The FTC read the whole website, not just the privacy policy
The FTC's Hims and Hers complaint builds its deception case from homepage copy, ads, and influencer posts, which changes what a wellness brand has to audit.
On July 29 the FTC, joined by the California Attorney General and the Utah Division of Consumer Protection, sued Hims and Hers over its handling of consumer health data. The core allegation is familiar: sensitive health information flowed to third-party advertising platforms while the company told users it would stay private. What makes the complaint worth reading is where the FTC found the promises it says were broken.
They did not come primarily from the privacy policy. The FTC’s Section 5 deception theory is built out of homepage copy, online and offline advertising, and paid influencer endorsements, alongside the policy language. The words “private” and “secure” on a landing page were treated as representations to consumers. So were statements that health information would be shared only with a user’s medical provider. If your compliance review consists of a lawyer reading the privacy policy once a year, you are auditing a small fraction of what an enforcer will read.
That has a practical consequence for how a wellness brand is organized. Marketing writes homepage copy. An agency writes ad creative. Influencers write their own captions under a brief they were given. Engineering decides which pixels and SDKs load on which pages. Nobody in that chain is checking their output against anybody else’s, and the privacy policy is usually the only document that ever gets legal review. The gap the FTC is pointing at is not really a legal gap. It is an operational one, and it exists because the promise and the data flow are made by different teams that do not talk.
Two other features of the complaint matter. First, the FTC did not use the Health Breach Notification Rule here, even though prior actions on similar facts did. It went with plain Section 5 deception instead. Second, California and Utah both have omnibus privacy statutes with sensitive-data provisions, and both declined to use them, bringing UDAP claims instead. California also invoked its state constitutional privacy right. The signal is that you do not get safe by mapping your obligations to whichever statute seems to govern health data. The older and broader theory, that you must do what you said you would do, applies regardless of whether HIPAA or a state privacy law reaches you.
The concrete thing to do this quarter is a claims-to-flows reconciliation, and it takes two lists. On one side, every privacy or security representation your company currently makes anywhere a consumer can see it: homepage, pricing page, ad copy, app store listing, onboarding screens, and the influencer briefs you have sent out in the last year. On the other side, an actual inventory of the pixels, SDKs, and server-side integrations firing on pages where a user discloses a health condition, selects a treatment, or completes an intake form. Have engineering produce the second list from the code, not from memory. Then read them side by side. Where a line on the left is contradicted by a line on the right, you either change the copy or kill the tag, and it is usually cheaper to kill the tag.