ConsentPixel – Privacy · Verified

HomeCIPA Lawsuit Tracker › Mass General Brigham Tracking Pixel Litigation
Case Deep-Dive · Healthcare

Mass General Brigham Tracking Pixel Litigation

Before "pixel litigation" was a category anyone tracked, Mass General Brigham paid $18.4 million to settle a class action over cookies and tracking pixels on its public informational websites. Finalised in early 2022, it was one of the first eight-figure healthcare tracking settlements — the case that showed the plaintiffs' bar this theory could command serious money.

⚖️ Case snapshot
Case
John Doe and Jane Doe, et al. v. Partners Healthcare System, Inc., et al. (now Mass General Brigham)
Court
Suffolk Superior Court, Commonwealth of Massachusetts (Business Litigation Session) — Judge Brian A. Davis
Case No.
1984CV01651-BLS1
Legal theory
Common-law invasion of privacy (not a HIPAA claim; not a wiretap claim)
Class period
May 23, 2016 – July 31, 2021
Defendants
38 healthcare providers, incl. Mass General, Brigham & Women's, Dana-Farber, Mass Eye and Ear, Wentworth-Douglass
Tracking tech
Cookies, tracking pixels & web-analytics tools on public informational sites (massgeneralbrigham.org, massgeneral.org, brighamandwomens.org, dana-farber.org)
Settlement
$18.4 million — up to $100 per claimant
Status
Final approval granted January 20, 2022 (preliminary approval Sept 24, 2021). Case closed.
Defendant
Denies all allegations; no admission of liability; states no PHI was disclosed and no data breach occurred

What the case is about

Two anonymous plaintiffs, John Doe and Jane Doe, sued Partners Healthcare System, Inc. — since renamed Mass General Brigham — along with 38 affiliated healthcare providers, alleging that their public informational websites contained third-party analytics tools, cookies, and tracking pixels that caused visitors' browsers to divulge information about their web activity, and that this information was transferred and sold to third parties such as Facebook (Meta) and Google without consent.

The named sites were the health system's public-facing informational domains — massgeneralbrigham.org, massgeneral.org, brighamandwomens.org, and dana-farber.org — pages through which visitors could learn about services, programs, and procedures, or make appointments. Crucially, per the reporting, these sites do not require visitors to register or create accounts. This was public web browsing, not authenticated portal activity.

Why this case is the origin point

Look at the dates. The conduct dates back to May 2016. The settlement received final approval in January 2022months before The Markup published its landmark June 2022 investigation that found the Meta Pixel on a third of the largest US hospitals, the report usually credited with igniting the healthcare pixel wave.

In other words, Mass General Brigham settled for eight figures before "pixel litigation" was a named category anyone tracked. It is less a case in the wave than a case that helped start it — an early signal to the plaintiffs' bar that ordinary web-analytics tags on hospital sites could support a very large settlement.

The legal theory — invasion of privacy, plain and simple

This case is instructive precisely because its legal theory was not exotic. The later cases in this series lean on specific statutes — California's CIPA, Pennsylvania's WESCA, the federal ECPA. Mass General Brigham predates most of that. The claim was, at its core, a common-law invasion of privacy: the websites allegedly caused visitors' browsers to divulge their activity, and that activity was transferred and sold to third parties without consent.

Two features of how it was framed matter:

  • It was not a HIPAA case. The plaintiffs did not need to prove a HIPAA violation, and Mass General Brigham was adamant that no protected health information was disclosed and there was no data breach. The alleged harm was the unconsented disclosure of browsing activity on public pages — not the leak of medical records.
  • It was not a wiretap case. Unlike the CIPA and ECPA matters that followed, this was grounded in general privacy law, not an interception statute. The theory was simpler and older, which is part of why it was such an early mover.
The uncomfortable implication

Because the theory was general invasion of privacy — not a specific wiretap or health-data statute — it didn't depend on any of the legal machinery that later cases turned on. That makes it, in a sense, the most portable theory of all: it doesn't need a two-party-consent state, a federal interception claim, or a HIPAA hook. It needs only unconsented tracking on a site people reasonably expected to browse privately.

A health system also couldn't argue nobody expected privacy: a person browsing hospital and cancer-center websites, reading about procedures and booking appointments, has a strong privacy interest even on "public" pages. Context did the work, just as it later would in the California cases.

THE ORIGIN POINT MGB settles $18.4M Jan 2022 The Markup exposé Jun 2022 CIPA · WESCA · ECPA wave 2023–2026 The eight-figure settlement came first — the statutes and the headlines followed

Mass General Brigham's settlement was finalised before the investigation and the statutory theories that defined the wave — which is why it reads as an origin point rather than a chapter within it.

Would a plaintiff firm find pixels on your public pages?

Mass General Brigham's exposure sat on ordinary public informational pages. See which trackers fire before consent on your site, in about 10 seconds — the exact surface these cases target. It's the same scan a plaintiff firm would run.

Scan your site free →

No account needed · then a 14-day free trial, no credit card, from $8.99/mo

Where it stands

Unlike some matters in this series, this case is fully resolved and has been for years:

  • Settlement fund: $18.4 million, covering class payments, attorneys' fees, and administrative costs.
  • Per-claimant payment: up to $100, depending on the number of valid claims filed.
  • Preliminary approval: September 24, 2021, by Judge Brian A. Davis.
  • Final approval: granted January 20, 2022, by the Suffolk Superior Court. The claim deadline had passed on December 15, 2021.
  • Class: Massachusetts residents and US residents who received medical care at Partners/Mass General Brigham in Massachusetts and visited the named informational websites between May 23, 2016, and July 31, 2021.
  • Settlement administrator: Angeion.

Mass General Brigham denied all allegations and admitted no liability, maintaining that class members suffered no injury, that no protected health information was disclosed, and that there was no data breach. It agreed to settle to avoid the cost and uncertainty of a trial and any appeals. The court did not rule on the merits.

How Mass General Brigham fits the 2026 landscape

If Sutter, Penn, and Inova are chapters in the healthcare pixel wave, Mass General Brigham is closer to the prologue. Since 2023, US healthcare organisations have reportedly paid $100M+ across roughly 19 analysed pixel cases, and the consolidated In re Meta Pixel Healthcare Litigation gathers dozens of hospital-system defendants. The Markup's 2022 investigation found the Meta Pixel on 33 of the 100 largest US health systems. Mass General Brigham's settlement predates nearly all of that activity — which is exactly its significance.

FactorMGB (2022)Sutter (2026)Penn / Inova (2026)
Legal theoryInvasion of privacyCIPA + confidentialityWESCA / ECPA wiretap
EraEarly landmark (pre-wave)Mid-waveMid-wave
SurfacePublic informational sitesPortal login pagePortal / public sites
Class period start2016 (oldest)20152021 / 2022
Settlement$18.4M$21.5M$9.5M / $3.15M
StatusFinal (Jan 2022)Final (Mar 2026)Preliminary / final

The through-line: the eight-figure settlement here, years before the statutory theories matured, is what made healthcare an obvious target. Later plaintiffs added CIPA, WESCA, and ECPA as sharper legal tools — but Mass General Brigham had already proven the commercial case.

Why this case matters for website operators

First: you don't need an exotic statute to be exposed. Mass General Brigham was a plain invasion-of-privacy claim — no wiretap law, no HIPAA hook. Unconsented tracking on pages people expected to browse privately was enough to support $18.4 million. Operators who assume they're safe because their state lacks a CIPA-style law should note that the earliest, largest healthcare settlement needed no such law.

Second: "public" pages are not low-risk pages. The sites here were public and account-free — the pages a marketing team feels most comfortable instrumenting. That comfort is exactly the trap. A person reading about cancer treatment or booking a cardiology appointment has a privacy interest regardless of whether the page sits behind a login.

Third: old tracking creates present liability. The class period reaches back to 2016. Tags placed years earlier, by people long gone, drove a multimillion-dollar settlement. This is the oldest class period in the series, and it's a warning about how far back exposure runs.

Fourth: scale multiplies through affiliates. The settlement named 38 providers. For any organisation with multiple brands, sites, or entities, a single tracking decision replicated across the portfolio multiplies the exposed population — and the settlement.

What this means for your site

The controls that would have addressed this are technical, not legal:

  • Don't treat "public" as "safe." Any page whose subject matter reveals something about the visitor — a condition, a procedure, a provider relationship — carries a privacy interest, login or no login. Those pages need no third-party marketing tags before consent.
  • Block before consent, everywhere. Cookies, pixels, and analytics tags should not fire until the visitor affirmatively agrees. The alleged disclosure only happens if the tag loads and transmits.
  • Audit across every property. A tracking decision copied across 38 sites becomes 38 sites' worth of exposure. Inventory every domain and subdomain you operate, not just the flagship.
  • Look at inherited and legacy tags. A 2016 class-period start means the risk is often a tag nobody remembers adding. You cannot govern a tracker you don't know is running.
  • Keep an auditable consent log. Timestamped proof of affirmative consent is the record that shortens these disputes.

ConsentPixel — Privacy · Verified blocks Meta, Google, and other third-party trackers at the browser level until the visitor consents — across every page and every property, including the public informational sites teams assume are low-risk — and logs each decision. It also surfaces the tags you inherited but never inventoried, which is where cases like this begin.

Frequently asked questions

What is the Mass General Brigham tracking pixel lawsuit about?

It is a class action, John Doe and Jane Doe, et al. v. Partners Healthcare System, Inc. (now Mass General Brigham), Case No. 1984CV01651-BLS1, in the Suffolk Superior Court of Massachusetts. The plaintiffs alleged that the health system's public informational websites — including massgeneralbrigham.org, massgeneral.org, brighamandwomens.org, and dana-farber.org — used cookies, tracking pixels, and analytics tools that caused visitors' browsers to divulge their web activity, and that this information was transferred and sold to third parties such as Facebook and Google without consent. Mass General Brigham denied all allegations, maintaining no protected health information was disclosed and no data breach occurred.

How much was the Mass General Brigham settlement, and is it final?

The settlement was $18.4 million, with each class member who filed a valid claim eligible to receive up to $100 depending on the number of claims. It is fully final and closed: the Suffolk Superior Court granted preliminary approval on September 24, 2021, and final approval on January 20, 2022. The claim deadline was December 15, 2021. The $18.4 million fund covered class payments, attorneys' fees, and administrative costs. Mass General Brigham admitted no liability and settled to avoid the cost and uncertainty of continued litigation.

Why is this case considered the start of the healthcare pixel wave?

Timing. The conduct dated back to May 2016, and the settlement received final approval in January 2022 — months before The Markup published its influential June 2022 investigation that found the Meta Pixel on a third of the 100 largest US hospitals, the report usually credited with igniting the surge of healthcare pixel litigation. Mass General Brigham settled for eight figures before "pixel litigation" was a named category. That made it an early proof point for the plaintiffs' bar: ordinary web-analytics tags on hospital websites could support a very large settlement, even without the specific wiretap or health-data statutes that later cases would use.

What law did the Mass General Brigham case use — was it a HIPAA or wiretap case?

Neither. Unlike the later California cases brought under CIPA or the federal cases brought under the ECPA, the Mass General Brigham claim was grounded in common-law invasion of privacy. It was not a HIPAA-led lawsuit — the plaintiffs did not need to prove a HIPAA violation, and the health system was adamant that no protected health information was disclosed and there was no data breach. It was also not a wiretap case. The theory was simply that unconsented tracking on the health system's public websites caused visitors' browsing activity to be disclosed and sold to third parties. That older, more general theory is part of why the case was such an early mover.

Were the affected websites patient portals or public sites?

They were public informational websites — massgeneralbrigham.org, massgeneral.org, brighamandwomens.org, and dana-farber.org — that, per the reporting, do not require visitors to register or create accounts. These were the pages through which visitors could read about services and procedures or make appointments, not authenticated patient portals. This is an important point for ordinary website operators: the exposure sat on the public marketing layer, the surface teams feel most comfortable instrumenting with analytics and advertising tags, not on a login-protected system.

What should my website do to avoid a claim like this?

Treat your public pages as in-scope, not just the obviously sensitive ones, and block cookies, pixels, and analytics tools until the visitor affirmatively consents — the alleged disclosure only happens if the tag loads and transmits. Because this case involved 38 affiliated providers, audit every domain and property you operate, not just the flagship site. Pay particular attention to inherited or legacy tags, since the class period reached back to 2016 and old tags are often the ones nobody remembers adding. Keep a timestamped consent log. This is general information, not legal advice, and it concerns your website's public layer rather than internal clinical systems.

Not legal advice. This article is an educational summary of public settlement documents and legal reporting, and does not constitute legal advice. The settlement received final approval on January 20, 2022, and the case is closed. Mass General Brigham (formerly Partners Healthcare System) denied all allegations and settled without any admission of liability; the court did not decide the merits, and the health system maintains no protected health information was disclosed and no data breach occurred. Verify details via the court docket (Suffolk Superior Court, No. 1984CV01651-BLS1) and consult a qualified attorney about your specific situation.

Sources

  1. Society of Corporate Compliance & Ethics (HCCA) / COSMOS, "Patient Privacy Court Case: February 2022" — Suffolk County Superior Court final approval (Jan 20, 2022), $18.4M, preliminary approval Sept 24, 2021.
  2. HIPAA Journal, "Mass General Brigham Settles 'Cookies Without Consent' Lawsuit for $18.4 Million" — 38 providers, class period May 23, 2016–July 31, 2021, up to $100 per claimant, public account-free sites, no PHI disclosed.
  3. Top Class Actions / claim notice — John Doe and Jane Doe, et al. v. Partners Healthcare System, Inc., No. 1984CV01651-BLS1 (Suffolk Super. Ct.); class definition and named websites.
  4. Osano, "Mass General to settle lawsuit over patient cookies" — Judge Brian A. Davis, preliminary approval, 38 healthcare entities, settlement administrator Angeion.
  5. Universal Hub, "If you got something in the mail about a 'cookie settlement'…" — class period, appointment/information pages, Facebook and Google.
Scroll to Top