HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Hims & Hers Sued Over Alleged Health Data Privacy Failures Impacting 1.2 M Patients

A class‑action suit claims Hims & Hers exposed protected health information of about 1.2 million users due to inadequate privacy controls. The case highlights why continuous SOC 2 privacy‑control evidence is essential for audit readiness.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
malwarebytes.com

Hims & Hers Sued Over Alleged Health Data Privacy Failures Impacting 1.2 M Patients

What Happened — A class‑action lawsuit was filed against Hims & Hers, alleging that the tele‑health provider failed to protect protected health information (PHI) of roughly 1.2 million users, resulting in unauthorized exposure of medical records and personal identifiers.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a privacy breach that SOC 2 CC6 (Confidentiality) and HIPAA‑aligned controls are designed to prevent and document.
  • Continuous evidence of privacy‑control enforcement (consent management, data‑subject request handling) is critical to demonstrate due diligence during audits.
  • Verisq’s CookiePLUS capability can map consent and DSAR processes to SOC 2 requirements, providing auditable proof of privacy‑control maturity.

Who Is Affected – Health‑tech providers, tele‑medicine platforms, and any organization handling PHI.

Recommended Actions

  • Review and tighten consent capture, data‑retention, and DSAR workflows against SOC 2 CC6.
  • Collect and archive evidence of privacy‑control enforcement (policy updates, audit logs).
  • Conduct a gap analysis with a privacy‑focused control mapping tool to prepare for potential audit inquiries.

Technical Notes – The lawsuit alleges inadequate access controls, insufficient encryption at rest, and failure to honor data‑subject requests, leading to exposure of names, dates of birth, and medical diagnoses. Source: Malwarebytes Labs – A week in security (July 27 – August 2)

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-july-27-august-2

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →