Advocate Aurora Health Tracking Pixel Litigation
Advocate Aurora Health paid $12.25 million to settle a consolidated class action covering roughly 2.5 million patients — one of the largest exposed populations in the healthcare pixel wave. And it began in an unusual way: not with a plaintiff's discovery, but with the health system reporting the problem on itself to federal regulators.
- Case
- In re Advocate Aurora Health Pixel Litigation (consolidated class action)
- Court
- U.S. District Court, Eastern District of Wisconsin
- Legal theory
- Federal Wiretap Act & Stored Communications Act, state wiretap laws (IL/WI), plus common-law invasion of privacy, breach of fiduciary duty & unjust enrichment (HIPAA referenced as a standard, not a private claim)
- Class period
- Oct 24, 2017 – Oct 22, 2022
- Class size
- ~2.5 million individuals (breach filing referenced a patient base up to ~3M)
- Tracking tech
- Meta Pixel & Google Analytics on Advocate Aurora's website, LiveWell app, and MyChart patient portal
- Settlement
- $12,225,000 — up to $50 per claimant
- Status
- Final approval granted July 10, 2024. Case closed.
- Defendant
- Advocate Aurora Health (IL/WI, 27-hospital system) — denies wrongdoing; has removed the tracking tools
What the case is about
Advocate Aurora Health — a large non-profit system operating across Illinois and Wisconsin — used Meta Pixel, Google Analytics, and other tracking tools on its website, its LiveWell app, and its MyChart-integrated patient portal. The plaintiffs alleged those trackers transmitted patients' information to third parties such as Meta and Google without consent as patients browsed, searched for doctors, scheduled appointments, and used patient-facing features.
The information allegedly disclosed was unusually specific for a pixel case: dates and times of appointments and procedures, the identity of treating physicians, health-insurance information, IP addresses and physical locations, and communications made through the patient portal. That specificity — tying a named person to a named doctor and a scheduled procedure — is part of why the exposure was taken so seriously.
Most pixel cases begin when a plaintiff's firm or a journalist discovers trackers on a site. Advocate Aurora is different. In October 2022, the health system itself posted a data-breach notification and reported the incident to the U.S. Department of Health and Human Services' Office for Civil Rights, disclosing that its tracking technologies may have transmitted patient information to third-party vendors. Its HHS filing referenced a patient base of up to roughly three million people.
The class actions followed that self-disclosure — and were then consolidated. In other words, the notice the organisation issued to comply with breach-reporting obligations became the roadmap for the litigation that produced a $12.25 million settlement. Doing the responsible thing on breach reporting did not, and could not, undo the underlying exposure.
The litigation traced directly from the organisation's own breach disclosure — a sequence unique among the cases in this series.
The legal theory — a stacked, multi-statute claim
Because the disclosed data was so specific and the population so large, the consolidated complaint stacked federal and state theories rather than relying on any single one:
- Federal Wiretap Act (18 U.S.C. § 2511) and the Stored Communications Act — the interception and stored-data theories at the national level.
- State wiretap laws — including Illinois (720 ILCS 5/14-2) and Wisconsin, reflecting the health system's two-state footprint.
- Common-law claims — invasion of privacy, breach of fiduciary duty, and unjust enrichment, the last leaning on the special provider–patient relationship.
- HIPAA as a standard, not a claim — HIPAA has no private right of action, so patients cannot sue under it directly; it was referenced as the benchmark for the duty allegedly breached, with the actionable claims brought under the statutes above.
This stacking is a recurring strategic feature of healthcare pixel litigation: no single theory has to carry the case, and a defendant must contest several fronts at once. It also illustrates why the surface matters more than the statute — the same fact pattern supports a federal wiretap claim, two state wiretap claims, and three common-law claims simultaneously.
Unlike some cases in this series, the tracking here was described as running not only on the public website but also on the LiveWell app and the MyChart-integrated patient portal. That's worth stating plainly rather than glossing over.
ConsentPixel's role is specifically the website and web-delivered consent layer — blocking third-party trackers on web pages before consent. It is not a tool for securing the internals of a native mobile app or an authenticated clinical system, and we won't claim otherwise. What this case reinforces for the surface we do govern is straightforward: wherever web-based tracking tags are deployed on patient-facing pages, they need to be blocked before consent. The web layer was central to Advocate Aurora's exposure, and it is exactly the layer a consent pixel addresses.
Would a plaintiff firm find pixels on your patient-facing pages?
Advocate Aurora's exposure spanned its patient-facing web properties. See which trackers fire before consent on your site, in about 10 seconds — the exact surface these cases target. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then a 14-day free trial, no credit card, from $8.99/mo
Where it stands
This case is fully resolved:
- Settlement fund: $12,225,000, non-reversionary, covering class payments, fees, and administration.
