Kaiser Permanente

Kaiser Permanente’s pixel settlement: about $47.5M, and not a Meta Pixel in sight (2025)

Private litigationLast updated

At a glance

Brought by
Private litigation
Company
Kaiser Permanente
Sector
Integrated health system
Law
Wiretap-style interception claims
Amount
about $47.5M (motion pending)
Date
Final approval Jul 14, 2026
Status
Final approval granted

Summary

In July 2026 a federal court granted final approval of a settlement of about $47.5 million, resolving claims that third-party code on Kaiser Permanente‘s logged-in websites and apps shared members’ information, including health topics they searched. Kaiser denied wrongdoing. A motion to amend the approval order was pending as of September 2026, so the figure could change.

What happened

The case is Doe v. Kaiser Foundation Health Plan, Inc., in the U.S. District Court for the Northern District of California, brought by private plaintiffs with no regulator involved. The class is approximately 13.1 million people. Kaiser has said it conducted a voluntary internal investigation and removed the technologies.

The mechanism

This is the case that shows the problem is not one or two famous pixels. The trackers named were Quantum Metric (a session-replay tool), X (Twitter), Adobe, Microsoft/Bing, and Google, with no Meta Pixel among them. The court’s final approval order also names Dynatrace. Kaiser’s own notice lists the search terms members used in its health encyclopedia among the information involved. Every one of those is a tag a scan can detect.

A clinic booking page's pixel sends the cardiology page and a hashed email to an ad platform: health data tied to a person.

Why it was preventable

A tag inventory that only looks for Meta and Google would have missed this entirely. Full-coverage scanning reads every tracker on the page, including session-replay tools and analytics vendors, and payload inspection shows what each one sends. That is how you catch an Adobe or a Quantum Metric leaking search terms, even when no Meta Pixel is present.

In the court filing’s words

The complaint alleged that Kaiser “installed code from multiple third parties throughout the Kaiser Permanente website that allows third party companies such as Quantum Metric, Twitter, Adobe, Bing, and Google (collectively, ‘Third Party Wiretappers’) to intercept the content of Plaintiff and Class Members’ communications.”

Timeline

  1. Nov 2017 to May 2024exposure period.
  2. Dec 5, 2025preliminary approval.
  3. May 7, 2026final approval hearing.
  4. Jul 14, 2026final approval granted.
  5. Jul 22, 2026final judgment entered.
  6. Aug 10, 2026some opt-out claimants moved to amend the approval order. The motion was pending as of September 2026.
  7. Early Nov 2026payments expected, per the settlement administrator.

Source

Complaint, order granting final approval and final judgment, Doe v. Kaiser Foundation Health Plan (N.D. Cal., 3:23-cv-02865), via kaiserprivacysettlement.com.

kaiserprivacysettlement.com

Questions

How big is the Kaiser pixel settlement?

About $47.5 million, covering approximately 13.1 million people. A federal court granted final approval on July 14, 2026, and payments are expected in early November 2026. As of September 2026, a motion by some opt-out claimants to amend the approval order was pending, so the final figure could change.

Which trackers were named?

Quantum Metric (a session-replay tool), X (Twitter), Adobe, Microsoft/Bing, and Google. There was no Meta Pixel, which is what makes this case notable.

Why does the missing Meta Pixel matter?

Because a tag inventory that only looks for Meta and Google would have missed this case entirely. The exposure came from session-replay and analytics trackers, which a full-coverage scan reads too.

Private litigation2026 (proposed, final hearing Oct 2026)
$3.03M (proposed)

LifeStance’s $3M pixel settlement

Meta and Google tracking; mental-health data; 5-year limit on non-HIPAA-compliant pixels

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue