When a Telehealth App Promises Privacy

A lot of people use telehealth precisely because it feels private. You fill in an intake form at home rather than saying the words out loud in a waiting room, and the appeal is discretion. On July 29, 2026, the Federal Trade Commission, joined by Utah and by California acting through Los Angeles County Counsel, sued the telehealth company Hims and Hers, alleging it shared consumers' sensitive health information with third-party advertising platforms including Meta and Snap while promising to protect patient privacy. The company denies the allegations, says the suit disregards substantial evidence from a nearly three-year investigation, and none of the claims have been proven. Whatever the outcome, the case is a clear window into how health data moves online.

What is actually alleged?

Two broad things. On privacy, the complaint alleges the company shared health information with advertising platforms in two ways: by sending those companies lists of certain customers, and through third-party tracking technologies embedded in its website that automatically transmitted events, meaning the actions visitors took on the site. On billing, it alleges consumers were enrolled in prescription subscriptions without adequate disclosure, in some cases as soon as they submitted a medical intake form and before consulting a provider, and that cancelling was made difficult.

The legal claims run under Section 5 of the FTC Act and the Restore Online Shoppers' Confidence Act, with Utah and California adding state consumer protection claims. The FTC vote to authorize the complaint was 2-0. Again, these are allegations, the company disputes them, and a court has not ruled.

Why is this kind of data so sensitive?

Because of what the treatment implies. This company provides care for conditions including weight loss, hair loss, and erectile dysfunction, and the fact of seeking treatment is itself the private information. Nobody needs to see a diagnosis or a prescription. Knowing that a specific person visited a page about a specific condition is enough to infer something they may have chosen telehealth specifically to keep quiet.

This is why tracking pixels on health-related pages draw so much regulatory attention. A pixel does not need your medical record to be revealing. It only needs to report which page you looked at, attached to an identifier that ties back to you.

Doesn't HIPAA cover this?

Not in the way most people assume, and the fact that the FTC brought this case rather than health regulators tells you something. HIPAA applies to covered entities, essentially healthcare providers, health plans, and clearinghouses, along with their business associates. Plenty of consumer health services sit partly or wholly outside that perimeter, and even where clinical care is involved, the marketing and website analytics side of a business is a different matter from the treatment record.

This is the same structural gap we covered in whether health apps are sharing your data and in how apps track and sell your data. The protection you have depends on who is holding the information, not on how sensitive it is. The FTC has increasingly filled that gap by treating a broken privacy promise as a deceptive practice, which is the theory at work here.

What does this mean for using telehealth?

Not that you should avoid it. Telehealth has made care accessible to a lot of people who would otherwise go without, and that matters more than a theoretical privacy risk. The takeaway is narrower: treat a marketing promise of privacy as a claim rather than a guarantee, and take the practical precautions that reduce what leaks regardless of the provider's practices.

  • Use a browser that blocks trackers when researching health topics, since a great deal of exposure happens before you ever create an account.
  • Do not sign up through a social media login, which links your health activity to your social profile by design.
  • Read the subscription terms carefully, and note how cancellation works before you enter payment details.
  • Consider an email alias for health services, so the address cannot be used to match you across marketing databases.
  • Check the privacy policy for advertising and analytics language, which is usually where third-party sharing is disclosed if it is disclosed at all.

Where does data removal fit?

Honestly, only at the edges, and it would be easy to overclaim here. Removing your people-search listings does nothing about a tracking pixel on a health website, does not retrieve data already shared with an advertising platform, and does not affect any company's internal records. That is a different problem with different solutions, mostly regulatory ones.

The connection is the same one that runs through most health-adjacent data: an event tied to a device or an email is fragmentary until it is matched to a real identity, and the public identity layer is what makes matching easy. Reducing your published name, address, and household details makes you a slightly harder record to join up, and it addresses the exposures that show up in everyday life regardless. That layer rebuilds from public records, so it takes maintaining. Consumer Reports found that opt-outs done by hand or by automation cleared roughly 27 percent of exposed listings, while removals handled by real people who monitor and refile reached about 70 percent.

We cannot pull data back from an ad platform. Nobody can.

Privoria does not touch tracking pixels or a company's internal records, and we will not suggest otherwise. What we remove is the public people-search layer that ties your name to your address and household. A free scan shows what is published about you, and our team of real people removes it and keeps checking as it returns.

Run my free scan Start free trial

Frequently asked questions

Has the company been found guilty of anything?

No. A complaint is an allegation, not a finding. The company has publicly denied the claims and said the action mischaracterizes its practices. The matter is before a federal court, and the outcome is not yet determined.

How would I know if a health site is tracking me?

Mostly you would not, since trackers are invisible by design. A tracker-blocking browser or extension will show you how many are present on a page, which is often startling on health sites. The privacy policy's advertising section is the other place to look.

Can I ask a health company to delete my data?

If you live in a state with a comprehensive privacy law you generally have deletion and access rights, and a few states have laws specifically covering consumer health data collected outside HIPAA. Data already transmitted to a third party is much harder to claw back, which is why prevention matters more than cleanup here.

Should I stop using telehealth services?

That is not the conclusion to draw. Access to care matters, and this case involves one company's alleged practices rather than the whole model. Use the services, read the subscription terms, and take basic tracking precautions when researching and signing up.

Related reading

Back to blog