Five Healthcare Providers Settle Pixel Class Action Lawsuits
Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and analytics tools. The list continues to grow with a further five settlements recently announced; however, class action lawsuits stemming from the use of tracking and analytics tools do not always result in settlements.
A proposed class action lawsuit against CRH Healthcare, doing business as Peachtree Immediate Care in Georgia, that alleged violations of the federal Electronic Communications Privacy Act and asserted claims for negligence/negligence per se, breach of implied contract, breach of express contract, breach of fiduciary duty, and unjust enrichment, has been dismissed with prejudice.
The judge ruled that the complaint was speculative, as the plaintiff failed to explain what damages had been suffered as a result of the defendant’s actions. The plaintiff has been given 14 days to file an amended complaint, or the lawsuit will be permanently dismissed. The decision shows that while tracking and analytics tools may result in disclosures of sensitive data to third parties, the plaintiff(s) must demonstrate that the disclosures resulted in a compensable injury.
Emanate Health Medical Center Pixel Settlement
Emanate Health Medical Center, a nonprofit healthcare organziation based in Covina, California, Emanate Health Medical Center faced multiple class action lawsuits over the use of tracking tools such as pixels. The lawsuits were consolidated into a single complaint – Ortega, et al., v. Emanate Health Medical Center – in the Superior Court of the State of California, County of Los Angeles.
The consolidated lawsuit asserted claims for violations of the California Invasion of Privacy Act, California Confidentiality of Medical Information Act, invasion of privacy under the California Constitution, and common law invasion of privacy – intrusion upon seclusion. Emanate Health Medical Center denies all allegations of wrongdoing and liability, and all material allegations in the lawsuit; however, it agreed to a settlement to avoid the risks and costs of lengthy litigation and the uncertainty of a trial and appeals.
Emanate Health has agreed to establish a $777,000 settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives. The net settlement fund after costs and expenses have been deducted is expected to be approximately $433,709, which will be divided pro rata between all individuals who submit a claim. In the unlikely event that every class member submits a claim, that would equate to a payment of $11 per class member.
The class consists of individuals who logged in to the Emanate Health patient portal, and/or submitted an online form and/or scheduled an appointment on the Emanate Health website between August 30, 2019, and April 30, 2024. The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 29, 2026, and the final fairness hearing has been scheduled for November 19, 2026.
Bayhealth Medical Center Pixel Settlement
Bayhealth Medical Center, a hospital system serving patients in central and southern Delaware, faced multiple class action lawsuits over its use of third-party tracking pixels on its website, resulting in disclosures of website users’ sensitive data to third parties. The lawsuits were consolidated into a single complaint – Doe et al. v. Bayhealth Medical Center Inc., d/b/a Bayhealth – in the Superior Court of the State of Delaware
Bayhealth denies all wrongdoing and liability and sought to have the lawsuit dismissed; however, the motion to dismiss was denied, and the claims for negligence, breach of implied covenant of good faith and fair dealing, unjust enrichment, breach of confidentiality, and violation of the Delaware Consumer Fraud Act were allowed to proceed. After prolonged and extensive arm’s length negotiations and mediation, all parties agreed to a settlement to avoid the cost and time required for continued litigation and the uncertainties associated with a trial and related appeals.
Bayhealth has agreed to cover the cost of attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives, and will pay for two benefits for the class members. Class members are eligible to enroll in one year of medical data monitoring services and may submit a claim for a one-time cash payment of $25 per class member. The class consists of all patient portal users who used Bayhealth websites and patient portal websites between January 1, 2019, and December 31, 2025. The deadline for objection and opting out is September 4, 2026. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for October 29, 2026.
Mount Sinai Medical Center of Florida Pixel Settlement
Mount Sinai Medical Center of Florida, aka Mount Sinai Medical Center, a Miami, FL-based hospital and the largest private, independent not-for-profit teaching hospital in the state, faced multiple class action lawsuits over its use of tracking, analytics, and advertising technologies on its website and patient portal. The lawsuits were consolidated into a single action – Boggiano, et al. v. Mount Sinai Medical Center of Florida a/k/a Mount Sinai Medical Center – in the Circuit Court for Broward County, Florida.
The lawsuit alleged that these tools resulted in the impermissible disclosure of personal and protected health information to third parties, without the knowledge or consent of patients. The lawsuit asserted claims for invasion of privacy and unjust enrichment. The defendant denies wrongdoing and liability, and disagrees with the claims and contentions in the lawsuit; however, after several months of negotiation and mediation, the terms of a settlement were agreed upon.
Mount Sinai Medical Center of Florida will pay attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives, as well as benefits for the class members. The class consists of individuals who accessed the Mount Sinai Medical Center’s Website or Patient Portal between June 10, 2021, and September 18, 2025.
Class members will receive an activation code for one year of medical data monitoring services without submitting a claim. Claims may be submitted for a one-time cash payment from a $220,000 settlement fund. Based on a typical claim volume, the cash payments are expected to be around $20 per class member but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 14, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 13, 2026.
University of Pennsylvania Health System (Penn Medicine) Pixel Settlement
The University of Pennsylvania Health System, doing business as Penn Medicine, was sued over its use of Meta Pixel, Google Analytics code, and other tracking, analytics, and advertising tools, which were alleged to have disclosed sensitive website user data to third parties such as Meta and Google.
Several lawsuits were filed in response to the alleged unlawful disclosures of personal and protected health information. The lawsuits were consolidated into a single complaint – Mohr, et al. v. The Trustees of The University of Pennsylvania as Owner and Operator of The University of Pennsylvania Health System (d/b/a Penn Medicine) – in the Court of Common Pleas of Philadelphia County, Pennsylvania. The lawsuit alleged the disclosures of personal and protected health information via these tools violated the Pennsylvania Wiretapping and Electronic Surveillance Control Act. Penn Medicine denies the claims and contentions in the lawsuit, including those related to negligence, fault, wrongdoing, and liability.
All parties agreed to a settlement to avoid the cost and risk of a trial, and the settlement has received preliminary approval from the court. Penn Medicine will establish a $9,500,000 settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may claim a one-time cash payment of up to $15. The defendant has stopped using Meta Pixel on its website, and will not use analytics and advertising technologies on the website for a period of at least two years.
The settlement class consists of individuals who used the myPennMedicine Patient Portal between January 23, 2021, and January 23, 2023. The deadline for objection and opting out is September 1, 2026. Claims must be submitted by September 16, 2026, and the final fairness hearing has been scheduled for November 12, 2026.
Concord Hospital Pixel Settlement
Concord Hospital Health System, a health system based in Concord, New Hampshire, was sued over its use of website tracking tools. The lawsuit – Branson v. Concord Hospital Inc. et al – names Concord Hospital, Inc., Concord Hospital – Laconia, Concord Hospital – Franklin, and Capital Region Healthcare Corporation as defendants, and was filed in the Hillsborough Superior Court, Manchester, New Hampshire.
The lawsuit alleges that the deployment of these tools resulted in disclosures of personal and protected health information to third parties such as Google and Geonetric, without the knowledge or consent of patients, in violation of the New Hampshire Wiretapping and Electronic Surveillance Act and New Hampshire Patient Privacy Law. The defendants deny all allegations in the lawsuit. The parties agreed to a settlement to avoid the costs and risk of a trial.
The settlement class consists of individuals whose information was allegedly intercepted by the tools between May 9, 2021, and the date of the preliminary settlement agreement. The defendants have agreed to establish an $800,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration costs, and service awards have been deducted. Each individual who submits a valid claim will receive an equal pro rata share of the remaining funds. The deadline for objection, opting out, and submitting a claim is September 11, 2026. The final fairness hearing has been scheduled for November 3, 2026.
The post Five Healthcare Providers Settle Pixel Class Action Lawsuits appeared first on The HIPAA Journal.
OCR Director Says Carry On: Usually Sleepy July Sees News of Security Delay, Surprise Access Reg – JD Supra
HIPAA Security Rule Revamp? – McAfee & Taft
Ransom Cartel Mastermind Sentenced to 16 Years in Prison
The Belarusian cybercriminal behind the Ransom Cartel ransomware group has been sentenced to 16 years in prison for his role in ransomware attacks on at least 18 companies worldwide.
Maksim Silnikau, 40, was the creator and administrator of the Ransom Cartel ransomware-as-a-service operation and recruited other cybercriminals to conduct ransomware attacks globally. According to court documents, Silnikau began developing the ransomware operation in May 2021, initially under a different name, before rebranding it as Ransom Cartel in 2022. Between 2021 and 2023, along with his co-conspirators, at least 18 companies fell victim to attacks, including companies in California, New York, and Nebraska. The attacks caused more than $6.7 million in losses, and the group attempted to extort at least $5.2 million from victims.
Silnikau did not conduct many of the intrusions himself. He was the administrator of the operation and purchased stolen credentials from initial access brokers, recruited affiliates to conduct attacks, negotiated with victims, used cryptocurrency mixers to hide the proceeds from the attacks, and split the money with the group’s affiliates.
Silnikau has a long history of cybercrime, having reportedly been a core member of the REvil ransomware operation, a member of Russian-speaking cybercrime forums since at least 2005, and a member of the cybercrime website Direct Connection from 2011 until the site was shut down in 2016. Silnikau was involved in the distribution of the Angler exploit kit and various malvertising and malware distribution schemes between October 2013 and March 2022. Along with a Ukrainian national and a Russian national, Silnikau was charged with participation in the distribution of the Angler exploit kit in a separate indictment in New Jersey.
Following an international law enforcement investigation, Silnikau was arrested in Spain on July 18, 2023; however, fled while awaiting extradition to the United States to face the charges. He was recaptured attempting to return to Belarus from Poland and was extradited to the U.S. from Poland in 2024 to face the charges in the Eastern District of Virginia. Prosecutors charged Silnikau with seven counts, although he was only convicted on three: conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft, and was sentenced to 16 years in jail.
The post Ransom Cartel Mastermind Sentenced to 16 Years in Prison appeared first on The HIPAA Journal.
Your blood pressure cuff may expose your health data – Fox News
Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance – The HIPAA Journal
Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance
Settlements have been agreed to resolve class action data breach lawsuits against McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts.
McKenzie Health System Data Breach Settlement
McKenzie Health System, the operator of the McKenzie Memorial Hospital, a critical access hospital in Sanilac County, Michigan, has settled a class action lawsuit that was filed in response to an April 2025 cyberattack and data breach. McKenzie Health identified unauthorized access to its computer network on April 15, 2025. The forensic investigation determined that an unauthorized third party accessed its network between April 14, 2025, and April 15, 2025, and potentially obtained files containing patient information.
Data potentially compromised in the incident included names, addresses, birth dates, Social Security numbers, patient account numbers, medical record numbers, diagnosis and treatment information. The data breach was reported to the HHS’ Office for Civil Rights as affecting 58,839 individuals, who started to be notified on or around July 24, 2025.
Several class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In Re: McKenzie Memorial Hospital d/b/a McKenzie Health System 2025 Data Breach Litigation – in the Circuit Court for Sanilac County, Michigan. The consolidated lawsuit alleges that the cyberattack and data breach should have been prevented and occurred due to the defendant’s negligence.
McKenzie Health denies wrongdoing and liability; however, it agreed to a settlement to avoid the litigation costs and expenses, distractions, burden, expense, and disruption to its business operations associated with further litigation. McKenzie Health has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the eight class representatives.
Under the terms of the settlement, all class members are eligible to enroll in two years of credit monitoring and identity theft protection services. In addition, they may either submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,000 per class member or claim a one-time $50.00 cash payment. The deadline for opting out, objecting, and submitting a claim is August 24, 2026. The final fairness hearing has been scheduled for October 6, 2026.
Aspire Health Alliance Data Breach Settlement
South Shore Mental Health Center, Inc., doing business as Aspire Health Alliance, a state-designated community behavioral health center with facilities in Quincy, Braintree, and Marshfield in Massachusetts, has agreed to settle class action litigation stemming from a September 2023 cybersecurity incident that affected 17,490 individuals.
Aspire Health Alliance detected unauthorized network access on September 13, 2023, and confirmed that an unauthorized third party accessed and acquired files containing patient information, including names, dates of birth, dates of service, health insurance information, condition or treatment information, Medicare/Medicaid numbers, and patient account numbers. The affected individuals started to be notified about the data breach on April 26, 2024.
On May 10, 2024, a class action lawsuit was filed in the Superior Court of the Commonwealth of Massachusetts, Norfolk County, which was subsequently moved to the Superior Court of the Commonwealth of Massachusetts, Suffolk County. The lawsuit – Joan Tozzi v. South Shore Mental Health Center, Inc. d/b/a Aspire Health Alliance – alleged that the data breach could have been prevented as it occurred as a result of the failure to implement reasonable and appropriate cybersecurity measures. The lawsuit asserted claims for negligence, breach of implied contract, breach of fiduciary duty, and unjust enrichment. Aspire Health Alliance denies wrongdoing or liability.
All parties agreed to a settlement to avoid further legal costs and the uncertainty of a trial and related appeals. Under the terms of the settlement, Aspire Health Alliance has agreed to establish a $400,000 settlement fund to cover class member benefits, attorneys’ fees and expenses, settlement administration costs, and a service award for the class representative.
Class members are entitled to a one-year membership to the CyEx Medical Shield medical data monitoring service and may also submit a claim for one of two cash payments: reimbursement of documented, unreimbursed losses up to a maximum of $2,500 per class member, or a pro rata cash payment, the value of which will depend on the number of valid claims received. The deadline for objection, opting out, and submitting a claim is September 16, 2026. The final fairness hearing has been scheduled for October 1, 2026.
The post Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance appeared first on The HIPAA Journal.