The Federal Trade Commission filed suit against Hims & Hers Health on July 29, joined by Utah and California. The core allegation: the telehealth company used tracking technology on its website to share patients’ sensitive health information with advertising platforms — including Meta, Snap, Microsoft, Pinterest, Reddit, and X — without meaningful consent.
Hims & Hers has denied wrongdoing. But the lawsuit is less about one company than about a mechanism that is widespread across digital health and, increasingly, the broader consumer web.
What Tracking Pixels Actually Are
A tracking pixel is a small, usually invisible piece of code embedded on a website. When a page loads, the pixel fires — sending a signal to a third-party server about what page the user visited and, depending on configuration, additional data about the session.
The signal typically includes:
- The URL of the page visited
- The user’s IP address
- Browser and device details
- Time of visit
- Information about actions taken on the page (button clicks, form submissions, purchases)
What makes health-related tracking pixels particularly sensitive is that the URL structure itself can reveal health intent before a user completes any form. A URL like /treatment/anxiety or /consultation/hair-loss tells an advertising platform what a user was seeking the moment the page loaded.
Why Health Data in Pixels Violates More Than Trust
The intersection of tracking pixels and health data sits at the edge of multiple legal frameworks, none of which were designed with this specific mechanism in mind.
HIPAA, the Health Insurance Portability and Accountability Act, applies to covered entities and their business associates. It requires any third party receiving Protected Health Information to sign a Business Associate Agreement committing to specific data protection obligations. No major advertising platform has signed a BAA for their standard pixel implementations — meaning any health data flowing through tracking pixels is flowing without that contractual protection.
The Office for Civil Rights at the Department of Health and Human Services issued guidance in 2023 clarifying that tracking pixels transmitting PHI to third parties without a BAA constitutes a HIPAA violation. That guidance was partially contested in litigation but remained a benchmark for enforcement.
FTC Act Section 5, which prohibits unfair or deceptive trade practices, forms the basis of the lawsuit against Hims & Hers. The allegation is that the company’s privacy representations — including claims of handling health data with discretion — were materially inconsistent with what its tracking technology was actually transmitting.
State laws add another layer. California’s Confidentiality of Medical Information Act and comprehensive consumer privacy law, and Utah’s consumer privacy law, provide additional legal hooks beyond the federal framework. Both states are co-plaintiffs in the current suit.
The Gap the Lawsuit Exposes
The Hims & Hers case is not primarily about rogue data practices at a single telehealth company. It is about a structural gap between how modern digital advertising technology is built and what health data protection law requires.
Standard web analytics tools — including those provided by Meta, Google, and others — are designed to track user behavior across pages and sessions. For e-commerce, this tracking enables understanding of the customer journey from ad click to purchase. The same technology applied to a telehealth checkout flow means behavioral data about health-seeking activity gets fed into advertising platforms.
Many digital health companies have used these tools without fully auditing what data flows from their specific implementation. The result is that advertising infrastructure designed for retail ends up knowing which medications a user searched before making a purchase.
This is not a new problem. Investigations in 2023 and 2024 found tracking pixels at major hospital systems, fertility apps, mental health platforms, and pharmacy chains. Hims & Hers is not the first health company sued over pixels — it is the highest-profile recent case.
What Data Was Actually Shared
The FTC’s complaint identifies specific data flows. The company’s website placed Meta’s Pixel, Snap’s Pixel, and tags from Microsoft, Pinterest, Reddit, and X on its pages.
These pixels transmitted health-related browsing behavior to those platforms when users sought treatment. The FTC contends this occurred as users researched and sought treatment for conditions including hair loss, erectile dysfunction, and anxiety — categories of health information that carry particular sensitivity under both law and common understanding of personal privacy.
Once received by advertising platforms, this data can influence targeting across those platforms’ full advertising ecosystems. Users who sought treatment from a telehealth provider may subsequently receive ads shaped by inferences about their health conditions, on platforms they use for entirely unrelated purposes.
The Billing Complaint Alongside the Privacy Case
The FTC’s lawsuit against Hims & Hers combines the pixel-tracking privacy allegations with separate billing practice complaints, and the billing side is worth understanding in its own right.
The FTC alleges the company charged customers for prescriptions before they had spoken with a healthcare provider — billing after an intake form, rather than after a clinical consultation. The complaint also alleges the company made subscription cancellation unreasonably difficult, failing to clearly disclose when prescription refills would occur each billing cycle.
These billing allegations are independent of the health data sharing allegations, but together they paint a picture that regulators characterize as a pattern of consumer harm — not an isolated technical oversight.
What Consumers Can Do
This vulnerability exists at the intersection of advertising technology and health data, and individual users have limited ability to prevent it at the source. That is the platform’s responsibility. But there are steps that reduce exposure.
Use a browser that blocks third-party trackers by default. Firefox, Brave, and Safari with default settings all provide meaningful protection against pixel-based tracking. Chrome’s default settings offer less protection without additional configuration.
Disable cross-site tracking in iOS Settings. Settings → Privacy & Security → Tracking → toggle off “Allow Apps to Request to Track.”
Read a health platform’s privacy policy before you use the service. Look specifically for the section about third-party sharing and advertising technologies. Explicit disclosure of advertising pixels and what they transmit is what you’re looking for. The absence of that disclosure is informative.
Request your data. GDPR Article 15 and CCPA give you the right to request what data a company holds about you and what it has shared with third parties. Submitting this request can surface data flows you weren’t aware of.
Look for platforms that don’t use advertising technology. Some digital health services have explicitly committed to not deploying advertising pixels. Verifying this claim against what specific FTC complaints identify is the appropriate way to evaluate it.
The Data You Browse vs. the Data You Store
There is a distinction worth drawing between data that health platforms collect through tracking pixels and data you actively choose to store in a service.
Pixel tracking is automatic — it happens as a byproduct of using a website, without you choosing to submit any information. Your browsing signals get transmitted the moment a page loads.
Personal health records you actively store are different: you’ve placed them in a service, and the question is what that service does with the files you’ve entrusted to it. If you store lab results, prescriptions, treatment documentation, or other personal health records in an ad-supported platform — or any service that embeds advertising tracking technology — the infrastructure that transmits browsing data to advertisers can interact with your stored files too.
A platform that doesn’t serve ads, doesn’t use advertising pixel technology, and doesn’t sell user data is structurally different. daftei doesn’t run ads, doesn’t deploy advertising tracking technology, and never sells user data. Files are encrypted in transit with TLS 1.3 and at rest with AES-256. GDPR and CCPA compliance, and an explicit policy against third-party AI training on user content, mean the documents you store aren’t flowing to any party you haven’t chosen.
What to Watch as the Lawsuit Develops
The Hims & Hers case will take time to resolve. Several threads are worth following.
Whether the FTC pursues advertising platforms directly. The complaint focuses on Hims & Hers as the deployer of the tracking technology, but the platforms receiving the data are named in the complaint. The extent to which regulators pursue the receiving side is an open question.
Whether other states join or file parallel actions. California and Utah are co-plaintiffs. States with comprehensive privacy laws — including Colorado, Connecticut, Virginia, and Texas — have their own enforcement mechanisms and may bring parallel actions against the broader telehealth sector.
What injunctive relief the settlement produces. FTC settlements in data cases typically include requirements around specific disclosure and consent practices. The standards produced here, if a settlement is reached, are likely to become a benchmark for health-adjacent advertising technology going forward.
Whether other telehealth companies update their practices proactively. The filing is a signal to the industry. Companies with similar pixel implementations are evaluating their exposure. The next several months will reveal how the broader sector responds.