H A.I CyberSecurity Scoring
H
Company Information
Website:https://bit.ly/4blaSl2
Employees number:2,002
Number of followers:221,459
NAICS:71394
Industry Type:Wellness and Fitness Services
Homepage:bit.ly
H Risk Score (AI oriented)
Between 650 and 699
HWellness and Fitness Services
Updated:
30/07/2026
30/07/2026
659/1000
Weak
B
H Global Score (TPRM)
xxxx
HWellness and Fitness Services
Score locked

HWeak
Current Score
659B (WEAK)
01000
3 incidents
-57 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
662
JULY 2026
688
JUNE 2026
686
MAY 2026
680
APRIL 2026
679
MARCH 2026
784
FEBRUARY 2026
726
Breach
04 Feb 2026 • H
Third-party customer service platform and Hims & Hers: Hims & Hers Data Breach Exposes Customer Service Records
Hims & Hers Third-Party Data Breach Affecting Customer Support Tickets
669
CRITICAL-57
HIMCRI1775162652
Hims & Hers Discloses Third-Party Data Breach Affecting Customer Support Tickets
Hims & Hers, a U.S.-based telehealth company, reported a data breach involving unauthorized access to its third-party customer service platform. The incident, detected on February 5, 2026, exposed personal information from service tickets submitted between February 4 and 7, 2026.
The breach targeted support requests managed by an external vendor, where customer interactions including names and contact details were accessed without authorization. The company confirmed on March 3, 2026, that a limited number of individuals were affected, though the total figure remains undisclosed. Notably, medical records and provider communications were not compromised.
Hims & Hers responded by securing the platform and launching an investigation. Affected individuals were notified via letters dated April 2, 2026, and offered 12 months of complimentary credit monitoring and identity restoration services through Cyberscout (a TransUnion subsidiary). The services include single-bureau credit monitoring, fraud alerts, and proactive assistance. Enrollment requires a unique code from the notification letter and must be completed within 90 days.
The company reported the breach to the California Attorney General and provided a dedicated support line (1-833-319-5614) and mailing address for inquiries. No further details on the breach’s origin or the threat actor involved have been released.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
784
DECEMBER 2025
784
NOVEMBER 2025
784
OCTOBER 2025
784
SEPTEMBER 2025
784
FEBRUARY 2025
781
Breach
04 Feb 2025 • H
Hims & Hers: Hims & Hers says limited data stolen in social engineering attack
Hims & Hers Social Engineering Attack
714
CRITICAL-67
HIM1775492890
Hims & Hers Hit by Sophisticated Social Engineering Attack in February
Hims & Hers, a San Francisco-based telehealth provider with 2.5 million subscribers, disclosed a social engineering attack that compromised its third-party customer service platform in early February. According to regulatory filings, an unknown attacker gained unauthorized access to service tickets between February 4 and 7, with suspicious activity detected on February 5.
The company confirmed that the breach was limited to its customer service software, with exposed data primarily including customer names and email addresses. While electronic medical records and provider communications remained secure, the attackers may have accessed treatment information for certain customers who engaged with customer service between February 2025 and February 2026.
The attack targeted two employees, as outlined in the company’s February 22 SEC filing (10-K). Hims & Hers reported no material financial impact from the incident but has notified law enforcement and is reviewing internal policies to prevent future breaches. The company recently expanded its services through a partnership with Novo Nordisk to offer FDA-approved weight-loss medications.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2024
789
Breach
01 Jan 2024 • H
Hims & Hers: FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap
FTC Sues Hims & Hers Over Alleged Unauthorized Sharing of Sensitive Health Data
724
CRITICAL-65
HIM1785450848
FTC Sues Hims & Hers Over Alleged Unauthorized Sharing of Sensitive Health Data
The Federal Trade Commission (FTC) has filed a lawsuit against telehealth provider Hims & Hers, accusing the company of sharing customers’ medical and healthcare data with advertisers and tech platforms including Meta, Snap, Microsoft, Pinterest, Reddit, and X without proper disclosure. The complaint, filed in a California federal court, alleges that Hims & Hers deployed pixel trackers on its website, which captured and transmitted users’ sensitive health information, contradicting its own privacy policy.
Hims & Hers, a publicly traded company specializing in prescription medications for sexual wellness, mental health, and weight loss, is also accused of deceptive billing practices and making it difficult for customers to cancel services, violating federal consumer protection laws.
The FTC’s complaint highlights that the company used Meta’s tracking tools to monitor user interactions, such as clicks and website activity, further exposing personal health data. While Hims & Hers has not directly denied the allegations, it stated in a response that its privacy policy "makes clear" users can control data usage and expressed confidence in its legal position.
This lawsuit is part of the FTC’s broader crackdown on healthcare companies misusing patient data. Previous targets include Cerebral, Monument, GoodRx, and BetterHelp, all accused of sharing sensitive information with third-party advertisers via similar tracking technologies.
The case underscores ongoing concerns about pixel trackers and misconfigured data-sharing practices, which have previously exposed sensitive information such as the U.S. Postal Service’s accidental sharing of users’ home addresses with Meta, LinkedIn, and Snap in early 2024. The USPS removed the tracking code following the discovery.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for H ??
What was H's A.I Rankiteo Cyber Score in July 2026 ??
What was H's A.I Rankiteo Cyber Score in June 2026 ??
What was H's A.I Rankiteo Cyber Score in May 2026 ??
What was H's A.I Rankiteo Cyber Score in April 2026 ??
What was H's A.I Rankiteo Cyber Score in March 2026 ??
What was H's A.I Rankiteo Cyber Score in February 2026 ??
What was H's A.I Rankiteo Cyber Score in January 2026 ??
What was H's A.I Rankiteo Cyber Score in December 2025 ??
What was H's A.I Rankiteo Cyber Score in November 2025 ??
What was H's A.I Rankiteo Cyber Score in October 2025 ??
What was H's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on H's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with H ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view H's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?