Five healthcare providers have agreed to proposed class action settlements resolving claims concerning tracking and analytics technologies on their websites or patient portals.

 

What happened

The lawsuits alleged that these technologies transmitted users’ personally identifiable, health-related, or confidential information to third parties without consent. Emanate Health Medical Center agreed to a $777,000 gross settlement fund for eligible portal and website users. Bayhealth Medical Center agreed to provide eligible class members with a $25 payment and one year of CyEx PrivacyShield.

Mount Sinai Medical Center of Florida established a $220,000 pool for valid cash claims, with payments estimated at $20, along with one year of medical-data monitoring. Penn Medicine agreed to pay up to $9.25 million, including payments of up to $15, and accepted conditions governing certain analytics and advertising technologies for two years. Concord Hospital agreed to create an $800,000 common fund for qualifying claimants. The settlement notices state that each defendant denies wrongdoing or liability, and the courts have not determined the merits of the allegations. Each agreement remains subject to final court approval.

 

Going deeper

The settlement records do not establish that confirmed HIPAA breaches occurred. Still, they identify a common alleged cause: third-party tracking, analytics, and advertising code were embedded in healthcare websites or patient portals and allegedly transmitted identifiable, health-related, or confidential user information to external companies without consent.

The technologies included tools associated with Meta, Google, and Geonetric. However, the specific tools and information differed between Emanate Health, Bayhealth, Mount Sinai Medical Center of Florida, Penn Medicine, and Concord Hospital. The broader problem is that third-party pixels can transmit information outside the provider’s systems when a webpage loads or a patient interacts with an online service, reducing the provider’s control over how that information is stored, combined, or shared.

A Rutgers study found that 66% of the 1,201 hospitals studied used third-party pixels. Hospitals using pixels had a 1.4-percentage-point higher breach probability, equal to a 46% relative increase over the study’s 3% baseline, and a 13% increase in unintended disclosures. Only 14% used first-party pixels, which keep data within the organization, and researchers found no significant relationship between first-party pixels and breaches.

 

What was said

In Doe v. CRH Healthcare, allegations noted that, “Any protected health information (PHI) and personally identifying information (PII) entered by these patients is shared with Google through their tracking tools. This sharing occurred without the written authorization of the Plaintiff or other patients using the Website.”

 

Why it matters

The five proposed settlements reinforce the same warning identified in Paubox’s coverage of Allina Health, which agreed to a proposed $12.5 million settlement covering approximately 2.5 million people over allegations that website trackers disclosed personal and health-related information to third parties. Allina denied wrongdoing, as have the five providers in the latest cases. Together, the settlements show why healthcare organizations must treat analytics and advertising code as a privacy and security decision rather than a routine marketing choice.

Organizations must determine what information each tool collects, where it transmits that information, whether it operates on authenticated portals or appointment forms, and whether the recipient is authorized to handle PHI.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Does a cookie-consent banner make pixel tracking HIPAA compliant?

No, clicking ‘accept cookies’ usually does not satisfy the detailed requirements of a HIPAA authorization, and it does not make an otherwise impermissible disclosure lawful.

 

Does publishing a privacy policy resolve the risk?

A privacy policy can improve transparency, but merely telling patients that tracking occurs does not automatically provide authorization to disclose PHI.

 

Does signing a business associate agreement (BAA) make every use of a tracking tool permissible?

A BAA establishes safeguards and permitted responsibilities, but the underlying use or disclosure must still be allowed under HIPAA. A BAA cannot turn an impermissible advertising disclosure into a permitted one.