Three more healthcare orgs just wrote very large checks over data breaches. The total damage this week? $18.5 million in settlements. Meanwhile, regulators are gearing up to drop the biggest HIPAA Security Rule overhaul in over a decade.
Let's get into it.
The $1.88M Pixel Tracking Settlement You Need to Know About
Duly Health and Care just agreed to pay $1.88 million to settle a class action over Meta Pixel tracking on its website and patient portal.
The short version: patients thought they were privately browsing their healthcare provider's site. Instead, Meta Pixel was quietly shipping their IP addresses, unique identifiers, and health-related browsing activity straight to Facebook. The lawsuit called the pixel "effectively a bug planted on their browsers." Hard to argue with that framing.
The pixel was live from July 2020 through April 2023. Six of eight original claims got tossed, but negligence and federal Electronic Communications Privacy Act violations stuck. That was enough for $1.88M.
The takeaway: If you have any tracking pixels running on patient-facing pages (scheduling tools, symptom checkers, provider search, portals), you need a documented legal rationale for every data element those pixels touch. "We didn't know what it collected" stopped being an excuse a long time ago.
Ransomware Settlements Keep Getting More Expensive
Two more settlements hit this week, and the numbers are rough.
McLaren Health Care: $14 Million
Two separate ransomware attacks (ALPHV/BlackCat in August 2023, Inc Ransom in late 2024) exposed data on 3.2 million+ people combined. Class members can claim up to $5,000 in documented losses plus credit monitoring. The final hearing is set for April 21, 2026.
American Addiction Centers: $2.75 Million
A Rhysida ransomware attack in September 2024 hit 423,000+ individuals. Twelve separate lawsuits got consolidated into one. The core argument? Inadequate security measures. The claims deadline is March 23, 2026.
Northeast Rehabilitation Hospital Network
Northeast Rehab also settled after a Hunters International attack affected 136,000+ people. Claimants can get up to $5,000 for documented losses or a flat $75 cash payment. That claims deadline is this Monday, February 17.
5 HIPAA Enforcement Priorities for 2026
A deep analysis from Foley Hoag lays out where enforcement is heading this year. Five things to have on your radar:
- The fundamentals still matter. Encryption, MFA, patch management, incident response documentation. Regulators don't just want to see policies on paper. They want proof controls are actually working.
- Vendor risk management is getting real. Having the right contract language isn't enough anymore. Regulators want to see outcomes.
- Tracking technology is still a target. Can you prove your pixels and tags aren't disclosing PHI without authorization? If not, that's a problem.
- Cross-agency coordination is ramping up. OCR, DOJ, and state AGs are now teaming up when cyber incidents overlap with fraud or false statements. One incident, multiple investigations.
- AI is on the watchlist. Training data, PHI access, minimum necessary compliance. If you're deploying AI tools that touch patient data, regulators are paying attention.
Oh, and the FTC is still treating undisclosed data flows as deceptive practices wherever HIPAA doesn't reach. So a single incident can now trigger an OCR inquiry, consumer litigation, an FTC examination, and state AG scrutiny. All at once. Fun.
The Biggest HIPAA Security Rule Overhaul Since 2013
The proposed HIPAA Security Rule update is set to be finalized in May 2026, with compliance deadlines potentially landing before the end of the year. This is the first major revision since 2013.
Here is what is changing:
- No more "addressable" safeguards. Everything becomes mandatory.
- Annual compliance audits are now required.
- Full technology asset inventory, including any AI tools touching ePHI.
- Network mapping showing all ePHI data flows.
- MFA required for all ePHI access.
- Encryption mandatory for data at rest and in transit.
- 72-hour disaster recovery capability.
- Business associates must provide annual written confirmation of their safeguards.
- 24-hour notification when activating contingency plans.
For some context on what noncompliance costs: OCR collected over $6.6 million in HIPAA fines during 2025, with individual penalties ranging from $80,000 to $3 million. Most were tied to weak risk assessments and technical safeguards.
Bottom Line
The pattern keeps repeating: ransomware attacks, pixel tracking lawsuits, and security gaps are generating eight-figure liability. And with the biggest Security Rule changes in a decade coming this year, the bar is only going up.
If you are still running standard tracking pixels on patient-facing pages, the clock is ticking. Curve handles HIPAA-compliant tracking so you can keep your conversion data without the legal exposure that is costing other healthcare orgs millions. Worth a look before your pixel becomes someone else's lawsuit.
