← Back to BrewedIntel
incidenthighData BreachPHI ExposurePrivacy Violation

Apr 10, 2026 • Nate Nelson

Hims Breach Exposes the Most Sensitive Kinds of PHI

Hims, a telehealth company, suffered a data breach exposing sensitive Protected Health Information (PHI) including personal health details. The compromised...

Source
Dark Reading
Category
incident
Severity
high

Executive Summary

Hims, a telehealth company, suffered a data breach exposing sensitive Protected Health Information (PHI) including personal health details. The compromised data reportedly includes information about conditions such as hair loss, weight issues, and erectile dysfunction. This breach represents a significant privacy violation, as such sensitive health data could be exploited for identity theft, insurance fraud, embarrassment-based extortion, or targeted phishing campaigns. Healthcare organizations handling PHI must ensure robust security controls, encryption, and access management to protect patient data. Affected individuals should monitor for suspicious communications and consider placing fraud alerts on their accounts.

Summary

Threat actors breached the telehealth brand, and now they may know who's bald, overweight, and impotent. What could they do with that information?

Published Analysis

Hims, a telehealth company, suffered a data breach exposing sensitive Protected Health Information (PHI) including personal health details. The compromised data reportedly includes information about conditions such as hair loss, weight issues, and erectile dysfunction. This breach represents a significant privacy violation, as such sensitive health data could be exploited for identity theft, insurance fraud, embarrassment-based extortion, or targeted phishing campaigns. Healthcare organizations handling PHI must ensure robust security controls, encryption, and access management to protect patient data. Affected individuals should monitor for suspicious communications and consider placing fraud alerts on their accounts. Threat actors breached the telehealth brand, and now they may know who's bald, overweight, and impotent. What could they do with that information? Threat actors breached the telehealth brand, and now they may know who's bald, overweight, and impotent. What could they do with that information?