Hims & Hers Health, Inc.
bd_0cc210b877a07d46 · schema v1 · pii pii-v1
Full breach record for Hims & Hers Health, Inc. →Hims & Hers Health disclosed a cybersecurity incident in its 10-K filing. In early February 2026, an unauthorized third party gained access to systems via social engineering/phishing of two employees. The actor accessed customer service software, obtaining PII (names, emails, addresses) and potentially treatment category data for customers active between Feb 2025 and Feb 2026. EMRs were not accessed. The investigation is ongoing, and notifications are pending. The company does not believe the incident is materially impactful to financials.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 15, 2025
Begins
Feb 1, 2026
Discovered
Feb 23, 2026
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_3ace3aee1cea21e82026-04-02 · +38dVerified
- Vermont State AGbd_af58dc468106a80b2026-04-02 · +38dVerified
- Texas State AGbd_92ad67154a74fee82026-04-06 · +42dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Feb 23, last Apr 6 (TX) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.