Healthline’s $1.55M CCPA settlement: a consent banner that didn’t stop the tracking (2025)
At a glance
- Brought by
- Regulator: California Attorney GeneralRegulator
- Company
- Healthline Media
- Sector
- Health-information publishing
- Law
- CCPA (California)
- Amount
- $1.55M settlement
- Date
- Settled Jul 1, 2025
- Status
- Settled
Summary
In July 2025, the health publisher Healthline agreed to $1.55 million in civil penalties to settle claims by the California Attorney General, which said its consent banner did not disable tracking cookies and that sharing continued even after readers opted out. It was the largest CCPA settlement to date at the time (July 2025).
What happened
According to the Attorney General, the trackers were cookies and pixels that shared visitor data with advertisers. It also said Healthline shared article titles suggesting a reader may already have been diagnosed with a condition, and that its ad contracts lacked the privacy terms the CCPA requires.
The mechanism
The banner recorded the choice without controlling the tracking cookies, so the sharing carried on in the background.

Why it was preventable
The gap between what a banner claims and what the tags do is measurable. Opt out, then read what each tag still sends. That check surfaces both the ignored opt-out and any sensitive data leaving the page.
In the Attorney General’s words
Attorney General Rob Bonta said: “Businesses that collect consumer data must honor consumers’ privacy rights.”
Timeline
- Jul 1, 2025settled.
Source
Questions
Who brought the Healthline case, and how much?
The California Attorney General. Healthline agreed to $1.55 million in civil penalties in July 2025, the largest CCPA settlement to date at the time.
The site had a consent banner. Why did Healthline still pay penalties?
According to the Attorney General, the banner did not disable tracking cookies, and even after an opt-out, cookies and pixels kept sharing data with advertisers.
What made the shared data sensitive?
The Attorney General said Healthline shared article titles suggesting a reader may already have been diagnosed with a condition. On a health-information site, what a reader looked at can reveal a health condition.
Related cases
CNIL’s €750,000 fine against Condé Nast
Cookies on arrival; “reject” did not stop tracking
The health-pixel lawsuit wave
Disney’s $2.75M CCPA settlement
Opt-out not carried across devices and services
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
