Atrium Health’s $1.8 Million Pixel Settlement Shows Healthcare Tracking Lawsuits Are Not Going Away

Table of Contents

We just covered the recent CVS & Criteo $20.5 million pixel and tracking settlement. This is a litigation trend we’ve been warning businesses in the healthcare space about and that having good privacy hygiene while using tools like the ones developed by Captain Compliance can protect against these very expensive lawsuits. As we look back now to how Atrium Health who this summer had news about a proposed $1.8 million settlement over allegations that tracking technologies on its patient portal disclosed patient information to third parties, adding another healthcare system to a growing list of organizations paying to resolve lawsuits over pixels, analytics tools and other website trackers.

The case is particularly relevant for healthcare privacy teams because it involved an authenticated patient portal, not simply visitors browsing a hospital’s public website.

Plaintiffs alleged that tracking technologies used by the North Carolina health system transmitted patient information to third parties, including Meta and Google, for marketing-related purposes without the patients’ knowledge or consent. Atrium operates an academic medical center in Charlotte, 11 other hospitals and more than 900 care locations across North and South Carolina.

The settlement has received preliminary approval but is not yet final. The court has scheduled a final approval hearing for September 30, 2026. Class members have until September 28 to submit claims.

Atrium has not admitted liability through the settlement.

The case is another reminder that the legal risk surrounding website tracking in healthcare has not disappeared. If anything, it is becoming easier to separate two different questions that were sometimes treated as one: what federal regulators consider a HIPAA violation, and what plaintiffs can successfully pursue through privacy litigation.

The Atrium Case Goes Back Years

The alleged tracking did not begin recently.

Atrium previously reported to federal regulators that tracking technology had been used on its patient portal from January 2015 through July 2019, affecting nearly 586,000 individuals, according to Information Security Media Group.

The proposed class settlement covers U.S. residents who had a MyAtriumHealth or MyCarolinas patient portal account between January 1, 2015 and April 10, 2024.

The settlement separates claimants into two groups.

One group consists of people who actually used their patient portal accounts between January 1, 2015 and July 31, 2019, while the trackers at issue were allegedly present. A $1.5 million settlement fund will cover payments to those class members along with administration expenses, attorneys’ fees and service awards.

A second group includes patients who had a portal account between January 1, 2015 and April 10, 2024, but did not use the portal during the earlier tracking period. Atrium agreed to make up to another $300,000 available for that group.

The total proposed resolution is therefore up to $1.8 million.

The amount is notable, but the underlying technology is more important for privacy teams.

Why Patient Portals Are Different

The legal arguments surrounding healthcare tracking technologies have become complicated because not every visit to a healthcare website necessarily reveals health information.

Someone visiting a hospital homepage could be a patient. They could also be a doctor looking for a phone number, a journalist researching the organization, a job applicant, or someone who accidentally clicked a search result.

That distinction played a significant role in litigation over federal tracking guidance.

In June 2024, a federal court vacated part of HHS guidance that treated the combination of an IP address and a visit to certain public healthcare webpages as protected health information under some circumstances.

HHS subsequently modified its guidance. The agency now acknowledges that merely connecting an IP address with a visit to an unauthenticated page discussing a health condition or provider does not automatically make that information individually identifiable health information.

An authenticated patient portal presents a much less ambiguous situation.

HHS says tracking technologies operating on authenticated healthcare webpages can potentially receive information such as medical record numbers, email addresses, appointment dates, prescription information, diagnoses, treatment information and billing data.

HHS continues to take the position that regulated healthcare organizations must configure trackers on authenticated pages so that any use or disclosure of protected health information complies with HIPAA.

That makes the difference between a public hospital webpage and a logged-in patient portal more than a technical distinction.

It can change the privacy analysis substantially.

The Tracking Pixel Problem Is Usually Invisible to the Patient

Most patients logging into a healthcare portal are not thinking about web analytics architecture.

They see an appointment page, prescription information, test results or a message from a doctor.

Behind that page, however, ordinary web technologies can generate additional requests to outside services.

A tracking pixel is typically a small piece of code that records an action and sends information to another system. Analytics scripts, advertising pixels, tag management systems, session replay products and conversion tools can perform related functions.

The existence of these technologies does not automatically mean there has been an unlawful disclosure.

Configuration matters.

A pixel might transmit only limited technical information in one implementation and substantially more information in another. The page where the technology operates matters. So does the information contained in URLs, page titles, event parameters, form fields and identifiers transmitted with requests.

This is why simply looking at a list of cookies is no longer enough for a serious healthcare tracking audit.

Privacy teams increasingly need to understand the actual network traffic leaving the site.

A Cookie Banner Alone Does Not Solve the HIPAA Issue

Healthcare organizations also need to be careful about assuming that ordinary website consent mechanisms solve every tracking problem.

HHS explicitly says that a standard cookie banner asking a visitor to accept or reject tracking technologies does not itself constitute a valid HIPAA authorization.

Where a tracker receives PHI on behalf of a regulated healthcare organization, the analysis can involve whether the vendor is acting as a business associate, whether an appropriate business associate agreement exists and whether the disclosure is otherwise permitted under the HIPAA Privacy Rule.

That is a different standard from ordinary advertising-cookie consent.

For healthcare organizations, consent management therefore has to be part of a larger tracking governance program rather than the entire program.

Private Lawsuits May Be the Bigger Immediate Risk

The Atrium case also illustrates an important change in the healthcare tracker debate.

For several years, much of the attention centered on warnings and enforcement activity from the Department of Health and Human Services and the Federal Trade Commission.

In 2023, HHS and the FTC jointly warned hospital systems and telehealth providers about the privacy and security risks associated with technologies including the Meta Pixel and Google Analytics.

But the litigation did not depend solely on those regulators.

Patients began filing lawsuits based on a broader collection of legal theories involving privacy, interception of communications, consumer protection and state privacy laws.

The source material accompanying the Atrium settlement notes that healthcare privacy attorneys increasingly view private class actions as a larger practical risk than regulatory enforcement in this particular area.

Other settlements show why.

Atrium Is Far From the Largest Healthcare Tracker Settlement

Atrium’s proposed $1.8 million resolution looks relatively modest beside some other healthcare tracking settlements.

Kaiser Permanente agreed to a settlement involving at least $46 million and potentially as much as $47.5 million to resolve claims concerning tracking technologies on authenticated Kaiser websites and mobile applications. Kaiser denied the allegations and the settlement is not an admission of liability.

Allina Health agreed to a $12.5 million settlement in litigation alleging that tracking technologies disclosed patient information without consent.

Other healthcare providers have reached smaller settlements, while additional cases continue through courts around the country.

The numbers vary because the cases involve different facts, class sizes, technologies, legal theories and procedural histories.

But collectively, they make one point difficult to ignore: website tracking has developed into a recurring healthcare litigation category rather than a short-lived response to regulatory guidance.

The Risk Goes Beyond Meta Pixel

It would also be a mistake to treat this as exclusively a Meta Pixel problem.

Healthcare websites can contain a large collection of third-party technologies.

Google Analytics, Google Tag Manager, advertising pixels, Microsoft tools, session replay technologies, embedded videos, chat software and other scripts can all create data flows that need to be understood.

A modern privacy audit should therefore start with the question, “What information is leaving this page?” rather than, “Do we use Meta Pixel?”

That distinction becomes particularly important when development and marketing teams can add scripts without privacy teams reviewing each deployment.

A hospital may remove one problematic tracker and still introduce another several months later through a marketing campaign, tag manager update or website redesign.

Authenticated Pages Deserve Their Own Controls

One of the practical lessons from Atrium is that organizations should not necessarily apply one tracking configuration across their entire digital environment.

A public hospital homepage and an authenticated patient portal serve very different purposes.

The same is true for appointment scheduling pages, prescription portals, symptom checkers and pages containing test results.

Organizations should map where trackers operate and consider the sensitivity of each environment separately.

In many cases, the safest design may be to remove unnecessary third-party marketing technology from authenticated healthcare environments entirely.

Where third-party technologies remain necessary, the organization should know exactly what they collect, where the information goes and under what legal and contractual authority the vendor receives it.

Healthcare Organizations Need Evidence, Not Just Policies

Another lesson from tracking litigation is that written policies only answer part of the question.

A privacy notice might accurately state that an organization does not sell patient information. That does not establish what a particular JavaScript tag transmitted from a patient portal three years earlier.

Organizations need technical evidence.

That can include tracker inventories, website scans, tag-manager configurations, consent logs, vendor agreements, network-request testing and records showing when technologies were added or removed.

This becomes especially important because tracker lawsuits can look backward several years.

A privacy team investigating a current website can determine what happens today. Reconstructing what happened on a particular page in 2019 can be far more difficult if nobody preserved the relevant configuration.

The Atrium Settlement Is Not Final Yet

For Atrium Health, the legal process is not quite finished.

The settlement administrator says the court will hold its final approval hearing on September 30, 2026. The deadline for eligible class members to file a claim is September 28.

The case is formally Julie Roberts, et al. v. The Charlotte-Mecklenburg Hospital Authority, doing business as Atrium Health, in the Superior Court of Mecklenburg County, North Carolina.

Whether the court ultimately grants final approval will determine the settlement’s next stage.

For healthcare privacy teams, however, the broader lesson does not depend on that hearing.

Tracking technologies that were once treated as routine components of website marketing and analytics now sit squarely inside privacy, security and litigation risk management.

The most important question is no longer whether a healthcare organization uses trackers.

It is whether the organization knows exactly where those technologies are running, what they transmit, whether they belong on those pages in the first place, and whether the organization can prove the answers if a patient, regulator or plaintiffs’ attorney asks years later.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.