Skip to main content
Guide

Pennsylvania Consumer Data Privacy Bill: What PA Healthcare Marketers Should Prepare For

The Pennsylvania House passed HB 1201, the Pennsylvania Consumer Data Privacy Act, advancing the Commonwealth toward joining roughly twenty other states with comprehensive privacy laws. For...

12 min read

The Pennsylvania House passed HB 1201, the Pennsylvania Consumer Data Privacy Act, advancing the Commonwealth toward joining roughly twenty other states with comprehensive privacy laws. For healthcare marketers operating in Pennsylvania, the bill arrives at a moment of intense federal scrutiny: [1] in 2024 alone, the HHS Office for Civil Rights closed numerous HIPAA enforcement cases with civil monetary penalties or settlements, and federal courts approved multimillion-dollar class-action settlements tied to website tracking pixels. This article explains what Pennsylvania consumer data privacy obligations would layer on top of existing HIPAA exposure, where current enforcement is concentrated, and how PA healthcare marketing teams can lock down their tracking stack before regulators or plaintiffs' lawyers arrive.

The Pennsylvania Consumer Data Privacy Bill at a Glance

HB 1201 establishes consumer rights and controller obligations for businesses processing personal data of Pennsylvania residents. Like other state comprehensive privacy laws, its applicability thresholds focus on companies conducting business in Pennsylvania or targeting Pennsylvania residents that process personal data above defined volume or revenue thresholds.

The bill defines sensitive data broadly to include personal data revealing health conditions plus biometric or genetic identifiers, requiring affirmative opt-in consent before processing. Targeted advertising based on data collected across non-affiliated websites or apps is specifically regulated and subject to consumer opt-out rights; first-party and contextual ads fall outside that provision.

Critically for marketers, controllers must conduct a Data Protection Assessment before engaging in heightened-risk processing, and the Pennsylvania Attorney General can compel disclosure of those assessments during an investigation. The bill, as drafted, does not include a private right of action, leaving enforcement to the Attorney General. PA marketers should also study compliance models taking shape in neighboring and similar states; see Curve's coverage of the Indiana Consumer Data Protection Act and the multi-state compliance challenge for context.

The Current Enforcement Landscape

OCR Enforcement Trends

2024 was one of the busiest enforcement years on record. [1] The OCR Director confirmed at year-end that 22 investigations of data breaches and complaints resulted in civil monetary penalties or settlements in 2024, with 16 announced during the calendar year and the remainder published in January 2025. [2] Across 20 publicly announced enforcement actions since the start of 2024, organizations paid a combined $9,436,346.

Recent representative actions illustrate the range:

  • Gulf Coast Pain Consultants: A $1.19 million penalty was imposed in December 2024 for HIPAA Security Rule violations.[1]
  • Children's Hospital Colorado: A $548,265 penalty was assessed in December 2024 following phishing breaches affecting employee email accounts containing PHI.
  • Holy Redeemer Family Medicine: A November 2024 settlement resolved allegations involving disclosure of a patient's reproductive health information to a prospective employer without consent.

OCR's most-cited violation across 2024 enforcement actions was inadequate risk analysis, appearing in 13 of 20 matters, prompting the agency's formal Risk Analysis Initiative.

FTC Involvement

The Federal Trade Commission opened a second enforcement front against non-HIPAA digital health entities. [3] In February 2023, GoodRx agreed to a $1.5 million civil penalty in the FTC's first-ever Health Breach Notification Rule enforcement action for sharing personal health information with Facebook, Google, and Criteo. One month later, BetterHelp agreed to pay $7.8 million to consumers, the first FTC action returning funds to consumers whose health data was compromised. [4] In April 2024 the FTC finalized amendments to the Health Breach Notification Rule, codifying that unauthorized disclosures (not just hacks) trigger notification duties.

Class-Action Lawsuit Explosion

Pixel-tracking class actions are now the dominant litigation theory against hospitals. Settlement values vary widely:

  • Advocate Aurora Health: A $12.25 million settlement covered claims that the system shared user information with Meta and Google through a tracking pixel; an HHS breach filing indicated approximately 3 million people could be affected.[5]
  • MarinHealth: A $3 million settlement fund resolved claims that Meta Pixel and other tracking tools transmitted sensitive information to third parties.[6]
  • Jefferson Healthcare: The settlement requires the provider to refrain from using Meta Pixel for at least two years and pay $125,000 in attorneys' fees.[7]

The flagship multidistrict matter, In re Meta Pixel Healthcare Litigation, is proceeding in the Northern District of California after Judge William H. Orrick denied Meta's second motion to dismiss on January 29, 2024.[8]

State-Level Actions and the Pennsylvania Layer

State attorneys general increasingly pursue HIPAA-equivalent violations under state law, which can be easier to win and sometimes carry higher penalty ceilings than HIPAA itself. Once Pennsylvania consumer data privacy legislation passes, the PA Attorney General will hold a parallel enforcement lever for marketing-driven data flows on top of federal HIPAA and FTC exposure.

Specific Risks and Consequences

Financial Penalties

  • OCR civil monetary penalties: Tiered by culpability; under the 2019 Notice of Enforcement Discretion, the willful-neglect-uncorrected tier carries a $1,500,000 annual cap for identical offenses, subject to annual inflation adjustment.[13]
  • FTC penalties: $1.5 million against GoodRx[3] and $7.8 million against BetterHelp[4] under the Health Breach Notification Rule and Section 5 of the FTC Act.
  • Class-action settlements: From $3 million (MarinHealth)[6] to $12.25 million (Advocate Aurora)[5] for pixel-tracking claims.
  • State AG penalties: Pennsylvania HB 1201 designates privacy violations as unfair or deceptive practices under PA consumer protection law, exposing controllers to additional state-level penalties on top of federal exposure.

Reputational Damage

OCR publicly posts every breach affecting 500 or more individuals to its breach portal (commonly called the "Wall of Shame"), and every settlement is announced through a press release archived on hhs.gov.[9] The Advocate Aurora pixel breach notification, for example, disclosed that up to 3 million patients (the system's entire patient base) may have been affected, generating sustained national press coverage.

Operational Disruption

OCR's preferred outcome is a settlement paired with a multi-year Corrective Action Plan that imposes ongoing policy development, technical remediation, workforce training, reporting, and monitoring obligations. CAPs frequently run two years or longer, diverting compliance, IT, and marketing resources from growth initiatives.

Personal Liability

OCR refers cases involving the knowing disclosure or obtaining of PHI to the Department of Justice for criminal prosecution; cumulative referrals stand in the thousands.[10] Executives and board members can face personal exposure where they participated in or knowingly tolerated impermissible disclosures, and cyber insurance often excludes intentional violations of privacy laws.

How Violations Happen

Technical Configurations

The OCR tracking technology bulletin specifically calls out cookies, web beacons or tracking pixels, session replay scripts, and fingerprinting scripts as common mechanisms for impermissible PHI disclosure.[11] Real-world failure modes documented in enforcement and litigation include:

  • Meta Pixel on appointment-booking pages: Transmits URL paths, button clicks, and form fields tied to specific conditions to Facebook, often combined with hashed identifiers that Facebook can rejoin to user profiles, as alleged in In re Meta Pixel Healthcare Litigation.
  • Google Analytics default configurations: Capture IP addresses (one of the 18 HIPAA identifiers per HHS) alongside page paths that may reveal condition-specific browsing.
  • Form-submission tracking: The GoodRx complaint specifically alleged that custom events sent through the Facebook Pixel conveyed medication names and health conditions.
  • Hashed email uploads: The BetterHelp action established that uploading hashed emails to Facebook for lookalike-audience targeting still constituted disclosure because Facebook could re-identify the underlying individuals.

Note that in June 2024, the U.S. District Court for the Northern District of Texas vacated portions of the OCR tracking technology bulletin that treated an IP address plus a visit to an unauthenticated public webpage as automatically constituting PHI; OCR is evaluating next steps and the bulletin remains posted with the vacatur acknowledged.[12] The ruling narrows but does not eliminate enforcement risk, and class-action plaintiffs continue to advance theories under wiretap, common-law privacy, and state consumer protection statutes.

