ConsentPixel – Privacy · Verified

§
HomeBlogHealthcare › Can You Be Sued?
Healthcare · Legal Risk

Can You Be Sued for a HIPAA Violation?

It's the question that follows every pixel headline and breach notice: if my website mishandled health data, can someone actually sue me? The honest answer has two halves — a reassuring one about HIPAA, and a much less reassuring one about the state laws stacked on top of it. Here's exactly who can sue, under what law, and why website tracking is where the real litigation risk now lives.

By ConsentPixel TeamUpdated July 202613 min readInformation, not legal advice
The short answer

You cannot sue under HIPAA itself — it has no private right of action. A patient can't take you to court for a "HIPAA violation" directly; only regulators can enforce HIPAA.

But you can absolutely be sued for the same underlying conduct under state laws that do allow private lawsuits — California's CIPA and CMIA chief among them — plus common-law claims like negligence and invasion of privacy. For websites, that state-law layer is exactly where the pixel-and-tracking litigation wave is happening. This is general information, not legal advice.

If you run a healthcare website — a hospital, a clinic, a telehealth service, a health-adjacent app — you've probably felt a jolt of worry reading about eight-figure pixel settlements and demand letters. The natural question is blunt: can a patient actually sue me for this? The answer people repeat ("you can't sue for a HIPAA violation") is technically correct and dangerously incomplete. It's true you can't be sued under HIPAA. It's false that you can't be sued. Let's separate the two cleanly. None of this is legal advice — your exposure depends on your facts, your data, and your state, and you should confirm it with qualified counsel.

Why you can't sue under HIPAA itself

Start with the reassuring half, because it's real and worth understanding. HIPAA has no private right of action. That's a settled legal fact, not a gray area. An individual patient cannot walk into court and sue you for "violating HIPAA," no matter how clear the violation or how real the harm.

The reason is structural: Congress designed HIPAA as a regulatory scheme enforced by the government, not a basis for private lawsuits. Enforcement runs through three channels:

  • The HHS Office for Civil Rights (OCR) — investigates complaints, conducts compliance reviews, and imposes civil monetary penalties and corrective action plans. OCR has resolved thousands of cases since 2003, with a record enforcement year of about $28.7 million in 2018 (per HHS / HIPAA Journal).
  • State attorneys general — empowered to bring HIPAA enforcement actions on behalf of their residents.
  • The Department of Justice — pursues criminal cases for willful misuse of protected health information.

So when someone tells you "patients can't sue for HIPAA violations," they're right. If that were the whole story, healthcare litigation risk would be modest — a regulatory matter, not a courtroom one. But it isn't the whole story, and the gap between "can't sue under HIPAA" and "can't be sued" is exactly where organizations get blindsided.

The catch: the same facts, a different law

Here's the half that matters. The absence of a HIPAA private right of action doesn't make the underlying conduct un-sueable — it just means plaintiffs sue under other laws for the same facts. As one 2026 legal analysis put it plainly: even though a patient can't sue you under HIPAA, your HIPAA failures can absolutely be used against you in state court.

Think of HIPAA as setting the standard for how health data should be handled. When you fall short of that standard and someone is harmed, they don't need HIPAA's permission to sue — they reach for a state statute or a common-law tort that does let them into court, and they point to your HIPAA shortfall as evidence you failed to meet the expected standard of care. The federal floor becomes the yardstick; the state law becomes the weapon.

This is why "we're careful about HIPAA" is not the same as "we can't be sued." The lawsuits come through a different door — and for websites, that door is wide open.

State statutes that let patients sue directly

The most direct route into court is a state privacy statute that includes its own private right of action — something HIPAA withholds but many states grant. These are the laws doing the heavy lifting in health-data litigation:

  • CMIA (California's Confidentiality of Medical Information Act). Lets individuals sue directly for unauthorized disclosure of medical information, with nominal statutory damages reported around $1,000 per violation — without proof of actual harm. Its definition of "medical information" is broader than HIPAA's PHI, and class actions under it have settled for tens of millions.
  • CIPA (California Invasion of Privacy Act). A wiretapping statute now applied to website tracking, with a private right of action and statutory damages commonly cited at $5,000 per violation, or treble actual damages, under Penal Code § 637.2. This is the engine behind the website pixel wave.
  • Other state health-privacy and wiretap laws. States including Texas (with its medical privacy act) and Illinois have their own health-privacy regimes, and more than two dozen states have wiretapping statutes that plaintiffs are testing against websites. The patchwork is growing, and multi-state operators face several at once.

The through-line: each of these gives a private plaintiff — and a class of them — the standing HIPAA denies. That's what turns a regulatory concern into a class action.

Common-law claims and the negligence-per-se debate

Beyond statutes, plaintiffs reach for long-established common-law torts, using your HIPAA shortfall as evidence rather than as the claim itself:

  • Negligence — failing to protect health information with reasonable care. Courts frequently treat HIPAA as evidence of the applicable standard of care, so a HIPAA violation helps prove the provider was negligent.
  • Invasion of privacy — including intrusion upon seclusion or public disclosure of private facts, where sensitive medical information was exposed or disclosed.
  • Breach of confidentiality — the duty a provider owes a patient to keep medical information private. In the well-known Byrne v. Avery Center line of cases, a claim initially framed as a HIPAA violation where a claim initially dismissed as a HIPAA matter was allowed to proceed once framed as common-law negligence / breach of confidentiality, with HIPAA informing the standard of care.

There's an important nuance here that courts are split on: negligence per se. This is the argument that a HIPAA violation automatically establishes negligence. Many courts reject it — reasoning that letting a HIPAA violation serve as automatic negligence would be a backdoor to the private HIPAA lawsuit Congress didn't create (the Sheldon v. Kettering line of cases). But even where negligence per se fails, courts routinely allow HIPAA to come in as evidence of the standard of care in an ordinary negligence claim. Either way, the HIPAA violation ends up in front of the jury — the only question is whether it's automatic proof or persuasive evidence.

The practical upshot

You cannot be sued under HIPAA — but a HIPAA violation can be the centerpiece of a state-law lawsuit against you, whether as the basis for a CMIA or CIPA claim, or as evidence of negligence. The "no private right of action" shield protects the label, not the conduct.

Protect your site now

The lawsuits start with what fires before consent

Nearly every website tracking claim begins the same way: a tracker sending visitor data to a third party before consent. See exactly what fires on your site — the same scan a plaintiff's firm would run — or start protecting it today.

Scan needs no account · trial needs no credit card · from $8.99/mo · information, not legal advice

Why websites are the hot zone for these lawsuits

Of all the ways a health-data claim can arise, one now dominates: website and patient-portal tracking. The reason is that it's easy to allege, easy to prove, and easy to bring as a class action — and it doesn't require a data breach or any traditional "disclosure" at all.

The pattern is consistent across the litigation. A healthcare site runs third-party tags — a Meta Pixel, Google Analytics, an ad tracker, or a session-replay tool like Hotjar or FullStory — that fire the moment a page loads, transmitting the visitor's activity to third parties before the visitor has consented. Under CIPA, that pre-consent transmission is framed as unlawful interception. Under CMIA, the transmission of medical information without authorization is the violation. Neither requires a hacker or a breach — just a tag firing too early on a page about a health condition, an appointment, or a symptom search.

This is not hypothetical. Our CIPA Lawsuit Tracker documents dozens of these cases with more than 46 cases / $153.4M+ in disclosed settlements, and the healthcare examples are stark:

  • Sutter Health — a $21.5M settlement over third-party pixels on its patient portal and marketing site transmitting data without patient consent.
  • Advocate Aurora Health — a $12.25M settlement covering roughly 2.5 million patients, beginning with the system's own self-reported breach.
  • Mass General Brigham — an $18.4M settlement, one of the payouts that helped start the healthcare pixel wave.
  • Penn Medicine — an up-to-$9.5M settlement over pixels on its patient portal, brought under Pennsylvania's WESCA wiretap law rather than CIPA.

Notice the pattern: these are brought under wiretap, invasion-of-privacy, and state medical-privacy theories — not "HIPAA lawsuits," because there's no such thing as a private HIPAA lawsuit. They're the state-law layer doing exactly what this article describes.

So who can actually sue you — and for how much?

Pulling it together, here's the realistic map of who can bring what against a healthcare website, and why the state column is the one to worry about.

Who / whatUnder HIPAA?Under state law?
An individual patientNo — no private right of actionYes — CMIA, CIPA, negligence, privacy torts
A class of patientsNoYes — the pixel class actions
HHS Office for Civil RightsYes — penalties, corrective plans
State attorney generalYesYes — under state law too
Statutory damages without proving harmN/ACMIA ~$1,000/violation; CIPA ~$5,000/violation

The takeaway is uncomfortable but clarifying: the entity you can't be sued by directly (an individual, under HIPAA) is exactly the entity that can sue you under state law — and can do it as a class, with statutory damages, without proving anyone was harmed. That combination is what makes the website tracking wave so large.

The one thing plaintiffs still have to clear: standing

It would be misleading to suggest every website tracking suit succeeds — and honesty is the point here. Even with statutory damages and no harm requirement in the statute, a plaintiff in federal court still has to establish standing: a concrete injury the court will recognize. This is where many of these cases are actually won and lost, and courts have split sharply.

Some courts have dismissed website-tracking claims where the data captured was routine browsing metadata — IP address, device type, browser version — holding that generic metadata alone isn't the "embarrassing, invasive, or otherwise private" information a concrete injury requires. Others have let cases proceed where genuinely sensitive data was transmitted — health search terms, appointment details, medical conditions — because aggregating that into a profile resembles a traditional privacy harm. The dividing line, increasingly, is sensitivity: the more clearly health-related the intercepted data, the more likely a court treats it as a real injury. That's precisely why healthcare sites sit at the high-risk end — the data at issue is exactly the kind courts find concrete.

The practical implication isn't reassurance; it's focus. The defense that a claim lacks standing is real but uncertain, expensive to litigate, and weakest exactly where healthcare operates. Far cheaper and more reliable is to remove the factual basis for the claim in the first place — so there's no pre-consent interception to argue about.

How to reduce your exposure

Because the litigation risk runs through the state-law layer and concentrates on your website, the highest-leverage steps are practical and specific:

  1. See what fires before consent. Most exposure starts with trackers the site owner didn't know were running, or didn't know were firing before consent. A scan shows you the real picture — including on patient portals and authenticated pages, where the most sensitive activity happens.
  2. Block non-essential trackers until consent. This is the single most important technical fix. The tag must not load and transmit until the visitor opts in — not load-and-record-later. A tracker that fires before consent is the exact factual basis of a CIPA claim.
  3. Keep consent evidence. A timestamped, tamper-evident record showing consent was obtained before each tracker fired is the artifact that shortens or defeats a claim. Plaintiff firms and courts respond to demonstrable good-faith remediation.
  4. Handle the HIPAA layer separately. Where PHI genuinely flows to a vendor, that's a BAA / PHI-safe-path question for your counsel and HIPAA tooling — distinct from the state-law consent layer above.
  5. Document your good-faith efforts. Using a recognized consent tool and being able to show you respected visitors' choices goes a long way in reducing or settling a claim.

ConsentPixel — Privacy · Verified is built for that state-law consent layer: it blocks third-party trackers at the browser level until a visitor consents, honors opt-out signals, continuously scans what fires across your pages, and logs each consent decision as evidence. To be clear about our lane — because overclaiming to a healthcare buyer is the fastest way to lose trust — ConsentPixel is not a HIPAA product and does not make any website "HIPAA compliant." It reduces the state-law exposure (CIPA/CCPA/CMIA) where the tracking lawsuits actually happen, and it produces the consent evidence that helps if a claim ever comes. The HIPAA layer itself — BAAs, authorizations, PHI-safe data paths — you solve separately with counsel.

The bottom line

Can you be sued for a HIPAA violation? Not under HIPAA — it has no private right of action, so no individual patient can take you to court for a "HIPAA violation" itself. Enforcement of HIPAA belongs to OCR, state attorneys general, and the DOJ.

But that's only the label. You can absolutely be sued for the same conduct under state laws that do allow private lawsuits — CMIA and CIPA in California, similar laws elsewhere — and under common-law negligence and privacy claims where HIPAA sets the standard of care. For healthcare websites, that state-law layer is where the entire pixel-litigation wave lives: Sutter, Advocate Aurora, Mass General Brigham, Penn Medicine — none of them "HIPAA lawsuits," all of them very real.

So the honest reframe is this: "you can't sue for a HIPAA violation" is true and reassuring, and it's also the sentence that gets healthcare sites sued. The risk didn't disappear because HIPAA lacks a private right of action — it moved to the state laws stacked on top, and it concentrated on your website. Close that layer, and close it where it starts: what fires before consent.

Find your exposure before a plaintiff's firm does

The fastest way to see the risk this article describes is to scan your own site for trackers firing before consent — the exact pattern behind the CIPA and CMIA lawsuits. Free, no account, about 10 seconds.

Scan your site free →

Then a 14-day free trial, no credit card · from $8.99/domain/mo · information, not legal advice

CP
The ConsentPixel Team

We build prevention-first consent tooling that blocks trackers until visitors genuinely consent, continuously verifies what fires on your pages, and logs each decision as evidence. We cover the state-law consent and detection layers — honestly — and we'll always tell you plainly what sits outside our lane. This article is information, not legal advice; healthcare privacy litigation is evolving, so verify your specific exposure with qualified counsel. ConsentPixel — Privacy · Verified is not a law firm and does not make any website "HIPAA compliant."

