The health-pixel lawsuit wave: why hospitals and clinics are paying millions (2026)

Summary
Hospitals, clinics, dental groups, and telehealth companies across the US are settling lawsuits and facing regulator findings over tracking pixels that sent patient data to advertising platforms. On a health website, what a visitor looked at is sensitive health data, and a privacy notice does not stop a pixel from firing.
What’s happening
Some of these settlements run to tens of millions of dollars. The lawsuits allege that the pixels sent what patients looked at, and what they booked, to advertising platforms.
This is a wave, and it is still building.
How big it is
A few of the settlements, largest first (status as of September 2026):
- Kaiser Permanente, the largest among the cases we track, at about $47.5 millionsubject to a pending motion, as of September 2026
Final approval, July 2026. Trackers from Google, Microsoft, Adobe, X, and the session-replay tool Quantum Metric allegedly collected information from members’ logged-in pages, including the health topics they searched. Kaiser denied wrongdoing. The class is approximately 13.1 million people.
- Aspen Dental, up to about $18.47 millionproposed, no final approval entered
The claims allege that the Meta Pixel and Google Analytics on its appointment site shared patients’ information. Aspen Dental denies wrongdoing.
- Penn Medicine, up to $9.25 millionpreliminary approval
The complaint alleges that Meta, Google, LinkedIn, Snap, and TikTok trackers shared patient information. Penn Medicine denies wrongdoing. For two years, no analytics or advertising technology on pennmedicine.org unless its web governance committee finds that use lawful.
Below those sits LifeStance Health ($3.03M proposed, plus a five-year term on pixels other than HIPAA-compliant ones), over alleged disclosures through Meta and Google tracking. LifeStance denies wrongdoing. See the case pages for each.
How it happens
A tracking pixel is a small piece of code that reports what a visitor does on a page back to a third party, usually for advertising or analytics. On most sites that’s unremarkable. On a health site, the pages a visitor looks at reveal a condition, a treatment, a provider, or an appointment. When a pixel reports that to an ad platform, sensitive health data has left the building.

The pattern repeats across nearly every case:
Regulators are moving too
The lawsuits are the volume, and government enforcers are active too:
- The FTC has taken action against digital-health apps for sharing health data with ad platforms. Under a 2023 FTC order, BetterHelp paid $7.8 million for partial consumer refunds. Under a 2024 FTC order, Cerebral agreed to pay nearly $5.1 million in refunds over its cancellation practices and a $10 million civil penalty, suspended after $2 million was paid.
- The HHS Office for Civil Rights issued guidance in 2022, revised on March 18, 2024, warning that tracking technologies can create improper disclosures of protected health information under HIPAA. A federal court vacated part of that guidance in 2024, so the current scope is narrower. The rest remains HHS’s stated position as of that revision, and HHS says it is evaluating its next steps.
Why a HIPAA-compliant site can still get caught
A pixel sends what the code on the page tells it to send, whatever the privacy notice says. DataTrue loads your real pages in each consent state and reads what each tag sends, so health data heading to an ad platform shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
DataTrue helps you find these problems. It does not certify HIPAA compliance.

The cases
Aspen Dental
Meta and Google pixels on appointment booking.
Kaiser Permanente
the largest among the cases we track, at about $47.5 million (subject to a pending motion, as of September 2026), and not a Meta Pixel in it.
Penn Medicine
five trackers under a state wiretap law.
LifeStance
mental-health data and a five-year limit on non-HIPAA-compliant pixels.
Also in this wavethe FTC health-app actions (BetterHelp and Cerebral).
Questions
Which pixels cause these lawsuits?
Most name Meta and Google, and cases also involve Microsoft, Adobe, X, LinkedIn, TikTok, and session-replay tools. Any tag that reports health-related activity to a third party can be the basis of a claim.
Does a cookie banner protect against this?
No. Several settled cases had a banner. The pixels fired anyway, before consent or regardless of it. What matters is whether the banner actually stops the tags, which has to be tested.
Is a HIPAA-compliant provider safe?
Not automatically. HIPAA compliance is about policies and agreements. A pixel leaking data is a technical behavior that can happen underneath a compliant policy. The two have to be checked separately.
What’s the largest health-pixel settlement so far?
Kaiser Permanente’s is the largest among the cases we track, at about $47.5 million (subject to a pending motion, as of September 2026). It received final approval in July 2026. Figures and “largest” claims change, so this carries a date.