When Marketing Technology Becomes a Privacy Incident: Lessons from the FTC’s Hims & Hers Lawsuit
Jump to Section
A privacy incident does not always start with ransomware, a stolen device, or a malicious insider. Sometimes it starts with a marketing pixel, analytics tag, or audience-matching tool doing exactly what it was configured to do.
That is the operational lesson privacy leaders should take from the FTC’s lawsuit against Hims & Hers. The FTC, joined by California and Utah, alleges that the telehealth provider disclosed consumers’ sensitive health information to advertising platforms, including Meta and Snap, despite privacy promises to consumers. The complaint also challenges the company’s subscription billing and cancellation practices. Hims & Hers disputes the allegations, and the claims have not been proven in court.
Regardless of the outcome, the case highlights a growing privacy risk: ordinary digital marketing activity can become a high-risk privacy event when sensitive data is transmitted to unauthorized recipients. Privacy teams need a repeatable way to detect these events, assess applicable obligations, coordinate stakeholders, and document defensible decisions.
Can a Marketing Pixel Cause a Privacy Incident?
Yes. A privacy incident can occur when sensitive personal information is disclosed to a third party without proper authorization, even without a cyberattack or system intrusion.
Many organizations still associate “breach” with an external threat actor. That view is too narrow for modern privacy operations. Tracking pixels, analytics tools, audience-matching services, and tag managers can transmit information about a person’s activity, interests, identifiers, or interactions with health-related services.
In the Hims & Hers complaint, the FTC alleges that the company shared health information via customer list uploads and tracking technologies on its digital properties. If substantiated, those allegations show how privacy risk can arise from normal business activity rather than a traditional security failure.
The key questions are not only whether the technology worked as intended. Privacy teams also need to understand what data was transmitted, what it revealed, who received it, whether the disclosure was authorized, and whether the organization’s public promises matched its actual data practices.
HIPAA Is Only One Part of the Privacy Analysis
Healthcare privacy discussions often begin with HIPAA. They should not end there.
Depending on the organization, the data, the systems, and the activity involved, a digital health incident may implicate the FTC Act, the Health Breach Notification Rule, state consumer health data laws, general state privacy laws, contractual obligations, and the organization’s own public privacy representations.
The FTC’s Health Breach Notification Rule recognizes that a breach can include an unauthorized disclosure, not only a cybersecurity intrusion. For certain vendors of personal health records and related organizations outside HIPAA, notice may be required to affected individuals, the FTC, and, in some cases, the media.
That creates an operational challenge. Privacy teams need a structured way to answer:
- What information was transmitted?
- Could the information identify or be linked to an individual?
- Did it reveal a health condition, treatment interest, medication, or healthcare interaction?
- Which third parties received it?
- Was the disclosure authorized?
- How many individuals and jurisdictions were involved?
- Which federal, state, contractual, and internal requirements apply?
- Are notifications, remediation, or corrective actions required?
Those decisions are difficult to manage through scattered emails, informal escalation, or a spreadsheet. They require a consistent incident response process that preserves facts, applies the right regulatory analysis, and documents the rationale behind each decision.
Privacy Incidents May Start Outside the Privacy Team
Advertising and analytics technologies are often implemented by marketing, product, engineering teams, or external agencies. Configuration changes can happen quickly, and the resulting data flows may not be visible to privacy teams until after sensitive information has already been transmitted.
That makes early detection and centralized intake essential.
Organizations should give employees across the business simple ways to report suspected privacy issues. A marketing manager who discovers that a campaign audience included patient data should know how to escalate it. An engineer who finds that page events contain sensitive parameters should not have to decide alone whether the issue is legally reportable.
Once reported, the event should enter a repeatable privacy incident management process that assigns ownership, preserves the facts, coordinates stakeholders, and immediately begins assessing risk.
Five Actions Privacy Leaders Should Take Now
The Hims & Hers lawsuit is an opportunity for organizations that handle health information or other highly sensitive personal data to assess their readiness.
1. Inventory Tracking and Audience Technologies
Identify the pixels, software development kits, analytics tools, session-replay technologies, tag managers, and audience-matching services deployed across websites and applications. Include technologies introduced through vendors and agencies.
2. Test Actual Data Flows
Documentation and vendor assurances are not substitutes for observing what a tool transmits. Test pages, forms, URLs, event names, custom parameters, identifiers, and customer-list uploads. Pay particular attention to authenticated areas and journeys that reveal health interests or treatment activity.
3. Establish Privacy-Specific Escalation Triggers
Create clear criteria for escalating suspected unauthorized disclosures. Sensitive data sent to an unapproved recipient, unexpected data appearing in an advertising platform, or tracking technology operating on a health-related page should trigger immediate review.
4. Assess Events Across Applicable Requirements
Do not assume an incident falls outside the organization’s obligations because HIPAA does not apply or because there was no hacker. Evaluate the event under all relevant federal, state, contractual, and internal requirements, including the organization’s representations to consumers.
5. Preserve a Defensible Record
Document what happened, what data was involved, who received it, the applicable legal analysis, mitigation steps, notification determinations, and the rationale behind every decision. Regulators may examine not only the outcome, but also how the organization reached it.
Turn Privacy Promises Into Operational Decisions
A privacy policy may promise that sensitive information will be protected. Privacy incident management is how an organization demonstrates that promise when something goes wrong.
A mature process connects intake, investigation, risk assessment, notification analysis, remediation, and audit-ready documentation. It gives privacy, legal, compliance, security, marketing, and product teams a shared workflow for identifying risks early and making consistent decisions.
The allegations against Hims & Hers reinforce a broader reality: personal data can be exposed through ordinary business operations, even when no system has been “breached” in the conventional sense.
Organizations that recognize these events early, assess them consistently, and document their decisions are better positioned to meet regulatory obligations and protect consumer trust.
RadarFirst helps organizations operationalize privacy incident management with structured intake, guided risk assessment, regulatory intelligence, notification analysis, and defensible documentation. Learn how RadarFirst supports consistent, audit-ready incident response.
Let’s Get Started
Trusted by leading organizations, RadarFirst enables teams to manage incidents with speed, consistency, and defensibility by standardizing how incidents are captured, assessed, and actioned.