Visualização de leitura

Hims & Hers sued over alleged health data privacy failures

The US Federal Trade Commission (FTC), together with Utah and California, has filed a lawsuit against telehealth provider Hims & Hers.

The FTC alleges that the company shared consumers’ sensitive health information with third‑party advertising platforms despite promising strong privacy protections.

Hims & Hers is a telehealth and digital health platform that connects users with licensed medical providers for online consultations, prescription medications, and personal care products.

The complaint also accuses Hims & Hers of deceptive billing and subscription practices that made it hard for users to avoid charges or cancel subscriptions.

According to the FTC’s complaint, filed in federal court in California, Hims & Hers:

  • Shared sensitive health data, including details about medical conditions, with ad platforms such as Meta and Snap despite privacy promises.
  • Charged before consultations. The company promised users they could consult a medical provider before being charged, but the FTC says many consumers were enrolled in recurring prescription subscriptions shortly after they submitted an intake form, often without first having a consultation.
  • Made cancellation difficult. Before 2023, cancellation reportedly required contacting customer service by phone, email, or chat. Even after an online cancellation option appeared, the FTC alleges the button was hidden behind multiple steps and confusing options.

From a cybersecurity and privacy research perspective, this isn’t just about a single telehealth brand. It highlights three broader trends we see repeatedly in consumer programs:

Privacy policies versus reality. A company can market itself as privacy‑focused while still integrating third‑party advertising and analytics software development kits (SDKs) that leak sensitive information. This becomes especially concerning when health‑related events are linked to user accounts or tracking cookies.

Friction as a feature. Hard‑to‑find cancellation flows and unclear billing practices are examples of “dark patterns” that nudge users into paying for services they might not have chosen given all relevant information.

Regulatory pressure is growing. Health‑related services are under increasing scrutiny, especially when they handle sensitive data and combine it with advertising platforms.

The court will ultimately decide whether Hims & Hers violated the law, but the FTC’s action sends a clear signal: regulators are paying close attention to how health‑related services collect, use, and share sensitive data.

For anyone who values online privacy, the Hims & Hers case is a reminder that “health tech” does not automatically mean “privacy first.”

How to stay safe

More often than not, the privacy loopholes are hidden in the privacy policy somewhere.

Pro tip: one thing AI is good at is reading between the lines. Ask an AI chatbot to summarize a privacy policy and identify when your information may be shared with third parties. AI makes it much easier to understand lengthy privacy policies without reading every word yourself. If companies fail to follow their own privacy policies, regulators and consumers can hold them accountable.

Other than that:

  • Don’t share sensitive information unless it’s genuinely needed to provide the service.
  • Use strong, unique passwords and multifactor authentication (MFA). Even if a company is compliant, breaches happen. Unique passwords and two‑factor authentication limit the damage if your account details are exposed.
  • Check your browser and app permissions. Disable unnecessary tracking features where possible, and consider privacy‑focused browser settings or extensions that limit third‑party cookies and trackers.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

Company bragged phone mics could listen to conversations. They couldn’t.

A media company and two of its marketing partners have been fined for selling a service which, they said, listened in to people’s conversations through their phones. Actually they did nothing of the sort.

Most people have worried at some point that their phone has been listening to them through the microphone. You know how it goes: One minute you’re speaking to your friend about how you’ve always wanted to go to Fiji, the next minute you’re seeing social media ads for vacations there. However, as yet there hasn’t been much real proof that this is actually happening.

But that didn’t stop Cox Media Group from claiming it could listen in. Between 2023 and 2024, the company publicly promoted a service called “Active Listening” or “Voice Data,” claiming it used AI-powered voice-processing technology to capture conversations from smartphones, along with smart TVs and other devices with embedded microphones. 

The company told potential advertising clients that the system provided a tool to target, retarget, and retain customers.

The scandal came to light when 404 Media published internal pitch decks from Cox that detailed the supposed “Active Listening” capabilities. After the revelations, Cox initially backpedaled and denied listening to conversations, but the marketing materials contradicted these denials. 

The FTC found that the “Active Listening” service was completely fabricated. The service did not listen to consumers’ conversations or use voice data at all, nor did it accurately place ads in customers’ desired geographic locations. Instead, Cox and its partners simply resold email lists obtained from other data brokers at a significant markup.

Worst of all, the companies also falsely claimed that consumers had opted into voice data collection when they had not.

The Federal Trade Commission (FTC) fined the companies a total of $930,000 for falsely claiming they could spy on consumers. Cox Media Group must pay $880,000, while MindSift and 1010 Digital Works will each pay $25,000. The settlement funds will be used to provide refunds to Cox Media Group customers who were deceived by these false claims.


Personal Data Remover

Are your details being used by cybercriminals? 


How to safekeep your personal data

In this case, the data that was being sold came from data brokers. Keeping your personal data away from them requires a combination of preventive measures and active removal efforts.

  • Minimize what you share on social media and elsewhere online. Data brokers use scraping tools to gather information from forum posts and public profiles so avoid sharing sensitive details like your birth date, home address, phone number, and financial information. 
  • Before signing up for online services, loyalty programs, or apps, carefully read privacy policies to understand how companies will collect, use, and share your data.
  • For active data removal, your options depend largely on where you live. It’s often best to leave that work to a specialized service you can trust.
  • Disable advertising IDs on your smartphones, tablets, and computers through your device settings where possible.
  • Use a VPN to hide your IP address and encrypt your browsing traffic, install ad and tracking blockers, and consider using more privacy-focused browsers.

Still wondering if your phone is listening to you?

We looked into this very topic on our Lock and Code podcast. Listen to it below, or search for it on your favorite podcast player.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC

Active Listening, FTC, FTC Ruling, AI-Powered Marketing, Ai-Powered

The pitch for "Active Listening," an AI-powered advertising service that listened to consumers' real-world conversations through their smartphones and smart speakers and delivered targeted ads to those people within precise geographic areas, with consumers consent, was extremely compelling, but until it wasn't really what it claimed.

The Federal Trade Commission will require Cox Media Group and two smaller marketing firms to pay a total of $930,000 to settle allegations they deceived customers by falsely claiming to offer an AI-powered service that could target localized ads based on conversations captured from consumers' smart devices and that consumers had opted into such targeting.

"Not only did the product these companies marketed not do what they claimed it did, but they also misled potential customers by claiming consumers had opted into this service when it's clear they did not," said Christopher Mufarrige, Director of the FTC's Bureau of Consumer Protection.

Every material element of that pitch was false.

Also read: FTC Probes AI Chatbots Designed as “Companions” for Children’s Safety

Was 'Active Listening' Actually Being Sold

The case centers on a marketing product introduced in 2023 that CMG sold to local businesses. Through presentations, website materials and sales pitches, the company promoted "Active Listening" as a way for advertisers to identify potential customers at the precise moment they were discussing products or services around smart devices.

According to the complaints, this service did not, in fact, listen in on consumers' conversations or use voice data at all and neither did the service accurately place ads in customers' desired locations. Instead, the service the companies provided consisted of reselling — at a significant markup — email lists obtained from other data brokers.

FTC investigators say the service was pitched as a breakthrough tool powered by "voice data" and AI. According to the government, CMG told clients its technology partner could aggregate and analyze voice data from smartphones, tablets and other devices to determine when consumers were in the market for particular products. When prospective clients pressed sales representatives on how exactly the technology worked, FTC filings say sales presentations became increasingly specific when potential customers questioned how the technology worked.

The Consent Fabrication

The fraudulent capability claim was compounded by a fraudulent consent claim. The companies told prospective clients that consumers had "opted in" to the Active Listening service. In fact, no consent was ever sought or obtained. The companies characterized routine click-through acceptance of app terms of service as affirmative opt-in consent to the collection of voice data — a characterization the FTC flatly rejected.

This consent fabrication mattered legally in both directions. It deceived the businesses buying the service into believing they were running a legally compliant targeted advertising campaign. And it obscured from consumers that their conversations were purportedly being harvested and monetized — which those consumers had never agreed to.

Also read: FTC Sues Adobe for ‘Trapping’ Users in Deceptive Subscription Practices

The FTC's Bluntest Finding

The most pointed element of the FTC's action is not the settlement amount. It is the Commission's explicit statement that the illegality ran deeper than the fraud itself.

The Commission noted that, had the service actually functioned as advertised, collecting voice data from consumers' homes without genuine consent would itself have violated Section 5 of the FTC Act. In other words, CMG and its partners were not just selling a fake product. They were selling a fake version of something that would have been illegal to sell as real.

Who Pays and Who Supplied the Deception

Under the proposed consent orders, CMG must pay $880,000, while MindSift and 1010 Digital Works will each pay $25,000. The funds will be used to provide redress to CMG customers harmed by the practices. MindSift and 1010 Digital Works also face a second count for providing CMG with the "means and instrumentalities" to deceive customers through misleading marketing materials and sales presentations.

The Active Listening enforcement action arrives at a moment when AI capability claims are proliferating faster than any regulator can evaluate them. Aattaching the phrase "AI-powered" to a product does not immunize that product from consumer protection law, and fabricating both technical capability and consumer consent simultaneously creates compounding liability — not just for the company selling the product but for the partners who built the sales materials that made the deception work.

❌