Blog

FTC and States Sue Hims & Hers Over Health-Data Sharing; Vermont Releases Draft Age-Appropriate Design Code Rules

Julie Rubash, General Counsel and Chief Privacy Officer
August 4, 2026

Do you want to receive these privacy recaps in your inbox each week? Subscribe here or follow us on LinkedIn.

The FTC, joined by California and Utah, sued Hims & Hers over allegations it shared consumers’ sensitive health information with advertising platforms without adequate disclosure or consent. Meanwhile, the Vermont Attorney General released draft implementing rules for the state’s Age-Appropriate Design Code Act, taking a privacy-first approach to age assurance. 

Keep reading to discover my analysis and takeaways.

United States

FTC and States Sue Hims & Hers Over Allegedly Deceptive Health-Data Sharing

The FTC announced that it, together with Utah and California, sued Hims & Hers over allegations that the telehealth company shared consumers’ sensitive health information concerning medical conditions with third-party advertising platforms without adequately disclosing the practice or obtaining consumers’ consent. 

This occurred despite Hims & Hers representing that medical information would be accessed only by medical providers and describing its services as private or discreet. The complaint also contains separate allegations concerning Hims’s subscription billing and cancellation practices.

Takeaway

Looking purely at the privacy aspects, the complaint mostly applies the FTC’s established health-data enforcement playbook, previously reflected in actions against Flo, BetterHelp, GoodRx, Premom, Monument, Cerebral, and others. 

Many of those cases involved transmitting identifiable health information to advertising or analytics platforms through pixels, SDKs, APIs, customer-list uploads, or other audience tools for advertising, attribution, or audience development, without adequate notice or meaningful consent and, frequently, contrary to privacy promises. The FTC has treated such practices as deceptive and, in some earlier cases, also as unfair or as violations of the Health Breach Notification Rule. What may make Hims more consequential is its enforcement structure and litigated posture. 

Unlike the earlier matters that were introduced with proposed settlements or resolved through FTC administrative consent orders or stipulated federal-court orders, Hims is currently facing a contested federal lawsuit brought jointly with state enforcers. California alleges that the disclosures support false-advertising and unfair-competition claims, including theories based on California common-law and constitutional privacy protections. Utah alleges deceptive practices, including failure to disclose the sharing and failure to provide a clear and conspicuous opportunity to opt out. Those state claims create additional potential avenues for civil penalties and monetary relief beyond an FTC Section 5 deception claim standing alone. 

The complaint also alleges that Hims’s sharing of sensitive health information with advertising platforms was a material term of its negative-option transaction that Hims failed to disclose clearly and conspicuously before obtaining consumers’ billing information. This reinforces the FTC’s position that material privacy practices may need to be surfaced within a subscription-enrollment flow, rather than disclosed only in a privacy policy. 

If the case proceeds to a substantive ruling, it could answer questions that earlier consent resolutions did not definitively resolve, such as whether generalized representations that a service is “private” or “discreet” imply that health information will not be disclosed to advertising platforms. For now, however, these remain unproven allegations, and the case could still settle without producing judicial precedent. 

In the meantime, the complaint reminds companies to review advertising and influencer content for implied privacy promises; inventory customer-list uploads, pixels, APIs, and server-side advertising integrations; and determine whether those technologies allow an advertising platform to associate an identifiable consumer with a health condition, treatment, or use of a health service without adequate notice and meaningful consumer choice.

United States

Vermont AG Releases Draft Age-Appropriate Design Code Rules

Pursuant to the Vermont Age-Appropriate Design Code Act, scheduled to take effect January 1, 2027, the Vermont Attorney General has released draft implementing rules for public comment addressing the law’s design-practice and age-assurance requirements. The draft rules are likewise scheduled to take effect on January 1, 2027, if adopted.

Takeaway

One notable aspect of the draft rules is their privacy-first (as opposed to accuracy-first) approach to age assurance. The draft generally favors lower-intrusion methods, such as self-declaration and signals already available to the business, and allows more intrusive methods involving identity credentials or biometric information only when circumstances justify them and less intrusive alternatives are inadequate. 

That emphasis differs from several other emerging approaches. The FTC’s February 2026 COPPA enforcement-policy statement permits general- and mixed-audience operators to collect personal information for the limited purpose of determining a user’s age without first obtaining parental consent, provided they satisfy safeguards that include taking reasonable steps to ensure the method is likely to produce reasonably accurate results. The statement expressly encourages more robust methods than simple self-declaration, while also requiring purpose limitation, prompt deletion, security, transparency, and controls on service providers. Utah’s Minor Protection in Social Media Act (currently subject to preliminary injunction) goes further on accuracy, defining an age-assurance system for covered social-media companies as one capable of determining whether a Utah account holder is a minor with an accuracy rate of at least 95%. California’s Age-Appropriate Design Code (also subject to ongoing litigation) similarly calls for age estimation with a “reasonable level of certainty appropriate to the risks,” although the law does not prescribe a particular technology or categorically exclude self-declaration. 

The European Commission has meanwhile developed a privacy-preserving age-verification app based on the technical specifications used for the European Digital Identity Wallet. Its model is intended to let users prove that they exceed an age threshold without disclosing their exact age or identity and without enabling services to track the content they access. That approach does not map neatly onto Vermont’s apparent hierarchy because a credential-based method can be technically sophisticated and highly reliable while still minimizing the information disclosed to the relying service. 

Practically, the differing approaches may make a single, uniform age-assurance implementation difficult. A method designed to satisfy a demanding accuracy threshold may require greater collection or processing and therefore require additional justification under Vermont’s privacy-first framework. 

Conversely, reliance on self-declaration or existing signals may not provide sufficient confidence for higher-risk uses or jurisdictions imposing express accuracy requirements. Businesses may therefore need a modular system that adjusts the method, confidence threshold, escalation process, and documentation according to the applicable jurisdiction and the risks presented by the service.

A Little More Privacy, if You Please

A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.

Latest Blog Posts

New Jersey Signs Surveillance Pricing Law as South Korea Fines Apple and TikTok for Lacking a Legal Basis to Process Data

July 28, 2026

New Jersey signs surveillance pricing law banning personal-data-based grocery...

Latest White Papers

Connecting Legal & Marketing Teams on Consent and Preferences

February 4, 2025

Break down data silos and unlock better collaboration. Marketing...

Navigating Sensitive Data in the U.S.

February 4, 2025

Download our comprehensive guide to learn how different states...

Enterprise Guide To Cookie management & Tracker List Curation

July 1, 2024

How to review the tracking tech on your websites...

Keep in touch

Sign up for our newsletter to keep up with privacy news for adtech and martech,
plus occasional company news.

Let's explore what we can do together.

We'll be in touch within 48 hours

    First name *

    Last name *

    Email address *

    Company *

    Message *

    * indicates required fields