Skip to main content
Guide

New Jersey Privacy Act Healthcare Marketing: Compliance Updates for NJ Practices

On January 15, 2025, the New Jersey Data Privacy Act (NJDPA) took effect, layering a new set of consumer privacy obligations on top of HIPAA for healthcare organizations operating in the state. [1]...

12 min read

On January 15, 2025, the New Jersey Data Privacy Act (NJDPA) took effect, layering a new set of consumer privacy obligations on top of HIPAA for healthcare organizations operating in the state. [1] The stakes are real: under the New Jersey privacy act, violations are treated as unlawful practices under the New Jersey Consumer Fraud Act, with civil penalties of up to $10,000 for a first violation and up to $20,000 for each subsequent violation, alongside parallel HIPAA exposure from federal regulators. The mandatory 30-day notice-and-cure period sunsets in mid-2026, after which whether to offer a cure opportunity before taking enforcement action becomes entirely at the discretion of the Attorney General, who will no longer be required to give advance warning before pursuing penalties. This article explains how the NJDPA intersects with federal HIPAA marketing rules, the class-action wave hitting providers nationwide, and the concrete steps NJ practices should take now.

The Current Enforcement Landscape for NJ Healthcare Marketing

OCR HIPAA Enforcement Trends

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) closed 22 enforcement actions in 2024 with settlements or civil monetary penalties, collecting more than $9 million.[2] [3]

OCR has launched a Risk Analysis Initiative targeting providers that fail to assess vulnerabilities in their electronic PHI systems, including marketing technology stacks. The most frequently cited violation across 2024 enforcement was an inadequate risk analysis, and on average roughly 57 months elapsed between an OCR complaint or breach notice and the announcement of a settlement or penalty, meaning today's tracking configurations could surface in enforcement years from now.[3]

OCR Online Tracking Guidance Status

OCR's online tracking bulletin, originally issued in December 2022 and updated March 18, 2024, warns that healthcare entities cannot use pixels, cookies, or other tracking technologies in ways that result in impermissible disclosures of PHI to vendors.[4] A U.S. District Court for the Northern District of Texas vacated portions of the guidance on June 20, 2024, specifically the position that an IP address combined with a visit to an unauthenticated webpage automatically triggers HIPAA.[5] However, the rest of the guidance remains in force, and OCR continues to require business associate agreements (BAAs) with any tracking vendor that receives PHI.

FTC and Dual Enforcement Jurisdiction

In July 2023, OCR and the Federal Trade Commission jointly sent warning letters to approximately 130 hospitals and telehealth providers about tracking technology risks.[5] The FTC continues to enforce the Health Breach Notification Rule against non-HIPAA health apps and consumer health data brokers, and state attorneys general are pursuing parallel actions under state consumer protection statutes.

Class-Action Lawsuit Explosion

Since 2022, plaintiffs' firms have filed waves of class actions alleging unlawful disclosure of patient data through Meta Pixel and Google Analytics. Recent settlements include:

  • Advocate Aurora Health: $12.25 million settlement for sharing user data with Meta and Google through tracking pixels affecting up to 3 million people.[6]
  • MarinHealth: $3 million settlement for Meta Pixel use between 2019 and 2025.[7]
  • Pomona Valley Hospital Medical Center: $600,000 settlement covering California residents who used the patient portal between 2019 and 2022.[8]

Many of these cases rely on state wiretapping statutes and consumer protection laws that can survive even after federal HIPAA defenses are exhausted.

State-Level Action Under the New Jersey Privacy Act

New Jersey has been an active participant in multistate HIPAA enforcement. A multistate investigation by New York, New Jersey, and Connecticut against Enzo Biochem/Enzo Clinical Labs resulted in a $4.5 million penalty in 2024.[9] The New Jersey privacy act gives the NJ Attorney General additional authority under the Consumer Fraud Act to pursue marketing data violations that fall outside HIPAA's PHI definition. Enforcement of the NJDPA is the sole responsibility of New Jersey's Office of the Attorney General, with the Division of Consumer Affairs handling investigations and rulemaking.[10]

How the New Jersey Privacy Act Applies to Healthcare Marketing

On January 20, 2026, Governor Murphy signed Assembly Bill A5017, an amendment to the NJDPA that exempts data that is not protected health information ("non-PHI") from the NJDPA when it is handled by covered entities or business associates in accordance with the privacy and security requirements of HIPAA.[11] Critically, however, the exemption is data-specific, not entity-wide. Covered entities and business associates are not fully exempt from the NJDPA; the exemption depends on how non-PHI is collected and handled.

