ConsentPixel – Privacy · Verified

Healthcare · Settlement Roundup · 2026

Healthcare Pixel Settlements in 2026: The Payouts — and What a CMP Actually Governs

The healthcare pixel settlement wave has crossed from a trickle of filings into a steady stream of nine-figure payouts. Kaiser Permanente alone agreed to as much as $47.5 million; Sutter, Advocate Aurora, Mass General Brigham and Penn Medicine each settled in the eight figures; and a 2026 wave of smaller systems is settling every month. Almost none of these were private HIPAA lawsuits. This is the full roundup — the amounts, why they settle the way they do, and the honest limits of what a consent tool can and can't fix.

CPConsentPixel Team Updated September 2026 17 min read Information, not legal advice
$47.5M
Kaiser Permanente's settlement — the largest healthcare tracking payout, covering 13.4 million members
No HIPAA suit
HIPAA has no private right of action — these settle on wiretap, consumer-health-data and contract claims instead
One pattern
A tracker on a patient portal or booking flow sends identifiable activity to a vendor without consent

Key takeaways

  • The payouts are large and recurring. Kaiser up to $47.5M, Sutter $21.5M, Mass General Brigham $18.4M, Advocate Aurora $12.25M, Penn Medicine up to $9.5M — plus a 2026 wave of smaller systems settling in the low millions.
  • They aren't private HIPAA lawsuits. HIPAA has no private right of action, so patients sue under state wiretap laws, consumer-health-data laws (Washington's MHMDA has its own private right of action), negligence and contract instead.
  • The fact pattern is almost always the same: a tracker — Meta Pixel, Google Analytics, or a session recorder — on an authenticated patient portal or a booking/intake flow, transmitting identifiable activity to a third party without consent or a BAA.
  • The 2026 wave hit smaller operators. Plaintiff firms now file template complaints after a quick site scan, so mid-size clinics, telehealth and behavioral-health providers are being named, not just big systems.
  • A CMP governs the mechanism these cases turn on — but not HIPAA itself. No consent tool makes a site "HIPAA compliant." What it does is control and prove consent before trackers fire, which is the specific element nearly every one of these settlements is built on.

The 2026 healthcare pixel settlement wave

For four years, plaintiffs' firms have been suing hospitals and health systems over the tracking technologies on their websites — and in 2026, those suits are converting into settlements at a striking pace. Cumulative disclosed healthcare tracking settlements are well into nine figures, and new ones are announced almost every month. The dollar figures are large enough to reach a hospital board, and the fact pattern behind them is consistent enough that any provider running a patient portal should recognize the risk.

Here's the pattern that recurs in nearly every case: a healthcare organization places a common marketing or analytics tracker — the Meta Pixel, Google Analytics, or a session-replay tool — on a page that touches patient information, most often an authenticated patient portal (a MyChart login), an appointment-booking flow, or an intake form. That tracker quietly transmits identifiable activity to a third party like Meta or Google, without the patient's consent and without a Business Associate Agreement covering the vendor. Multiply that by every visitor to the portal, and you have a class of hundreds of thousands — sometimes millions — of patients. That's the whole engine, and it's remarkably uniform across the settlements below.

The settlements, biggest first

Every figure below reflects publicly reported settlement amounts as of September 2026; several are proposed and awaiting final court approval, and amounts can change. Companies settled without admitting wrongdoing except where noted. For the live, all-verticals case list, see our CIPA Lawsuit Tracker.

OrganizationAmountWhat was trackedLegal theory
Kaiser Permanente$46M–$47.5MPortals + apps, 13.4M membersECPA, CIPA, CMIA, negligence, contract
Sutter Health$21.5MPatient portal + marketing siteCIPA §631
Mass General Brigham$18.4MPublic hospital websitesCommon-law invasion of privacy
Advocate Aurora Health$12.25M~2.5M patients, MyChartFederal Wiretap Act
Penn Medicineup to $9.5MmyPennMedicine portalPennsylvania WESCA wiretap
BetterHelp (FTC)$7.8MMental-health intake → ad platformsFTC Act §5
Wellstar Health System$4.25M~870k patients, Wellstar MyChartConsent & disclosure claims
Inova Health$3.1MHealthcare site → vendorsCIPA §631
LifeStance Health$3.03MBehavioral-health booking toolConsent & disclosure claims
LiveHealth Online$2MTelehealth platformWebsite tracking
Call-On-Doc$1.8MTelehealth platformConsent & disclosure claims
Cone Health$1.765M375k people, MyChart + formsHIPAA-derivative + NC wiretap
GoodRx (FTC)$1.5MPrescription data → pixels/SDKsFTC Health Breach Notification Rule
Concord Hospital$800KWebsite tracking toolsNew Hampshire wiretap statute
Emanate Health$777KPortal + form + schedulingConsent & disclosure claims

Amounts as publicly reported, September 2026; several are proposed and pending final approval. Banner Health's settlement is structured as $20 plus a year of privacy monitoring per class member (~1,028,000 people) rather than a single announced fund. One outlet reported Wellstar at $4.5M; the court settlement fund and claim materials state $4.25M, used here. Verify current details before relying on any figure.

The eight-figure anchors

Kaiser Permanente ($46M–$47.5M) is the largest, and instructive. After an internal investigation in October 2023, Kaiser self-disclosed that tracking technologies on its websites and apps may have transmitted the data of 13.4 million members to Google, Microsoft Bing, X and Adobe — the second-largest healthcare data breach reported in 2024. That self-disclosure seeded the class action, which consolidated claims under the federal ECPA, California's CIPA and Confidentiality of Medical Information Act, negligence, invasion of privacy and multiple state laws. Payments are expected in the $20–$40 range per claimant, but across 13.4 million people the total reaches up to $47.5 million.

Sutter Health ($21.5M) settled over pixels on its patient portal and marketing site that transmitted protected health information to vendors without consent, providing roughly $90 per class member. Mass General Brigham ($18.4M) is one of the cases that started the wave — an eight-figure payout over cookies and pixels on public hospital websites, finalized in early 2022 before the trend accelerated. Advocate Aurora Health ($12.25M) covered ~2.5 million patients and, like Kaiser, began with the health system's own self-reported breach to HHS. Penn Medicine (up to $9.5M) settled over Meta and Google pixels on the myPennMedicine portal — notably under Pennsylvania's WESCA wiretap law, not California's CIPA, a reminder that this is a fifty-state problem.

The 2026 wave — smaller systems, same pattern

Wellstar Health System ($4.25M) is a textbook 2026 case: Meta Pixel and Google trackers on Wellstar.org and the Wellstar MyChart portal, affecting ~870,000 patients. A judge allowed some claims to proceed after finding Wellstar allegedly went "beyond the scope of patients' permission" — receiving enhanced advertising services rather than cash for the data. LifeStance Health ($3.03M) is among the most sensitive: a major outpatient mental-health provider whose booking tool allegedly signaled treatment for conditions like depression, PTSD and bipolar disorder to Meta and Google. Cone Health ($1.765M) covered 375,027 people over MyChart and form tracking, brought under HIPAA-derivative claims and North Carolina's Electronic Surveillance Act. And Emanate Health ($777K) shows how far down the wave now reaches — a mid-size system settling over its portal, forms and scheduling pages.

The two FTC actions round out the picture and point at a regulator, not a class. BetterHelp ($7.8M) was the first FTC action to return funds for health data, over sharing mental-health intake with Facebook and Snapchat — plus a ban on sharing health data for ads. GoodRx ($1.5M) was the first-ever enforcement of the FTC's Health Breach Notification Rule, over prescription data shared via Meta, Google and Criteo pixels.

Why healthcare gets hit hardest

Pixel litigation touches every industry, but healthcare produces the biggest settlements and the most cases — for structural reasons worth understanding, because they explain why this isn't slowing down.

1The trackers were nearly universalOne widely-cited study found roughly 99% of US hospitals had tracking tools on their websites. These were installed for ordinary marketing and analytics reasons, years before anyone framed them as a legal risk — so the exposure is broad and pre-existing across almost the entire sector.
2Authenticated portals connect activity to identityThe moment a patient logs into MyChart, the system knows who they are — so their page views, messages, and appointment details are tied to a named person and become, in effect, protected health information. A tracker on that page transmits identifiable health activity, which is far more sensitive than an anonymous marketing-page visit.
3Every portal visitor is a class memberBecause the tracker fires for everyone who uses the portal, the class is enormous — Kaiser 13.4 million, Banner ~1 million, Cone 375,000. Even a modest per-person payment multiplies into millions, which is exactly what makes the class-action model work financially for plaintiffs' firms.
4Self-reported breaches hand plaintiffs the caseBoth Kaiser and Advocate Aurora self-disclosed their tracking to regulators and notified patients — which then seeded the class actions. Doing the responsible thing under HIPAA's breach-notification rules effectively published the roadmap for the lawsuit.

Put those together and healthcare is uniquely exposed: near-universal deployment, on pages where activity is identifiable and sensitive, at a scale that guarantees a large class, often with a self-reported breach already on the record. The recurring fact pattern looks like this:

The recurring fact pattern behind the settlements 🔒 Patient logs intothe portal / books 📍 Tracker firesMeta Pixel · GA · replay → 3rd-party vendorno consent · no BAA = class actionevery visitor The element every case turns on: identifiable activity reached a vendor without consent

Why they settle without a private HIPAA suit

Here's the point that surprises people, and it's the key to understanding the whole wave: almost none of these are HIPAA lawsuits, because patients can't file one. HIPAA has no private right of action — an individual cannot sue a provider simply for violating HIPAA. Only the HHS Office for Civil Rights can enforce HIPAA directly. So how are patients recovering tens of millions of dollars?

They sue under other laws, using HIPAA as the yardstick rather than the cause of action. The recurring legal theories are:

§State wiretap lawsCalifornia's CIPA (§631), but also North Carolina's Electronic Surveillance Act (Cone Health), New Hampshire's wiretap statute (Concord), Pennsylvania's WESCA (Penn Medicine), and Maryland's Wiretapping Act (cited in Kaiser). The theory: the tracker intercepted a communication without all-party consent.
The federal Wiretap Act (ECPA)Used in Advocate Aurora and Kaiser — the federal analog to the state wiretap theories.
🩺Consumer-health-data laws with a private right of actionWashington's My Health My Data Act (MHMDA), effective March 2024, regulates "consumer health data" beyond HIPAA and — crucially — includes a private right of action. Similar laws in Connecticut and Nevada give plaintiffs statutory hooks that don't require proving a HIPAA violation at all.
📄Common law: negligence, invasion of privacy, breach of contractMass General Brigham settled on common-law invasion of privacy. Courts have accepted that patients reasonably expect a provider won't transmit their medical inquiries to advertisers — a fiduciary-like duty the provider breaches by deploying unconsented tracking.

Where does HIPAA come in, then? As the standard of care. The HHS OCR tracking guidance is used to argue the provider "knew or should have known" its trackers were transmitting PHI — which supports the negligence and breach claims. (That guidance was narrowed for public pages by AHA v. Becerra but left fully intact for authenticated portals, exactly where these cases live — we cover that ruling in detail in our HHS OCR tracking guidance explainer.) The practical upshot: you can't be sued for HIPAA directly, but the same conduct HIPAA prohibits becomes the basis for a stack of claims you can be sued for — and the settlements show what that's worth.

Is a tracker running on your patient portal right now?

Every settlement above started with a tracker firing where it shouldn't. See which third-party trackers load on your site — and before consent — in about 10 seconds, no account. It's the same scan a plaintiff's firm runs first.

Scan your site free →

The 2026 shift: smaller operators, real payouts

Two things changed in 2026, and both raise the stakes for the average provider.

First, the wave moved down-market. The early cases targeted the giants — Kaiser, Advocate Aurora, Mass General Brigham, UCSF. But plaintiffs' firms have since built template complaints that can be filed with minimal customization after a simple scan of a provider's website reveals a pixel deployment. That industrialized the process, and the 2026 docket reflects it: mid-size specialty practices, fertility clinics, behavioral-health providers, substance-use-disorder centers, and regional systems like Cone and Emanate. "We're too small to be a target" stopped being true the moment a lawsuit could be generated from an automated scan.

Second, the cases are converting from filings into payouts. For a while, healthcare tracking was mostly lawsuits; in 2026 it's settlements, with claim deadlines and fairness hearings stacking up across the calendar — Wellstar's claims close in November, Cone's in October, LifeStance's in September. The money is now real and flowing, which changes the calculus from "a risk we're watching" to "a cost the sector is actively paying." And because analysts estimate the all-in cost of a serious pixel incident above $5 million for an average hospital once you add legal defense, board scrutiny and reputational harm, the prevention math is stark: a tag audit and a consent layer cost a fraction of a single settlement.

What a CMP actually governs — and what it doesn't

This is the part to be scrupulously honest about, because healthcare is where overclaiming does the most damage. A consent management platform — ConsentPixel included — is not a HIPAA compliance solution, and no vendor should tell you it is. Here's the clear line between what a consent layer governs and what it doesn't.

✓ What a CMP governs

Exactly the mechanism these settlements turn on. It blocks non-essential third-party trackers until the visitor consents (the "without consent" element every case alleges); it scans and shows what fires and where — authenticated vs public — so you can see a portal leak before a plaintiff does; it honors opt-out signals like Global Privacy Control; and it keeps timestamped, verifiable consent records — the evidence that you didn't fire the tracker, and can prove it.

✗ What a CMP does NOT do

It does not sign a Business Associate Agreement, and it is not a HIPAA authorization mechanism. It doesn't make your site "HIPAA compliant" — that's a broader organizational and legal obligation (BAAs, risk analysis, safeguards, workforce training). It can't see or govern PHI your server sends to a vendor behind the scenes. And it doesn't replace the rule that non-BAA tools like the Meta Pixel and Google Analytics simply shouldn't run on authenticated or PHI-handling pages at all.

So where does that leave a consent layer in the healthcare picture? It governs the consent-and-disclosure mechanism that nearly every settlement on this page is built on — the tracker that fired without permission. That's necessary, but it is not sufficient on its own: it's one layer of a healthcare privacy program, alongside keeping non-BAA analytics off patient-facing pages (see HIPAA-compliant analytics), keeping session-replay tools off portals entirely (see session replay on patient portals), signing BAAs where PHI genuinely flows, and documenting a risk analysis with counsel. A CMP closes the specific gap the plaintiffs exploit; the rest of the program closes the rest.

That honesty is the point. If a consent tool could single-handedly prevent every case above, these wouldn't be settling for tens of millions — the problem is bigger than any one tool. But look back at the fact pattern: identifiable activity reached a vendor without consent. Controlling and proving consent before trackers fire is the one lever that directly addresses that element, on the pages where it matters, with evidence you can produce later. That's what ConsentPixel — Privacy · Verified is built to do — no more, and no less.

What healthcare organizations should do now

The settlements make the remediation checklist concrete. None of it is exotic; it's the specific set of moves that would have prevented most of the cases above.

1Map authenticated vs public pagesIdentify every page behind a login and every page that collects health information — portals, booking, intake, symptom checkers. Treat these as no-tracker zones for anything non-essential or non-BAA. This is where the guidance still fully applies and where the settlements live.
2Get the non-BAA tools off patient-facing pagesMeta and Google won't sign BAAs for their pixel and analytics products, so those can't lawfully receive PHI — remove them from portals, booking flows and health-information forms entirely.
3Gate the rest behind consent — and honor opt-outsOn public pages, hold non-essential trackers until the visitor consents, and honor Global Privacy Control. This directly addresses the "without consent" element every case alleges.
4Scan continuously — you can't govern what you can't seeTrackers get added through tag managers and forgotten; a marketing pixel ends up on the portal login. Continuous scanning catches the leak before a plaintiff's automated scan does.
5Keep proof, and do the broader HIPAA work with counselMaintain timestamped consent records as evidence, and — separately from any consent tool — sign BAAs where PHI flows, document a risk analysis, and train staff. The consent layer is one piece; the HIPAA program is the rest.

Frequently asked questions

How much are healthcare pixel settlements in 2026?

They range widely. The largest is Kaiser Permanente at up to $47.5 million, covering 13.4 million members. Other eight-figure settlements include Sutter Health ($21.5M), Mass General Brigham ($18.4M), Advocate Aurora ($12.25M) and Penn Medicine (up to $9.5M). A 2026 wave of smaller systems has settled in the low millions or high six figures — Wellstar ($4.25M), LifeStance ($3.03M), Inova ($3.1M), Cone Health ($1.765M) and Emanate Health ($777K), among others. Per-claimant payments are typically modest (often $20–$40), but the class sizes make the totals large. Figures are as publicly reported in September 2026 and several are pending final approval.

Can patients sue a hospital under HIPAA for pixel tracking?

No — HIPAA has no private right of action, so an individual cannot sue a provider simply for a HIPAA violation; only the HHS Office for Civil Rights enforces HIPAA directly. That's why the healthcare pixel settlements are built on other laws: state wiretap statutes (like California's CIPA, North Carolina's Electronic Surveillance Act, or Pennsylvania's WESCA), the federal Wiretap Act, consumer-health-data laws such as Washington's My Health My Data Act (which does have a private right of action), and common-law claims like negligence and invasion of privacy. HIPAA and the OCR tracking guidance are used as the standard of care to argue the provider knew or should have known. This is general information, not legal advice.

What do these cases have in common?

