
An odor of mendacity: FTC calls out telehealth provider for unlawful privacy practices
The FTC, California and Utah sued Hims & Hers, alleging the telehealth company misled consumers on privacy and subscriptions.
For those Tennessee Williams fans, the word “mendacity” may evoke Big Daddy’s monologue in Cat on a Hot Tin Roof. “What’s that smell in this room? Didn’t you notice a powerful and obnoxious odor of mendacity in this room?” So, too, is the stench of a palpable false statement about protecting individuals’ sensitive health information when, in fact, it is being shared with third-party advertising platforms despite promising patient privacy.
On
The
- Violations of Section 5(a) of the FTC Act; and
- Violations of Section 4 of the Restore Online Shoppers’ Confidence Act, 15 U.S.C. § 8403.
The opening facts of the case are shocking. Specifically paragraph 4, states:
Hims is an online telehealth company that has misled hundreds of thousands of consumers by charging them for unwanted prescription medication subscriptions without their express informed consent. Hims’ advertising and online medical intake forms mislead consumers into believing that, when submitting their intake form for review by a medical provider, they are not obligated to purchase or subscribe to the provider’s recommended treatment. Hims’ advertising and medical intake forms also misrepresent that consumers can consult with Hims’ medical providers about their treatment recommendations free of charge in order to determine whether a treatment is “right” for them.
Not surprisingly, injunctive relief, as well as monetary relief and civil penalties, are being sought.
Some of you may be wondering why the FTC did not utilize its Breach Notification Rule. The answer is simple: while the FTC has jurisdiction over consumer rights and issues, the enforcement of HIPAA, which is relevant here because of actual medical care being rendered and not just a commercial app used for tracking basic health metrics like heart rate, is within the purview of the U.S. Department of Health and Human Services – Office for Civil Rights (HHS-OCR) and the FTC’s Breach Notification Rule applies to vendors of personal health records. By way of contrast, HHS-OCR and HIPAA apply to patients, as well as covered entities and business associates. Hence underscoring that it is possible for an entity to face an FTC action without implicating its
This case is one to watch for a variety of reasons, including potential enforcement action from various government entities, as well as anticipating a class action. It also underscores that a trusted provider is essential, and likely that means having an appropriate medical professional available in-person and via telehealth, to address sensitive medical issues.






