On July 29, 2026, the Federal Trade Commission, joined by the Attorneys General of Utah and California, filed suit against telehealth provider Hims & Hers, alleging that the…


On July 29, 2026, the Federal Trade Commission, joined by the Attorneys General of Utah and California, filed suit against telehealth provider Hims & Hers, alleging that the company shared consumers' sensitive health information without adequate consent. The coordinated federal-state action underscores a growing regulatory focus on digital health platforms whose data practices may not align with evolving expectations for transparency and meaningful consumer choice.

The Hims & Hers action is not an isolated event. It reflects a continuing pattern of coordinated enforcement targeting telehealth, digital health, and consumer wellness businesses that handle protected health information outside traditional HIPAA-covered channels. Regulators have made clear that where information relates to a consumer's physical or mental health, treatment, or medications, they will scrutinize disclosures and consent flows with heightened rigor, regardless of whether the information is technically governed by HIPAA. Common areas of exposure include third-party advertising pixels, software development kits, analytics tools, and data-broker relationships that transmit user information away from a company's own systems.

The theories driving these cases typically rest on Section 5 of the FTC Act, which prohibits unfair or deceptive acts and practices, together with parallel state consumer protection statutes. Allegations often focus on inconsistencies between privacy policy representations and actual data flows, opaque or buried consent language, and the absence of affirmative, informed authorization before sensitive information is shared with third parties for advertising or measurement purposes. Enforcement remedies have included substantial civil penalties, injunctive relief restricting data uses, mandatory deletion of improperly obtained data, and multi-year compliance monitoring.

In light of these developments, telehealth, digital health, and consumer wellness companies should promptly reassess their public disclosures, in-product consent experiences, and vendor relationships. Priority steps include mapping all outbound data flows involving health-related information, evaluating whether current consent mechanisms satisfy an affirmative express consent standard for sensitive data, auditing ad-tech and analytics integrations on consumer-facing web and mobile properties, and confirming that internal representations match on-the-ground practices. Boards and senior management should also consider tabletop exercises addressing coordinated federal-state investigations, which increasingly demand rapid, cross-functional response.

This alert is provided for general informational purposes only and does not constitute legal advice. Clients facing specific questions about their data-sharing practices or potential regulatory exposure should seek tailored counsel.