In practical terms, if a healthcare business processes personal data that is not PHI (and is not afforded full HIPAA-equivalent safeguards) and meets the NJDPA's controller thresholds, it must comply with the Act with respect to that data. Examples include providers sending promotional emails about wellness services to non-patients from a purchased contact list, or providers operating consumer-facing services like tele-nutrition or cosmetic sign-up pages.

Key NJ healthcare marketing obligations under the New Jersey Privacy Act include:

  • Applicability thresholds: The law applies only when the personal data of 100,000+ residents are processed or if revenue is derived from selling the data of 25,000+ residents.
  • Sensitive data consent: The law requires permission before handling sensitive information such as health, financial, or biometric data.[12]
  • Universal opt-out: Controllers must recognize universal opt-out mechanisms such as Global Privacy Control for targeted advertising.
  • Data protection assessments: To evaluate high-risk data activities, like targeted advertising or profiling, they must also conduct data protection assessments to evaluate potential harm to consumers.

Specific Risks and Consequences for NJ Practices

Financial Penalties

NJ healthcare marketing violations can trigger multiple parallel penalty streams:

  • NJ Attorney General penalties: Up to $10,000 for an initial violation and $20,000 for each subsequent violation under the Consumer Fraud Act.[10]
  • OCR civil monetary penalties: Recent actions have ranged from tens of thousands to multi-million-dollar settlements per matter.[3]
  • Class-action settlements: Healthcare tracking pixel settlements have ranged from approximately $600,000 (Pomona Valley) to $12.25 million (Advocate Aurora).[6]
  • Legal defense costs: Often comparable to settlement amounts when factoring in expert witnesses, forensic review, and multi-year litigation.

Reputational Damage

OCR maintains a public breach portal listing incidents affecting 500 or more individuals, commonly called the "Wall of Shame." Advocate Aurora Health's breach notification disclosed that up to 3 million patients could have been affected by tracking pixel disclosures to Meta and Google.[6] Local NJ media coverage of patient data exposure can erode trust faster than direct marketing spend can rebuild it, and referral networks may distance themselves from providers under active investigation.

Operational Disruption

OCR investigations are slow and resource-intensive. Settlements typically include multi-year corrective action plans (CAPs) requiring documented risk analyses, ongoing monitoring, workforce training, and reporting to HHS.[2] Class actions add discovery burdens, deposition scheduling, and forensic preservation orders that pull executive attention from patient care and growth initiatives.

Personal Liability

HIPAA includes criminal penalties for knowing violations, and state consumer fraud statutes can reach individual officers who direct unlawful conduct. While the NJDPA does not provide consumers a private right of action, enforcement by the Attorney General can include civil penalties, injunctions, and damages, depending on the severity of the breach. Cyber liability insurance often excludes regulatory fines and intentional misconduct, leaving coverage gaps.

How Violations Happen in NJ Healthcare Marketing

Technical Configurations

Most NJ healthcare marketing violations are not the result of malicious conduct. They stem from default tracking configurations: Meta Pixel placed on appointment booking pages, Google Analytics capturing URL parameters that contain diagnosis codes or provider specialties, form-fill tracking that transmits patient names and email addresses, and chat widgets that record symptom information. The Advocate Aurora breach notification described tracking technology installed on the website, app, and patient portal to better understand patient needs and preferences, reflecting how routine marketing tooling becomes a HIPAA exposure.[6]

Vendor Relationships

OCR's guidance is unambiguous: regulated entities must have a signed BAA with any tracking technology vendor that receives PHI, or obtain a HIPAA-compliant authorization from each affected individual before disclosure.[4] Cookie banners do not constitute valid HIPAA authorization. Meta and Google generally refuse to sign BAAs for their advertising products, which means default implementations of those tools on healthcare sites are inherently noncompliant. OCR has acknowledged that providers may use an intermediary vendor that signs a BAA and de-identifies data before passing it downstream.

Staff Actions

Marketing teams add pixels to launch a campaign without consulting compliance. IT teams update content management systems and inadvertently restore previously removed tracking. Agency partners deploy tags via Google Tag Manager that bypass internal review. Social media managers cross-post patient testimonials without verifying authorizations.

