Sutter Health Tracking Pixel Litigation
Sutter Health paid $21.5 million over Google Analytics and the Meta Pixel running on a patient-portal login page. Nothing was tracked inside the portal. No usernames or passwords were shared. One page, before anyone logged in — and it produced one of the largest website-tracking settlements in US healthcare.
What the case is about
Two anonymous plaintiffs sued Sutter Health — one of California's largest non-profit health systems — alleging that it deployed third-party tracking, analytics, and advertising technologies on its web pages, and that those tools disclosed patients' personally identifiable information (PII) and protected health information (PHI) to third parties including Facebook and Google without consent.
The technologies named are the ones on a majority of the web: Google Analytics, the Meta Pixel, and assorted cookies, web beacons, and JavaScript. What makes this case singular — and far more dangerous than its headline suggests — is where they were running.
The trackers at issue were on the MyHealthOnline portal login webpage. Per the settlement's own official FAQ, there is no allegation of any tracking or sharing from inside the portal, and no allegation that any user IDs or passwords were shared.
In other words: nothing behind the login was touched. No credentials leaked. No medical records transmitted. The exposure was one page — the screen a patient sees before they log in.
That single page cost $21.5 million. If your mental model of tracking risk is "the sensitive data is safe behind our login, so the marketing tags on the public pages are fine," this case is a direct refutation of it.
The reason is context. A person loading a health system's patient-portal login page is, by the act itself, revealing something: that they are a patient of that provider. When a third-party tracker fires on that page, the allegation is that it transmits that fact — tied to an IP address, a device, and potentially a Facebook account — to an advertising company. No diagnosis needs to change hands for the disclosure to be meaningful.
The legal theory — CIPA plus a confidentiality stack
The operative Fourth Amended Complaint stacked several theories. Two things stand out: CIPA anchors the claim, and the rest of the stack leans on the special relationship between a healthcare provider and its patients.
- CIPA (Cal. Penal Code §631 et seq.) — California's wiretap statute. The theory: third-party trackers on the login page intercepted the contents of patients' communications with Sutter, in an all-party-consent state, without consent.
- Intrusion upon seclusion — the privacy tort.
- Breach of fiduciary duty of confidentiality — the claim available specifically because Sutter is a healthcare provider, not a retailer.
- Violation of California's Unfair Competition Law (UCL).
- Implied contract and breach of the covenant of good faith and fair dealing — the argument that patients were promised confidentiality.
This layering is the point. Even a defendant with a strong argument against the CIPA count must defend the confidentiality and contract theories too — and for a health system, the fiduciary framing is uniquely hard to shrug off. A retailer can argue nobody expected privacy while shopping. A hospital cannot make that argument about its own patients.
Where it stands (as of July 2026)
This case is over. Unlike most matters on the tracker, it has reached final judgment:
- Settlement fund: $21,500,000, non-reversionary.
- Preliminary approval: October 15, 2025.
- Final approval hearing: February 27, 2026, before Judge Lauri A. Damrell.
- Order and Judgment Granting Final Approval entered: March 6, 2026.
- Class payments: pro rata, capped at $90 per claimant, no documentation required. Claim deadline passed May 5, 2026.
- Court-approved fees and costs: attorneys' fees of $7,095,000, litigation costs of $216,639.11, and incentive awards of $10,000 to each Class Representative.
- Cy pres: residual funds go to the Privacy Rights Clearinghouse and the AHIMA Foundation.
Class counsel were Kiesel Law LLP (Jeffrey A. Koncius, Nicole Ramirez Jones) and Simmons Hanly Conroy LLP (Jason "Jay" Barnes, Eric Johnson). Sutter Health denies all of the allegations — it denies that any patient information was shared with unauthorized third parties, denies any violation or breach, and maintains it did nothing wrong. The case never went to trial and no court decided the merits; the parties settled to avoid the risk and expense of continued litigation. Status is stated as of publication.
How Sutter fits the 2026 landscape
Two features make this case a landmark rather than just another settlement.
It's a six-year case with a class period that predates the wave. Filed in 2019, over conduct dating back to June 2015, resolved with final judgment in March 2026. The tracking happened years before "pixel litigation" was a category anyone tracked. That's the retroactive trap: the analytics tags your team installed in 2016 and forgot about are actionable today, and the class period runs from whenever the tracking started — not from when you learned it was a problem.
Healthcare is the epicentre. Sutter settled alongside a broader wave: Lemonaid Health (23andMe-owned telehealth) and Redeemer Health resolved comparable pixel claims in the same period, and Podraza v. Nourish saw CIPA and federal wiretap claims survive dismissal against another telehealth provider. Patient portals, appointment pages, and symptom-search pages are the highest-risk surfaces on the web right now.
| Factor | Typical pixel case | Sutter Health |
|---|---|---|
| Pages at issue | Product, checkout, browsing | One portal login page |
| Data allegedly sent | Browsing behaviour, cart contents | Patient status & identifiers |
| Extra claims | Wiretap / privacy | + fiduciary duty of confidentiality |
| Class period start | Recent (1–3 years) | June 2015 — a decade back |
| Resolution | Often pending | Final judgment, $21.5M |
Why this case matters for website operators
First: the page itself can be the sensitive data. This is the lesson that generalises far beyond healthcare. You don't need to transmit a medical record to create exposure — you need only reveal which page someone loaded, when that page implies something private. A patient-portal login implies patient status. An addiction-services page implies a condition. A bankruptcy-services or divorce-attorney page implies circumstance. The URL is the disclosure.
Second: "it's behind the login" protects nothing. Sutter's authenticated portal was, by the plaintiffs' own framing, untouched. The liability sat entirely on the unauthenticated page in front of it — which is precisely where marketing teams feel safest putting conversion tags, because "no PHI is there." The $21.5 million says otherwise.
Third: old tracking is live liability. A class period beginning in 2015 means conduct from a decade ago drove a 2026 judgment. Nobody at Sutter in 2015 was thinking about CIPA pixel theories. That didn't help.
What this means for your site
The failure here was preventable with controls that are technical, not legal:
- Treat login pages as sensitive surfaces. Any page whose mere loading implies a status — patient, member, applicant, client — should carry no third-party marketing tags before consent. This is the single control that would have removed Sutter's exposure.
- Block before consent, everywhere. Google Analytics, the Meta Pixel, and similar tools should not fire until the visitor affirmatively agrees. The transmission being litigated only happens if the tag loads.
- Audit what's already running — including what you inherited. The Sutter class period starts in 2015. Tags added years ago by people who've since left are exactly the risk. You cannot control a tracker you don't know is there.
- Map "context sensitivity," not just "data sensitivity." Ask which of your URLs would embarrass a visitor if a third party knew they'd loaded it. Those pages need the strictest treatment, regardless of whether they contain a form field.
- Keep an auditable consent log. Timestamped proof of affirmative consent is the record that turns an all-party-consent question into a short conversation rather than a six-year one.
ConsentPixel — Privacy · Verified blocks Google Analytics, the Meta Pixel, and other third-party trackers at the browser level until the visitor consents — on every page, including the login screens teams forget to check — and logs each decision. It also surfaces the tags you inherited but never inventoried, which is where cases like this actually begin.
Worried your site has this exposure?
Scan free in about 10 seconds to see every tracker firing before consent — including on your login and account pages, the exact surface that cost Sutter $21.5 million. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What is the Sutter Health tracking pixel litigation about?
How much was the Sutter Health settlement?
Was patient data inside the portal tracked?
What laws did the lawsuit claim were violated?
What should my website do to avoid this outcome?
Sources
- Official settlement website, SutterAnalyticsSettlement.com (administered by Epiq) — Jane Doe I and Jane Doe II, et al. v. Sutter Health, No. 34-2019-00258072-CU-BT-GDS (Sacramento County Super. Ct.); Notice, FAQ, and approval details.
- Settlement Agreement (PDF), SutterAnalyticsSettlement.com and ClassAction.org — claim list, class definition, and release terms.
- HIPAA Journal, "Sutter Health, Lemonaid Health, & Redeemer Health Settle Pixel Data Breach Lawsuits" (December 2025).
- ClassAction.org, "$21.5M Sutter Health Settlement Ends Class Action Lawsuit Over Alleged Patient Info Sharing with Google, Facebook" (December 2025).
- Top Class Actions, "$21.5M Sutter Health privacy class action settlement."
All facts drawn from public settlement documents and legal reporting. Status stated as of publication (July 2026). Sutter Health denies all allegations; the settlement includes no admission of liability.