HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

FTC Sues Hims & Hers for Sharing Sensitive Patient Data with Advertising Platforms

The FTC, joined by Utah and California, sued telehealth firm Hims & Hers for providing customers' medical condition information to advertising platforms like Snap and Meta, violating its own privacy promises. The breach underscores the need for documented consent and SOC 2 privacy controls.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

FTC Sues Hims & Hers for Sharing Sensitive Patient Data with Advertising Platforms

What Happened — The Federal Trade Commission, together with Utah and California, filed a lawsuit alleging that telehealth company Hims & Hers disclosed patients’ medical‑condition information to advertising platforms such as Snap and Meta, and employed third‑party tracking technologies despite publicly promising privacy protection. The complaint says the firm provided lists of customers and their health data to these third parties for marketing purposes.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook violation of SOC 2 CC5 (Confidentiality) and privacy‑related criteria, highlighting the need for documented consent and strict data‑sharing controls.
  • Continuous monitoring of outbound data flows and retaining consent logs are essential audit artifacts to prove compliance with FTC, CCPA, and GDPR‑style obligations.
  • Verisq’s CookiePLUS capability can furnish the consent‑management records and third‑party transfer evidence required for a defensible SOC 2 privacy audit.

Who Is Affected — Telehealth providers, direct‑to‑consumer health brands, and any digital‑health service that integrates third‑party advertising or analytics platforms.

Recommended Actions

  • Inventory every third‑party service that receives health‑related data and map those flows to SOC 2 privacy controls.
  • Deploy a consent‑capture and revocation workflow that records user choices and ties them to each data‑transfer event.
  • Collect and retain detailed logs of data shared with ad platforms; conduct a privacy‑impact assessment for each integration and keep the evidence ready for audit.

Source: The Record

Technical Notes — The FTC alleges that Hims & Hers shared “sensitive health information about medical conditions” via customer lists and website tracking pixels to Snap, Meta, and other advertising networks. No software vulnerability or CVE is cited; the vector is a policy‑level data‑sharing practice that bypassed the firm’s own privacy statements. Source: The Record

📰 Original Source
https://therecord.media/hims-hers-privacy-lawsuit-ftc

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →