On July 29, the Federal Trade Commission (FTC), joined by the California attorney general and the Utah Division of Consumer Protection, filed a complaint against the telehealth and wellness platform Hims & Hers Health, Inc., alleging deceptive privacy practices.
Among other allegations, the complaint asserts that Hims & Hers disclosed sensitive consumer health information to third-party advertising platforms despite representing that such information would remain private. If litigation proceeds, this will be an important test case for theories introduced by federal and state privacy enforcers in recent years.
As outlined below, this complaint reinforces several themes that gained prominence in FTC privacy enforcement actions during the Biden administration. These themes yield important compliance takeaways for digital health companies and other organizations that process consumer data relating to health.
FTC Health Data Enforcement Continues to Target Advertising Technologies
This action demonstrates that the current FTC remains focused on scrutinizing the use of third-party online tracking technologies in connection with health data. The complaint reflects the FTC's ongoing view that health information is sensitive data that warrants heightened protections, even when such data falls outside sectoral health privacy laws like the Health Insurance Portability and Accountability Act.
This view aligns with state consumer privacy and health data privacy laws that require additional compliance measures for sensitive data processing, although the state enforcers relied on other consumer protection statutes in their claims against Hims & Hers. Notably, the FTC did not rely on the Health Breach Notification Rule in the complaint, in contrast to enforcement under the Biden administration involving similar practices.
FTC Deception Scrutiny Extends Beyond Privacy Policies
The complaint highlights that the FTC will evaluate companies' privacy representations holistically, rather than relying only on statements made in the privacy policy. In the deception claims brought under Section 5 of the FTC Act, the FTC pointed to statements made across the company's home page, online and offline advertisements, and paid influencer endorsements to allege that the company's data sharing with third-party advertising platforms contradicted its privacy representations that health data would be shared only with the consumers' medical providers and that the service was "private" and "secure."
State Privacy Claims Need Not Rely on Omnibus Privacy Laws
Both California and Utah have adopted omnibus consumer privacy laws that contain specific protections relating to sensitive personal data. The states are not, however, relying on these laws in bringing privacy claims against Hims & Hers. Instead, the states each brought claims under their unfair or deceptive acts or practices laws, asserting that the company's representations or omissions were material to consumers. California additionally alleges that the company's conduct violates the state constitution because the information disclosed was "highly sensitive and personal" and Hims & Hers "lacked consent or authorization" to disclose the data to advertisers.
This complaint serves as a reminder that the privacy principles that predated omnibus statutes remain in force and present ongoing compliance risks. Continuing to follow these bedrock principles remains essential for avoiding enforcement crosshairs.
Privacy Compliance Takeaways for Digital Health Companies
Sensitive data governance continues to be a crucial component of privacy compliance plans. In light of this enforcement action and the state privacy landscape more generally, digital health companies and other organizations handling consumer health data should:
- Assess third-party data sharing. Determine whether health data may be shared with analytics or advertising vendors through pixels, SDKs, APIs, or other tracking technologies
- Audit privacy disclosures and choices. Confirm that privacy representations accurately describe third-party sharing practices and clearly identify relevant consumer choices across the entire user experience, including marketing materials, influencer statements, and product interfaces
- Align advertising practices with applicable state privacy requirements. Although not a focus of this action, to reduce enforcement risk, ensure that any choices related to advertising are conspicuously disclosed and otherwise meet state privacy requirements where applicable. Additionally, assess and meet any obligations under state law relating to sensitive data
If you have questions about privacy enforcement trends, data governance, privacy disclosures, or related developments, please reach out to Venable's Privacy and Data Security Group for assistance.