- ✓The FTC sued Hims & Hers on July 29, alleging the company shared consumers' sensitive health information with third-party advertisers
- ✓The complaint also alleges deceptive billing and cancellation practices, but the data-sharing allegation is the one with direct relevance to image and marketing practices
- ✓Telehealth clinics that use patient photos in testimonials, before/after galleries, or ad campaigns face a version of the same exposure if consent and data-handling aren't airtight
- ✓The fix isn't avoiding patient imagery in marketing entirely — it's separating marketing consent from treatment consent and controlling exactly where those images travel

The FTC filed suit against Hims & Hers on July 29, alleging the telehealth company shared consumers' sensitive health information with third-party advertisers without adequate disclosure. The case is about data broadly, not photos specifically — but for any telehealth practice, dermatology clinic, or med spa running before/after photos or patient testimonials in marketing, it's a clear signal of where regulators are focused, and most clinics have gaps in exactly this area.
What the FTC Actually Alleged
The complaint centers on two things: sharing sensitive health information with advertisers in ways consumers weren't adequately informed about, and separate allegations around deceptive billing and cancellation practices. The billing side is its own story. The advertiser data-sharing side is the part worth every telehealth operator's attention, because it sits in exactly the gray area where marketing teams and clinical teams often aren't communicating clearly about what's permitted.
This isn't the FTC discovering a new category of harm. Health data shared with ad networks for targeting purposes has been on regulators' radar for several years, both from the FTC and through state-level health privacy laws that increasingly cover telehealth specifically. What makes the Hims & Hers case notable is the size and visibility of the company — a publicly traded, mainstream telehealth brand — which tends to accelerate broader industry attention and enforcement momentum well beyond the one company named in the complaint.
Where Photos Specifically Create Exposure
Health data sharing and patient photo marketing are different issues technically, but they share the same underlying failure mode: using something a patient gave for one purpose (their treatment, their care) for a second purpose (advertising, targeting, lead generation) without clear, separate consent for that second use.
Before/after photos are the clearest example in visual marketing. A patient who consents to their dermatologist taking clinical photos to track treatment progress has not automatically consented to those same photos appearing in a Instagram ad campaign or a website testimonial section. That gap — assuming clinical consent covers marketing use — is one of the most common compliance failures across telehealth, dermatology, and med spa marketing, and it's precisely the kind of blurred-purpose data use the FTC's complaint highlights at a larger scale.
Comparing Compliant and Risky Practice
| Practice | Compliance risk | Fix |
|---|---|---|
| Using clinical progress photos in ads without separate marketing consent | High | Get dedicated, written marketing-use consent per image |
| Uploading patient photos directly to ad platforms for creative testing | High | Route through internal review before any third-party upload |
| Storing marketing-consented photos in the same system as clinical records | Medium | Separate marketing asset storage from EHR/clinical systems |
| Leaving EXIF metadata (location, device, timestamp) embedded in shared images | Medium | Strip metadata before any external use |
| Stock or model photos used with a "results may vary" disclosure | Low | Standard, well-understood practice |
The pattern across every row: the risk drops sharply the moment marketing use is treated as a distinct, deliberately-consented activity rather than an assumed extension of treatment.
A Practical Compliance Sequence for Photo-Based Marketing
- Separate the consent forms entirely. Treatment consent and marketing-use consent should be two different documents, signed at different points, with marketing consent clearly optional and revocable.
- Specify the channels in the consent language. "May appear in advertising" is vague. "May appear in Instagram and Google ad campaigns, our website, and printed materials" is specific enough to hold up under scrutiny and clear enough for a patient to actually understand what they're agreeing to.
- Strip identifying metadata before the image leaves clinical systems. EXIF data can carry GPS coordinates, device identifiers, and timestamps that have nothing to do with the marketing use case and everything to do with unnecessary data exposure once that file reaches an ad platform or agency.
- Keep marketing-consented images in a separate system from clinical records. Mixing marketing assets into an EHR or clinical photo system increases the chance that a photo gets pulled into a data-sharing arrangement — like the kind alleged against Hims & Hers — that was never meant to include it.
- Revisit and re-confirm consent periodically, especially for testimonials and before/afters that stay in rotation for years. A patient's comfort with a photo circulating publicly can change well after the original consent was signed.

Why This Matters Beyond Avoiding a Lawsuit
Enforcement actions against high-visibility companies tend to shift what patients themselves expect and ask about. A telehealth or aesthetics practice that can clearly explain — in plain language, before a patient even asks — exactly how their photo will and won't be used is building the kind of trust that increasingly differentiates practices in a market where privacy has become a genuine competitive factor, not just a compliance checkbox.
Summary
- The FTC's July 29 suit against Hims & Hers centers partly on sharing sensitive health data with advertisers without adequate disclosure
- Treatment consent and marketing consent for patient photos are not the same thing, and conflating them is the most common compliance gap
- Strip metadata, separate storage systems, and specify exact channels in consent language
- Strip metadata from patient marketing photos free before they leave your clinical systems
Related reading:
- HIPAA Patient Photo Rights: The 2026 Rule — the broader regulatory landscape for patient imagery
- Telehealth Clinic Photo HIPAA Compliance in 2026 — clinical photo handling beyond marketing use
- What Is EXIF Metadata and Why Strip It — the technical background on hidden data in photo files
Frequently asked questions
What did the FTC allege against Hims & Hers?
The FTC's July 29 complaint alleges that Hims & Hers shared consumers' sensitive health information with third-party advertisers without adequate disclosure, alongside separate allegations of deceptive billing and cancellation practices. The case is ongoing.
Does a patient's consent to treatment also cover using their photo in marketing?
No, and this is one of the most common compliance gaps in telehealth and clinic marketing. Treatment consent covers care delivery. Using a patient's image, before/after photo, or testimonial in advertising requires separate, specific marketing consent that clearly states how and where the image will be used.
What's the safest way for a telehealth clinic to use before/after photos in ads?
Get written marketing-specific consent separate from treatment paperwork, strip identifying metadata and background details that could reveal location or other patients, store the marketing-consented originals separately from clinical records, and confirm with the patient exactly which channels the image will appear on before it's published anywhere.
Continue reading
Try Optimage — it's free
Compress, convert, and optimize images in seconds. No sign-up, no limits.
Start Optimizing Free