Healthcare systems have been settling website-tracking lawsuits for about a year and a half now. In early August, four of those cases wrapped up within days of each other. That kind of timing is mostly coincidence. Court calendars line up the way they line up. But looking at all four together tells you something useful about where this whole category of litigation is heading.
The Cases
Concord Hospital Health System in New Hampshire put $800,000 into a settlement fund. The claim: its website was sending patient information to Google and a vendor called Geonetric without anyone's knowledge, a violation of the state's wiretapping law and its patient privacy statute.
Emanate Health Medical Center, based in California, settled for $777,000. Patients who logged into the portal, filled out a form, or booked an appointment online had that activity tracked and shared, according to the suit, in violation of the California Invasion of Privacy Act.
Bayhealth Medical Center in Delaware tried to get its case thrown out first. The motion to dismiss failed, and the lawsuit, alleging third-party pixels were leaking sensitive data, moved forward until the two sides settled.
Penn Medicine paid the most by a wide margin: $9.5 million. Meta Pixel and Google Analytics code embedded in the patient portal allegedly sent personal health information out the door, running afoul of Pennsylvania's wiretapping statute. Penn has since pulled Meta Pixel entirely and committed to staying off analytics and ad tech for at least two years.
Worth Noting: Not Every Case Like This Settles
A fifth lawsuit from around the same time didn't end the same way. A court dismissed a case against CRH Healthcare (Peachtree Immediate Care), not because it doubted tracking had happened, but because the plaintiff couldn't point to any actual harm that came from it. The judge called the complaint speculative and gave the plaintiff 14 days to fix it before the dismissal becomes permanent.
It's a useful counterweight. Having a tracker on your site doesn't automatically mean you're exposed. Someone still has to show it cost them something real.
The Pattern Underneath All Four
Take away the company names and the dollar figures, and these four cases start to look almost identical. Somebody's marketing or analytics team added a tool, probably years ago, probably without much fanfare. That tool quietly sent patient data to Meta, Google, or some other third party. Nobody flagged it because nobody was really looking.
None of this involved a hacker. Nobody broke in. The organizations did this to themselves, one script tag and one vendor contract at a time, which is really the whole point. A data breach is something that happens to a company. This is something a company does, usually without realizing it.
What's Behind the Wildly Different Payouts
$777,000 on one end, $9.5 million on the other. More than a 12x gap. But that spread doesn't seem to track how bad the underlying conduct was so much as how big the class turned out to be and how long the tracker had been running. Penn's case covered a two-year window on one portal. Bayhealth's covered seven years. Same basic tools, wildly different exposure, purely because of how long they'd been sitting there unnoticed.
That's the uncomfortable part. There's no natural ceiling on this kind of liability. It just keeps growing the longer nobody checks.
A Few Questions Worth Asking Yourself and Your Team
You don't have to work in healthcare for this to apply to you. If your site collects anything sensitive, the same exposure exists.
Do you actually know every third-party script running on the pages where people hand over personal information?
If someone pulled up your site right now and watched what fired before, during, and after a visitor clicked "accept" or "reject," would it match what your privacy policy says?
When's the last time anyone looked at a tracking tool that's been live for years, just to check it's still doing what it was set up to do?
None of the four organizations above woke up one day and decided to violate patient privacy. They installed tools that thousands of other websites use the exact same way. What they lacked wasn't intent. It was visibility.
Sources
All case facts, settlement amounts, and legal claims referenced in this article are drawn from:
Alder, Steve. "Five Healthcare Providers Settle Pixel Class Action Lawsuits." The HIPAA Journal, August 7, 2026. https://www.hipaajournal.com/five-healthcare-providers-pixel-class-action-settlements/
Disclaimer
This article is for general informational purposes only and does not constitute legal, financial, or professional advice. While efforts have been made to ensure accuracy, laws and litigation outcomes are subject to change, and individual circumstances vary. Readers should consult an attorney before making decisions based on the information provided here.