FTC Lawsuit Signals Regulatory Linkage of Privacy and Consumer Protection

Federal and state regulators are expanding their scrutiny of digital business practices by treating privacy violations and deceptive consumer practices as part of the same enforcement framework. The trend that could have implications for companies handling sensitive personal data well beyond the healthcare sector.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The shift is illustrated by a recent enforcement action brought jointly by the Federal Trade Commission (FTC), California and Utah against telehealth provider Hims & Hers. According to a client alert from Lowenstein Sandler, the complaint combines allegations involving deceptive recurring billing practices with claims that the company improperly shared consumers’ sensitive health information with advertising platforms.

    The lawsuit reflects an evolving enforcement strategy in which regulators evaluate a company’s entire customer experience, from advertising and consent mechanisms to subscription billing, cancellation procedures and downstream data sharing, rather than treating privacy and consumer protection issues as separate compliance matters.

    For businesses, particularly those deploying artificial intelligence (AI) and data-driven personalization tools, the case serves as another reminder that compliance programs can no longer address privacy, marketing and subscription practices in isolation.

    One of the most significant aspects of the case is regulators’ continued emphasis on an expansive interpretation of what constitutes protected health information. While many organizations focus primarily on compliance with HIPAA, the FTC has repeatedly maintained that companies outside the traditional healthcare system may still violate Section 5 of the FTC Act if they collect, use or disclose information that reveals or permits reasonable inferences about an individual’s health.

    That position extends well beyond medical records. Information such as website browsing activity, purchases, location data or interactions with digital health services may all contribute to sensitive health profiles that regulators say warrant heightened protections.

    According to the Lowenstein alert, the complaint alleged that Hims & Hers shared consumers’ health-related information with online advertising platforms while also engaging in deceptive subscription practices. The regulators further alleged that some consumers were enrolled in recurring payment plans or charged before receiving promised consultations with healthcare providers, while cancellation procedures were made unnecessarily difficult.

    Rather than pursuing standalone privacy cases, per Lowenstein, regulators are combining allegations involving unauthorized data sharing, misleading disclosures, dark patterns and deceptive recurring billing into comprehensive consumer protection actions.

    The joint participation of California and Utah also points to the growing coordination between federal and state regulators.

    California has established itself as one of the nation’s most aggressive privacy regulators through the California Consumer Privacy Act and the California Privacy Protection Agency. Utah, while generally viewed as maintaining a more business-friendly regulatory environment, has also become active in digital consumer protection and privacy enforcement.

    Their collaboration with the FTC demonstrates that bipartisan cooperation on privacy and consumer protection continues even as broader political debates over artificial intelligence and technology regulation remain unsettled.

    For financial institutions, FinTech companies and other businesses outside the healthcare industry, the case offers lessons that extend beyond telehealth.

    Many organizations collect information that can reveal sensitive health conditions indirectly, including pharmacy purchases, insurance transactions, wearable device integrations, financial wellness applications or location data associated with medical facilities. Companies deploying AI systems to analyze customer behavior may generate additional health-related inferences without intending to collect traditional medical information.

    As a result, organizations should carefully evaluate whether their data governance practices, consumer disclosures and advertising relationships accurately reflect how sensitive information is collected, analyzed and shared.

    The lawsuit signals that regulators view privacy, data governance, billing practices and digital user experience as components of a single consumer protection framework. For companies operating in data-intensive industries, particularly those relying on AI-driven personalization or behavioral analytics, that integrated approach is likely to shape enforcement priorities well beyond the healthcare sector.