Skip to content

Key Takeaways

  • The FTC, joined by the Attorneys General of California and Utah, sued Hims & Hers alleging deceptive practices involving consumer marketing, subscription enrollment, recurring billing and the collection and use of sensitive consumer health information. The allegations remain to be resolved, but the complaint provides an important window into current enforcement priorities.
  • Companies should not assume consumer protection enforcement has slowed. Following the change in administration, it was widely expected that FTC consumer protection activity would become less aggressive. This case is a reminder that, particularly in areas involving consumer information and digital commerce, enforcement remains a priority.
  • Regulatory enforcement has finally caught up to the new tech-enabled reality. The FTC is evaluating businesses under a modern holistic model – not individual issues in isolation. The complaint is not simply about privacy, pixels, advertising claims or subscriptions, but the overall consumer impression. It examines the interconnected ecosystem in which digital businesses now operate. The very features that now make these platforms so effective – seamless connection between marketing, access, payment, subscriptions and technology – are the features now being scrutinized.
  • The consumer experience may matter as much as technical legal compliance. The question regulators are increasingly asking is not only, “Are we technically permitted to do this?” but also, “What does the consumer actually experience?” A process that is legally defensible on paper may still create enforcement risk if the overall journey is confusing, misleading or inconsistent with consumer expectations.
  • Health data remains a special enforcement priority, even outside HIPAA. Companies often focus heavily on HIPAA compliance while overlooking separate FTC risks involving website tracking technologies, adtech platforms, pixels, SDKs, analytics tools, cookies and vendor data flows.
  • Coordinated federal and state enforcement is becoming the norm. The involvement of California and Utah demonstrates that companies face scrutiny from multiple regulators applying overlapping consumer protection and deceptive advertising laws. For nationwide businesses, that creates a meaningful risk multiplier.
  • Other states may follow. Every state has consumer protection and deceptive advertising statutes, and significant FTC actions like this one serve as a roadmap for additional state investigations.
  • Plaintiffs’ bar is paying attention. Any company that markets directly to consumers, operates subscriptions, collects personal information or relies on digital advertising should view this case as a broader compliance signal.

What Happened?

On July 29, 2026, the Federal Trade Commission, joined by the Attorneys General of California and Utah, filed a lawsuit against Hims & Hers alleging that the company’s direct-to-consumer healthcare platform violated federal and state consumer protection laws. According to the complaint, Hims & Hers engaged in deceptive practices across multiple aspects of its consumer journey, including its marketing (including influencer marketing), online intake and enrollment processes, subscription model and offerings, recurring billing practices, cancellation procedures, privacy practices, and the collection, use, and disclosure of consumers’ sensitive health information.

The FTC alleges that Hims & Hers shared information with third-party advertising platforms through tracking technologies despite representations regarding consumer privacy. The complaint also alleges that the company’s subscription and billing practices resulted in consumers being enrolled in recurring programs and charged before certain healthcare interactions occurred. The complaint further challenges aspects of the consumer cancellation experience and the relationship between the company’s marketing messages, enrollment processes and actual consumer journey. Importantly, the FTC does not present these issues as separate events. Instead, the complaint connects all activities into a broader theory of an overall misleading consumer experience.

The complaint seeks relief under federal consumer protection authorities and state consumer protection laws. As with any government enforcement action, these allegations must be proven.

Why It Matters

A New Model of Evaluating Compliance Across a Business as a Whole

The most important lesson from this complaint is that enforcement has finally caught up to the new tech-enabled reality. Regulators appear to be evaluating companies the way consumers experience them: as an integrated journey.

This is not simply a privacy case.

This is not simply an advertising case.

This is not simply a subscription billing case.

The complaint connects marketing claims, consumer intake, provider interactions, payments, recurring billing, cancellation and data sharing. That is how online DTC businesses actually operate. The customer experience does not occur in silos. Marketing influences enrollment. Product design shapes disclosures. Technology enables customer acquisition. Billing systems influence consumer expectations. Privacy practices affect advertising and analytics. Increasingly, regulators are evaluating businesses through that same integrated lens.

For companies, this means that the old model of compliance reviews that examine only individual functions can miss the most significant risks. The modern evaluation of consumer harm is the interaction between functions. The very features that now make these platforms so effective – seamless connection between marketing, access, payment, subscriptions and technology – are the features now being scrutinized.

Consumer Protection Enforcement Remains a Priority

Following the change in administration, many companies assumed FTC consumer protection activity would slow, particularly after the Click-to-Cancel rule was vacated last year.

This case is a reminder that companies should be cautious about making compliance decisions based on assumptions. At least in areas involving digital commerce, consumer deception, sensitive consumer information or healthcare, enforcement remains active. The point is not political. It is practical: businesses should assss risk based on the regulatory environment that exists, not inferences about what may change.

Consumer Experience May Matter as Much as Legal Theory

Many founders and executives still approach compliance questions by asking:

“Are we technically allowed to do this?”

Increasingly, regulators are asking:

“What does the consumer actually experience?”

That distinction matters. A disclosure may exist. A process may have been reviewed by consel. A practice may have a legal argument supporting it and a contractual provision may be technically accurate. But if the overall customer journey feels confusing, misleading, or inconsistent with reasonable consumer expectations, that experience may attract scrutiny. The FTC’s approach reflects a broader trend: consumer protection anaysis is increasingly focused on the totality of the experience rather than isolated legal components. Those strategic considerations are a meaningful value-add to traditional legal review.

Health Data Remains a Special Enforcement Priority

The complaint also reinforces that consumer health information receives heightened scrutiny – even where HIPAA may not apply.

Many businesses devote significant resurces to HIPAA compliance while overlooking other pathways through which sensitive information may be collected, transmitted or shared. Examples include:

  • website tracking technologies;
  • advertising pixels;
  • SDKs;
  • analytics platforms;
  • cookies;
  • mobile applications; and
  • third-party vendors.

Companies should understand not only what information they collect, but where the information flows and whether those practices align with consumer expectations. For many organizations, the greatest privacy risk may not exist within their core systems. It may exist in the broader digital ecosystem supporting marketing, analytics and customer engagement. When it is easy to engage with lucrative modalities around data collection, it is particulalry critical to keep scrutiny in mind.

State Coordination Creates a Risk Multiplier

The participation of California and Utah highlights another important trend: coordinated federal and state enforcement.

Companies should not assume that an FTC action represents scrutiny from only one regulator. State attorneys general have their own consumer protection and deceptive advertising laws, authorities and agendas, and increasingly coordinate with federal agencies. The same facts are easily evaluated under multiple statutes by multiple regulators.

Businesses should also consider the possibility of follow-on private litigation. Significant FTC enforcement actions frequently become roadmaps for the plaintiffs’ bar, including consumer class actions alleging that plaintiffs were harmed by the same conduct laid out in a government complaint.

Questions Every Consumer-Facing Company Should Be Asking

The Hims & Hers complaint raises questions that apply far beyond healthcare. The primary question is:

If regulators walked through our customer journey from the first advertisement through cancellation, what would they see?

Companies should ask:

  • Does our marketing accurately reflect the experience consumers actually receive?
  • Are our intake, enrollment, payment, subscription and cancellation processes clear and consistent?
  • Have we mapped every place consumer information flows, including pixels, SDKs, analytics tools, advertising platforms and vendors?
  • Are marketing, privacy, legal, compliance, product and operations teams evaluating the customer journey together?
  • Are we relying on technical compliancre while overlooking potential consumer confusion?

Keep in mind that regulators are ghost shopping online DTC platforms alongside consumers.

A Proactive Approach to Modern Compliance

The significance of the FTC’s action against Hims & Hers is not limited to telehealth. It reflects the modern regulatory trend: DTC companies are increasingly being evaluated based on the complete consumer experience.

The companies best positioned to manage this environment are those that proactively pressure-test their operations. The most important lessons from the FTC’s Hims & Hers complaint may ultimately be the roadmap it provides to do that.

At Vedder, we help clients conduct multidisciplinary compliance assessments that bring together FDA regulatory strategy, FTC consumer protection, privacy, advertising and marketing, health care regulation, technology and litigation perspectives. We regularly review consumer-facing operations end-to-end to identify potential legal and operational gaps, classify risks by severity and provide practical recommendations that management teams can prioritize. If there are gaps, we can advise on closing them; if your consumer experience is solid, there is value in a documented legal opinion.

Related People

Stay up to date

Subscribe

Attorney Advertising ©2026 Vedder

cping