Three settlements this week. One proposed federal law. And a very clear message: hope is not a compliance strategy.
The $25-$38 Question
Here's what happened this week while you were optimizing your Meta campaigns:
University of Tennessee Medical Center and Margaret Mary Community Hospital both settled class action lawsuits over tracking pixels. The price tag? $25-$38 per class member, plus privacy protection services, plus legal fees, plus the kind of PR headache that makes your CMO age in dog years.
The timeline that got them there: 2015-2023 (UTMC) and 2020-2023 (Margaret Mary). Translation: this wasn't a quick oopsie. These were years of pixel-powered patient data flowing to Meta, Google, and friends.
Both organizations denied wrongdoing. Both paid anyway.
Willis-Knighton Medical Center in Louisiana took an even more interesting settlement: cash payments plus a two-year ban on 16 specific tracking tools. No Google DoubleClick. No Meta Pixel. No TikTok tracking. No Amazon. No Pinterest. No TheTradeDesk.
Read that list again. That's basically saying "no digital marketing as we know it" for two years.
The Part Where This Gets Personal
Remember when we said 99% of hospitals use tracking pixels?
The plaintiffs' attorneys remember too. And they're using it.
If you're reading this newsletter, there's a statistically significant chance your organization is in that 99%. Which means you're potentially in the crosshairs of the same legal machinery that just convinced three healthcare systems that settling was cheaper than fighting.
Claim deadlines: December 1-18, 2025
Final hearings: December-January
Mark your calendar. Or better yet, mark your audit schedule.
Senator Cassidy Has Entered the Chat
While you were dealing with the pixel problem, Senator Bill Cassidy (R-LA) decided things weren't complicated enough and proposed the Health Information Privacy Reform Act.
The short version: If you're collecting health or wellness data—even if you're not technically a covered entity—you'd now need HIPAA-level protections.
The long version includes:
- Plain language disclosures for all health data access
- Written consent before selling health info
- Expanded breach notification requirements
- Full HIPAA security standards (yes, all the documentation, training, and logging fun)
This hits health apps, fitness trackers, mental health platforms, and basically anyone adjacent to healthcare data. If you're working with any wellness tech partners, they're about to have a very different compliance conversation.
What Actually Matters Right Now
This week
- Audit your tracking stack. Every pixel. Every analytics tag. Every "harmless" marketing tool.
- Check your patient portal pages specifically—these settlements hit portal access hard
- Make sure you know what data is flowing where
This month
- If you're using standard pixels, you're playing settlement roulette
- If you're working with wellness tech partners, loop them into the Cassidy bill conversation
- If you think "we'll deal with it later," consider that "later" is currently costing organizations $25-$38 per patient plus legal fees
The reality
These aren't warning shots anymore. This is the actual enforcement wave. The settlements show that even organizations with strong legal cases are choosing to pay rather than fight, which tells you everything about how courts and juries view this issue.
The Bottom Line
You can run effective campaigns and stay compliant. But you can't keep pretending the pixel problem will resolve itself.
The math is simple: The cost of inaction is now quantified. It's $25-$38 per patient, multiplied by however many people accessed your patient portal, multiplied by legal fees, multiplied by the PR nightmare of explaining to local news why you settled a privacy lawsuit.
Or you could just fix the tracking problem.
Class action claim deadlines start December 1st. Your pixel audit should start today.
