Sample Scorecard · Public Demo
This is a publicly-available diagnostic run on a well-known company — Hims & Hers Health — so you can see exactly what your own scorecard will look like.
Run your own diagnostic here →
The Defensibility Diagnostic · Step 1
Hims & Hers Health
— moat scorecard.
A 0–3 score across the 8 moats, anchored to comparable companies. Surfaces where your defensibility is real and where it's thin.
Scored May 31, 2026 · The 8 Moats for the AI Era · Gokul Rajaram
Total Stack Score
10 / 24
FORTIFIED — five moats at score 2. Broad defensibility, but no single moat is yet category-defining.
⚠ The Moat Narrative Trap
The growth story leans on GLP-1s. The defensibility lives in the pharmacy underneath them.
The brand story leans hardest on the GLP-1 weight-loss franchise as the engine of growth and defensibility — but structurally, the medication itself is the least defensible thing Hims sells. The June 2025 Novo Nordisk split, which cut off direct Wegovy access barely a month after the partnership began and dropped the stock roughly 20% in a day, and the 2026 pivot to carrying branded Novo and Lilly product, both reveal the same thing: when the molecule is supplied by someone else, Hims is renting the position, not owning it. The real moat isn’t the drug — it’s the owned pharmacy fulfillment, the 50-state provider network, and the subscription and refill machinery the drug flows through. This is the most common trap for vertically integrated D2C health: the loudest part of the story (the hot category) is the part a partner or regulator can revoke, while the quiet infrastructure underneath is what’s actually hard to copy.
The scorecard at a glance
|
Moat |
Score |
One-line take |
| 01 | Data | 1 | Real subscriber + emerging biomarker data, but it doesn’t compound cross-customer yet |
| 02 | Workflow | 2 | Subscription, refill defaults, and async care relationship create real switching cost |
| 03 | Regulatory | 2 | 50-state telehealth + 503A/503B pharmacy licensing is operationally costly to replicate |
| 04 | Distribution | 2 | ~39%-of-revenue marketing spend bought genuine, owned brand equity + retail reach |
| 05 | Ecosystem | 0 | Pure D2C; nothing third parties build on top of |
| 06 | Network Effects | 0 | New subscribers don’t make the product better for existing ones |
| 07 | Physical / Infrastructure | 2 | Owned fulfillment, compounding, peptide manufacturing, and labs — hard-to-replicate capex |
| 08 | Scale | 1 | $2.35B revenue is real, but Q1 2026 margin compression showed the advantage is conditional |
Moat-by-moat
Each moat scored against comparable companies in the same category. Scores are anchored to the competitive set — not isolated opinion.
Hims has real subscriber data — intake responses, treatment history, refill behavior across roughly 2.6M subscribers — plus newer signals from the “Labs AI” biomarker agent and the YourBio diagnostics acquisition. But none of it yet compounds the way a true data moat does: more data doesn’t measurably make the clinical product better for the next user in a way a competitor can’t match. Ro scores the same here for the same reason — both sit on rich first-party data that functions as personalization fuel, not a defensible flywheel. It moves to a 2 only if the diagnostics-plus-AI layer starts producing care outcomes or matching that rivals structurally cannot replicate.
This is a real moat. The async-messaging care relationship, automatic refills, and subscription defaults mean that once a customer finds a discreet treatment that simply arrives, disrupting the routine carries friction — analyst commentary repeatedly flags low churn and strong habit formation, especially as the mix shifts toward daily combination treatments. Ro earns a comparable 2 with the same subscription-and-refill embedding. It’s not a 3 like Stripe’s revenue-ops lock-in, because any single condition (hair, ED, derm) is bundleable by a competitor and the switching cost is per-condition, not platform-wide.
Hims operates licensed telehealth across all 50 states plus the UK, runs 503A compounding pharmacies in Ohio and Arizona, and owns a 503B outsourcing facility (MedisourceRx) regulated directly by the FDA. That licensing-and-compliance footprint is genuinely costly and slow to assemble — Ro has a comparable footprint, while Sesame and Thirty Madison do not. It stops short of 3 because the same regulatory exposure cuts both ways: the FTC ROSCA accrual and the compounded-semaglutide scrutiny that triggered the Novo split show the regulatory position is a barrier and an attack surface, not a one-directional fortress.
