FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices: What Was Reportedly Exposed & What To Do
On July 29, 2026, the FTC and several states announced enforcement action against Hims & Hers, alleging the company engaged in deceptive and unlawful privacy practices. If you are or were a customer, review the official notices to determine whether your data was involved and what steps, if any, you should take.
Allegations that a telehealth provider shared sensitive health-related information with advertising platforms matter first to the people who used those services expecting privacy. If the claims in a federal complaint are accurate, details about medical conditions could have been handled in ways users were not clearly told about. As of writing, these remain allegations in a lawsuit; the company has not been treated here as having confirmed a data breach or an extortion-site event, and public detail on any separate cyber incident is limited.
What is on the public record in the material provided is an enforcement action reported on July 29, 2026. The number of people affected is not stated. Readers should treat any risk to their own information as conditional until more is established in court or by the company itself.
Inside the listing
There is no ransomware or extortion-group leak-site listing described in the available facts. What was reported is that the Federal Trade Commission, joined by Utah and California, by and through Los Angeles County Counsel, sued Hims & Hers alleging that the telehealth provider shared consumers’ sensitive health information about medical conditions with third-party advertising platforms despite claiming its services maintain consumers’ privacy, and that it deceives users about its billing and cancellation practices.
According to the reported summary of the complaint filed in federal court, the FTC and its state and local partners allege that Hims & Hers fails to clearly disclose that it charges consumers for prescriptions almost immediately—a description that cuts off in the source material. Scale, technical method of any unauthorized access, file inventories, and a count of affected individuals are not stated. The company’s public confirmation status regarding these allegations is not detailed in the facts provided; nothing here should be read as a verified inventory of stolen data.
How a breach like this happens
In general terms, incidents that involve consumer health or account data often unfold when information collected for care or billing is also routed into marketing, analytics, or advertising tools. That can occur through software development kits, pixels, or other tracking technologies embedded in apps or websites; through contracts with ad platforms; or through misconfigured access controls. Separately, credential theft, phishing against staff, or exposed cloud storage can lead to unauthorized copying of databases. None of those mechanisms is attributed as fact in the material for this matter, and no threat group is named in the facts.
Extortion crews sometimes later post claims on leak sites to pressure payment. Such posts are marketing by the claimant. They do not, by themselves, prove what was taken, whether the data is authentic, or whether the organization was at fault. When timing, method, and scope are undisclosed—as they are here beyond the lawsuit summary—the responsible approach is to keep every technical narrative labeled as background, not as a reconstruction of this case.
About FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices
The organization named in the record is framed around an FTC and state action concerning Hims & Hers, a telehealth business that offers remote access to clinicians and prescription-related services for various consumer health needs. Firms in this sector typically collect account identifiers, contact details, payment information, questionnaire answers about symptoms or goals, prescription and fulfillment records, and communications tied to care. That mix is inherently sensitive because it can reveal conditions people may not want employers, insurers, family members, or marketers to infer.
A public enforcement action alleging improper sharing of health-related information with advertising platforms is consequential because trust in telehealth depends on clear limits on how medical context is used. Even when the core dispute is framed as privacy and billing practices rather than a classic network intrusion, the practical stakes for users are similar: uncertainty about who else saw health-linked data and whether secondary use continues.
What data was at risk
The facts do not provide a confirmed inventory of exposed fields. Data types are described only as “Reported in the source,” without a stable public list in the material given. The complaint summary alleges sharing of consumers’ sensitive health information about medical conditions with third-party advertising platforms and raises billing and cancellation disclosure issues. It does not, in the text provided, itemize every category that may have been involved.
If health-linked records or advertising identifiers were shared in the manner alleged, organizations in telehealth commonly hold information such as names, email addresses, phone numbers, partial payment data, condition or treatment topics, prescription details, and device or advertising identifiers. Whether any of that left expected controls in a cyber “breach” sense, and exactly what third parties received, remains unconfirmed in the facts. Treat the attackers’-style data claims—if any appear elsewhere—as unverified marketing, not as an audit.
Why it matters
For individuals, the conditional risks are concrete. Health-topic data in advertising systems can support profiling, unwanted targeting, or embarrassment if categories surface in unexpected places. Billing and cancellation confusion can lead to unwanted charges and time spent disputing them. If credentials or contact data were ever involved in a wider incident, phishing and account-takeover attempts often follow known breach dumps—again, only if such data actually circulated.
For the organization, a federal and multi-state complaint creates legal, financial, and reputational pressure independent of any leak-site drama. What a lawsuit or a leak-site listing establishes is limited: it establishes that serious claims were made on a given date. It does not automatically establish negligence, the full truth of every allegation, or a complete map of affected customers. Readers should separate “alleged in court” from “proven” and from “confirmed by the company.”
Steps worth taking either way
Until more is confirmed, practical steps stay precautionary. They are worth taking if you used the service and are unsure how your information was handled:
- Review your account statements and prescription-related charges; dispute anything you do not recognize through your bank or card issuer promptly.
- If you still have an account, update the password to a unique one and enable multi-factor authentication where offered; do the same on email tied to the account.
- Be skeptical of unexpected messages that reference your health topics, prescriptions, or cancellations; verify through official app or website channels, not links in email or text.
- Consider placing fraud alerts or credit freezes if you believe financial identifiers may have been involved; monitor credit and medical-related identity tools your state or insurer provides.
- Read in-product privacy settings and ad-related preferences where available, and adjust sharing you no longer want.
- You can run a free exposure scan of your email to check whether your address has already appeared in known breach datasets—useful context even when a specific incident remains unconfirmed.
None of these steps requires assuming the worst about unproven claims. They reduce everyday risk if sensitive health or billing information was mishandled, and they remain sensible digital hygiene if the allegations are narrowed or contested over time. Public detail on people affected and exact data elements is limited; stay with primary sources—the court docket and any formal company notices—rather than secondhand inventories.
AICompiled with AI assistance from public sources and published under our editorial standards.
More recent breaches
FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized PricingFTC Stops Sprawling Credit Repair Scheme that Scammed Consumers Out of Nearly $200 MillionHealthfirst Bluegrass, Inc. Data Breach Notice (Vermont Attorney General)Murfreesboro Medical Clinic Data Breach Notice (Vermont Attorney General)Latest breaches
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.