On August 18, the FTC, California, and Utah filed a joint lawsuit against Hims & Hers, one of the largest telehealth companies in the country. The case is Federal Trade Commission v. Hims & Hers Health, Inc., No. 3:26-cv-07871, filed in the Northern District of California.
Most of the coverage will focus on the subscription claims. The complaint alleges that customers got charged before they ever spoke with a provider, and then ran into a maze when they tried to cancel.
But there’s another part of the complaint that healthcare marketing teams should read twice. It’s about the tracking technology running on the Hims website, and it isn’t a telehealth problem. It’s a problem for anyone using standard advertising and analytics tools on a healthcare site.
What the government alleges
Hims told customers its process was “100% online, private, and secure,” and that sensitive health information would only be accessed by the medical providers managing their care.
According to the complaint, the website was also running the Meta Pixel, Meta’s Conversions API, and tracking code from Google, TikTok, Pinterest, Reddit, Snap, Microsoft, Criteo, The Trade Desk, and others.
The government alleges roughly 8 million events went to Meta alone. Those events reportedly tied a person’s email address and IP address to the type of treatment they were seeking, including mental health and male sexual health services.
Hims allegedly used codewords for treatment categories. Mental health was “Apollo.” Erectile dysfunction was “Zeus.” The government says the codewords didn’t hide anything, because Hims told Meta what they meant. Internal Meta marketing materials spelled them out: “Apollo (MH),” “Atlas (PEJ),” and “Zeus (ED).”
On top of that, the complaint alleges Hims uploaded about 14 million customer email addresses to Meta to build advertising audiences. Some of those audience lists were reportedly named for the conditions the customers were seeking treatment for.
These are allegations. They haven’t been proven in court, and Hims will get its turn to respond. But the pattern the complaint describes shows up on healthcare websites constantly.
This isn’t a HIPAA case
The government didn’t bring a single HIPAA count.
The case runs on the FTC Act, the federal Restore Online Shoppers’ Confidence Act, California consumer protection and false advertising law, California’s constitutional right to privacy, and Utah’s consumer protection act.
That matters more than it might sound like it does. After a 2024 court decision narrowed part of HHS’s guidance on website tracking, plenty of healthcare organizations treated it as an all-clear and went back to their usual marketing stack. It wasn’t an all-clear. The FTC has gone after BetterHelp, GoodRx, Cerebral, and now Hims without touching HIPAA once.
The government’s position is simple. If you promise privacy while your website hands sensitive information to advertising platforms, that promise may be deceptive.
So go read the language on your own site. If it tells patients their privacy matters while Google Tag Manager quietly loads a stack of ad pixels, you’ve got a gap between what you’re promising and what your technology is doing. That gap is where the risk lives.
The industry has already paid for this
Government enforcement is only half of it.
Sutter Health paid $21.5 million over claims involving Google Analytics and the Meta Pixel on its patient portal. Aspen Dental settled for roughly $18.5 million. Mass General Brigham, Advocate Aurora, GoodRx, and BetterHelp have all been through some version of this.
The legal theories vary. Some cases lean on state privacy laws, others on wiretap statutes, negligence, breach of confidentiality, or consumer protection law. What stays the same is the technology, and it’s almost always ordinary.
In our work with healthcare websites, these trackers are rarely installed because someone set out to disclose patient information. They’re installed because the marketing team wants to measure campaigns, build audiences, improve conversions, and report results to leadership.
Those are good goals. The trouble is that most of the tools being used were built by advertising companies, for advertising, and healthcare privacy was never part of the design.
Five questions to ask about your website
- Do you have a complete list of the trackers running on your site right now, including tags somebody added through Google Tag Manager two years ago?
- Which vendors receive data from your website, and do you have the right agreements in place? Google Analytics and Meta don’t offer BAAs for their standard analytics and advertising products.
- Does your privacy policy actually describe what your website sends to outside companies? A policy doesn’t protect you when it doesn’t match reality.
- Are trackers running on appointment-request pages, condition pages, online forms, or your patient portal? On those pages, the visit itself can reveal something about a person’s health.
- If your counsel or a regulator asked where your website data goes, could you answer completely today?
If you can’t answer all five with confidence, that’s worth an afternoon of your time. It’s a lot cheaper than a settlement.
Turning off analytics isn’t the answer
Some organizations have responded to all this by ripping out analytics entirely, which just trades one problem for another.
Your marketing team still needs to know which campaigns bring in appointment requests, which pages are working, where visitors come from, and where people give up and leave. Healthcare doesn’t need less information. It needs a safer way to collect it.
That’s why we built Ghost Metrics.
Ghost Metrics is web analytics built around healthcare privacy from the start. Every subscription includes a signed BAA. Your data sits on secure U.S. servers, encrypted in transit and at rest. It’s never sold, never handed to advertising companies, and never used to build ad audiences. Instead of tracking individual patients, we give you aggregate, anonymized information you can actually make decisions with.
Your marketing team gets its numbers, and your compliance team knows exactly where the data goes.
Take a look at the live demo at ghostmetrics.io/demo, or reach out and we’ll walk through what’s currently running on your site. That first review is free and usually takes about twenty minutes.
The Hims complaint is 48 pages. Fixing your analytics setup might take an afternoon. Better to do that work now than to hear about the problem from a regulator.
Source: Complaint for Permanent Injunction, Monetary Judgment, Civil Penalty Judgment, and Other Relief, Federal Trade Commission v. Hims & Hers Health, Inc., No. 3:26-cv-07871-VC (N.D. Cal. filed Aug. 18, 2026), ECF No. 28.
This post discusses allegations in a government complaint that have not been proven in court. It’s provided for general informational purposes and is not legal advice. Consult your legal counsel about your organization’s specific circumstances.


