FTC Sues Hims & Hers for Sharing Sensitive Health Data with Advertising Platforms
What Happened — The U.S. Federal Trade Commission, together with Utah and California, filed a lawsuit accusing telehealth provider Hims & Hers of disclosing consumers’ medical‑condition information to third‑party advertising platforms such as Meta and Snap, contrary to the privacy assurances it gave users. The complaint also alleges deceptive billing practices and hidden cancellation flows that kept users on recurring prescription subscriptions.
Why It Matters for Trust & Control Assurance
- The case spotlights a failure to enforce privacy‑by‑design and third‑party data‑handling controls—exactly the type of control an ongoing assurance program must monitor and evidence.
- Continuous monitoring of consent records and data‑sharing agreements provides the defensible audit trail regulators now expect.
- Demonstrable privacy governance (e.g., consent management, DSAR readiness) is a single control objective that maps to HIPAA, GDPR, and many other frameworks.
Who Is Affected – Telehealth and digital‑health platforms, consumer‑health mobile apps, and any service that blends health data with advertising or analytics SDKs.
Recommended Actions –
- Map all data flows to third‑party advertising SDKs and verify a lawful basis for each transfer.
- Deploy a consent‑management solution that captures, stores, and can produce evidence of user opt‑ins/opt‑outs.
- Review and simplify billing and cancellation processes to eliminate “dark‑pattern” friction.
- Prepare documentation and evidence of privacy controls for potential FTC or state investigations. Source: Malwarebytes Labs
Technical Notes – The FTC complaint alleges that Hims & Hers shared health‑condition details with Meta and Snap despite privacy promises, charged users before medical consultations, and made subscription cancellations difficult through hidden UI steps. Source: Malwarebytes Labs