Frequently asked questions

Can a patient sue me directly for a HIPAA violation?

No. HIPAA has no private right of action, so an individual cannot sue you in court for a "HIPAA violation" itself, regardless of how clear the violation or how real the harm. HIPAA is enforced by the HHS Office for Civil Rights, state attorneys general, and — for willful misuse — the Department of Justice. However, a patient can pursue the same underlying conduct through other laws: state privacy statutes that do allow private lawsuits (like California's CMIA and CIPA), or common-law claims such as negligence, invasion of privacy, and breach of confidentiality, often using your HIPAA shortfall as evidence of the standard of care. This is general information, not legal advice.

If HIPAA has no private right of action, how are hospitals getting sued over pixels?

Because those aren't HIPAA lawsuits — they're state-law lawsuits over the same conduct. The healthcare pixel cases are brought under wiretapping statutes (California's CIPA, Pennsylvania's WESCA), state medical-privacy laws (CMIA), and common-law invasion-of-privacy theories, none of which require HIPAA's permission to sue. Sutter Health settled for $21.5M, Advocate Aurora for $12.25M, Mass General Brigham for $18.4M, and Penn Medicine for up to $9.5M — all over website and portal trackers transmitting data without consent, and all under state or common-law theories rather than HIPAA itself. The absence of a HIPAA private right of action simply routes the litigation through state law.

What is "negligence per se" and why does it matter for HIPAA?

Negligence per se is the argument that violating a law automatically establishes negligence, without separately proving the defendant failed to act reasonably. Plaintiffs have tried to use HIPAA violations this way — arguing a HIPAA breach is automatic negligence. Courts are split: many reject it (the Sheldon v. Kettering line), reasoning that allowing HIPAA to serve as automatic negligence would create the private HIPAA lawsuit Congress deliberately withheld. But even where negligence per se fails, courts routinely let HIPAA in as evidence of the applicable standard of care in an ordinary negligence claim. Either way, your HIPAA compliance ends up in front of the jury — the debate is only whether it's automatic proof or persuasive evidence.

Which state laws let patients sue over health data?

Several. California's Confidentiality of Medical Information Act (CMIA) allows individuals to sue for unauthorized disclosure of medical information, with statutory damages reported around $1,000 per violation and no need to prove harm. California's Invasion of Privacy Act (CIPA) allows suits over website tracking, with statutory damages commonly cited at $5,000 per violation or treble damages under Penal Code § 637.2. Other states — including Texas and Illinois — have their own health-privacy laws, and more than two dozen states have wiretapping statutes plaintiffs are testing against websites. Multi-state operators can face several of these at once. Because they carry private rights of action and statutory damages, these state laws, not HIPAA, are where the class actions happen.

Do I need to prove harm to be sued?

Often not, which is a large part of why these cases are so common. Under CMIA, statutory damages of roughly $1,000 per violation are available without proving actual harm, and under CIPA, statutory damages commonly cited at $5,000 per violation apply without proof of harm. That's what makes class actions viable: plaintiffs don't have to show each class member suffered a measurable loss, only that the unlawful conduct — such as a tracker firing before consent — occurred. Standing requirements still apply and courts have split on what counts as a concrete injury for website-tracking claims, but the absence of a harm requirement in the statutes themselves is a major driver of the litigation. This is general information, not legal advice.

What's the fastest way to reduce my litigation risk?

Scan your website to see what trackers fire before consent — it's free and takes about ten seconds. Because the litigation concentrates on pre-consent website tracking, the highest-leverage fix is to block non-essential trackers until a visitor genuinely opts in, rather than letting tags fire on page load. Keep a timestamped record proving consent came before each tracker fired, since demonstrable good-faith remediation helps reduce or settle claims. Solve the HIPAA layer — BAAs and PHI-safe data paths — separately with your counsel. Starting with the scan tells you where your exposure actually is before you spend anything fixing it. This is general information, not legal advice.

Not legal advice. This article is general information and does not constitute legal advice or create an attorney–client relationship. Whether you can be sued, by whom, and under what theory depends on your specific facts, the data involved, and your jurisdiction; health-privacy litigation is unsettled and evolving. The $5,000-per-violation figure reflects statutory damages under California Penal Code § 637.2; CMIA damages figures are as commonly reported; settlement figures are as publicly disclosed and may change. Verify your exposure with qualified counsel. ConsentPixel — Privacy · Verified is not a law firm and does not make any website "HIPAA compliant." It addresses the state-law consent and detection layer where website tracking claims arise.
Scroll to Top