Spending roughly 39% of revenue on marketing has bought something durable: a consumer health brand most rivals can’t out-acquire profitably, plus owned retail shelf presence at Target and Walmart that extends the funnel offline. This is owned reach, not rented — distinct from a startup buying clicks. It’s a 2 rather than a 3 because the brand wins customers but doesn’t lock out well-funded competitors (Ro, Thirty Madison) or platform giants (Amazon Clinic, manufacturer-direct channels like LillyDirect), and the Novo episode showed the supply side of distribution can be severed by a partner overnight.
None. Hims is a pure direct-to-consumer model — there is no marketplace, no API, no third-party developers or integrators building on top of the platform. Like every D2C telehealth peer (Ro, Thirty Madison, LifeMD), there’s simply no platform layer here. This is structurally unavailable rather than merely undeveloped.
None. A new Hims subscriber does not make the product better for existing subscribers — there’s no cross-customer value transfer, no two-sided marketplace, no data network effect that improves care for everyone as the base grows. This is the most overrated moat generally, and here it’s genuinely absent. Same as every D2C subscription health peer.
The capex moat is real and growing. Hims owns large-scale pharmacy fulfillment (the New Albany, Ohio facility), 503A compounding pharmacies, a 503B outsourcing facility, a peptide manufacturing facility, and lab/diagnostics capacity — a vertically integrated stack that disintermediates the wholesaler and PBM. International acquisitions (ZAVA, Medici, the planned Eucalyptus deal) extend the physical footprint abroad. Ro has built comparable owned fulfillment; this is the dimension that most separates the two leaders from asset-light telehealth. Not a 3 because it’s expensive-to-replicate, not impossible-to-replicate — Ro has already done it.
$2.35B in FY2025 revenue and roughly 2.6M subscribers are real, and at that size there’s some cost leverage in fulfillment and acquisition. But Q1 2026 exposed how conditional the scale advantage is: the pivot from compounded to branded GLP-1s pushed gross margin from 73% to 65%, halved adjusted EBITDA, and swung the company to a $92M net loss. Genuine scale moats (the kind that give pricing power smaller rivals can’t touch) don’t compress that fast on a single mix shift. It’s a 1, not a 2 — the size is there, the pricing power isn’t yet.
What this tells you
Hims & Hers is a genuinely fortified business, but its strength is its breadth, not its depth: four real moats (Workflow, Regulatory, Distribution, Physical) stacked inside one vertically integrated model, each reinforcing the next as a subscriber moves from acquisition to consultation to fulfillment to refill. The risk the scorecard surfaces is that none of those four has crossed into category-defining (3) territory, and the two dimensions everyone talks about — the GLP-1 growth story and “scale” — are the weakest legs (a rented molecule and a margin profile that just proved fragile). The durable value is upstream and quiet: the pharmacy, the licensing, the provider network, the brand. The strategic question at this tier isn’t “do we have moats” — it’s which of the four 2s is worth pushing toward 3, and which is quietly eroding.
Structural availability
Not every moat is on the table for every business. Three buckets: moats already real that could deepen, moats this business model could build, and moats that simply don't fit. This narrows the field. It does not name which available moat to pursue. That's the Playbook's job.
Available to Deepen
Moats at 2+ where investment compounds
- Workflow (2)
- Regulatory (2)
- Distribution (2)
- Physical / Infrastructure (2)
Available to Build
Moats this model could support
- Data (1) — subscriber base, diagnostics, and AI layer could compound into a real data moat
- Scale (1) — size exists; pricing power and cost leverage could harden as the model matures
Structurally Unavailable
Moats the model doesn't fit
- Ecosystem (0) — pure D2C; nobody builds on top of a consumer health subscription
- Network Effects (0) — no cross-customer value transfer in a 1:1 care-and-fulfillment model
Next Step · The 8 Moat Stress Test
You’re fortified. The question is which moat is doing the work.
What this scorecard doesn’t tell you yet: which moats are doing the actual work versus which the marketing emphasizes; the trajectory of each moat — strengthening, holding, or eroding over the next 24 months; and which of the 6 durable archetypes your stack matches, plus the missing leg if there is one. You’re in the strongest tier — multiple moats compounding. The 8 Moat Stress Test reveals trajectory direction across the stack and surfaces the most common pattern at this tier: companies marketing their downstream moats while their actual hard-to-copy moats live upstream and invisible. The full Stacking Moats Playbook then identifies the archetype and sequences future moat investment. Next step: book a discovery call to scope the Stress Test.
Get the Stacking Moats Playbook →