A remarkably consistent fact pattern: a common tracker — the Meta Pixel, Google Analytics, or a session-replay tool — placed on a page that touches patient information, most often an authenticated patient portal (a MyChart login), an appointment-booking flow, or an intake form. The tracker transmits identifiable activity to a third party like Meta or Google without the patient's consent and without a Business Associate Agreement covering that vendor. Because the tracker fires for every portal visitor, the class becomes enormous. The element every case turns on is the same: identifiable activity reached a vendor without consent.

Does a consent tool make my healthcare site HIPAA compliant?

No, and any vendor claiming otherwise is overstating it. No consent management platform, ConsentPixel included, makes a site "HIPAA compliant" — that's a broader organizational and legal obligation involving Business Associate Agreements, a risk analysis, safeguards and workforce training. A consent tool does not sign a BAA and is not a HIPAA authorization mechanism. What it does govern is the specific mechanism these settlements turn on: blocking non-essential trackers until consent, showing what fires and where, honoring opt-out signals, and keeping verifiable consent records. It's a necessary layer for the consent element, not the whole HIPAA program.

Why is healthcare targeted more than other industries?

Several structural reasons. Tracking tools were nearly universal — one study found roughly 99% of US hospitals had them on their websites. Authenticated portals connect activity to a known patient, so the data is identifiable and sensitive. Every portal visitor becomes a class member, producing enormous classes (Kaiser 13.4 million, Banner ~1 million). And several systems self-disclosed their tracking to regulators under HIPAA's breach-notification rules, which then seeded the class actions. Together those factors make healthcare uniquely exposed and its settlements uniquely large.

Are smaller healthcare providers at risk, or just big systems?

Increasingly, smaller providers. The early cases targeted the giants, but plaintiffs' firms have developed template complaints that can be filed after a simple automated scan of a provider's website reveals a pixel. The 2026 wave reflects that shift — mid-size specialty practices, fertility clinics, behavioral-health providers, telehealth companies and regional systems are all being named and settling. If your site runs a patient portal or a booking flow with common trackers on it, size is no longer much protection. This is general information, not legal advice.

The bottom line

The healthcare pixel settlement wave is no longer a warning — it's a bill the sector is actively paying, from Kaiser's $47.5 million down to six-figure deals at regional systems, with new settlements landing monthly. And the striking thing is how uniform they are: almost none is a private HIPAA suit, because there's no such thing; they're wiretap, consumer-health-data, negligence and contract claims, all built on one element — a tracker that sent identifiable patient activity to a vendor without consent.

That uniformity is also the opportunity. You can't buy your way out of HIPAA with a tool, and no honest vendor will tell you otherwise. But the specific gap the plaintiffs exploit — trackers firing without consent, on the pages where activity is identifiable — is exactly the gap a consent layer is built to close and prove. Get the non-BAA tools off patient-facing pages, gate the rest behind consent, keep the receipts, and do the broader HIPAA work with counsel.

The providers writing eight-figure checks all had the same thing in common. So does the fix.

See what's firing on your patient-facing pages

Every settlement here started with a tracker firing where it shouldn't. ConsentPixel — Privacy · Verified scans what fires across your pages, blocks non-essential trackers before consent, and logs it as proof — the consent layer these cases turn on. It's not a BAA and won't make you "HIPAA compliant," and we'll always say so. Start with a free scan, then a 14-day trial.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified scans what fires on your live pages, blocks third-party trackers until affirmative consent, honors opt-out and Global Privacy Control signals, and logs each decision as immutable evidence — governing the consent-and-disclosure mechanism these settlements turn on. ConsentPixel is a consent and detection layer, not a law firm, not a Business Associate Agreement, and not a HIPAA authorization mechanism. This article is educational and not legal advice.

Information, not legal advice. This article summarizes publicly reported healthcare tracking settlements and related law for general educational purposes; it does not constitute legal advice or create an attorney–client relationship. Settlement amounts, class definitions, deadlines and approval status reflect public reporting as of September 2026 and change frequently — several settlements described here are proposed and pending final court approval, and companies settled without admitting wrongdoing except where a court finding is noted. One outlet reported Wellstar at $4.5M; the court settlement fund and claim materials state $4.25M, used here. HIPAA has no private right of action; the claims described arise under other statutes and common law. The $5,000-per-violation figure, where referenced, reflects statutory damages under California Penal Code §637.2. Verify any figure against primary sources and consult qualified counsel about your situation. ConsentPixel is not a law firm and does not sign Business Associate Agreements or make any site "HIPAA compliant."

Scroll to Top