Hims & Hers Health, Inc.
ent_019e57ea9d495868f8712ab29736b6be
Disclosures
4
State AG · SEC 10-K Item 1C · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
454
as filed · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hims & Hers Health, Inc.
- Normalized
- hims hers health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001773751
- Domain
- None on record
Disclosure history (4)newest first
- ⭐Texas State AGas victim2026-04-06
Hims & Hers, Inc. based in San Francisco, California, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-03-03 and reported on 2026-04-06. 454 Texas residents were affected. 3,385 individuals affected in total. Types of information involved: Medical Information. Consumers were notified via U.S. Mail.
- 🐻California State AGas victim2026-04-02
Hims & Hers, Inc. disclosed that from February 4-7, 2026, unauthorized parties accessed customer service tickets on a third-party platform. The incident involved names, contact info, and potentially health-related data for a limited set of individuals. Hims & Hers secured the platform, notified law enforcement, and is offering 12 months of credit monitoring.
- 🍁Vermont State AGas victim2026-04-02
Hims & Hers, Inc. notified Vermont AG that unauthorized access to its third-party customer service platform occurred Feb 4-7, 2026. Affected data included names and medical information for ~13 Vermont residents. The company secured the platform, notified law enforcement, and offered 12 months of credit monitoring.
- FEDERALSEC 10-K Item 1Cas victim2026-02-23
Hims & Hers Health disclosed a cybersecurity incident in its 10-K filing. In early February 2026, an unauthorized third party gained access to systems via social engineering/phishing of two employees. The actor accessed customer service software, obtaining PII (names, emails, addresses) and potentially treatment category data for customers active between Feb 2025 and Feb 2026. EMRs were not accessed. The investigation is ongoing, and notifications are pending. The company does not believe the incident is materially impactful to financials.