- Per-claimant payment: up to $50; over 500,000 claimants filed valid claims.
- Final approval: granted July 10, 2024, by the U.S. District Court for the Eastern District of Wisconsin, following the consolidation of several suits into In re Advocate Aurora Health Pixel Litigation.
- Attorneys' fees: the court reduced the fee award to approximately $2.8 million (about 30% of the net fund) — a notable detail, as the court trimmed the request rather than rubber-stamping it. Named class representatives received $3,500 each.
- Class: individuals who visited Advocate Aurora's website, LiveWell app, or MyChart portal between October 24, 2017, and October 22, 2022.
- Remediation: Advocate Aurora has disabled or removed the tracking tools from its website, app, and patient portal.
Advocate Aurora Health denies any wrongdoing and agreed to settle to avoid the cost and uncertainty of continued litigation. No court decided the merits.
How Advocate Aurora fits the 2026 landscape
Advocate Aurora is one of the highest-patient-count cases in the wave. Since 2023, US healthcare organisations have reportedly paid $100M+ across roughly 19 analysed pixel cases, and the consolidated In re Meta Pixel Healthcare Litigation gathers dozens of hospital-system defendants. The Markup's 2022 investigation found the Meta Pixel on 33 of the 100 largest US health systems. What Advocate Aurora contributes is scale — roughly 2.5 million people — and the self-reported origin.
| Factor | Advocate Aurora | Sutter | MGB |
|---|---|---|---|
| How it started | Self-reported breach to HHS | Plaintiff-driven | Plaintiff-driven |
| Class size | ~2.5 million | Undisclosed | Large (38 providers) |
| Surface | Website, app & portal | Portal login page | Public sites |
| Legal theory | Wiretap + SCA + state + common law | CIPA + confidentiality | Invasion of privacy |
| Settlement | $12.25M | $21.5M | $18.4M |
| Status | Final (Jul 2024) | Final (Mar 2026) | Final (Jan 2022) |
The comparison underscores a point that runs through the whole series: the specific statute varies, but the exposure is consistent. A self-reported incident, a plaintiff-discovered tracker, or a journalist's investigation can each seed a multi-million-dollar case from the same underlying fact — tags transmitting patient data before consent.
Why this case matters for website operators
First: breach reporting and litigation risk are linked. Advocate Aurora's own breach notice — the responsible, compliant act — became the foundation for the class actions. If your tracking configuration could ever require a breach disclosure, that same disclosure can invite litigation. The way to avoid both is to not create the exposure in the first place.
Second: scale is set by your traffic, not your intent. A single tracking decision applied across a health system's web properties reached ~2.5 million people. Exposure scales with how many people load the instrumented pages, which for a large provider is enormous — and entirely independent of whether anyone intended harm.
Third: specific data makes the harm concrete. Appointment times, physician identity, and procedure information are not abstract. When a pixel transmits that a named person has a cardiology appointment on a given date, the alleged privacy harm is easy to articulate — which strengthens a plaintiff's case.
Fourth: removing the tags afterward doesn't undo the class period. Advocate Aurora removed the trackers, but the class period still ran five years, from 2017 to 2022. Remediation stops future accrual; it doesn't erase the past.
What this means for your site
The controls that address this are technical, not legal:
- Block before consent on every patient-facing page. Meta Pixel, Google Analytics, and similar web tags should not fire until the visitor affirmatively agrees — especially on pages for finding doctors, booking appointments, or reading about procedures.
- Treat appointment and scheduling pages as sensitive. Any page that ties a person to a specific service, provider, or procedure carries concrete privacy exposure. Those are exactly the conversion-focused pages teams most want to instrument.
- Audit across web, and know your app's separate risk. A consent pixel governs your web layer thoroughly; native apps and authenticated systems are a distinct workstream that needs its own review. Don't assume one control covers all three surfaces.
- Inventory inherited tags. A class period from 2017 shows how long-lived this risk is. Old tags nobody remembers are the classic trigger.
- Keep an auditable consent log. Timestamped proof of affirmative consent is the record that shortens these disputes.
ConsentPixel — Privacy · Verified blocks Meta, Google, and other third-party trackers at the browser level until the visitor consents — across your patient-facing web pages, including the appointment and doctor-finder pages these cases target — and logs each decision. It governs the web layer; native apps and internal clinical systems remain a separate matter.
Frequently asked questions
What is the Advocate Aurora Health tracking pixel lawsuit about?
