Healthline

Healthline’s $1.55M CCPA settlement: a consent banner that didn’t stop the tracking (2025)

Regulator: California Attorney GeneralLast updated

At a glance

Brought by
Regulator: California Attorney GeneralRegulator
Company
Healthline Media
Sector
Health-information publishing
Law
CCPA (California)
Amount
$1.55M settlement
Date
Settled Jul 1, 2025
Status
Settled

Summary

In July 2025, the health publisher Healthline agreed to $1.55 million in civil penalties to settle claims by the California Attorney General, which said its consent banner did not disable tracking cookies and that sharing continued even after readers opted out. It was the largest CCPA settlement to date at the time (July 2025).

What happened

According to the Attorney General, the trackers were cookies and pixels that shared visitor data with advertisers. It also said Healthline shared article titles suggesting a reader may already have been diagnosed with a condition, and that its ad contracts lacked the privacy terms the CCPA requires.

The mechanism

The banner recorded the choice without controlling the tracking cookies, so the sharing carried on in the background.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

Why it was preventable

The gap between what a banner claims and what the tags do is measurable. Opt out, then read what each tag still sends. That check surfaces both the ignored opt-out and any sensitive data leaving the page.

In the Attorney General’s words

Attorney General Rob Bonta said: “Businesses that collect consumer data must honor consumers’ privacy rights.”

Timeline

  1. Jul 1, 2025settled.

Source

oag.ca.gov.

oag.ca.gov

Questions

Who brought the Healthline case, and how much?

The California Attorney General. Healthline agreed to $1.55 million in civil penalties in July 2025, the largest CCPA settlement to date at the time.

The site had a consent banner. Why did Healthline still pay penalties?

According to the Attorney General, the banner did not disable tracking cookies, and even after an opt-out, cookies and pixels kept sharing data with advertisers.

What made the shared data sensitive?

The Attorney General said Healthline shared article titles suggesting a reader may already have been diagnosed with a condition. On a health-information site, what a reader looked at can reveal a health condition.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue