Skip to content
Back to Blog
medium severity July 29, 2026 · 4 min read

FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

If you are a customer of FTC and States Act Against Hims, here’s what’s now in circulation.

The Federal Trade Commission, joined by Utah and California, by and through Los Angeles County Counsel, today sued Hims & Hers alleging that the telehealth provider shared consumers’ sensitive health information about medical conditions with third-party advertising platforms despite claiming its services maintain consumers’ privacy and deceives users about its billing and cancellation practices. In a complaint filed in federal court, the FTC and its state and local partners allege that Hims & Hers (Hims) fails to clearly disclose that it charges consumers for prescriptions almost immediately a

FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

Your health data from Hims & Hers has appeared on a ransomware group's leak site. The group claims it obtained files containing sensitive medical and personal information from the telehealth provider. As of this writing, Hims & Hers has not publicly confirmed any breach or data theft.

This means that information you shared with the company — potentially including details about your health conditions, treatments, or prescriptions — could be in the hands of criminals. Unlike a password breach, no login credentials were listed. What was reportedly taken cannot be changed like a password can. It stays tied to you permanently, and its value to advertisers, insurers, and potential employers does not expire.

What the Listing Actually Contains

According to the group's posting, the data includes categories of health-related records typical for a telehealth platform. No passwords or login credentials appear in the exposed data. The listing does not mention government identifiers such as Social Security numbers.

If the claim is accurate, the files would likely contain information many customers consider deeply private: details about hair loss, sexual health, mental health, or weight management treatments. These are exactly the kinds of records people expect to remain between them and their doctor. The absence of credentials is genuinely good news here. It means this incident does not put your Hims & Hers account at direct risk of takeover. The exposure is about the non-credential personal and medical data instead.

What a Leak-Site Listing Does and Does Not Establish

Ransomware crews maintain public leak sites to pressure victims into paying. They post company names, sample files, and dramatic claims long before anyone else can verify them. Many listings turn out to be recycled data from older incidents, exaggerated descriptions, or outright bluffs. Some groups have been caught posting data they never actually stole, hoping the mere appearance of a listing will force a payout.

A single leak-site entry, therefore, does not equal proof that a breach occurred or that customer data left the company's control. Real confirmation usually requires an independent investigation, a regulatory filing, customer notifications, or an admission by the company itself. None of those have happened here yet. Until they do, this remains an unverified accusation by a group whose business model depends on being believed. Treat it seriously enough to take protective steps, but do not treat it as settled fact.

The Persistent Value of Health Data

Health information carries lifelong consequences that financial data often does not. A record of mental health treatment, erectile dysfunction medication, or weight-loss prescriptions can affect insurance premiums, job applications, or even personal relationships years later. Advertisers pay substantial sums for detailed health profiles because they allow precise targeting. Once this data moves beyond the doctor's office, you lose control over who sees it and for what purpose.

Because no permanent government identifiers were listed, the risk of full identity theft is lower than in many other incidents. However, the combination of your name, contact details, and specific medical conditions can still enable highly personalized scams, blackmail attempts, or discriminatory practices. The data's value does not decay. A record from today can be sold or used a decade from now.

The Wider Pattern in Telehealth

Direct-to-consumer health platforms have repeatedly been caught transmitting sensitive medical data to advertising networks while promising strong privacy protections. Regulators have taken action against multiple companies in this sector for exactly these practices. When customer data moves through third-party advertising ecosystems, the boundary between "secure medical record" and "marketable profile" becomes dangerously thin. This pattern makes health platforms an attractive target, whether through technical compromise or questionable data-sharing arrangements.

Understanding this larger industry behavior gives you a practical lens for the next time a telehealth or wellness app asks for intimate details. Ask harder questions upfront about exactly who will have access to your information and under what legal agreements.

What You Can Still Control

Even when medical data has left one company's systems, you retain power over how you respond and protect yourself going forward. Start by reviewing every service where you have shared similar health information. Close accounts you no longer use. Request that remaining providers delete data they no longer need for treatment.

Monitor for unusual activity on linked financial accounts and be wary of unsolicited communications claiming to be from pharmacies, insurers, or clinics. Scammers armed with partial medical histories can sound extremely convincing. Consider freezing your credit reports as a precaution against any future attempts to use your information in combination with data from other sources.

Be selective about which health platforms you trust with sensitive conditions in the future. The convenience of online prescriptions comes with permanent privacy trade-offs that many users do not fully weigh at signup.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and over 100 platforms, along with identity-chain mapping and remediation support by specialists.

Report details & sourcing

Severity Medium
Disclosed July 29, 2026
Affected not stated
Data exposed Reported in the source
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email