Privacy Policies and Practices: Hims & Hers Enforcement

Most people are familiar with the idea of a privacy policy – the long document we often agree to when signing up for a service or purchasing goods. But what does a privacy policy actually do? In short, it outlines how a business collects, uses and shares personal information. The contents of a privacy policy may depend on the size and function of the business, the sector in which the business operates, and the jurisdictions in which the business is located or does business. 

Drafting and publishing the policy is only part of the job though. Businesses also need to also confirm that their actual practices, including the technology operating behind their website, match the promises that they make to their consumers in these policies.

The Federal Trade Commission (FTC) has long warned businesses that if they make privacy representations, they must honor them. The FTC specifically advises companies to review their privacy policies and ensure that their actual practices are consistent with those representations. As the recent FTC  lawsuit against Hims & Hers demonstrates, it is imperative that consumers are adequately informed about business practices in a clear and conspicuous manner. 

What are the risks of misalignment between business practices and consumer representations? 

In the United States, the FTC has the power to enforce the terms of privacy practices via the authority in Section 5 of the FTC Act, which prohibits unfair or deceptive advertising practices. The Commission’s landmark 1999 consent order with the web host GeoCities was the FTC’s first public settlement in the area of internet privacy, and as of 2023, the FTC has brought at least 97 internet privacy cases. 

Most recently, in July 2026, the FTC was joined by California and Utah authorities in a lawsuit against the telehealth company Hims & Hers for deceptive and unlawful privacy practices. This lawsuit alleged that the company shared customers’ sensitive health data, including medical conditions, with advertising platforms, despite implying that they keep health information private on their privacy policy. 

According to the FTC, some information was shared to third-party advertising platforms through customer lists, while other information was transmitted through third-party tracking technologies; the consumers’ health information was allegedly shared with Meta, Snap and other third parties. In its complaint, the FTC states that Hims & Hers also fails to disclose its billing practices adequately and makes it difficult for consumers to cancel their subscriptions. Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection claims this creates a scenario where “consumers [are] unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers’ most private health information without their consent.” 

This case remains pending and the allegations have not been adjudicated. Still, the lesson here is clear: a business’s sharing and selling practices must be accurately disclosed to the consumer via their privacy policy. 

This does not mean that businesses need to abandon tracking, analytics, or subscription services. Rather, this case – and many of the other enforcement actions highlighted by the FTC – emphasize an organization’s need to understand what these technologies do before describing their privacy practices to consumers and ensure that privacy policies accurately disclose these practices. 

Key Takeaways: 

Privacy policies should accurately disclose the business’s privacy practices to the consumer in a clear and conspicuous way. By reviewing both their privacy representations and the technologies behind them, an organization can take steps to ensure their privacy practices are accurate and up to date. Some of these compliance review measures may include: 

  • Inventorying pixels, cookies, analytical tools, chat-bot features, and other third-party technologies. 
  • Identifying what personal information each tool may collect or transmit, and who receives it. 
  • Paying particular attention to sensitive information and data entered into forms, portals and chat features. 
  • Reviewing vendor configurations and contractual terms governing data use.
  • Comparing actual data flows against the company’s privacy policy and other consumer-facing statements.
  • Requiring reviews before changing internal business practices that impact personal privacy.

Drafting and publishing a privacy policy may be required under certain state laws. However, this policy – like most privacy and compliance efforts – should not be treated as a one-time task. Websites, vendors and business practices change, and privacy policies should stay in alignment with these changing practices.  

social network patents

Facebook, Patents, and Privacy: Social Media Innovations to Mine Personal Data

Social Media Patents & Privacy Data

[©2016. Published in GPSOLO, Vol. 37, No. 5, September/October 2020, by the American Bar Association. Reproduced with permission. All rights reserved. This information or any portion thereof may not be copied or disseminated in any form or by any means or stored in an electronic database or retrieval system without the express written consent of the American Bar Association or the copyright holder]

* Updated November 25 to include references to CPRA/ Prop24.

The episode “Nosedive” of the television series Black Mirror envisions a society built on social credit scores. In this dystopia, all social media networks have converged into one platform—think Facebook, TikTok, Yelp, and Equifax combined.

This umbrella social platform allows users to rate each other on a five-point scale after each social interaction. Those with a high score gain access to job opportunities, favorable zip codes, and even high-status relationships. Those with a low score have the social ladder kicked out from under them, leading to a downward cycle of estrangement—and in the case of Black Mirror’s protagonist, jail time.

While the society in “Nosedive” seems far-fetched, is the technology behind it plausible?

Facebook Patents That Impact Privacy

According to Facebook’s patents, the answer is a resounding “yes.”

In a series of filings spanning almost a decade, Facebook has obtained several patents that allow social media platforms to track, identify, and classify individuals in new and innovative ways. Below are just few.

Tracking individuals via dust. U.S. Patent No. 9485423B2, “associating cameras with users and objects in a social networking system” (filed September 16, 2010, patented June 25, 2013), allows social media networks to identify an individual’s friends and relationships by correlating users across the same camera. To do so, an algorithm analyzes the metadata of a photo to find a camera’s “signature.”

Read More
Gold gavel on platform

Searching for the One Ring to Rule Them All: A Look at 8 U.S. Federal Privacy Bills

Image Credit: 3D Animation Production Company from Pixabay

This article is Part 1 of 2 in a series exploring proposed federal privacy laws in the United States. Part 2 will discuss the constitutional challenges facing not only a proposed federal privacy law but those facing existing state privacy laws as well.

As predicted in our Privacy Law Forecast for 2019, legislators have raced to introduce national privacy regulation in both the House and Senate this year.

In contrast to the European Union’s GDPR, a hodgepodge of sectoral laws govern privacy in specific industries: medical, financial, educational, and marketing sectors, among others. States have enacted laws to protect their residents. And on top of that, Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45) grants authority to the FTC to enforce against unfair and deceptive acts and practices.

This all results in a confusing and burdensome “patchwork” of national, state and sectoral rules. (For more in-depth discussion on the current U.S. privacy regulatory landscape, please see American Privacy Laws in a Global Context.)

Given this regulatory environment, legislators are keen to put forth a single federal privacy law to standardize this “patchwork” and forestall the passage of dozens more state privacy bills. Some have set a deadline, hoping to pass a federal privacy law before the CCPA comes into effect on January 1, 2020. Since the start of 2019, lawmakers have introduced about 230 bills that regulate privacy in some way in either the House or Senate.

The following is a sample of comprehensive bills from both sides of the aisle. Though these bills are unlikely to pass committee, they indicate what policies lawmakers are considering in the current negotiations:

Read More
Pole with sign saying "future".

Privacy Law Forecast for 2019

Image Credit: ID 23689850 © Steve Ball | Dreamstime.com

This past year was quite a whirlwind for privacy and cybersecurity watchers. Just to sum up a few of the top events of last year:

  • Facebook’s Cambridge Analytica scandal rocked political headlines
  • Europe introduced the GDPR, the most comprehensive data protection legislation to date in the world
  • California enacted the California Consumer Privacy Act, becoming the first US state to create GDPR-style rules
  • Google came under fire for allowing app developers to read your email, and track your location (even with location tracking off!)
  • Marriott’s guest reservation system was hacked, exposing the personal information of up to 500 million guests, including passport numbers and payment numbers for some of those hacked

What will happen in 2019? Here are our top 5 predictions:

Read More