ConsentPixel – Privacy · Verified

CIPA Case Deep-Dive

Sutter Health Tracking Pixel Litigation

Sutter Health paid $21.5 million over Google Analytics and the Meta Pixel running on a patient-portal login page. Nothing was tracked inside the portal. No usernames or passwords were shared. One page, before anyone logged in — and it produced one of the largest website-tracking settlements in US healthcare.

By ConsentPixel Team Published July 2026 11 min read
⚖️ Case snapshot
Court
Superior Court of California, Sacramento County (Judge Lauri A. Damrell)
Case No.
34-2019-00258072-CU-BT-GDS (Jane Doe I & II, et al. v. Sutter Health)
Class period
June 10, 2015 – March 20, 2020
Status (as of Jul 2026)
Settled — $21.5M, final approval judgment entered Mar 6, 2026
Tracking tech
Google Analytics · Meta Pixel · cookies, web beacons & JavaScript on the MyHealthOnline login page
Defendant
Sutter Health — California non-profit health system
On the case name. This matter is widely referred to as the Sutter Health tracking pixel litigation, but there is no consolidated "In re" proceeding by that name. The formal caption is Jane Doe I and Jane Doe II, et al. v. Sutter Health, No. 34-2019-00258072-CU-BT-GDS, in Sacramento County Superior Court. We use the correct caption throughout.

What the case is about

Two anonymous plaintiffs sued Sutter Health — one of California's largest non-profit health systems — alleging that it deployed third-party tracking, analytics, and advertising technologies on its web pages, and that those tools disclosed patients' personally identifiable information (PII) and protected health information (PHI) to third parties including Facebook and Google without consent.

The technologies named are the ones on a majority of the web: Google Analytics, the Meta Pixel, and assorted cookies, web beacons, and JavaScript. What makes this case singular — and far more dangerous than its headline suggests — is where they were running.

The detail that should stop every operator cold

The trackers at issue were on the MyHealthOnline portal login webpage. Per the settlement's own official FAQ, there is no allegation of any tracking or sharing from inside the portal, and no allegation that any user IDs or passwords were shared.

In other words: nothing behind the login was touched. No credentials leaked. No medical records transmitted. The exposure was one page — the screen a patient sees before they log in.

That single page cost $21.5 million. If your mental model of tracking risk is "the sensitive data is safe behind our login, so the marketing tags on the public pages are fine," this case is a direct refutation of it.

The reason is context. A person loading a health system's patient-portal login page is, by the act itself, revealing something: that they are a patient of that provider. When a third-party tracker fires on that page, the allegation is that it transmits that fact — tied to an IP address, a device, and potentially a Facebook account — to an advertising company. No diagnosis needs to change hands for the disclosure to be meaningful.

The legal theory — CIPA plus a confidentiality stack

The operative Fourth Amended Complaint stacked several theories. Two things stand out: CIPA anchors the claim, and the rest of the stack leans on the special relationship between a healthcare provider and its patients.

  • CIPA (Cal. Penal Code §631 et seq.) — California's wiretap statute. The theory: third-party trackers on the login page intercepted the contents of patients' communications with Sutter, in an all-party-consent state, without consent.
  • Intrusion upon seclusion — the privacy tort.
  • Breach of fiduciary duty of confidentiality — the claim available specifically because Sutter is a healthcare provider, not a retailer.
  • Violation of California's Unfair Competition Law (UCL).
  • Implied contract and breach of the covenant of good faith and fair dealing — the argument that patients were promised confidentiality.

This layering is the point. Even a defendant with a strong argument against the CIPA count must defend the confidentiality and contract theories too — and for a health system, the fiduciary framing is uniquely hard to shrug off. A retailer can argue nobody expected privacy while shopping. A hospital cannot make that argument about its own patients.

One page. Before the login. $21.5 million. Nothing inside the portal was tracked — and it didn't matter PORTAL LOGIN PAGE Patient loads the page 🔒 Google Analytics + Meta Pixel fire on load before any login, before consent WHAT IT REVEALS "This person is a patient of this health system" + IP address, device, possible Facebook match no diagnosis needed $21.5M settlement final Mar 2026 The page a visitor loads can itself be the sensitive disclosure. Blocking before consent is what breaks the chain.
The login page is the disclosure. Context, not content, created the exposure — which is why "our data is behind the login" was never a defense.

Where it stands (as of July 2026)

This case is over. Unlike most matters on the tracker, it has reached final judgment:

  • Settlement fund: $21,500,000, non-reversionary.
  • Preliminary approval: October 15, 2025.
  • Final approval hearing: February 27, 2026, before Judge Lauri A. Damrell.
  • Order and Judgment Granting Final Approval entered: March 6, 2026.
  • Class payments: pro rata, capped at $90 per claimant, no documentation required. Claim deadline passed May 5, 2026.
  • Court-approved fees and costs: attorneys' fees of $7,095,000, litigation costs of $216,639.11, and incentive awards of $10,000 to each Class Representative.
  • Cy pres: residual funds go to the Privacy Rights Clearinghouse and the AHIMA Foundation.

Class counsel were Kiesel Law LLP (Jeffrey A. Koncius, Nicole Ramirez Jones) and Simmons Hanly Conroy LLP (Jason "Jay" Barnes, Eric Johnson). Sutter Health denies all of the allegations — it denies that any patient information was shared with unauthorized third parties, denies any violation or breach, and maintains it did nothing wrong. The case never went to trial and no court decided the merits; the parties settled to avoid the risk and expense of continued litigation. Status is stated as of publication.

Plaintiffs allege that Sutter Health violated the California Invasion of Privacy Act … by disclosing patients' PII and/or PHI to third parties like Facebook and Google … on certain of its webpages, including the MyHealthOnline portal login webpage (but there is no allegation of any tracking or sharing from inside the MyHealthOnline portal and no allegation that any user IDs or passwords were shared). — Official settlement FAQ

How Sutter fits the 2026 landscape

Two features make this case a landmark rather than just another settlement.

It's a six-year case with a class period that predates the wave. Filed in 2019, over conduct dating back to June 2015, resolved with final judgment in March 2026. The tracking happened years before "pixel litigation" was a category anyone tracked. That's the retroactive trap: the analytics tags your team installed in 2016 and forgot about are actionable today, and the class period runs from whenever the tracking started — not from when you learned it was a problem.

Healthcare is the epicentre. Sutter settled alongside a broader wave: Lemonaid Health (23andMe-owned telehealth) and Redeemer Health resolved comparable pixel claims in the same period, and Podraza v. Nourish saw CIPA and federal wiretap claims survive dismissal against another telehealth provider. Patient portals, appointment pages, and symptom-search pages are the highest-risk surfaces on the web right now.

FactorTypical pixel caseSutter Health
Pages at issueProduct, checkout, browsingOne portal login page
Data allegedly sentBrowsing behaviour, cart contentsPatient status & identifiers
Extra claimsWiretap / privacy+ fiduciary duty of confidentiality
Class period startRecent (1–3 years)June 2015 — a decade back
ResolutionOften pendingFinal judgment, $21.5M

Why this case matters for website operators

First: the page itself can be the sensitive data. This is the lesson that generalises far beyond healthcare. You don't need to transmit a medical record to create exposure — you need only reveal which page someone loaded, when that page implies something private. A patient-portal login implies patient status. An addiction-services page implies a condition. A bankruptcy-services or divorce-attorney page implies circumstance. The URL is the disclosure.

Second: "it's behind the login" protects nothing. Sutter's authenticated portal was, by the plaintiffs' own framing, untouched. The liability sat entirely on the unauthenticated page in front of it — which is precisely where marketing teams feel safest putting conversion tags, because "no PHI is there." The $21.5 million says otherwise.

Third: old tracking is live liability. A class period beginning in 2015 means conduct from a decade ago drove a 2026 judgment. Nobody at Sutter in 2015 was thinking about CIPA pixel theories. That didn't help.

The uncomfortable takeaway: most organisations audit the pages they consider sensitive and ignore the ones they consider marketing surfaces. Sutter inverts that instinct. If loading a page reveals something about the person loading it — and login pages almost always do — then the third-party tags on that page are the exposure, no matter what's behind it.

What this means for your site

The failure here was preventable with controls that are technical, not legal:

  • Treat login pages as sensitive surfaces. Any page whose mere loading implies a status — patient, member, applicant, client — should carry no third-party marketing tags before consent. This is the single control that would have removed Sutter's exposure.
  • Block before consent, everywhere. Google Analytics, the Meta Pixel, and similar tools should not fire until the visitor affirmatively agrees. The transmission being litigated only happens if the tag loads.
  • Audit what's already running — including what you inherited. The Sutter class period starts in 2015. Tags added years ago by people who've since left are exactly the risk. You cannot control a tracker you don't know is there.
  • Map "context sensitivity," not just "data sensitivity." Ask which of your URLs would embarrass a visitor if a third party knew they'd loaded it. Those pages need the strictest treatment, regardless of whether they contain a form field.
  • Keep an auditable consent log. Timestamped proof of affirmative consent is the record that turns an all-party-consent question into a short conversation rather than a six-year one.

ConsentPixel — Privacy · Verified blocks Google Analytics, the Meta Pixel, and other third-party trackers at the browser level until the visitor consents — on every page, including the login screens teams forget to check — and logs each decision. It also surfaces the tags you inherited but never inventoried, which is where cases like this actually begin.

Worried your site has this exposure?

Scan free in about 10 seconds to see every tracker firing before consent — including on your login and account pages, the exact surface that cost Sutter $21.5 million. It's the same scan a plaintiff firm would run.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What is the Sutter Health tracking pixel litigation about?
It's a class action alleging that Sutter Health used third-party tracking, analytics, and advertising technologies — including Google Analytics and the Meta Pixel — on certain webpages, including the MyHealthOnline patient portal login page, and that these disclosed patients' personally identifiable information and protected health information to third parties like Facebook and Google without consent. The formal caption is Jane Doe I and Jane Doe II, et al. v. Sutter Health, No. 34-2019-00258072-CU-BT-GDS, in Sacramento County Superior Court.
How much was the Sutter Health settlement?
$21.5 million. The court granted final approval following a February 27, 2026 hearing, and the Order and Judgment Granting Final Approval was entered on March 6, 2026. Class members received a pro rata cash payment capped at $90 with no documentation required. The court approved attorneys' fees of $7,095,000, litigation costs of $216,639.11, and $10,000 incentive awards to each Class Representative, with residual funds going to the Privacy Rights Clearinghouse and the AHIMA Foundation.
Was patient data inside the portal tracked?
No. Per the official settlement FAQ, there is no allegation of any tracking or sharing from inside the MyHealthOnline portal, and no allegation that any user IDs or passwords were shared. The claims concerned trackers on certain webpages including the portal login page — the screen a patient sees before logging in. That single unauthenticated page drove a $21.5 million settlement, which is why "the sensitive data is behind our login" is not a defense.
What laws did the lawsuit claim were violated?
The operative complaint stacked several theories: the California Invasion of Privacy Act (Cal. Penal Code §631 et seq.), intrusion upon seclusion, breach of fiduciary duty of confidentiality, violation of California's Unfair Competition Law, and implied contract and breach of the covenant of good faith and fair dealing. The fiduciary and contract claims were available specifically because Sutter is a healthcare provider with a confidentiality relationship to its patients. Sutter denies all allegations and the case settled without any admission of liability.
What should my website do to avoid this outcome?
Treat any page whose mere loading implies a private status — login, account, patient, or client pages — as a sensitive surface with no third-party marketing tags before consent. Block Google Analytics, the Meta Pixel, and similar tools until the visitor affirmatively agrees, audit tags you may have inherited years ago, and keep a timestamped consent log. The Sutter class period began in 2015, so historical tracking creates present liability. This is general information, not legal advice.
Not legal advice. This article is an educational summary of public settlement documents and legal reporting, and does not constitute legal advice. Sutter Health denies all allegations and settled without any admission of liability; no court decided the merits. Verify current details via the official settlement site and the court docket (Sacramento County Superior Court, No. 34-2019-00258072-CU-BT-GDS), and consult a qualified attorney about your specific situation.

Sources

  1. Official settlement website, SutterAnalyticsSettlement.com (administered by Epiq) — Jane Doe I and Jane Doe II, et al. v. Sutter Health, No. 34-2019-00258072-CU-BT-GDS (Sacramento County Super. Ct.); Notice, FAQ, and approval details.
  2. Settlement Agreement (PDF), SutterAnalyticsSettlement.com and ClassAction.org — claim list, class definition, and release terms.
  3. HIPAA Journal, "Sutter Health, Lemonaid Health, & Redeemer Health Settle Pixel Data Breach Lawsuits" (December 2025).
  4. ClassAction.org, "$21.5M Sutter Health Settlement Ends Class Action Lawsuit Over Alleged Patient Info Sharing with Google, Facebook" (December 2025).
  5. Top Class Actions, "$21.5M Sutter Health privacy class action settlement."

All facts drawn from public settlement documents and legal reporting. Status stated as of publication (July 2026). Sutter Health denies all allegations; the settlement includes no admission of liability.

Scroll to Top