Vendor Relationships

OCR's position remains that regulated entities may not share PHI with tracking technology vendors absent a business associate agreement or HIPAA-permitted authorization. Major ad platforms (Meta, Google Ads, TikTok) do not sign BAAs for their standard pixel products, which is precisely why default implementations on patient-facing properties create exposure.

Staff Actions and Audit Triggers

Marketing teams routinely add pixels via tag managers without security review. The July 2023 joint OCR/FTC warning letter campaign reached roughly 130 hospitals and health systems whose websites were observed using third-party trackers, demonstrating that regulators run their own automated detection. Other common audit triggers include patient complaints, breach disclosures, and competitor or whistleblower tips.

Protection Strategies

Immediate Actions (This Week)

  1. Run a tag inventory on every patient-facing page, appointment scheduler, symptom checker, and authenticated portal.
  2. Identify every third-party vendor receiving website data and verify whether a signed BAA exists.
  3. Pull the last 30 days of conversion events sent to Meta and Google and review for PHI elements (URLs containing condition names, email or phone fields, MRN-style parameters).
  4. Document findings with timestamps; this becomes evidence of good-faith remediation if regulators later inquire.

Short-Term Fixes (This Month)

  1. Remove or reconfigure any pixel that cannot transmit data through a BAA-covered intermediary.
  2. Migrate to server-side tracking that strips PHI before any data leaves your controlled environment.
  3. Update privacy policies to accurately describe tracking practices; the BetterHelp action makes clear that inaccurate privacy promises are independently actionable under Section 5 of the FTC Act.
  4. Train marketing, web, and agency staff on what constitutes PHI in a tracking context.

Long-Term Compliance Infrastructure

Pennsylvania consumer data privacy compliance, layered over HIPAA, requires a documented tracking governance program: vendor BAAs, signed Data Protection Assessments, opt-out mechanisms for targeted advertising, and a clear consent pathway for sensitive (health) data processing. Therapist practices and other behavioral health providers face heightened sensitivity; Curve's guide to therapist practice marketing without exposing patient data walks through specialty-specific controls.

Vendor Evaluation Criteria

  • BAA availability: Will the vendor execute a BAA covering all data flows, including subprocessors?
  • Server-side architecture: Does the vendor strip PHI before transmission to ad platforms, or does it merely proxy raw events?
  • Audit trail: Can the vendor produce per-event logs showing what was filtered, retained, or forwarded?
  • Healthcare specificity: Generalist analytics vendors do not understand condition-revealing URLs, appointment metadata, or insurance-related parameters.

How Curve Addresses Each Risk

Curve was designed for HIPAA-regulated marketing teams that need ad-platform performance without the data exposure that drives OCR enforcement and pixel-tracking class actions.

  • Automated PHI stripping: Curve filters identifiers and condition-revealing parameters at the server layer before any data reaches Meta, Google, or TikTok, addressing the technical vector cited in the GoodRx, BetterHelp, and Aurora actions.
  • Signed BAAs included: Every Curve deployment ships with a signed Business Associate Agreement, closing the vendor-relationship gap that OCR cites as a baseline requirement for any vendor receiving PHI.
  • Server-side conversion APIs: Curve uses Meta's Conversions API and Google's enhanced conversions in a configuration that keeps raw PHI inside your controlled environment.
  • Audit trails: Every event Curve processes is logged with timestamp, filter actions taken, and destination, producing the documentation OCR investigators and class-action defense counsel routinely request.
  • Healthcare-specific design: Curve's filtering rules are built around the 18 HIPAA identifiers, common appointment-booking patterns, and condition-revealing URL structures rather than generic PII heuristics.
  • Rapid implementation: Most healthcare organizations move from risk identification to compliant tracking within days, not the months typical of custom server-side builds.

For organizations operating across state lines, the same architecture supports compliance with emerging laws covered in Curve's analyses of the Minnesota Consumer Data Privacy Act and the Oregon Consumer Privacy Act.

Don't Wait for Enforcement

Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve to review your current tracking stack and document your remediation path before Pennsylvania consumer data privacy enforcement activates.

