READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FTC Sues Hims & Hers Over Data Sharing and Auto-Billed Prescriptions

FTC Sues Hims & Hers Over Data Sharing and Auto-Billed Prescriptions
The FTC filed a lawsuit this week accusing Hims & Hers of sharing customer health data with Meta and Google while marketing itself as 100% private, and of auto-enrolling patients in recurring prescriptions they barely got to review. Hims says the suit is a headline grab. Either way, the case exposes a real gap: HIPAA doesn't cover most telehealth apps, and nobody in Washington has fixed that yet.

The Federal Trade Commission sued Hims & Hers on Wednesday, September 16, 2026, accusing the telehealth company of running a business built on deception. According to the FTC's complaint, Hims marketed itself as a "100% online, private and secure" platform while sharing customers' sensitive health data with Meta and Google without proper consent.

The FTC also alleges Hims automatically enrolled customers in recurring prescriptions and billed them with, in the agency's words, "virtually no opportunity to review the provider's recommended treatment." The company allegedly decided what drugs customers keep taking and charged their card without giving them a real say.

Hims isn't rolling over. The company disputed the government's claims outright, calling the lawsuit "an effort to generate headlines at our expense," according to the Associated Press. No trial date or settlement has been reported, so the allegations remain just that: allegations, unproven in court.

This isn't Hims's problem alone

The FTC has gone after telehealth companies before. In recent years, the agency filed similar cases against online therapy provider BetterHelp and pharmacy discount service GoodRx, both accused of sharing user health data with Meta and Google without permission, per the Associated Press.

That's three companies now, all built on the same pandemic-era pitch: skip the waiting room, get your prescription in minutes. Since COVID-19, dozens of these services have launched for ADHD meds, sexual dysfunction drugs, anxiety treatment and weight-loss injections.

The real gap: nobody covers this data

Most Americans assume HIPAA, the federal medical privacy law, protects any health information they hand over online. It doesn't.

HIPAA applies to doctors' offices, hospitals and insurers. It generally does not apply to telehealth apps selling prescriptions, DNA tests or online counseling, according to the Associated Press. Andrew Crawford, an attorney with the Center for Democracy and Technology, put it bluntly: "There's an entire universe of companies collecting huge amounts of consumer health data every day that aren't covered by our current health sector-specific laws."

Lawmakers wrote HIPAA for a healthcare system that didn't include apps texting you a weight-loss prescription after a five-minute questionnaire. Nobody's updated the law to catch up.

The 'quick consult' problem is industry-wide

A study led by Dr. Reshma Ramachandran of Yale University looked at nearly 50 telehealth companies selling GLP-1 weight-loss drugs, the same class as Ozempic and Wegovy. Less than a third required any real-time video or audio consultation with a physician. In some cases, prescriptions got approved within minutes.

"What we saw overwhelmingly was that it was incredibly easy to get access to the GLP-1s," Ramachandran said, according to the Associated Press. "Most of the time, the prescription was automatically sent, without even an opportunity to stop the dispensing." These are injectable drugs that typically call for a physical exam first. Skipping that is a shortcut around basic medical caution, not a convenience feature.

The fair counterargument

Telehealth defenders have a real point here, one that shouldn't get buried under the scandal headlines. For millions of Americans, especially in rural areas or without easy access to a specialist, an app that gets you a prescription in ten minutes beats waiting three weeks for an appointment that requires driving an hour each way. Convenience isn't automatically fraud. Speed isn't automatically deception.

The problem the FTC is pointing to isn't that these companies are fast. It's that customers allegedly weren't told the truth about where their data was going, and weren't given a real chance to say no to auto-renewing prescriptions. Those are two different things, and only one of them is actually illegal if proven.

What's next

The FTC's case against Hims & Hers is now working through the legal process, with no resolution reported yet. Hims maintains the suit has no merit. Meanwhile, Congress still hasn't closed the HIPAA gap that lets companies like Hims, BetterHelp and GoodRx collect and share health data with tech giants under laws written for a different era of medicine. Until that changes, the advice from privacy experts is the same one you'd give a teenager: assume anything you type into a health app questionnaire could end up somewhere you didn't expect.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
U.S. News & World ReportTelehealth Companies Keep Exposing Their Customers' Medical Data. What Should They Do?
center
KIRO 7Telehealth companies keep exposing their customers' medical data. What should they do?
right
NY PostTelehealth services increased since COVID-19 — but have been accused of deceptive practices
unknown
Ground NewsTelehealth Companies Keep Exposing Their Customers' Medical Data. What Should They Do?
unknown
Head TopicsTelehealth services increased since COVID-19 — but have been accused of deceptive practices
unknown
WBOCTelehealth companies keep exposing their customers' medical data. What should they do?
unknown
Bangor Daily NewsTelehealth companies keep exposing their customers' medical data. What should they do?