FTC sues Hims & Hers over data breaches, deceptive telehealth practices
Federal regulators accuse telehealth companies of sharing patient data with Meta and Google, auto-enrolling users in subscriptions, and bypassing doctor consultations.
What to know
- The FTC sued Hims & Hers for disclosing customer health data to Meta and Google, auto-enrolling users in recurring subscriptions, and bypassing real-time doctor consultations—practices the agency alleges violate consumer protection laws.
- Telehealth companies operate in a regulatory blind spot: HIPAA privacy protections don't apply to most of them, allowing them to collect and share health data that would be illegal for traditional healthcare providers to handle the same way.
- Research shows less than one-third of GLP-1 telehealth providers require real-time consultation with doctors, and many prescriptions are approved in minutes without discussion of medical history or contraindications like eating disorders.
- The FTC has pursued similar enforcement actions against more than six other telehealth and online health companies, signaling broader regulatory pressure on the industry.
Federal Trade Commission (FTC) RegulatorHims & Hers Telehealth companyAndrew Crawford Attorney, Center for Democracy and TechnologyDr. Reshma Ramachandran Yale University researcher
How it unfolded 1 development · click the chart to see its coverage articlesposts
-
1
Hims & Hers disputes FTC allegations as 'effort to generate headlines'
Hims & Hers responded to the FTC lawsuit by rejecting the government's claims and characterizing the legal action as motivated by publicity rather than legitimate regulatory concerns.
“an effort to generate headlines at our expense…”
— Hims & Hers -
C
CDT’s Andy Crawford in AP: “There’s an entire universe of companies collecting huge amounts of consumer health data every day that aren’t covered by our current health sector-specific laws.”
1 more of the top 2 · 2 posts in this stretch
-
C
apnews.com/article/tele... companies keep exposing their customers' medical data. What should they do?
-
-
background
HIPAA doesn't cover most telehealth companies collecting patient data — Federal privacy laws governing health information generally do not apply to the telehealth industry, leaving a regulatory gap. Experts note that the FTC has filed similar cases against more than half a dozen telehealth companies, including BetterHelp and GoodRx, for sharing user health data with Meta and Google without permission.
-
background
Research finds most GLP-1 telehealth providers skip real-time consultations — An analysis of nearly 50 telehealth companies selling GLP-1 weight-loss drugs found less than one-third required real-time video or audio consultation with a physician. Many prescriptions were approved within minutes, and only half the websites asked about eating disorders, which the drugs can induce or worsen.
-
background
FTC alleges Hims & Hers engaged in data disclosure and deceptive practices — The Federal Trade Commission filed a lawsuit against telehealth pioneer Hims & Hers, accusing the company of deceptive and unethical business practices including disclosing customer health data, automatically enrolling users in subscriptions without clear opportunity to review treatment, and bypassing real-time doctor consultations.