Old Statute, New Liability: ECPA’s Quiet Takeover of Healthcare Privacy Litigation
The Electronic Communications Privacy Act predates the commercial internet. It was written to extend wiretap protections to email and voicemail at a time when “going online” meant a dial-up modem. Nobody drafting it in 1986 was thinking about tracking pixels, session replay software, or embedded chat widgets, because none of that existed yet. Four decades later, that same statute, alongside a handful of state-level wiretap and eavesdropping laws written on the same legal logic, has become the backbone of a litigation wave that has cost healthcare companies well over $70 million in settlements in just the past two years, with a live federal enforcement case still working its way through the system.
If your organization runs a website, a patient portal, or an app with any kind of analytics, advertising, or chat functionality on it, this is not background legal trivia. It’s an active exposure most compliance teams still route through the wrong review process, or no review process at all.
How a 1986 Wiretap Law Ended Up Governing Your Website
ECPA’s core concept is straightforward: intercepting a communication without the consent the law requires is unlawful, a principle that originally applied to phone calls and was extended to digital communications like email and stored messages. The legal theory now fueling healthcare privacy litigation applies that exact same concept to a browser session. When a tracking pixel, session replay tool, or chat widget captures what a website visitor does on the page, and sends that data to a third party without proper consent, plaintiffs argue that’s functionally the same thing as an illegal wiretap, just intercepting a webpage interaction instead of a phone call.
State wiretap and eavesdropping statutes, in California, Illinois, Florida, and Pennsylvania among others, layer directly on top of this federal theory, and in several of these states the underlying consent standard is stricter than a typical cookie banner is built to satisfy. That gap, between what a standard cookie consent banner covers and what these statutes actually require, is exactly where this entire wave of litigation lives.
Why Healthcare Keeps Ending Up as the Defendant
Any industry can get swept into pixel litigation, but healthcare carries a distinct kind of exposure: what gets captured isn’t generic browsing behavior, it’s a visitor searching for a medication, researching a diagnosis, or navigating a patient portal. That’s the difference between a nuisance lawsuit and a settlement with eight figures attached.
CVS Health’s recent $20.5 million settlement with advertising firm Criteo alleged exactly this: that tracking technology on CVS’s websites and apps disclosed patients’ medical conditions, immunizations, and prescription activity without consent. It’s not an isolated case. Atrium Health paid $1.8 million after pixel tracking on its patient portal was also reported to federal regulators as a HIPAA breach affecting nearly 586,000 people. Kaiser Permanente’s settlement ran as high as $47.5 million, tied to a HIPAA breach affecting 13.4 million patients from trackers on its websites, portals, and apps. And the FTC, alongside Utah and California, is currently suing telehealth company Hims & Hers over allegations that it shared sensitive health data with advertising platforms including Meta.
The detail worth sitting with: none of these organizations built something exotic. Every one of these cases traces back to widely used, standard marketing and analytics tools, the kind installed by a marketing team in an afternoon. The tool was never the problem. The absence of a compliance checkpoint before it went live was.
You’re Actually Managing Two Separate Risks, Not One
This is the part that trips up otherwise well-run compliance programs. A HIPAA breach assessment and an ECPA-based litigation exposure assessment are not the same analysis, and clearing one doesn’t clear the other. HIPAA governs whether the disclosure counts as a reportable breach of protected health information, with its own notification obligations to regulators and affected patients. ECPA and its state counterparts govern whether the interception itself was unlawful, a question that doesn’t depend on whether the data meets HIPAA’s definition of PHI, and one the plaintiffs’ bar has shown it will pursue regardless of an organization’s HIPAA-covered status. A program built to satisfy HIPAA alone is only handling half of this exposure.
Closing the Gap: What Actually Works
- Route every new tracking, analytics, or chat tool through compliance review before it goes live. The single biggest driver behind every case above is a tool that shipped without anyone outside the marketing team reviewing what it could actually access.
- Audit your current tag stack for what it can capture, not what it was installed to do. A pixel installed to track ad conversions can still pick up form fields, URL parameters, or page content revealing a health condition, regardless of its intended purpose.
- Build consent gating specifically for health-adjacent tracking, rather than relying on a general cookie banner that was never drafted with this kind of disclosure, or this level of statutory scrutiny, in mind.
- Extend vendor due diligence to every advertising and analytics partner, not just the vendors your organization formally treats as HIPAA business associates. Criteo and Meta weren’t business associates in these cases, which is exactly why they slipped past the usual vendor review.
- Run your HIPAA breach analysis and your ECPA litigation exposure analysis separately. Treating them as one combined review is how organizations end up covered on one front and exposed on the other.
- Monitor your tag environment continuously, not just at initial setup. New tools get added constantly, usually by teams with no reason to loop in compliance, which is exactly why a one-time audit stops being useful the day after you run it.
This is precisely the gap platforms like Captain Compliance are built to close operationally rather than procedurally. Our consent management platform gates tracking technology behind properly scoped, health-aware consent rather than a generic cookie banner, and our Patrol monitoring tool continuously scans for new or changed tags across your site so a marketing team’s afternoon pixel install doesn’t turn into next year’s demand letter. Vendor disclosure tracking and DSAR workflows round out the picture, so the same platform managing your consent collection is also the one flagging the gap before a plaintiff’s firm does.
The Bottom Line
ECPA’s application to modern tracking technology isn’t a fringe legal theory anymore. It has a settlement track record exceeding $70 million in healthcare alone, an active federal enforcement case running in parallel, and a root cause, tools shipped without compliance review, that shows up in every single case. Organizations still treating tracking pixel deployment as a marketing decision rather than a governed compliance process should expect to be the next data point in this pattern, not the exception to it.
Frequently Asked Questions
What is ECPA and why does it apply to website tracking?
The Electronic Communications Privacy Act extends wiretap-era interception rules to electronic communications. Plaintiffs have applied its interception concept to tracking pixels and session replay tools, arguing that capturing and transmitting a website visitor’s activity without proper consent functions the same way as an illegal wiretap.
Why is healthcare specifically targeted in this kind of litigation?
Because the data captured, medication searches, diagnosis research, patient portal activity, is far more sensitive than typical browsing behavior, which increases both the settlement value and the likelihood of a parallel HIPAA breach finding on top of the underlying wiretap-style claim.
Does fixing a HIPAA compliance gap also fix ECPA litigation exposure?
Not automatically. HIPAA and ECPA-based claims are governed by different legal standards and require separate analysis. An organization can be fully HIPAA-compliant on a specific disclosure and still face civil liability under ECPA or a state wiretap statute for the same underlying tracking activity.
What’s the most common root cause behind these settlements?
A standard, widely used marketing or analytics tool deployed without compliance review. In nearly every major case to date, the tool itself was ordinary; the missing step was a review of what data it could access before it went live.
How can a consent management platform reduce this risk?
By gating tracking technology behind consent that’s properly scoped to the sensitivity of the data involved, rather than a generic cookie banner, and by continuously monitoring the site for new or modified tags that haven’t gone through that same consent gate.