US Regulators Sue Telehealth Giant Over Tracking Pixels Sent to Meta and Snap
Federal complaint alleges Hims & Hers embedded ad-tech code that captured prescription, mental health, and weight-loss data without proper consent
The Complaint
The Federal Trade Commission filed suit against Hims & Hers in California federal court, alleging the telehealth company deployed tracking pixels from Meta, Snap, Microsoft, Pinterest, Reddit, and X that captured users' health information. The complaint centers on a familiar tension in digital healthcare: the collision between performance marketing imperatives and patient privacy obligations.
At DailyTechWire, we've tracked how ad-tech infrastructure has become standard in consumer health platforms across Asia and North America. Hims & Hers, now publicly traded, handles prescription orders for sexual wellness, mental health medication, and weight-loss treatments. The FTC alleges the company placed pixel code on its website that transmitted user actions, clicks, and health-related browsing behavior to advertising platforms, behavior the agency claims violated the company's own privacy policy.
The complaint also accuses Hims & Hers of deceptive billing practices and creating cancellation flows that make it difficult for customers to exit subscriptions, violations of federal consumer protection statutes.
Why Pixels Matter in Healthcare
Tracking pixels are snippets of code, typically one pixel in size, that fire when a user visits a page or completes an action. Advertisers use them to build audience profiles, measure campaign performance, and retarget users across the web. In e-commerce, they are ubiquitous. In healthcare, they present a legal minefield.
The data these pixels collect can include information about which pages a user visited (for example, a product page for erectile dysfunction medication or antidepressants), how long they stayed, what they clicked, and whether they completed a purchase. When combined with login state or device identifiers, that data can be linked back to an individual.
For telehealth platforms operating at scale, the trade-off is clear: pixel-based attribution drives customer acquisition efficiency, but misconfigurations or overly broad data sharing can expose protected health information to third parties. According to the FTC, Hims & Hers crossed that line.
The company has not explicitly denied the allegations. In a statement, Hims & Hers said its privacy policy allows users to choose how their data is used and that it is confident in its legal position. The company indicated it will contest the suit.
A Pattern Across Digital Health
This is not the first time US regulators have targeted healthcare companies for pixel-related data sharing. The FTC has brought enforcement actions against telehealth startup Cerebral, alcohol recovery platform Monument, prescription data broker GoodRx, and online therapy provider BetterHelp. In each case, the agency alleged that sensitive health data flowed to advertising platforms without adequate user consent or disclosure.
The pattern reflects a structural problem in how digital health companies are built. Many telehealth startups rely on direct-to-consumer models and performance marketing to scale quickly. They use the same ad-tech stack as e-commerce brands: Meta Pixel, Snap Pixel, Google Analytics, TikTok Pixel. But unlike apparel or consumer electronics, the products being sold are medications and mental health services, and the data being captured is protected under health privacy laws in many jurisdictions.
The US Health Insurance Portability and Accountability Act (HIPAA) governs how covered entities handle protected health information, but many direct-to-consumer telehealth platforms argue they fall outside HIPAA's scope or that pixel data does not constitute identifiable health information. The FTC, which enforces the FTC Act's prohibition on unfair and deceptive practices, has taken a broader view: if a company promises privacy and then shares data in ways users did not expect, that is deceptive regardless of HIPAA applicability.
Misconfigurations and Unintended Leakage
Pixel tracking is not inherently illegal, but implementation details matter. A misconfigured pixel can send far more data than intended. In 2024, the US Postal Service was found to be sharing logged-in users' home addresses with Meta, LinkedIn, and Snap through pixel code embedded on its website. The agency removed the tracking after the issue was reported.
Similar leakage has been documented in hospital systems, pharmacy benefit managers, and health insurance portals. In many cases, the companies involved were unaware of the full scope of data being transmitted. Pixels are often deployed by marketing teams without full technical or legal review, and the data flows they enable can be opaque even to internal stakeholders.
For platforms handling prescription data, the stakes are higher. Information about medications for mental health conditions, sexual dysfunction, or weight loss carries stigma. If that data is used to build advertising profiles or shared with data brokers, it can have consequences beyond targeted ads, including employment discrimination, insurance underwriting, or social harm.
The Asia Angle
While this case is US-focused, the issues it raises are relevant across Asia, where telehealth adoption has accelerated rapidly. In markets like India, Indonesia, and the Philippines, direct-to-consumer health platforms are using similar growth playbooks: aggressive digital marketing, performance tracking, and reliance on Meta and Google as primary acquisition channels.
Regulatory frameworks vary widely. India's Digital Personal Data Protection Act, which came into force in 2023, includes provisions for sensitive personal data but enforcement is still ramping up. Singapore's Personal Data Protection Act requires consent for collection and use of personal data, but pixel-based tracking often falls into a gray area. In China, where data localization and cybersecurity laws are strict, foreign ad platforms have limited reach, but domestic equivalents like ByteDance and Tencent operate extensive tracking infrastructure.
The regulatory arbitrage is real. A telehealth company operating in Southeast Asia can deploy the same ad-tech stack used in the US or Europe, but face far less scrutiny, at least for now. As these markets mature and regulators gain capacity, expect similar enforcement actions.
What Comes Next
The Hims & Hers case will likely take months or years to resolve. If the FTC prevails, the company could face civil penalties, injunctive relief requiring changes to its data practices, and reputational damage. If Hims & Hers successfully defends its position, it may embolden other telehealth platforms to maintain aggressive tracking practices.
For the broader industry, the message is clear: pixel-based tracking in healthcare is under regulatory scrutiny, and the cost of getting it wrong is rising. Companies that want to use ad-tech tools while handling sensitive health data need to invest in legal review, technical controls to limit data sharing, and transparent user consent flows.
The alternative is to join the growing list of healthcare companies that learned those lessons the hard way, in federal court.


