LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

CRITICAL severityReportedHow we verify

FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 29, 2026
FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

Reported July 29, 2026. Approximately not stated people affected.

CRITICAL
Severity
not stated
People affected
1
Data types exposed
July 29, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On July 29, 2026, the FTC and several states announced enforcement action against Hims & Hers, alleging the company engaged in deceptive and unlawful privacy practices. If you are or were a customer, review the official notices to determine whether your data was involved and what steps, if any, you should take.

Severity & verification
CRITICAL severityReported
Exposes medical data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
not stated accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Allegations that a telehealth provider shared sensitive health-related information with advertising platforms matter first to the people who used those services expecting privacy. If the claims in a federal complaint are accurate, details about medical conditions could have been handled in ways users were not clearly told about. As of writing, these remain allegations in a lawsuit; the company has not been treated here as having confirmed a data breach or an extortion-site event, and public detail on any separate cyber incident is limited.

What is on the public record in the material provided is an enforcement action reported on July 29, 2026. The number of people affected is not stated. Readers should treat any risk to their own information as conditional until more is established in court or by the company itself.

Inside the listing

There is no ransomware or extortion-group leak-site listing described in the available facts. What was reported is that the Federal Trade Commission, joined by Utah and California, by and through Los Angeles County Counsel, sued Hims & Hers alleging that the telehealth provider shared consumers’ sensitive health information about medical conditions with third-party advertising platforms despite claiming its services maintain consumers’ privacy, and that it deceives users about its billing and cancellation practices.

According to the reported summary of the complaint filed in federal court, the FTC and its state and local partners allege that Hims & Hers fails to clearly disclose that it charges consumers for prescriptions almost immediately—a description that cuts off in the source material. Scale, technical method of any unauthorized access, file inventories, and a count of affected individuals are not stated. The company’s public confirmation status regarding these allegations is not detailed in the facts provided; nothing here should be read as a verified inventory of stolen data.

How a breach like this happens

In general terms, incidents that involve consumer health or account data often unfold when information collected for care or billing is also routed into marketing, analytics, or advertising tools. That can occur through software development kits, pixels, or other tracking technologies embedded in apps or websites; through contracts with ad platforms; or through misconfigured access controls. Separately, credential theft, phishing against staff, or exposed cloud storage can lead to unauthorized copying of databases. None of those mechanisms is attributed as fact in the material for this matter, and no threat group is named in the facts.

Extortion crews sometimes later post claims on leak sites to pressure payment. Such posts are marketing by the claimant. They do not, by themselves, prove what was taken, whether the data is authentic, or whether the organization was at fault. When timing, method, and scope are undisclosed—as they are here beyond the lawsuit summary—the responsible approach is to keep every technical narrative labeled as background, not as a reconstruction of this case.

About FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

The organization named in the record is framed around an FTC and state action concerning Hims & Hers, a telehealth business that offers remote access to clinicians and prescription-related services for various consumer health needs. Firms in this sector typically collect account identifiers, contact details, payment information, questionnaire answers about symptoms or goals, prescription and fulfillment records, and communications tied to care. That mix is inherently sensitive because it can reveal conditions people may not want employers, insurers, family members, or marketers to infer.

A public enforcement action alleging improper sharing of health-related information with advertising platforms is consequential because trust in telehealth depends on clear limits on how medical context is used. Even when the core dispute is framed as privacy and billing practices rather than a classic network intrusion, the practical stakes for users are similar: uncertainty about who else saw health-linked data and whether secondary use continues.

What data was at risk

The facts do not provide a confirmed inventory of exposed fields. Data types are described only as “Reported in the source,” without a stable public list in the material given. The complaint summary alleges sharing of consumers’ sensitive health information about medical conditions with third-party advertising platforms and raises billing and cancellation disclosure issues. It does not, in the text provided, itemize every category that may have been involved.

If health-linked records or advertising identifiers were shared in the manner alleged, organizations in telehealth commonly hold information such as names, email addresses, phone numbers, partial payment data, condition or treatment topics, prescription details, and device or advertising identifiers. Whether any of that left expected controls in a cyber “breach” sense, and exactly what third parties received, remains unconfirmed in the facts. Treat the attackers’-style data claims—if any appear elsewhere—as unverified marketing, not as an audit.

Why it matters

For individuals, the conditional risks are concrete. Health-topic data in advertising systems can support profiling, unwanted targeting, or embarrassment if categories surface in unexpected places. Billing and cancellation confusion can lead to unwanted charges and time spent disputing them. If credentials or contact data were ever involved in a wider incident, phishing and account-takeover attempts often follow known breach dumps—again, only if such data actually circulated.

For the organization, a federal and multi-state complaint creates legal, financial, and reputational pressure independent of any leak-site drama. What a lawsuit or a leak-site listing establishes is limited: it establishes that serious claims were made on a given date. It does not automatically establish negligence, the full truth of every allegation, or a complete map of affected customers. Readers should separate “alleged in court” from “proven” and from “confirmed by the company.”

Steps worth taking either way

Until more is confirmed, practical steps stay precautionary. They are worth taking if you used the service and are unsure how your information was handled:

None of these steps requires assuming the worst about unproven claims. They reduce everyday risk if sensitive health or billing information was mishandled, and they remain sensible digital hygiene if the allegations are narrowed or contested over time. Public detail on people affected and exact data elements is limited; stay with primary sources—the court docket and any formal company notices—rather than secondhand inventories.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

More recent breaches

FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized PricingAugust 19, 2026FTC Stops Sprawling Credit Repair Scheme that Scammed Consumers Out of Nearly $200 MillionAugust 10, 2026Healthfirst Bluegrass, Inc. Data Breach Notice (Vermont Attorney General)August 27, 2026Murfreesboro Medical Clinic Data Breach Notice (Vermont Attorney General)August 27, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices →

Source: FTC consumer protection

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram