The lawsuit accuses an HCA Healthcare-owned urgent care chain of gating access to its own booking site behind consent to Google cookies, then feeding patient appointment data straight into Google's advertising systems.
What happened
Three plaintiffs identified as Jane Does filed suit against CareNow on June 11, 2026, in Davidson County Circuit Court, accusing the urgent care operator of disclosing patient information to Google and other marketing companies without consent. According to the Nashville Banner, CareNow operates more than 20 urgent care centers across Middle Tennessee and is owned by HCA Healthcare, the nation's largest for-profit hospital operator and Nashville's second-largest employer with 27,000 local employees at the end of 2025. The complaint alleges CareNow used tracking technologies on its online appointment scheduling platform that allowed Google to link patients to their personal Google accounts and use their health information for advertising purposes, which the plaintiffs argue violates HIPAA. HCA responded to the allegations in a statement to the Nashville Banner, "We disagree with the allegations that have been made, and we plan to defend them aggressively through the legal process."
Going deeper
The complaint describes a specific mechanism for how the tracking occurred. When patients visited CareNow's appointment scheduling website, they were repeatedly presented with a CAPTCHA verification challenge until they allowed first-party cookies, small data files that let a website remember a visitor's activity and preferences. Once a patient allowed those cookies, the site was able to deposit Google's own tracking cookies on the patient's device as well, relaying their activity to third-party marketing organizations without separate consent for that disclosure. The lawsuit alleges CareNow disclosed a patient's status as a CareNow patient, their use of the scheduling website, their appointment details, the names of their physicians, the reason for their visit, their physical location, and their IP address. The complaint states this information can be used for a process called ID bridging, piecing together a person's identity across platforms, which the plaintiffs describe as a mechanism that helps advertisers target people likely to want specific products and can extend beyond advertising into political targeting.
What was said
The complaint alleges the conduct was knowing rather than negligent, stating, "Defendant did all this knowing it constituted a violation of HIPAA and state law, for the purpose of reaping the illicit financial gains from its criminal and tortious disclosures of patients' PHI." The plaintiffs frame the stakes in paragraph 16, "Information about a person's physical and mental health is among the most confidential and sensitive information in our society, and the mishandling of medical information can have serious consequences including, but certainly not limited to, discrimination in the workplace or denial of insurance coverage." HCA Healthcare responded in a statement to the Nashville Banner saying that "we disagree with the allegations that have been made, and we plan to defend them aggressively through the legal process."
In the know
The CareNow lawsuit was filed the same month that 12 separate lawsuits were consolidated into a class action against XSolis, a Franklin, Tennessee-based healthcare AI company, over a January data breach that exposed the personal and medical information of approximately 1.4 million patients nationwide. According to the Nashville Banner, the XSolis complaints allege the company failed to encrypt or redact patient data, resulting in what the plaintiffs describe as a foreseeable and preventable breach. The near-simultaneous filing of both cases against Tennessee-based healthcare companies shows a broader wave of litigation targeting how healthcare organizations, whether through website tracking tools or vendor security failures, handle patient data outside of direct clinical care.
The big picture
CareNow's scheduling site did not simply fail to protect patient data. According to the complaint, it was built so that using the site at all meant accepting Google's tracking. A patient trying to book an urgent care visit had no version of that page that let them schedule care without also feeding Google their appointment reason, physician name, and location. It’s a different problem than what some other hospitals face, where they forget to remove a pixel it inherited from a marketing vendor years ago. It is a scheduling system where the tracking was load-bearing. The surrounding litigation shows how much company CareNow has, with Becker's Hospital Review reporting that consolidated litigation over Meta's tracking pixel identified at least 664 medical provider websites transmitting patient data, and citing a Health Affairs study that found 98.6% of U.S. hospital and health system websites ran tracking technologies sending visitor data to third parties such as Alphabet, Meta, and Adobe. For any health system auditing its own web presence, the CareNow complaint is a reminder to check which trackers are present, and whether any of them are doing work the site cannot function without.
FAQs
What is ID bridging, and why does the lawsuit call it a "money-making machine"?
ID bridging is the process of connecting a person's activity across different platforms and accounts to build a single, more complete identity profile. When a healthcare website's tracking data is linked to a patient's existing Google account, advertisers and marketing companies gain a far more precise, cross-platform picture of that person than an anonymous website visit would normally reveal, making the resulting profile much more valuable for targeted advertising.
Why would forcing patients to accept cookies through a CAPTCHA screen make a stronger legal case than passive tracking?
Passive tracking pixels operate in the background without any specific action from the visitor, which can make it harder to establish that a healthcare provider deliberately engineered a disclosure. A mechanism that blocks access to a core function, like appointment scheduling, until cookies are accepted demonstrates an active, structural choice by the organization to condition patient care access on data sharing, which strengthens claims that the disclosure was intentional rather than incidental.
Does Google allow its tracking tools to be used on HIPAA-covered pages?
According to the lawsuit, Google's own website states that certain of its tracking tools, including Google Analytics, are not permitted for use by HIPAA-bound entities on pages that could transmit protected health information. That existing restriction is central to the plaintiffs' argument that CareNow knowingly used a tool in a way inconsistent with its own permitted use.
What is the significance of these lawsuits being filed in state court rather than federal court?
The CareNow lawsuit was filed in Davidson County Circuit Court, a Tennessee state court, rather than a federal court. State court litigation can proceed under different procedural rules and state-specific privacy statutes alongside HIPAA-based claims, giving plaintiffs additional legal theories that may not be available in a purely federal HIPAA enforcement action.
What should healthcare organizations review on their own patient-facing websites in light of this case?
Organizations should audit every point on their website, particularly appointment scheduling and patient portal access, where a visitor is required to accept cookies or tracking consent as a condition of completing a task. Any mechanism that gates a core patient function behind acceptance of third-party tracking tools should be reviewed for HIPAA compliance and reworked to offer patients a genuine alternative that does not require handing over identifiable health information to advertising platforms.
