OCR Is Coming for Everyone, Ad Platforms Are Locking Down, and the Bill for Bad Data Practices Just Hit $9M+

The Enforcement Machine Is Warming Up
If 2025 was OCR finding its footing, 2026 is OCR finding its teeth. Three major signals dropped in the past few weeks that should have every healthcare marketer paying attention:
-
Substance use disorder data just got the HIPAA treatment. HHS OCR established a formal civil enforcement program for 42 CFR Part 2, the rule governing confidentiality of substance use disorder (SUD) patient records. OCR is now accepting complaints and has made Part 2 noncompliance an enforcement priority. If you're marketing for behavioral health, addiction treatment, or adjacent services, your tracking and ad tools handling SUD-related data now carry HIPAA-level enforcement risk. Full stop.
-
Right of Access enforcement is surging. OCR launched a new wave of enforcement actions around patient record access requests in late 2025, making clear that delays and noncompliance won't slide. Not a direct marketing issue, but a flashing neon sign: OCR is actively expanding the surface area of what it enforces.
-
They're going after vendors, not just providers. MMG Fusion, a software provider for oral healthcare practices, settled with OCR for an unreported 2020 breach affecting 15 million individuals. OCR only found out because someone filed a complaint. MMG never reported it themselves.
Read that last one again. A tech vendor. Serving dental practices. Never reported. Got caught anyway.
The message is unmistakable: if your vendor touches patient data and doesn't have a BAA, breach notification procedures, and actual security controls, you're exposed.
The Class Action Tab: $9M+ and Counting
While OCR turns up enforcement, the plaintiffs' bar is having its own field day. Here's what Q1 2026 settlements look like:
- General Physician, P.C. (NY) — Settlement: $2.5M, Individuals affected: 167,387
- Consulting Radiologists (MN) — Settlement: $2.2M, Individuals affected: 583,000+
- Northeast Rehab Hospital Network — Settlement: Undisclosed, Individuals affected: Hundreds of thousands
- American Addiction Centers — Settlement: Undisclosed, Individuals affected: Hundreds of thousands
- Duly Health and Care (IL) — Settlement: Undisclosed, Individuals affected: Hundreds of thousands
That's over $4.7M in disclosed settlements alone, with three more on top. All stemming from 2024 breaches. All involving PHI exposure through various data touchpoints.
General Physician's case is particularly instructive for marketers: their breach came through a compromised email environment that went undetected for two months. Email marketing platforms, CRMs, scheduling tools, analytics suites — every system with access to patient data is a potential $2M+ lawsuit waiting to happen.
And it's not just cyberattacks. The legal theory in many of these cases extends to any "impermissible disclosure" of PHI — including data leaked through tracking pixels, analytics tools, and ad platform integrations that were never designed with HIPAA in mind.
The Big Picture: 62 Million Records Exposed in 2025
HIPAA Journal's annual breach report puts the 2025 numbers at 710 large breaches affecting nearly 62 million individuals. That's technically a 4.3% year-over-year decline, but "only 62 million people had their health data exposed" is a strange thing to celebrate.
A 43-day government shutdown in late 2025 likely delayed breach reporting, so the real number could be higher. January 2026 showed 46 breaches affecting 1.4 million individuals — part of a five-month downward trend, though portal update delays may be masking the true picture.
The takeaway isn't "things are getting better." It's that the per-breach impact remains massive, enforcement is intensifying, and the financial consequences are climbing.
Meanwhile, the Ad Platforms Are Rewriting the Rules
As if the regulatory environment weren't enough, the platforms healthcare marketers depend on are tightening their own screws.
Google Ads rolled out targeted policy updates heading into 2026:
- HCP targeting is back (in limited form) for eligible advertisers
- New Google Shopping eligibility standards for healthcare products
- Stricter requirements around data collection, tracking, and personalization for health advertisers
Social platforms are moving even faster:
- Meta escalated enforcement of health-related conversion tracking restrictions, limiting lower-funnel optimization events for healthcare advertisers. Your ability to optimize for appointments booked, forms submitted, and calls made just got harder if you're using standard pixel-based tracking.
- LinkedIn updated its health advertising policy to restrict ads that imply or rely on sensitive health information, including certain audience targeting methods.
- TikTok continues tightening health content and advertising policies.
Policy violations can result in ad disapprovals or full account suspensions with no warning required. This is the squeeze healthcare marketers are living in: OCR wants you to stop sending PHI to ad platforms, the ad platforms also want you to stop sending them PHI, but they still want your ad dollars and expect you to optimize campaigns effectively.
The AI Wild Card
Onspire Health Marketing published a report analyzing how AI search and privacy expectations are reshaping healthcare marketing in 2026. Two big forces are at play:
- "Answer engine optimization" is replacing traditional SEO for many health queries. Patients increasingly get answers from AI summaries rather than clicking through to websites. Your content strategy needs to account for this.
- Patient privacy expectations are rising faster than regulations. Consumers now expect their health data to be handled carefully online, and they notice — and litigate — when it's not.
Your Q1 Action Items
- Audit your vendor BAAs. If any tech vendor touching patient data doesn't have a signed BAA and documented breach notification procedures, fix that this week.
- Behavioral health teams: treat SUD data like plutonium. OCR's new Part 2 enforcement program means any tracking tool processing SUD-related data is now squarely in the crosshairs.
- Review your Meta and Google setups. If you're still running standard client-side pixels, you're likely both violating HIPAA and running afoul of platform policies. Server-side solutions exist. Use them.
- Pressure-test your email environment. General Physician's $2.5M settlement came from a two-month email breach. What systems have access to patient data in your org?
- Start thinking about AI search. The tracking and attribution challenges are only getting more complex as patients move to AI-driven search experiences.
The organizations writing seven-figure settlement checks right now aren't the ones that ignored HIPAA entirely. They're the ones that thought their setup was "probably fine." Don't be probably fine. Be actually fine.
Keep exploring
Related articles
Piwik PRO vs Curve: Which HIPAA-Compliant Analytics Platform Fits Your Practice
Read articleConnected TV Healthcare Ads: Streaming Platform Targeting for Medical Practices
Read articleComplete HIPAA Marketing Platform vs. Data Pipeline Tools: The Healthcare Practice Guide
Read articleWant to stay up to date on the latest in healthcare marketing?
Sign up for our newsletter to receive our articles directly in your inbox—covering compliance updates, platform changes, and industry insights.
We respect your privacy. Unsubscribe at any time.