Virginia VCDPA Healthcare Marketing: Patient Data Rights for Virginia Providers
In June 2024, a federal judge approved a $6.6 million class-action settlement against Novant Health after a Meta Pixel on the hospital system's MyChart portal allegedly transmitted protected health...
In June 2024, a federal judge approved a $6.6 million class-action settlement against Novant Health after a Meta Pixel on the hospital system's MyChart portal allegedly transmitted protected health information to Facebook, in a case filed on behalf of patients alleging invasion of privacy, breach of contract, and HIPAA violations.[1] Novant is one of several systems sued over pixel use, alongside Advocate Aurora Health, which settled for $12.225 million.[1] For Virginia providers, these cases illustrate the dual exposure created by federal HIPAA enforcement and state privacy regimes. Understanding how VCDPA healthcare rules interact with HIPAA, and where the Virginia Consumer Data Protection Act leaves gaps that can still create liability, is now an operational requirement, not a legal footnote. This guide explains who VCDPA covers, what Virginia consumer data protection medical exemptions actually mean, and how to keep marketing compliant under both regimes.
The Current Enforcement Landscape
OCR Enforcement Trends
The Office for Civil Rights (OCR) has steadily escalated HIPAA enforcement against providers. According to OCR's published Enforcement Highlights, the agency has resolved a substantial volume of cases through corrective action plans, settlements, and civil money penalties.[2] Recent settlements show the breadth of agency reach: OCR imposed a $1.19 million penalty against Gulf Coast Pain Consultants for HIPAA Security Rule violations on December 3, 2024, and a $548,265 penalty against Children's Hospital Colorado on December 5, 2024.[3] The most common allegations cumulatively include impermissible uses and disclosures of protected health information, lack of safeguards, and lack of administrative safeguards of electronic protected health information.
FTC Involvement and the Online Tracking Bulletin
OCR and the Federal Trade Commission have moved jointly against tracking technologies. On July 20, 2023, the agencies sent a joint letter to approximately 130 companies that included hospitals, other HIPAA-covered entities, telehealth providers, and health app developers, alerting recipients to the risks that tracking technologies, including Meta/Facebook pixel and Google Analytics, pose to the privacy and security of consumers' personal health information.[4] The FTC has warned that even companies not covered by HIPAA still have obligations under the FTC Act and the FTC's Health Breach Notification Rule to protect against impermissible disclosures of personal health information.[4]
In June 2024, a federal court partially vacated the OCR Bulletin. HHS has acknowledged that the court vacated the guidance to the extent it provides that HIPAA obligations are triggered when an online technology connects an individual's IP address with a visit to an unauthenticated public webpage addressing specific health conditions or healthcare providers; HHS is evaluating its next steps.[5] Authenticated portal pages and the underlying obligation not to disclose PHI to vendors without a BAA remain firmly in place.
The Class-Action Lawsuit Explosion
Private litigation has driven the largest dollar exposure. Beyond Novant's $6.6 million resolution, other settlements over pixel tracking technology include NewYork-Presbyterian Hospital ($300,000), Advocate Aurora Health ($12.25 million), and Froedtert Health ($2 million).[1] These complaints typically allege invasion of privacy, breach of contract, and HIPAA-based negligence, even though HIPAA itself has no private right of action; most lawsuits involved privacy tort claims or claims arising under state privacy or federal wiretap statutes.[6]
State-Level Actions and the VCDPA
The Virginia Consumer Data Protection Act took effect on January 1, 2023.[7] The Virginia Attorney General enforces VCDPA, with civil penalties of up to $7,500 per violation and a right to cure within a set period. Importantly, in March 2025, Virginia broadened state-level health-privacy reach by amending the Virginia Consumer Protection Act. On March 24, 2025, Governor Glenn Youngkin signed SB 754 into law; effective July 1, 2025, the amendment prohibits certain entities from, in connection with a consumer transaction, obtaining, disclosing, selling, or disseminating any personally identifiable reproductive or sexual health information without consumer consent.[8] Critically, SB 754 is enforceable through a private right of action, opening a state-law door that VCDPA itself does not.[8]
How VCDPA Healthcare Exemptions Actually Work
Virginia providers often assume VCDPA simply does not apply to them. The reality is more nuanced. Under Va. Code § 59.1-576, the chapter shall not apply to any covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and HITECH, or to nonprofit organizations, or to institutions of higher education.[9]
The Virginia AG's own consumer summary confirms that the following types of data are not covered by the VCDPA: protected health information under HIPAA, health records, patient identifying information, and other sets of data identified in Va. Code § 59.1-576 that relate to compliance with various federal laws.[7]
But the exemption is not absolute. While HIPAA-regulated entities and data are generally exempt, VCDPA can still reach health-related information that falls outside HIPAA (for example, consumer wellness or health app data processed by non-covered entities). If you operate in that space and meet VCDPA's applicability thresholds, you must honor consumer rights requests, uphold data minimization, and conduct risk assessments in addition to your HIPAA obligations. The same applies to marketing data generated about prospective patients who have never become patients, employee data, and ancillary consumer products. For background on broader state requirements, see our guide to Virginia VCDPA: Healthcare Marketing Compliance for Virginia Medical Practices.
VCDPA applicability thresholds matter too. The statute applies to persons that conduct business in the Commonwealth or produce products or services targeted to residents of the Commonwealth and that meet defined consumer-volume or revenue criteria tied to processing personal data and selling personal data.[9]
Specific Risks and Consequences
Financial Penalties
The financial exposure stacks across overlapping regimes:
- OCR civil monetary penalties (federal HIPAA): Penalties assessed on or after August 8, 2024 apply to violations occurring on or after November 2, 2015, calculated by applying the 1.03241 cost-of-living multiplier published by HHS in the Federal Register.[10] Tier 1 ranges from $141 to $71,162; Tier 2 from $1,424 to $71,162; Tier 3 from $14,232 to $71,162; Tier 4 from $71,162 to $71,162, with a calendar-year cap of $2,134,831 per identical provision in each tier.[10]
- HIPAA criminal exposure: Knowing wrongful conduct involving individually identifiable health information can bring criminal penalties: up to $50,000 and 1 year; under false pretenses up to $100,000 and 5 years; and with intent to sell, transfer, or use for gain or malicious harm up to $250,000 and 10 years.
- VCDPA penalties: Up to $7,500 per violation, enforced by the Virginia Attorney General, with a statutory right to cure.[7]
- VCPA SB 754 (reproductive/sexual health): Private right of action, no applicability threshold, broad "supplier" definition.[8]
- Class-action settlements: Novant Health $6.6 million, Advocate Aurora $12.25 million, Froedtert Health $2 million, NewYork-Presbyterian $300,000.[1]
Reputational Damage
OCR maintains a public breach portal for incidents affecting 500 or more individuals. Pixel-related breach notifications have been among the most visible. Novant Health reported its use of online trackers to federal regulators on August 14, 2022, as a HIPAA breach affecting more than 1.36 million individuals, and the breach later became the subject of consolidated class-action litigation.[1] These incidents routinely draw local and national press coverage and erode patient trust, regardless of whether OCR ultimately imposes a monetary penalty.
Operational Disruption
HIPAA's breach notification rule requires affected individuals be notified without unreasonable delay and no later than 60 days after discovery, with additional notice to HHS and prominent media when an incident affects 500 or more individuals in a state or jurisdiction. Investigations often produce multi-year corrective action plans and ongoing monitoring requirements.
Personal Liability
Criminal HIPAA exposure can attach to individuals, not just entities. Executives and officers approving non-compliant marketing programs may face derivative claims, and most cyber-liability policies exclude intentional acts and certain regulatory penalties.
How Violations Happen
Technical Configurations
Most violations are not malicious. They result from default tool behavior. In OCR's view, the use of third-party tracking technologies on websites, web applications, and mobile apps without a business associate agreement (BAA) is a HIPAA violation if the tracking technology collects and transmits individually identifiable health information; even with a BAA in place, the use of the tracking technology may still violate the HIPAA Rules.[11]
Specific patterns that have triggered enforcement:
- Meta Pixel on patient portals: The Markup's reporting examined Meta Pixel deployments on hospital websites and telehealth platforms, prompting subsequent class actions against named providers.[4]
- URL parameter leakage: Procedure names, condition names, or provider specialties in URLs can be transmitted as event data to ad platforms.
- Google Analytics on intake forms: Form-field capture and IP-address transmission to Google when consent and a BAA are absent.
- Embedded widgets: Chat, scheduling, and review widgets that load third-party JavaScript on pages where users discuss conditions or providers.
Vendor Relationships
OCR has been explicit on vendor status: the provider of code such as Meta Pixel or Google Analytics is classed as a business associate and must enter into a business associate agreement with the HIPAA-regulated entity before the code can be added to a website or application, and the BAA must specify the responsibilities of the vendor with respect to PHI.[11] If the vendor will not sign a BAA, PHI cannot legally be provided to that vendor. Meta and Google have generally declined to sign healthcare BAAs for their advertising pixels.
Staff Actions
Marketing teams routinely add pixels to launch campaigns. IT teams reinstall removed scripts during platform migrations. Content managers embed third-party widgets (chat, scheduling, reviews). Each of these can re-introduce risk silently. Practices that handle sensitive populations should review our adjacent guide on therapist practice marketing for parallel considerations.
Audit Triggers
OCR investigations begin with patient complaints, breach notifications, media reports, and competitor or whistleblower tips. OCR has stated it is prioritizing compliance with the HIPAA Security Rule in investigations involving online tracking technologies, with a principal interest in ensuring that regulated entities have identified, assessed, and mitigated the risks to ePHI.[5]
Protection Strategies
Immediate Actions (This Week)
- Inventory every tracking script on your website and mobile app (Meta Pixel, GA4, LinkedIn Insight, TikTok, chatbots, scheduling widgets).
- Identify which pages handle health-related interactions (symptom checkers, condition pages, appointment requests, portal logins).
- Pull a current list of vendor BAAs and flag any tracking vendor without one.
- Document everything in a written internal memo with a date stamp.
Short-Term Fixes (This Month)
- Remove ad-platform pixels from authenticated portal pages and pages discussing specific conditions or providers.
- Move from client-side to server-side tracking that strips identifiers before transmission.
- Update your Notice of Privacy Practices and website privacy policy to reflect actual data flows. Website banners that ask a visitor to consent to cookies and the use of web tracking technologies do not constitute valid HIPAA authorizations.[5]
- Train marketing and IT staff on what triggers PHI and what BAA coverage requires.
Long-Term Compliance Infrastructure
Build a compliance stack that includes a server-side tagging layer, an automated PHI filter, signed BAAs with every analytics or ad vendor that can touch user data, and quarterly script audits. Document data protection assessments where VCDPA applies to non-HIPAA marketing data. For specialty-specific approaches, see how aesthetic clinics track consultations without exposing patient data and our dental marketing compliance checklist.
Vendor Evaluation Criteria
- BAA availability: Will the vendor sign a HIPAA-compliant BAA covering all advertising and analytics use cases? Generic terms-of-service do not qualify.
- PHI handling: Does the vendor strip identifiers server-side before data leaves your infrastructure?
- SOC 2 / HITRUST: Independent attestations of administrative and technical safeguards.
- Healthcare-specific design: Built for the OCR Bulletin's requirements, not retrofitted from generic marketing tooling.
- Audit trails: Complete logs you can produce if OCR or the Virginia AG comes asking.
How Curve Addresses Each Risk
Curve was designed specifically for the HIPAA tracking problem identified in the OCR Bulletin and the wave of pixel litigation. The platform pairs technical controls with the legal documentation OCR investigators expect to see.
- Automated PHI stripping: Curve filters identifiers (names, email, phone, MRN, IP where applicable, condition-related URL parameters) before any data leaves your environment, eliminating the configuration mistakes that drove the Novant and Advocate Aurora incidents.
- Server-side tracking: Conversion events flow to Meta Conversions API, Google Ads, and analytics platforms through a sanitized server-side layer, not browser pixels that capture form fields and URLs verbatim.
- Signed BAAs: Curve executes a Business Associate Agreement with every healthcare client, satisfying the threshold requirement OCR identified for tracking-technology vendors.
- Audit trails: Every event, transformation, and transmission is logged, giving you the documentation required for OCR investigations, state AG inquiries, or class-action discovery.
- Healthcare-specific design: The platform was built around the OCR Bulletin and subsequent 2024 update, including the distinction between authenticated and unauthenticated pages.
- Rapid implementation: Most practices complete deployment in days, not the multi-month engineering effort required to build server-side infrastructure in-house.
Don't Wait for Enforcement
Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve.
VCDPA Healthcare Compliance Self-Assessment Checklist
- Entity status mapped: You have determined whether each business line is a HIPAA covered entity, a HIPAA business associate, or a non-HIPAA consumer offering subject to VCDPA.
- Threshold analysis complete: If non-HIPAA, you have measured your processing activity against VCDPA's applicability thresholds in Va. Code § 59.1-576.
- Tracking inventory current: Every script, pixel, and SDK on web and mobile is documented.
- BAAs verified: Every vendor that could touch PHI has a signed BAA on file; vendors that refuse have been removed.
- Authenticated pages clean: No advertising pixels on patient portals, scheduling pages, or condition-specific content.
- Server-side architecture in place: Marketing data flows through a PHI-filtering layer before reaching ad platforms.
- Notice of Privacy Practices updated: Reflects actual data flows, not boilerplate.
- SB 754 reviewed: Reproductive and sexual health information handling, including non-HIPAA contexts, has explicit consent flows.
- Staff trained: Marketing, IT, and content teams know what triggers a BAA and what cannot be installed unilaterally.
- Audit logs retained: Documentation sufficient to respond to OCR or Virginia AG inquiries within statutory timelines.
Frequently Asked Questions
What are the penalties for HIPAA marketing violations?
Federal civil penalties under the inflation-adjusted schedule effective August 8, 2024 range from a minimum of $141 per violation in Tier 1 up to $71,162 per violation across Tiers 1 through 4, with a calendar-year cap of $2,134,831 per identical provision in each tier.[10] Criminal penalties for knowing violations can reach $250,000 and 10 years imprisonment. VCDPA adds up to $7,500 per violation under Virginia AG enforcement. Class-action settlements in pixel cases have included Novant Health at $6.6 million and Advocate Aurora at $12.225 million.[1]
Can healthcare practices be sued for using Meta Pixel?
Yes. Although HIPAA has no private right of action, plaintiffs have successfully brought claims for invasion of privacy, breach of contract, and state wiretap or consumer-protection violations. Following The Markup's reporting, several class actions were filed against named providers, with most involving privacy tort claims or claims arising under state privacy or federal wiretap statutes.[6] Virginia's SB 754 adds an explicit private right of action for reproductive and sexual health information.[8]
Does VCDPA apply to my Virginia medical practice?
If you are a HIPAA covered entity or business associate, VCDPA largely exempts your PHI processing under Va. Code § 59.1-576.[9] However, VCDPA can still reach health-adjacent marketing data, wellness-app data, and consumer-facing offerings that fall outside HIPAA, provided you meet the statute's applicability thresholds. Many practices are also subject to the amended Virginia Consumer Protection Act under SB 754, which has no threshold and a private right of action.
How do I know if my healthcare marketing is compliant?
Conduct a tracking-technology inventory, verify BAAs with every vendor that can touch user data, audit which pages contain pixels or analytics scripts, and confirm that authenticated portal pages have no advertising trackers. Since the vendors of these tools are classed as business associates under HIPAA, a HIPAA-compliant BAA must be obtained from the vendor before these technologies are used anywhere where they can touch ePHI, and any sharing of ePHI must be permitted by the HIPAA Privacy Rule; otherwise, a valid HIPAA authorization must be obtained in advance.[12]
What should I do if I discover a compliance violation?
Stop the offending data flow immediately, preserve logs, engage healthcare privacy counsel, and conduct a breach risk assessment under the HIPAA Breach Notification Rule. If the assessment confirms a reportable breach, notify affected individuals within 60 days of discovery, notify HHS, and notify prominent media if the incident affects 500 or more residents of a state. Then implement structural fixes (server-side filtering, signed BAAs, monitoring) to prevent recurrence.
Sources
- HIPAA Journal, Novant Health Settles $6.6 Million Pixel Privacy Breach Lawsuit
- HHS OCR, Enforcement Highlights
- HHS OCR, Resolution Agreements
- FTC, FTC-HHS Joint Letter on Tracking Technologies
- HHS, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
- Moore & Van Allen, New OCR Guidance on Tracking Technologies
- Virginia Office of the Attorney General, VCDPA Summary
- WilmerHale, Virginia Amends Consumer Protection Act (SB 754)
- Code of Virginia § 59.1-576, Scope; exemptions
- Federal Register, Annual Civil Monetary Penalties Inflation Adjustment (Aug. 8, 2024)
- HIPAA Journal, OCR Confirms Tracking Technologies Without BAA Are HIPAA Violations
- HIPAA Guide, OCR Revises Online Tracking Technology Guidance
Related articles
- GuideAdvocate Aurora $12.2M Pixel Settlement: Anatomy of a Healthcare Data Lawsuit
- GuideVirginia VCDPA: Healthcare Marketing Compliance for Virginia Medical Practices
- GuideInova Health $3.1M Settlement: The Pixel Configuration That Cost Them
- GuideCurve Compliance Freshpaint Essential Cookies Classification: Plain-English Guide
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit