Compliance

You Asked, We Answered: Your Top Questions About the Hims & Hers Complaint

Let’s get into it: Why is HIPAA not in the conversation? Is it time to turn off paid media?

Disclaimer: Freshpaint does not provide legal advice. All claims against Hims & Hers are alleged; Hims & Hers disputes the allegations. 

About two weeks ago, the FTC, California, and Utah filed a joint complaint against Hims & Hers alleging unfair and deceptive privacy practices, alongside unfair and deceptive claims related to subscriptions and cancellations.

At the time, I wrote about the immediate implications for healthcare marketers and privacy leaders: audit your privacy claims, understand exactly what you're sending to advertising platforms, take a hard look at audience creation, and revisit consent.

Over the last couple of weeks: the questions I've been hearing from healthcare marketers have shifted from “What does this mean for us?” to “What actions should we take today to strengthen our privacy stance?”

So I want to address five of the questions I’ve heard from you most often since the complaint was filed – and actions you can take today towards understanding and improving your privacy posture.

First, a quick refresher.

On July 29, the FTC, the California People via Los Angeles County Counsel, and the Utah Division of Consumer Protection filed a joint complaint against Hims & Hers.

Among subscription and cancellation allegations, regulators allege Hims shared consumers’ sensitive health information with advertising platforms despite making promises about protecting their privacy. Hims disputes the allegations, and the claims will now be litigated in the Northern District of California.

While this complaint will evolve in the months to come, I do want to note that it specifically points to two practices healthcare marketers should recognize immediately:

  • Customer-list uploads used for audience matching
  • Tracking technologies, including the Meta Pixel and Conversions API

And, unsurprisingly, these practices are at the center of many of the questions I’ve been hearing from healthcare marketers over the last two weeks. So let’s get into it.

Breaking down your top questions about the complaint.

1. Why weren’t the Office for Civil Rights (OCR) and the Department of Health and Human Services (HHS) involved?

This is probably the question I’ve received most since the complaint came out: if we’re talking about health information and tracking technologies, why are OCR and HIPAA missing from the conversation?

It’s a valid question (and candidly, one that I’ve seen even privacy vendors get wrong on LinkedIn). What I want to discuss is less about the Hims case specifically and more about how HIPAA is actually built. The important distinction is that OCR enforces HIPAA, which only applies to covered entities and business associates. Generally speaking, a HIPAA privacy violation comes from a covered entity (or business associate) mishandling PHI in its capacity as a covered entity or business associate. 

Unless you live and breathe privacy, you may not realize why this distinction matters for direct-to-consumer telehealth and digital wellness brands. According to CMS, providers that submit HIPAA electronic transactions, such as claims, are covered entities. In reality, many cash-pay DTC telehealth companies simply don’t operate this way. 

They often bill consumers directly and are structured with a consumer-facing marketing and technology entity – for example, a website with a health intake quiz – that sits apart from an affiliated medical group that delivers the actual clinical care. In short, the entity that runs the consumer-facing marketing and demand-generation layer may not be a HIPAA-covered entity at all, and may only operate as a business associate in certain capacities. 

And just to be clear, this isn’t a legal assessment of Hims’ privacy posture or of OCR’s jurisdiction in this specific case, but rather general information about HIPAA’s applicability to covered entities and business associates and the gray area that DTC, cash-pay digital health platforms often play in. 

I see this moment as a good reminder for healthcare marketers: HIPAA is one lane, but not the whole highway. Whether or not an organization is subject to HIPAA, healthcare marketers and privacy leaders should still consider the expanse of the FTC, state privacy laws, and consumer-protection laws when crafting digital ad strategies, policies, and marketing copy. 

2. Are privacy claims in our marketing copy and privacy policies inherently wrong?

This is basically the same rule that applies everywhere else in life: don't make promises you can't keep.

If your website says something is “100% private,” your paid social ad says consumers' information “stays between you and your provider,” and your influencer tells followers their experience is “completely confidential,” those aren't just nice marketing phrases. They're representations about how your organization handles information.

And one of the themes running through the FTC's allegations is the potential gap between what consumers were allegedly told or might reasonably expect and what happened to their information downstream.

I suggest partnering with your legal team to compare your actual data flows with language on your website, paid media, emails, SMS, FAQs, consent language, and privacy policy.

If the two don’t match, it’s a good time to look deeper and make the changes necessary to ensure that your privacy claims and advertising practices are aligned. And if a privacy claim feels misleading, overly broad, or difficult to substantiate, don’t publish it until your legal and privacy teams have had a chance to review it.

3. Should I turn off my paid media?

This moment actually reminds me of what happened after the 2022 HHS guidance. The healthcare marketers who came out stronger didn’t rip out every pixel and hope for the best. They took a step back, got more intentional about how data was collected and shared, and built a stronger measurement foundation around consented first-party data. What looked like a compliance nightmare ultimately made them more effective.

I think there’s a similar opportunity here. The answer to privacy risk isn’t necessarily to shut off your paid media. It’s to understand and control what information is moving through your marketing stack — and build the governance framework that lets you keep marketing effectively without unnecessarily exposing sensitive information.

I’ve been recommending four steps to healthcare marketing leaders I’ve spoken with over the last couple of weeks:

  • Identify and remove any risky third-party trackers that could be exposing sensitive health information downstream. This isn’t a one-time activity either. Marketers should maintain a constant pulse of the tracking technology operating on their website and quickly intervene if unwanted tracking technology makes its way back to the site.
  • Gather and enforce consent where required or appropriate, and validate that consent is working as designed. While some may argue that data is gold; I would argue that consented data is platinum. 
  • Audit the privacy claims made in your ads (digital, offline, and influencer) and policies, and ensure they accurately reflect data handling and sharing practices. It’s probably worth establishing some repeatable privacy guidelines for advertising and marketing content as well. 
  • Review your data controls and ensure they’re safeguarding sensitive information before sharing downstream. Tools like Freshpaint can help, giving teams a control layer to govern which data is shared with advertising platforms.

4. Should we stop using audiences?

There’s no one-size-fits-all approach in healthcare marketing. This question ultimately comes down to how audiences are built and the information that gets shared with advertising platforms in the process – and your organization’s own privacy posture. 

Your legal and privacy teams should evaluate your specific audience strategy, consent requirements, disclosures, and compliance obligations. 

Me, personally? I wouldn’t abandon audiences altogether, but rather have clear governance and documentation of how they’re built and activated. 

For what it’s worth, this is exactly the problem we designed Freshpaint Audiences to help solve. Instead of uploading raw customer lists or sensitive health information directly to an advertising platform, healthcare marketers gain additional controls over the data used to build and activate audiences downstream.

Is this complaint the first of many – or the last of our worries?

I don’t have a crystal ball, but both the FTC and states have publicly signaled their interest and commitment to protecting and enforcing consumer privacy. Healthcare and health information have been an especially visible part of that conversation.

Said another way: If you live in southern Florida and you get a hurricane warning, are you going to evacuate or take steps to protect your home while you hunker down? Or are you going to do nothing and see what the storm is really about? 

Here’s what I’d do this week: Take one important patient acquisition journey and trace it from beginning to end.
  1. Start with the ad and follow the consumer to the landing page.
  2. Go through the intake or conversion flow yourself.
  3. Look at the privacy claims the consumer encounters.
  4. Look at the consent choices they’re offered and validate that those choices are actually being enforced.
  5. Then follow the data.

Which events fire? Which parameters are collected? Which third parties receive them? Trace the full data flow from the browser through your server-side infrastructure and into each downstream destination. Don’t rely on your browser’s developer tools alone to tell you what’s being shared – take the extra step to validate the data your servers are sending to advertising and analytics platforms, including the events, parameters, identifiers, and audience statistics that ultimately reach them.

Then ask: Is what we're actually doing consistent with what we've told the consumer we're doing?

If you can't answer that confidently, you've found a good place to start.

Freshpaint is here to help you evaluate and improve your privacy posture.

We spend our days living and breathing the intersection of healthcare marketing, privacy, and compliance. With the right governance in place, healthcare marketers can act like marketers – acquiring patients and members, proving marketing’s ROI, and safeguarding sensitive information, confidently.

Want to see where your current setup may be creating risk? We’re here - let’s talk.

Key capabilities / features

Get insights, strategies, and data that help you stay ahead