Hims & Hers · Hims & Hers Privacy Policy · View original document ↗

HIPAA Business Associate Status Disclosure

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Hims & Hers changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Hims & Hers recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Hims & Hers Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Hims & Hers is not a HIPAA covered entity, acknowledges it may in some cases function as a HIPAA business associate, and notes that HIPAA protections may not apply to user transactions depending on the specific service and entity involved.

This analysis describes what Hims & Hers's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that the full range of HIPAA protections does not apply to all user interactions with the Hims & Hers platform, and that the applicability of HIPAA depends on the specific transactional context, creating a variable protection landscape across the company's telehealth, pharmacy, and consumer wellness services.

Interpretive note: The specific transactions and service contexts in which Hims & Hers operates as a HIPAA business associate are not fully enumerated in the policy, and the practical scope of HIPAA protection for any given user interaction requires case-specific assessment.

Consumer impact (what this means for users)

The agreement states that HIPAA may not apply to transactions or communications with Hims & Hers, the Medical Groups, the Providers, the Labs, or the Pharmacies depending on context, and that information not qualifying as Protected Information under applicable law is governed by the Privacy Policy rather than HIPAA. The scope of HIPAA protection applicable to any specific user interaction depends on which entities and services are involved.

Cross-platform context

See how other platforms handle HIPAA Business Associate Status Disclosure and similar clauses.

Compare across platforms →

Monitoring

Hims & Hers has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Hims & Hers is not a 'covered entity' under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and its related regulations and amendments from time to time (collectively, 'HIPAA'). One or more of the Labs, Pharmacies or Medical Groups (as defined in our Terms and Conditions) may or may not be a 'covered entity' or 'business associate' under HIPAA, and Hims & Hers may in some cases be a 'business associate' of a Pharmacy or Medical Group. It is important to note that HIPAA does not necessarily apply to an entity or person simply because there is health information involved, and HIPAA may not apply to your transactions or communications with Hims & Hers, the Medical Groups, the Providers, the Labs, or the Pharmacies.

Excerpt from Hims & Hers's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly implicates HIPAA covered entity and business associate definitions enforced by HHS OCR. The company's characterization of its HIPAA status as variable depending on the transaction context reflects the complexity of the telehealth platform model, where the company provides management services to medical providers and pharmacies. State health information privacy laws in California (CMIA), Washington (My Health MY Data Act), and other states may provide protections for health information that apply independently of HIPAA covered entity status. 2. GOVERNANCE EXPOSURE: High. The variable HIPAA applicability disclosure creates compliance complexity because users may not be able to readily determine which of their interactions are subject to HIPAA protections and which are governed only by the company's privacy policy. This is operationally significant given the breadth of sensitive health data the policy authorizes the company to collect and use for advertising and other purposes outside of Protected Information classifications. 3. JURISDICTION FLAGS: States with independent consumer health data privacy statutes, including Washington, Nevada, Connecticut, and others, may impose HIPAA-equivalent or stricter protections on consumer health data regardless of the company's HIPAA covered entity status. California's Confidentiality of Medical Information Act may apply to health information collected in the context of medical consultations facilitated through the platform. The company's telehealth operations create heightened exposure under these state frameworks. 4. CONTRACT AND VENDOR IMPLICATIONS: Business associate agreements with the Medical Groups, Pharmacies, and Labs should be reviewed to confirm they are in place where required and that they accurately reflect the scope of PHI handled by Hims & Hers in its business associate capacity. The management services relationship described in the policy may affect the scope and terms of applicable business associate agreements. 5. COMPLIANCE CONSIDERATIONS: Legal teams should map which specific service transactions trigger HIPAA business associate obligations for Hims & Hers and confirm that business associate agreements are in place for those relationships; evaluate whether state health data statutes apply to health information collected through the platform that falls outside HIPAA Protected Information definitions; and assess whether user disclosures about the variable application of HIPAA are sufficiently clear and prominent for the user population served.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA business associate obligations and may evaluate whether Hims & Hers' business associate status is accurately characterized and whether required business associate agreements are in place
    File a complaint →
  • FTC
    The FTC has jurisdiction over health data privacy practices for entities not covered by HIPAA and may evaluate whether the company's health data practices constitute unfair or deceptive acts
    File a complaint →

Provision details

Document information
Document
Hims & Hers Privacy Policy
Entity
Hims & Hers
Document last updated
July 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015440
Document ID
CA-D-00907
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c988ded09cde26ad7361730320c4689ff467340d29b135981d8ab4d8be8c7714
Analysis generated
July 9, 2026 08:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Hims & Hers
Document: Hims & Hers Privacy Policy
Record ID: CA-P-015440
Captured: 2026-07-09 08:00:22 UTC
SHA-256: c988ded09cde26ad…
URL: https://conductatlas.com/platform/hims-hers/hims-hers-privacy-policy/provision/CA-P-015440/hipaa-business-associate-status-disclosure/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Hims & Hers's HIPAA Business Associate Status Disclosure clause do?

This provision establishes that the full range of HIPAA protections does not apply to all user interactions with the Hims & Hers platform, and that the applicability of HIPAA depends on the specific transactional context, creating a variable protection landscape across the company's telehealth, pharmacy, and consumer wellness services.

How does this clause affect you?

The agreement states that HIPAA may not apply to transactions or communications with Hims & Hers, the Medical Groups, the Providers, the Labs, or the Pharmacies depending on context, and that information not qualifying as Protected Information under applicable law is governed by the Privacy Policy rather than HIPAA. The scope of HIPAA protection applicable to any specific user interaction …

Is ConductAtlas affiliated with Hims & Hers?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Hims & Hers.