FTC Sues Telehealth Giant Hims & Hers Over Deceptive Practices
Regulators accuse the online health service of mishandling customer data and employing misleading subscription models.
The Federal Trade Commission (FTC) has filed a lawsuit against telehealth provider Hims & Hers, alleging deceptive business practices, including the improper sharing of customer health data and the use of hard-to-cancel subscriptions. This action highlights growing scrutiny of the telehealth industry, which saw a significant expansion during the COVID-19 pandemic.
The FTC's complaint accuses Hims & Hers of violating U.S. consumer protection laws by engaging in practices such as disclosing customer health data without consent, enrolling users in recurring subscriptions without clear review opportunities, and circumventing real-time doctor consultations. The company has disputed the government's claims, characterizing them as an attempt to generate publicity.
This is not an isolated case; the FTC has previously taken action against several other telehealth companies, including BetterHelp and GoodRx. In those instances, regulators alleged that the companies shared user health information with platforms like Meta and Google without explicit permission.
Experts point to a gap in federal law as a contributing factor to these issues. Unlike traditional healthcare providers, many telehealth companies are not covered by HIPAA, the primary federal law governing health information privacy. This leaves a broad category of companies collecting significant amounts of consumer health data without the same regulatory oversight.
"There’s an entire universe of companies collecting huge amounts of consumer health data every day that aren’t covered by our current health sector-specific laws," said Andrew Crawford, an attorney with the Center for Democracy and Technology.
Before signing up for telehealth services, consumers should be aware of potential practices. Many online health consultations begin with questionnaires, and a significant portion of these services may not involve a real-time video or audio consultation with a physician. For example, a review of nearly 50 telehealth companies offering GLP-1 drugs found that less than a third required such direct interaction, with some approvals occurring within minutes.
The FTC's lawsuit against Hims & Hers alleges that the company promoted itself as a private and secure platform for sharing information with medical professionals, yet, according to the complaint, it shared this data with Meta and other online platforms. This practice circumvents privacy expectations, as many consumers assume their health information is protected under HIPAA, a law that does not universally apply to all direct-to-consumer health services.
"There isn’t a clear federal law saying: ‘Don’t do this,’" said Justin Brookman, Consumer Reports’ director of technology policy. "There’s just a body of soft law and settled cases with the FTC that many companies probably aren’t even aware of."
While state laws in places like California and Connecticut have introduced specific protections for health information, enforcement against telehealth companies remains a challenge. The penalties available to regulators are often limited, with companies typically agreeing to cease the practices in question rather than facing significant fines.
Privacy advocates suggest that consumers use ad blockers and private browsing modes when accessing telehealth websites to limit tracking of personal information and online history. Additionally, carefully reviewing user agreements for policies on data usage, which may explicitly permit the sale of sensitive information, is advised. However, experts note that the responsibility often falls heavily on consumers to navigate complex privacy policies, and even then, their control over their data can be limited.