Self-Assessment Compliance Checklist

  • Tag inventory complete: Every script, pixel, and tag manager rule on patient-facing properties has been catalogued in the last 90 days.
  • BAA coverage verified: Every vendor receiving website event data has a signed BAA, or is no longer receiving that data.
  • Server-side tracking in place: Conversions reach ad platforms through a server-side pipeline that strips PHI.
  • Authenticated pages locked down: No third-party trackers fire inside patient portals, scheduling tools, or symptom checkers absent a BAA.
  • Privacy policy accurate: The privacy policy describes actual tracking practices, vendors, and consumer rights.
  • Data Protection Assessment ready: A documented DPA exists for any targeted advertising or sensitive-data processing, anticipating PA HB 1201 and similar laws.
  • Audit logs preserved: Per-event logs are retained for at least the statutory limitations period.
  • Workforce trained: Marketing, web, and agency staff have received documented training on PHI in a tracking context within the last 12 months.
  • Incident response tested: A documented playbook exists for responding to a suspected impermissible disclosure within 60 days.

Frequently Asked Questions

What are the penalties for HIPAA marketing violations?

OCR civil monetary penalties are tiered by culpability. Under the 2019 Notice of Enforcement Discretion, the willful-neglect-uncorrected tier carries an annual cap of $1,500,000 for identical offenses, with per-violation amounts adjusted upward for inflation each year.[13] In 2024 OCR closed 22 enforcement cases with penalties or settlements,[1] and total payments since the start of 2024 exceeded $9.4 million across 20 publicly announced actions.[2] Add FTC penalties (up to $7.8 million in BetterHelp) and class-action settlements (up to $12.25 million in Advocate Aurora) for non-HIPAA-only exposure.

Can healthcare practices be sued for using Meta Pixel?

Yes, and dozens have been. Advocate Aurora Health agreed to a $12.25 million class-action settlement over Meta Pixel use,[5] MarinHealth settled for $3 million,[6] and the multidistrict In re Meta Pixel Healthcare Litigation is proceeding in the Northern District of California after Judge Orrick denied Meta's second motion to dismiss in January 2024.[8] Settlements typically include both monetary payments and injunctive relief requiring the provider to stop using the pixel for a specified period.

How do I know if my healthcare marketing is compliant?

Compliance turns on three documented elements: (1) a current inventory of all tracking technologies on patient-facing properties, (2) a BAA in place for every vendor receiving data that could be PHI, and (3) technical controls that prevent PHI transmission to vendors that will not sign a BAA. The OCR tracking technology bulletin emphasizes that investigations are fact-specific and may involve review of technical configurations and deployment evidence.

What should I do if I discover a compliance violation?

First, stop the data flow immediately and document the configuration before and after remediation. Second, assess whether the disclosure meets the threshold for breach notification under the HIPAA Breach Notification Rule and (for non-HIPAA entities) the FTC's Health Breach Notification Rule, which now expressly covers unauthorized disclosures, not just data security breaches. Third, engage privacy counsel before initiating any external communications, because the FTC's BetterHelp matter showed that inaccurate public statements about data practices create independent Section 5 liability.

Will the Pennsylvania Consumer Data Privacy Act create a private right of action against my practice?

As currently drafted, HB 1201 does not include a private right of action; enforcement authority rests with the Pennsylvania Attorney General. However, PA healthcare marketing data flows that violate HIPAA or transmit PHI to advertising platforms can still trigger federal class actions under wiretap, common-law privacy, and state consumer-protection theories independent of HB 1201.

Sources

  1. HIPAA Journal, HIPAA Violation Fines
  2. Shook, Hardy & Bacon, OCR Enforcement Activity: Trends and Insights
  3. FTC, Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info
  4. FTC, Updated Health Breach Notification Rule
  5. Milberg, Aurora Health Agrees to $12.25M Settlement in Tracking Pixel Suit
  6. HIPAA Journal, MarinHealth Pays $3 Million to Settle Meta Pixel Lawsuit
  7. HIPAA Journal, Jefferson Healthcare Agrees to Settle Meta Pixel Class Action
  8. Cohen Milstein, In re Meta Pixel Healthcare Litigation
  9. HHS.gov, Resolution Agreements
  10. HHS.gov, Enforcement Highlights
  11. HHS.gov, Use of Online Tracking Technologies by HIPAA Covered Entities
  12. Nixon Peabody, Portions of OCR's Tracking Technologies Bulletin Deemed Unlawful
  13. Federal Register, Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit