Health-pixel lawsuits

Enforcement Watch

The health-pixel lawsuit wave: why hospitals and clinics are paying millions (2026)

Last updated

Summary

Hospitals, clinics, dental groups, and telehealth companies across the US are settling lawsuits and facing regulator findings over tracking pixels that sent patient data to advertising platforms. On a health website, what a visitor looked at is sensitive health data, and a privacy notice does not stop a pixel from firing.

What’s happening

Some of these settlements run to tens of millions of dollars. The lawsuits allege that the pixels sent what patients looked at, and what they booked, to advertising platforms.

This is a wave, and it is still building.

How big it is

A few of the settlements, largest first (status as of September 2026):

  1. Kaiser Permanente, the largest among the cases we track, at about $47.5 million
    subject to a pending motion, as of September 2026

    Final approval, July 2026. Trackers from Google, Microsoft, Adobe, X, and the session-replay tool Quantum Metric allegedly collected information from members’ logged-in pages, including the health topics they searched. Kaiser denied wrongdoing. The class is approximately 13.1 million people.

  2. Aspen Dental, up to about $18.47 million
    proposed, no final approval entered

    The claims allege that the Meta Pixel and Google Analytics on its appointment site shared patients’ information. Aspen Dental denies wrongdoing.

  3. Penn Medicine, up to $9.25 million
    preliminary approval

    The complaint alleges that Meta, Google, LinkedIn, Snap, and TikTok trackers shared patient information. Penn Medicine denies wrongdoing. For two years, no analytics or advertising technology on pennmedicine.org unless its web governance committee finds that use lawful.

Below those sits LifeStance Health ($3.03M proposed, plus a five-year term on pixels other than HIPAA-compliant ones), over alleged disclosures through Meta and Google tracking. LifeStance denies wrongdoing. See the case pages for each.

How it happens

A tracking pixel is a small piece of code that reports what a visitor does on a page back to a third party, usually for advertising or analytics. On most sites that’s unremarkable. On a health site, the pages a visitor looks at reveal a condition, a treatment, a provider, or an appointment. When a pixel reports that to an ad platform, sensitive health data has left the building.

A clinic booking page's pixel sends the cardiology page and a hashed email to an ad platform: health data tied to a person.

The pattern repeats across nearly every case:

1
Pixels on appointment booking, symptom or condition pages, or the patient portal (often MyChart).
2
Data sent to Meta and Google, and just as often to Microsoft, Adobe, X, LinkedIn, TikTok, and session-replay tools. The problem is any tag reporting health activity to a third party, whatever the vendor.
3
A privacy notice or a cookie banner that did not actually stop the pixel from firing.

Regulators are moving too

The lawsuits are the volume, and government enforcers are active too:

  • The FTC has taken action against digital-health apps for sharing health data with ad platforms. Under a 2023 FTC order, BetterHelp paid $7.8 million for partial consumer refunds. Under a 2024 FTC order, Cerebral agreed to pay nearly $5.1 million in refunds over its cancellation practices and a $10 million civil penalty, suspended after $2 million was paid.
  • The HHS Office for Civil Rights issued guidance in 2022, revised on March 18, 2024, warning that tracking technologies can create improper disclosures of protected health information under HIPAA. A federal court vacated part of that guidance in 2024, so the current scope is narrower. The rest remains HHS’s stated position as of that revision, and HHS says it is evaluating its next steps.
30-day free trial

Why a HIPAA-compliant site can still get caught

A pixel sends what the code on the page tells it to send, whatever the privacy notice says. DataTrue loads your real pages in each consent state and reads what each tag sends, so health data heading to an ad platform shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue helps you find these problems. It does not certify HIPAA compliance.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue

The cases

Private litigation2025 (prelim approval; no final approval entered)
Up to ~$18.47M (proposed)

Aspen Dental

Meta and Google pixels on appointment booking.

Private litigationJul 14, 2026 (final approval)
about $47.5M (motion pending)

Kaiser Permanente

the largest among the cases we track, at about $47.5 million (subject to a pending motion, as of September 2026), and not a Meta Pixel in it.

Private litigation (PA WESCA)2026 (prelim approval, final Nov 2026)
Up to $9.25M (proposed)

Penn Medicine

five trackers under a state wiretap law.

Private litigation2026 (proposed, final hearing Oct 2026)
$3.03M (proposed)

LifeStance

mental-health data and a five-year limit on non-HIPAA-compliant pixels.

Also in this wavethe FTC health-app actions (BetterHelp and Cerebral).

Questions

Which pixels cause these lawsuits?

Most name Meta and Google, and cases also involve Microsoft, Adobe, X, LinkedIn, TikTok, and session-replay tools. Any tag that reports health-related activity to a third party can be the basis of a claim.

Does a cookie banner protect against this?

No. Several settled cases had a banner. The pixels fired anyway, before consent or regardless of it. What matters is whether the banner actually stops the tags, which has to be tested.

Is a HIPAA-compliant provider safe?

Not automatically. HIPAA compliance is about policies and agreements. A pixel leaking data is a technical behavior that can happen underneath a compliant policy. The two have to be checked separately.

What’s the largest health-pixel settlement so far?

Kaiser Permanente’s is the largest among the cases we track, at about $47.5 million (subject to a pending motion, as of September 2026). It received final approval in July 2026. Figures and “largest” claims change, so this carries a date.