Audit Triggers and Red Flags

  • Patient complaints to OCR or the NJ Division of Consumer Affairs
  • Competitor or journalist tip-offs (the Markup/STAT investigation that triggered the pixel litigation wave began as a journalism project)
  • Data breach notifications that mention tracking technology
  • Whistleblower reports from former marketing or IT staff
  • NJ AG investigations triggered by complaints under the new NJDPA opt-out framework

Protection Strategies for NJ Practices Under the New Jersey Privacy Act

Immediate Actions (This Week)

  1. Run a full inventory of every tracking tag, pixel, and script on patient-facing properties using browser developer tools or a tag auditing service.
  2. Identify which vendors currently receive any visitor data and confirm whether a signed BAA exists.
  3. Document data flows for appointment booking, symptom checkers, contact forms, and patient portal pages.
  4. Check whether your privacy notice complies with NJDPA opt-out and disclosure requirements.

Short-Term Fixes (This Month)

  1. Remove or reconfigure tracking tools that send PHI to vendors lacking a BAA.
  2. Implement server-side tracking with a HIPAA-compliant intermediary that strips identifiers before sending data to ad platforms.
  3. Update the privacy notice to disclose targeted advertising and explain how NJ residents can exercise opt-out rights.
  4. Train marketing, IT, and agency staff on PHI definitions and BAA requirements.
  5. Implement a Global Privacy Control honoring mechanism on your website.

Long-Term Compliance Infrastructure

  • Establish a quarterly tracking audit cadence with documented findings.
  • Conduct NJDPA data protection assessments for any high-risk processing.
  • Maintain a vendor inventory with BAA expiration tracking.
  • Document every marketing-tech change through a formal change-management process.

Vendor Evaluation Criteria

  • BAA availability: Vendor signs a BAA covering all data flows, not just storage.
  • PHI handling: Vendor strips identifiers server-side before transmission to ad platforms.
  • Audit certifications: SOC 2 Type II or HITRUST certifications with current attestations.
  • Healthcare experience: Demonstrated track record with covered entities, not just general e-commerce.
  • Audit trails: Logged evidence of what data was collected, transformed, and transmitted.

For NJ practices managing overlapping obligations, see our related guides on managing compliance across overlapping state privacy laws and Oregon's parallel framework taking effect in July 2026.

How Curve Addresses Each Risk

Curve is purpose-built for healthcare marketing compliance under HIPAA and state privacy laws including the New Jersey privacy act:

  • Automated PHI stripping: Curve intercepts data at the server level before it reaches Meta, Google, or other advertising platforms, removing the 18 HIPAA identifiers (including IP address combinations OCR considers PHI) so ad platforms receive only de-identified conversion signals.
  • Signed BAAs included: Every Curve deployment ships with an executed BAA, satisfying OCR's clear requirement that vendors handling PHI must be under a business associate agreement.
  • Server-side tracking architecture: Replaces browser-based pixels with a controlled, auditable conversion pipeline aligned with OCR's expectation that providers contract with vendors willing to sign BAAs and de-identify data before downstream disclosure.
  • Audit trails and documentation: Every event is logged with what was collected, what was stripped, and what was transmitted, creating evidence usable in OCR investigations, NJ AG inquiries, or class-action defense.
  • Healthcare-specific configuration: Pre-built handling for appointment forms, symptom checkers, patient portals, and condition-specific landing pages.
  • Rapid implementation: Most practices reach a compliant state within days rather than the multi-month re-architecture projects required to retrofit general-purpose analytics platforms.

NJ practices weighing similar state frameworks may also benefit from our breakdowns of Texas HB 300 and the Minnesota Consumer Data Privacy Act, both of which interact with HIPAA in similar ways.

Don't Wait for Enforcement

The NJDPA's mandatory notice-and-cure period sunsets in mid-2026, after which the NJ Attorney General can pursue penalties without giving controllers an opportunity to remediate first.[10] Every day a noncompliant pixel runs on an NJ healthcare site adds another day of exposure across HIPAA, state consumer fraud, and class-action wiretap theories. Schedule a Compliance Assessment with Curve.

NJ Healthcare Marketing Compliance Self-Assessment Checklist

  • We have inventoried every tracking tag on patient-facing web properties
  • We have signed BAAs with every vendor that receives any visitor data from our healthcare properties
  • We have removed or replaced Meta Pixel and Google Analytics implementations that send PHI
  • Our server-side tracking strips the 18 HIPAA identifiers before any data leaves our environment
  • Our privacy notice complies with NJDPA disclosure and opt-out requirements
  • We honor universal opt-out mechanisms (such as Global Privacy Control) for targeted advertising
  • We process consumer opt-out requests within the timeframe required by the NJDPA
  • We have obtained opt-in consent before processing health-related sensitive data of NJ consumers
  • We have completed data protection assessments for targeted advertising and profiling activities
  • We maintain audit logs of marketing data flows for at least six years
  • Our marketing, IT, and agency partners have completed HIPAA and NJDPA training in the past 12 months
  • We have a documented incident response plan for marketing data exposures

Frequently Asked Questions

What are the penalties for HIPAA marketing violations?

Under the New Jersey privacy act, the NJ Attorney General can impose penalties of up to $10,000 for an initial violation and $20,000 for each subsequent violation through the Consumer Fraud Act.[10] At the federal level, OCR collected more than $9 million across 22 HIPAA enforcement actions in 2024.[3] Class-action settlements involving Meta Pixel use have ranged from $600,000 to $12.25 million in recent cases.[6]

Can NJ healthcare practices be sued for using Meta Pixel?

Yes. Plaintiffs have filed and settled multiple class actions against healthcare providers for using Meta Pixel and similar tracking technologies, including Advocate Aurora ($12.25 million), MarinHealth ($3 million), and Pomona Valley Hospital ($600,000).[7] [8] Most claims rely on state wiretap and consumer protection statutes rather than HIPAA directly, since HIPAA does not provide a private right of action.

Does the NJ Privacy Act apply to my healthcare practice if I am a HIPAA covered entity?

The NJDPA exempts PHI processed by HIPAA covered entities and business associates, and a 2026 amendment expanded that to certain non-PHI handled in accordance with HIPAA safeguards, but the exemption remains data-specific rather than entity-wide.[11] If your practice processes non-PHI personal data of NJ residents (for example, promotional email lists from purchased contacts, consumer-facing wellness or cosmetic services, or marketing analytics on prospects who are not yet patients) and meets the controller thresholds, the NJDPA likely applies to that data.

How do I know if my healthcare marketing is compliant?

Start with three questions: (1) What tracking tools are running on your patient-facing pages, and what data do they transmit? (2) Do you have a signed BAA with every vendor that receives any of that data? (3) Does your privacy notice meet NJDPA disclosure, opt-out, and sensitive-data consent requirements?[12] If you cannot answer all three with documented evidence, a compliance audit is the next step.

What should I do if I discover a compliance violation?

First, stop the disclosure: disable the tracking tag or block the vendor connection immediately. Second, document the scope: what data was transmitted, to whom, and for how long. Third, evaluate breach notification obligations under HIPAA, which presume a breach when PHI is impermissibly disclosed to a tracking vendor without a BAA, unless you can demonstrate a low probability of compromise.[4] Fourth, engage counsel before making public statements. Finally, remediate the underlying vendor and technical gaps so the violation cannot recur, since OCR corrective action plans and NJ AG settlements will require documented evidence of fixes.

Sources

  1. NJCCIC: New Jersey Enacts Comprehensive Data Privacy Law
  2. HIPAA Journal: What are the Penalties for HIPAA Violations?
  3. Shook, Hardy & Bacon: OCR Enforcement Activity Trends and Insights
  4. HHS OCR: Use of Online Tracking Technologies by HIPAA Covered Entities
  5. Nixon Peabody: Portions of OCR's Bulletin on Online Tracking Technologies Deemed Unlawful
  6. Milberg: Aurora Health Agrees To $12.25M Settlement in Tracking Pixel Suit
  7. HIPAA Journal: MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit
  8. HIPAA Journal: Pomona Valley Hospital Medical Center Pays $600K to Settle Meta Pixel Lawsuit
  9. HIPAA Journal: HIPAA Enforcement by State Attorneys General
  10. Ogletree Deakins: New Jersey Data Protection Act Becomes Effective in January 2025
  11. Alston & Bird: New Jersey Expands HIPAA-Based Exemptions Under Its Comprehensive Privacy Law
  12. NJ Division of Consumer Affairs: New Jersey Data Privacy Law FAQs

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit