Skip to main content
Guide

Pixel Settlements to Date: A Running Reference

A running reference of healthcare tracking pixel class action settlements, the dollar figure and class period for each, and the pattern the complaints share.

9 min read

Healthcare tracking pixel class action settlements have cumulatively crossed $100 million, with individual funds ranging from a few hundred thousand dollars for a single hospital to $46 million for Kaiser Permanente. None of these cases were brought under HIPAA, which has no private right of action. They run on state wiretap statutes, consumer protection law, and breach of confidence claims, which is why the exposure exists even where OCR never opens a file. Curve is HIPAA-compliant ad tracking with a signed BAA on every plan, built to remove the specific mechanism every one of these complaints describes.

How to read this list

Three things are worth understanding before the numbers.

First, the legal theory. Plaintiffs allege that embedding a third-party tag on a health-related page or a patient portal intercepts communications, and they plead it under statutes like the California Invasion of Privacy Act, the federal Wiretap Act, and state consumer protection laws, often alongside breach of confidence and unjust enrichment. HIPAA appears in these complaints as a standard of care, not as a cause of action.

Second, the settlement funds are gross. Attorneys' fees, notice and administration costs, and service awards to named plaintiffs come out before class members are paid, which is why a $3 million fund can produce roughly $111 per person while a $21.5 million fund produces up to $90.

Third, a settlement is not a finding. Every defendant below settled without admitting wrongdoing. What the list demonstrates is not guilt, it is the cost of defending a configuration that is difficult to explain to a jury.

The large settlements

  • Kaiser Permanente, $46 million base fund, up to $47.5 million. Preliminary approval December 2025. Roughly 13.4 million individuals who accessed authenticated Kaiser websites and mobile apps between 2017 and 2024. Claims pleaded under CIPA, the Electronic Communications Privacy Act, and state consumer protection law. Kaiser had separately notified 13.4 million individuals of the underlying disclosure.
  • Sutter Health, $21.5 million. Approved by the court in early 2026. Alleged that Google Analytics, the Meta Pixel, and other advertising tools ran on the MyHealthOnline portal and main site, including the portal login page. Eligible class members could claim up to $90.
  • Mass General Brigham and Dana-Farber Cancer Institute, $18.4 million combined. Filed in Suffolk Superior Court in May 2019 and settled, covering site visitors between May 23, 2016 and July 31, 2021 across 38 named providers. Payments of up to $100. This is the earliest large settlement of its kind and predates the OCR tracking bulletin by years.
  • Advocate Aurora Health, $12.225 million. Final approval July 10, 2024. The complaint covered more than 2.5 million people whose information was allegedly disclosed to Meta and Google. Advocate Aurora had notified roughly 3 million patients of a tracking-related disclosure, treating every MyChart and LiveWell user and every scheduling widget user as potentially affected.
  • University of Pennsylvania Health System, $9.5 million. Covers myPennMedicine portal users between January 23, 2021 and January 23, 2023, with payments up to $15. Fairness hearing scheduled for November 2026.
  • Novant Health, $6.6 million. Stemmed from tracking pixels on the MyChart patient portal, with up to 1.36 million patients affected.

The smaller wave

The pattern through 2025 and 2026 is more filings against smaller providers with proportionally smaller funds. Plaintiffs' firms can identify a candidate by loading a provider's site and reading what loads with it, which makes the filing cost low and the target list long.

  • Inova Health Care Services, $3,147,390.04. Preliminary approval December 17, 2025. Covers Inova MyChart account holders who visited a public Inova website between April 29, 2022 and April 29, 2024. Fairness hearing April 2026.
  • MarinHealth Medical Center, $3 million. Preliminary approval May 27, 2025. Covers anyone in the United States who visited a MarinHealth website between August 1, 2019 and May 27, 2025. Class members received roughly $111 each. MarinHealth also agreed to remove the Meta Pixel and not reinstall it without notice and consent.
  • Concord Hospital Health System, $800,000. Covers information alleged to have been intercepted starting May 9, 2021, distributed pro rata. Fairness hearing November 2026.
  • Emanate Health Medical Center, $777,000. Net fund of roughly $433,709 after deductions, producing payments in the region of $11 per claimant. Fairness hearing November 2026.
  • Mount Sinai Medical Center of Florida, $220,000. Covers website and portal users between June 10, 2021 and September 18, 2025, with expected payments near $20 plus a year of data monitoring. Fairness hearing October 2026.
  • Bayhealth Medical Center. Fund amount not stated in the class notice. Portal users between January 1, 2019 and December 31, 2025 receive a $25 cash payment plus a year of data monitoring. Fairness hearing October 2026.

Consolidated litigation against Meta itself over healthcare pixel data remains pending and is not included above, because no settlement figure exists to report.

What the complaints consistently allege

Read enough of these and the fact pattern repeats almost word for word.

A third-party tag was present on pages that reveal something about health: a condition page, a physician directory filtered by specialty, an appointment scheduler, or a portal login. The tag transmitted the page URL, the referrer, and an identifier, usually a cookie value that the receiving platform can associate with a real account. In portal cases, the complaint adds that the transmission continued after authentication, so the data was tied to a known patient rather than an anonymous visitor.

The defense that fails most often is the one that sounds most reasonable: we never sent any medical information. In these cases the health inference does not come from a diagnosis field. It comes from the URL. A page path naming an oncology service line, transmitted alongside an identifier, is the disclosure. That is also the position HHS OCR took in its December 2022 bulletin on online tracking technologies, updated in March 2024, which states that tracking technologies transmitting individually identifiable health information to vendors constitute a PHI disclosure.

One qualification worth stating plainly: in June 2024, a federal court vacated the portion of that bulletin addressing unauthenticated public webpages, holding that OCR exceeded its authority by treating an IP address combined with a visit to a public health-topic page as a PHI disclosure. OCR withdrew its appeal in August 2024. That ruling narrowed OCR's stated position on public pages. It did not touch the private litigation theories, and the settlements above have continued at pace since.

The costs that do not appear in the fund

The settlement number is the visible line. Several others are not.

Breach notification is its own expense and its own reputational event. Kaiser notified 13.4 million individuals. Advocate Aurora notified 3 million. Cerebral notified more than 3.17 million after disclosing pixel-related transmissions covering October 2019 through January 2023. Those notifications appear on the HHS breach portal, which is public and permanently searchable.

Injunctive terms carry forward. MarinHealth agreed to remove the Meta Pixel and to obtain consent before any reinstallation. Terms like that constrain the marketing stack for years after the money is paid.

And the campaigns still have to run. Pulling every tag off a site solves the legal problem by destroying conversion tracking, which is why most organizations that settle end up rebuilding the measurement layer rather than abandoning it.

How Curve removes the mechanism

Every complaint above turns on the same architectural fact: a third-party script running in the patient's browser, sending data directly to a company that will not sign a BAA. Meta and Google do not sign BAAs for their advertising products, which means no configuration of a client-side pixel makes that transmission authorized.

Curve changes what is in the browser. Its tracking script installs in place of the Meta Pixel and Google tag, and events go to Curve's US-hosted infrastructure instead of directly to ad platforms. What forwards from there is decided server-side by per-destination field mapping, where the default is that nothing is sent and only explicitly mapped fields move. Identifiers are SHA-256 hashed to each platform's conversion API requirements. Neutral event aliases mean the platform receives a generic conversion name rather than a service line, so the ad interface never displays a condition. PHI-pattern detection monitors payloads for PHI-shaped values and flags them, so a form change upstream surfaces as an alert rather than as a class notice two years later.

The signal the ad platform receives contains no health context and no unhashed identifier, which is why it requires no BAA. The data that does carry health context stays with a vendor that has signed one. For the technical detail, see our overviews of conversion API architecture and Meta Conversions API implementation for healthcare.

What this list tells you to check

The class periods are the most useful column. Several of them start in 2019 or 2021 and run to a date in the last year, which means the exposure window is measured from when a tag was installed, not from when a complaint was filed. If a pixel has been live on your site since 2021, the relevant period is already five years long.

Check three things. What scripts load on your condition pages, your scheduling flows, and your portal login. What each of those scripts transmits, including the full URL and referrer. And whether any of the receiving vendors has signed a BAA with you. Our explanation of why client-side pixels create a HIPAA violation walks through what to look for, and our answer on the Meta Pixel and Conversions API addresses the server-side version of the same question.

Frequently asked questions

Why can patients sue over pixels when HIPAA has no private right of action?

Because the claims are not HIPAA claims. They are brought under state wiretap statutes, consumer protection acts, and common law theories like breach of confidence. HIPAA is cited to establish what a reasonable standard of care looks like.

Does removing the pixel end the exposure?

It stops new transmissions. It does not affect the period the tag was live, which is what the class definitions cover. Removal is necessary and not retroactive.

Did the 2024 court ruling make pixels legal again on public pages?

It vacated part of OCR's bulletin as applied to unauthenticated public webpages, which narrowed one regulator's stated position. It did not change state wiretap law, and the settlements listed above include cases filed and resolved after it.

Are small practices actually being sued?

Yes. The funds in the $220,000 to $800,000 range belong to single hospitals and regional systems. Identifying a target requires only loading a website, which makes practice size a weak defense.

Is consent a defense?

A properly implemented consent mechanism materially improves the position, and several settlements include consent requirements as injunctive relief. It is not a substitute for controlling what leaves, because consent obtained through a banner rarely matches the specificity HIPAA authorization requires for PHI.

How do these funds get calculated?

Generally by class size, statutory damage exposure under the pleaded statutes, and the cost of continued defense. They are negotiated, not computed from a formula, which is why per-person payments vary from $11 to $111 across the list.

Where to start

Load your own site the way a plaintiffs' firm would. Open the network tab on a condition page, a scheduling page, and your portal login, and read what leaves the browser and where it goes. Then check which of those destinations has a BAA with you. The answer for the ad platforms will be none, because they do not offer one.

Our free compliance scanner does the first pass automatically and tells you which tracking scripts are live on your site. To see how the ad tracking layer works when it sits behind a signed BAA, visit curvecompliance.com.

Reviewed August 2026. This is general information, not legal advice. Settlement figures and approval status change as cases progress, and any figure here should be confirmed against the court record before it is relied on. Consult qualified counsel about your own exposure.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit