CVS Health and digital advertising firm Criteo have agreed to pay $20.5 million to settle claims that web trackers embedded on CVS’s websites and apps disclosed patients’ health information, including medical conditions, immunizations, prescriptions, and searches for sensitive healthcare products, to Criteo without consent. The Florida class action alleged violations of the Electronic Communications Privacy Act, along with state statutory claims, breach of confidence, invasion of privacy, and negligence. Both companies deny wrongdoing, and a digital advertising firm also originally named in the suit, Medallia, was dropped from the litigation before this settlement.
The number itself isn’t the notable part anymore. This is now the fourth major healthcare web tracker settlement in roughly two years: Atrium Health paid $1.8 million after pixel tracking on its patient portal was also reported to federal regulators as a HIPAA breach affecting nearly 586,000 people; Kaiser Permanente agreed to pay up to $47.5 million after disclosing a HIPAA breach involving trackers that affected 13.4 million patients; and the FTC, joined by Utah and California, sued telehealth firm Hims & Hers over alleged unlawful sharing of sensitive health information with advertising platforms including Meta. Add CVS and Criteo, and healthcare has now produced some of the largest tracking technology settlements of any industry, private litigation and federal enforcement running in parallel.
Why Healthcare Keeps Landing in This Exact Position
The legal theory driving these cases is the same one behind the broader wave of tracking-pixel litigation across every industry: a tool that captures a visitor’s interaction with a page and transmits it to a third party without consent can be treated as an illegal interception under wiretapping and eavesdropping statutes, and under ECPA at the federal level, the same legal architecture originally built for phone lines, applied to a browser session instead. What makes healthcare distinct is what’s actually being intercepted. A retail website’s tracking pixel captures browsing behavior. A pharmacy or patient portal’s tracking pixel can capture what medication someone searched for, what condition they’re managing, or whether they visited a page about a specific diagnosis, data that carries an entirely different weight in front of a jury or a regulator, and that frequently qualifies as a reportable HIPAA breach even when the underlying tracking tool is a standard, off-the-shelf marketing or analytics product.
That last point is the one healthcare privacy and compliance teams most consistently underweight. A pixel doesn’t have to be unusual or custom-built to create this exposure. Atrium Health’s and Kaiser’s incidents both involved widely used third-party tools deployed for ordinary marketing and analytics purposes, not some novel or unauthorized system. The tool itself wasn’t the anomaly. The absence of a compliance review before it went live was.
The Two-Track Enforcement Pattern
What’s notable about this cluster of cases is that they aren’t coming from one direction. The FTC and HHS OCR have both issued direct warnings to hospitals and telehealth companies about tracking technology risk in recent years, and the FTC’s own suit against Hims & Hers shows regulators are willing to pursue this as an unfair-and-deceptive-practices matter independent of HIPAA’s applicability. At the same time, the plaintiffs’ bar has built a reliable, repeatable litigation model around the same underlying facts, one that doesn’t require waiting for a regulator to act first. A healthcare organization facing this risk today is exposed on both tracks simultaneously, and a compliance posture built only around HIPAA breach reporting misses the parallel civil litigation exposure entirely, and vice versa.
What Actually Needs to Change, Not Just What Needs to Be Fixed
The pattern across every one of these settlements is the same one that shows up in nearly every tracking-technology enforcement action, healthcare or otherwise: a specific tool gets named, gets removed or reconfigured, and the underlying governance gap that let it ship without review in the first place goes unaddressed. For healthcare organizations specifically, closing that gap requires a few things a generic cookie-consent fix doesn’t cover on its own.
- Treat any tracking technology on a patient-facing property as a HIPAA and consent question before deployment, not after a complaint. Marketing and product teams adding analytics or advertising pixels to a patient portal or scheduling page need a compliance review gate before launch, not a retroactive audit after a regulator or plaintiff’s firm finds it.
- Audit every existing tag against what data it can actually access, not just its stated purpose. A pixel installed for conversion tracking can still capture URL parameters, form data, or page content that reveals a health condition, regardless of what the vendor’s documentation says it’s meant to do.
- Map where consent is actually required versus assumed. A cookie banner accepted for general site analytics does not necessarily cover the specific disclosure of health-related browsing activity to an ad tech vendor, and treating those as equivalent is exactly the gap this entire line of litigation exploits.
- Determine HIPAA breach reporting obligations independently from any litigation exposure analysis. Both Atrium Health’s and Kaiser’s incidents were reported to federal regulators as HIPAA breaches separately from the civil litigation that followed; these are two distinct obligations that need two distinct assessments, not one combined afterthought.
- Extend vendor due diligence to every advertising and analytics partner, not just core clinical vendors. Criteo and Meta aren’t business associates in the traditional HIPAA sense in most of these arrangements, which is exactly why they fell outside the scrutiny clinical vendor relationships usually receive, despite handling data just as sensitive.
- Build a recurring tag audit into the compliance calendar, not a one-time cleanup following a specific incident. Given how consistently these cases show the same root cause across different organizations, a periodic, proactive re-audit is meaningfully cheaper than the next settlement.
The Bottom Line
Four major settlements and an active federal enforcement action in roughly two years is no longer an emerging trend for healthcare; it’s an established pattern regulators and plaintiffs’ firms both know how to find. The organizations still treating tracking pixels as a marketing team’s tooling decision, rather than a compliance-reviewed data governance question, are the ones most likely to be the next name in this list.
Frequently Asked Questions
What did CVS and Criteo settle claims over?
A proposed class action alleged that web trackers on CVS’s websites and apps disclosed patients’ health information, including medical conditions, immunizations, and prescriptions, to advertising firm Criteo without consent, in violation of the Electronic Communications Privacy Act and related state law claims.
Why do tracking pixels create HIPAA exposure even when they’re standard marketing tools?
A pixel or analytics tool doesn’t need to be unusual or custom-built to capture health-related browsing activity. Widely used, off-the-shelf marketing and analytics tools were the source of both the Atrium Health and Kaiser Permanente incidents, both of which were reported to federal regulators as HIPAA breaches.
Is web tracker litigation only a HIPAA issue?
No. These cases are typically brought under the Electronic Communications Privacy Act and state wiretapping or consumer protection statutes as civil litigation, independent of any separate HIPAA breach reporting obligation, and the FTC has also pursued this conduct as an unfair or deceptive practice.
What should healthcare organizations do to reduce this risk?
Require compliance review before any tracking technology is deployed on patient-facing properties, audit existing tags for what data they can actually access, extend vendor due diligence to advertising and analytics partners, and assess HIPAA breach reporting obligations separately from litigation risk.