Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Hims & Hers is not a HIPAA covered entity, acknowledges it may in some cases function as a HIPAA business associate, and notes that HIPAA protections may not apply to user transactions depending on the specific service and entity involved.
This analysis describes what Hims & Hers's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that the full range of HIPAA protections does not apply to all user interactions with the Hims & Hers platform, and that the applicability of HIPAA depends on the specific transactional context, creating a variable protection landscape across the company's telehealth, pharmacy, and consumer wellness services.
Interpretive note: The specific transactions and service contexts in which Hims & Hers operates as a HIPAA business associate are not fully enumerated in the policy, and the practical scope of HIPAA protection for any given user interaction requires case-specific assessment.
The agreement states that HIPAA may not apply to transactions or communications with Hims & Hers, the Medical Groups, the Providers, the Labs, or the Pharmacies depending on context, and that information not qualifying as Protected Information under applicable law is governed by the Privacy Policy rather than HIPAA. The scope of HIPAA protection applicable to any specific user interaction depends on which entities and services are involved.
Cross-platform context
See how other platforms handle HIPAA Business Associate Status Disclosure and similar clauses.
Compare across platforms →Monitoring
Hims & Hers has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Hims & Hers is not a 'covered entity' under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and its related regulations and amendments from time to time (collectively, 'HIPAA'). One or more of the Labs, Pharmacies or Medical Groups (as defined in our Terms and Conditions) may or may not be a 'covered entity' or 'business associate' under HIPAA, and Hims & Hers may in some cases be a 'business associate' of a Pharmacy or Medical Group. It is important to note that HIPAA does not necessarily apply to an entity or person simply because there is health information involved, and HIPAA may not apply to your transactions or communications with Hims & Hers, the Medical Groups, the Providers, the Labs, or the Pharmacies.Excerpt from Hims & Hers's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly implicates HIPAA covered entity and business associate definitions enforced by HHS OCR. The company's characterization of its HIPAA status as variable depending on the transaction context reflects the complexity of the telehealth platform model, where the company provides management services to medical providers and pharmacies. State health information privacy laws in California (CMIA), Washington (My Health MY Data Act), and other states may provide protections for health information that apply independently of HIPAA covered entity status. 2. GOVERNANCE EXPOSURE: High. The variable HIPAA applicability disclosure creates compliance complexity because users may not be able to readily determine which of their interactions are subject to HIPAA protections and which are governed only by the company's privacy policy. This is operationally significant given the breadth of sensitive health data the policy authorizes the company to collect and use for advertising and other purposes outside of Protected Information classifications. 3. JURISDICTION FLAGS: States with independent consumer health data privacy statutes, including Washington, Nevada, Connecticut, and others, may impose HIPAA-equivalent or stricter protections on consumer health data regardless of the company's HIPAA covered entity status. California's Confidentiality of Medical Information Act may apply to health information collected in the context of medical consultations facilitated through the platform. The company's telehealth operations create heightened exposure under these state frameworks. 4. CONTRACT AND VENDOR IMPLICATIONS: Business associate agreements with the Medical Groups, Pharmacies, and Labs should be reviewed to confirm they are in place where required and that they accurately reflect the scope of PHI handled by Hims & Hers in its business associate capacity. The management services relationship described in the policy may affect the scope and terms of applicable business associate agreements. 5. COMPLIANCE CONSIDERATIONS: Legal teams should map which specific service transactions trigger HIPAA business associate obligations for Hims & Hers and confirm that business associate agreements are in place for those relationships; evaluate whether state health data statutes apply to health information collected through the platform that falls outside HIPAA Protected Information definitions; and assess whether user disclosures about the variable application of HIPAA are sufficiently clear and prominent for the user population served.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that the full range of HIPAA protections does not apply to all user interactions with the Hims & Hers platform, and that the applicability of HIPAA depends on the specific transactional context, creating a variable protection landscape across the company's telehealth, pharmacy, and consumer wellness services.
The agreement states that HIPAA may not apply to transactions or communications with Hims & Hers, the Medical Groups, the Providers, the Labs, or the Pharmacies depending on context, and that information not qualifying as Protected Information under applicable law is governed by the Privacy Policy rather than HIPAA. The scope of HIPAA protection applicable to any specific user interaction …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Hims & Hers.