It is a consolidated class action, In re Advocate Aurora Health Pixel Litigation, resolved in the U.S. District Court for the Eastern District of Wisconsin. The plaintiffs alleged that Advocate Aurora used Meta Pixel, Google Analytics, and other tracking tools on its website, LiveWell app, and MyChart patient portal, and that those trackers transmitted patients' information — including appointment times, physician identity, procedures, IP addresses, and insurance information — to third parties like Meta and Google without consent. The class covered people who used those properties between October 24, 2017, and October 22, 2022. Advocate Aurora denies wrongdoing and has since removed the tracking tools.
How much was the Advocate Aurora settlement, and is it final?
The settlement was $12,225,000 — commonly reported as "$12.25 million" — with each valid claimant eligible for up to $50; more than 500,000 claims were filed. It is fully final: the U.S. District Court for the Eastern District of Wisconsin granted final approval on July 10, 2024. Notably, the court reduced the attorneys' fee award to approximately $2.8 million, about 30% of the net fund, rather than granting the full amount requested. Named class representatives received $3,500 each. Advocate Aurora admitted no wrongdoing and settled to avoid the cost and uncertainty of continued litigation.
How did the Advocate Aurora case start?
Unusually, it began with the health system reporting itself. In October 2022, Advocate Aurora posted a data-breach notification and reported the incident to the U.S. Department of Health and Human Services' Office for Civil Rights, disclosing that its tracking technologies may have transmitted patient information to third-party vendors; its HHS filing referenced a patient base of up to roughly three million people. Several class action lawsuits were filed after that self-disclosure and were then consolidated into a single proceeding. So the breach notice the organisation issued to meet its reporting obligations effectively became the basis for the litigation that followed — a reminder that responsible breach reporting does not resolve the underlying exposure.
What laws did the Advocate Aurora case involve?
The consolidated complaint stacked several theories. At the federal level, it invoked the Wiretap Act (18 U.S.C. § 2511) and the Stored Communications Act. It added state wiretap laws, including Illinois (720 ILCS 5/14-2) and Wisconsin, reflecting the health system's footprint. It also brought common-law claims for invasion of privacy, breach of fiduciary duty, and unjust enrichment. HIPAA was referenced as the standard for the duty allegedly breached, but because HIPAA has no private right of action, patients could not sue under it directly — the actionable claims were the wiretap, stored-communications, and common-law theories. This multi-statute stacking is a common feature of healthcare pixel litigation.
Was the patient portal itself tracked in this case?
According to the allegations and the health system's own breach notice, the tracking tools were present not only on the public website but also on the LiveWell app and the MyChart-integrated patient portal. This is broader than some pixel cases, which concern only public pages. It's worth being precise about the boundary: a website consent tool like ConsentPixel governs web-based tracking on your pages — blocking third-party tags before consent — and is central to the web layer that featured heavily here. It is not a tool for securing the internals of a native mobile app or an authenticated clinical system; those are separate workstreams. The lesson that transfers directly is that web-based tracking tags on patient-facing pages should be blocked before consent.
What should my website do to avoid a claim like this?
Block Meta Pixel, Google Analytics, and similar web trackers until the visitor affirmatively consents, and pay particular attention to appointment, scheduling, and doctor-finder pages, since those tie a person to a specific service and make the alleged harm concrete. Audit every web property you operate, and treat native apps and authenticated systems as separate reviews rather than assuming one control covers them. Look hard at inherited and legacy tags — Advocate Aurora's class period ran from 2017, so old tags create long-tail exposure. Keep a timestamped consent log. And note that removing trackers later, as Advocate Aurora did, stops future accrual but doesn't erase a past class period. This is general information, not legal advice.
Related cases & reading
Sources
- National Law Review / Robinson & Cole (Data Privacy + Security Insider), "Advocate Aurora Health $12.2M Pixel Litigation Settlement Approved by Court" — final approval July 10, 2024 (E.D. Wis.), ~2.5M people, $50/claimant to 500,000+, data categories.
- HIPAA Journal, "Advocate Aurora Health Settles Pixel Lawsuit for $12.25 Million" — $12,225,000 fund, class period Oct 24 2017–Oct 22 2022, ~2.5M class, tools removed.
- Milberg (class counsel), "Aurora Health Agrees To $12.25M Settlement in Tracking Pixel Suit" — Oct 2022 HHS breach notification, ~3M patient base referenced, data categories, class counsel.
- Hamilton Lincoln Law Institute, "In re Advocate Aurora Health Pixel Litigation" — final approval and fee award reduced to $2.8M (30% of net fund).
- Top Class Actions, "Advocate Aurora Health pixel tracking $12.2M class action settlement" — website/LiveWell app/MyChart portal, deadlines, final approval July 10, 2024.