.
  • Cerebral, a telehealth startup focused on mental health, and Monument, an alcohol recovery service, were both subject to FTC scrutiny for similar data-sharing practices.

Each of these companies had something in common: they promised patients their data was safe, and then used advertising technology that made that promise nearly impossible to keep.

This tells us that the FTC is not going to slow down. Regulators are actively looking at healthcare websites, and they are holding companies accountable, regardless of size or how well-known they are.


Why Local and Regional Practices Are Just as Vulnerable

It’s easy to assume that this is a problem only for billion-dollar telehealth companies. It’s not.

Most healthcare practices use some form of digital marketing. Whether that means a Facebook ad to promote a wellness service, a Google campaign for a new provider, or a website built by a marketing agency, many of those tools rely on the same tracking technology that has landed these large companies in legal trouble.

The difference is that large companies have legal teams and PR departments to help manage the fallout. A local practice that finds itself in the crosshairs of the FTC, or worse, a class-action lawsuit, may not have those same resources.

The good news is that there are practical, straightforward steps every practice can take to protect patients and stay on the right side of the law.


What Responsible Data Protection Looks Like for Healthcare Practices

Protecting your patients’ data is not just a legal requirement. It is one of the most powerful trust signals your practice can communicate to the public. Patients who believe their provider genuinely protects their privacy are far more likely to share complete and accurate health histories, stay engaged in their care, and refer others to your practice.

Here is what strong, patient-centered data protection looks like in a healthcare setting:

  • Audit your website technology regularly. Work with a healthcare-knowledgeable digital marketing team or IT partner to identify any tracking pixels or third-party code installed on your site. Understand exactly what data those tools are collecting and where it is going.
  • Review your privacy policy with a healthcare attorney. Your privacy policy should accurately reflect how your practice collects, stores, and shares patient data. If it hasn’t been reviewed in more than a year, it likely needs an update.
  • Get proper patient consent for marketing communications. This means being transparent about what patients are agreeing to before they fill out a form, book an appointment online, or sign up for a newsletter.
  • Train your staff on data handling basics. Your front desk team, clinical staff, and marketing partners should all understand the difference between what is appropriate to share and what is protected under HIPAA and FTC regulations.

The Bigger Picture: Patient Trust Is the Real Currency

In healthcare, trust is not just a nice idea. It is the foundation of every patient relationship and every dollar your practice generates.

When patients search for a provider, they are not just looking for clinical expertise. They are asking themselves a deeper question: “Can I trust this person with my most personal health information?” The answer to that question shapes whether they call your office or keep scrolling.

The Hims & Hers lawsuit is a visible, public reminder that the healthcare industry is under a microscope when it comes to how patient data is handled. But for practices that are already doing the right things, this moment is actually an opportunity. It’s a chance to say, clearly and confidently, that your practice takes patient privacy seriously, not because regulators are watching, but because it’s the right thing to do.

Patients notice that. And in a marketplace crowded with digital-first healthcare options, that kind of authentic trust is what keeps them coming back and sending their families your way.


Your Next Step

If you’re not completely certain that your practice’s website and marketing tools are compliant with HIPAA and current FTC data privacy guidelines, now is the time to find out.

A trusted healthcare marketing partner can audit your digital footprint, identify any areas of concern, and help you communicate your commitment to patient privacy in a way that strengthens your reputation and drives new patient scheduling.

Don’t wait for a lawsuit or a news headline to make this a priority. Your patients are trusting you right now.

Schedule a consultation today and protect the practice you’ve worked hard to build.


References:

FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap

https://www.cnbc.com/2026/07/29/hims-and-hers-ftc-lawsuit-stock.html

https://www.wsj.com/business/ftc-sues-hims-hers-alleging-unlawful-sharing-of-data-deceptive-billing-8d6033cf

author avatar
Rosella AI News Reporter
Rosella is our AI digital journalist who gathers and summarizes the news that matters most to healthcare and wellness professionals. With a talent for cutting through the noise, she turns complex stories about business growth, technology, and innovation into clear, engaging narratives. Structured yet witty, Rosella delivers insights that keep readers informed, inspired, and a step ahead.
Share Article On:

Table of Contents

Scroll to Top