Legal News about HIPAA Compliance

CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation

Settlements have been agreed to resolve class action litigation against CVS Health & Criteo and American Wellness Corp. The lawsuits stem from their use of tracking technologies on their websites and mobile apps.

CVS Health & Criteo Corp. Pixel Settlement

A $20.5 million settlement has been agreed to resolve class action litigation against the U.S. healthcare company CVS Health and the digital advertising company Criteo to resolve claims related to the use of web tracking technologies. The tracking tools are alleged to have resulted in the unlawful disclosure of web users’ personal and protected health information to third parties, without the knowledge or consent of web users.

Multiple class action lawsuits were filed in response to the alleged disclosures. The lawsuits were consolidated into a single complaint as the lawsuits had overlapping claims and classes. The consolidated lawsuit – Brewer, et al. v. CVS Pharmacy, Inc. and Criteo Corp. – is pending in the Circuit Court of the 17th Judicial Circuit in and for Broward County, Florida.

According to the lawsuit, tracking tools were added to the CVS Health website and CVS Pharmacy mobile application, which collected users’ sensitive data and transmitted the information to companies such as Criteo, Adobe Inc., Medallia, and Quantum Metric. Web users were unaware that the tools were used and that their sensitive data was being collected and shared with third parties for advertising and marketing purposes, in an egregious violation of their privacy. The lawsuit asserted claims for negligence, breach of confidence, invasion of privacy, and violations of the Electronic Communications Privacy Act. The defendants deny that they violated any law and disagree with the claims in the lawsuit.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties attended mediation on March 17, 2026, and negotiations continued for several weeks thereafter. The terms of the settlement have now been agreed to by all parties, and the settlement has received preliminary approval from the court. The defendants have agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and cash payments to the class members. The settlement class consists of all individuals who accessed the CVS Health website or application prior to July 27, 2026.

Class members who can submit documentation proving they are a member of the class may submit a claim for up to $10.00. Individuals who submit a claim and cannot provide proof that they are a class member may claim up to $5.00. Claims are subject to a pro rata decrease if the cap is exceeded. The deadline for opting out and objection is November 1, 2026. Claims must be submitted by November 16, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

American Wellness Corp. Web Tracking Settlement

A settlement has been agreed to resolve class action litigation against American Wellness Corp. (AmWell) stemming from the use of website tracking technologies such as pixels, which are alleged to have resulted in web users’ personally identifiable medical information and confidential communications being transmitted to third-party companies without their knowledge or consent.

The lawsuit – Polk vs American Well Corp. – was filed in the Superior Court for the State of California, County of Sacramento, by Virginia Polk, individually and on behalf of similarly situated individuals. The lawsuit alleged violations of the Federal Wiretap Act, California Invasion of Privacy Act, California Confidentiality of Medical Information Act, California Constitution, and common law.

During mediation, all parties agreed to the terms of a settlement, which has now received preliminary approval from the court, with no admission of fault, wrongdoing, or liability by the defendant. The settlement class consists of all U.S. based persons who used the appointment booking tool on the LiveHealth Online website or the LiveHealth Online iOS or Android Apps between October 2024 and August 2025.

AmWell has agreed to establish a $2,037,751.46 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and a service award to the class representative will be deducted. The remainder of the fund will be divided pro rata between individuals submitting a valid claim. The cash payments are anticipated to be between $51.14 and $102.29, depending on the number of valid claims received. The deadline for objection, opting out, and submitting a claim is October 30, 2026. The final fairness hearing has been scheduled for January 15, 2027.

The post CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation appeared first on The HIPAA Journal.

Vasindas’ Around the Clock Care Settles Data Breach Litigation

Vasindas’ Around the Clock Care, Inc., a California-based provider of home care services, has settled class action litigation over a January 2024 targeted cyberattack. Suspicious activity was identified within its computer systems on or around June 18, 2024. The investigation determined that an unauthorized third party first accessed its network on January 30, 2024, and maintained access for almost five months. During that time, files were copied from its network that contained the personal and protected health information of customers, employees, and patients.

Data compromised in the incident included names, Social Security numbers, driver’s license numbers/state identification numbers, financial account information, medical information, and health insurance information. The breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 3,785 individuals, and the affected individuals were notified on August 16, 2024.

The first class action lawsuit was filed on August 27, 2024, alleging this was a ransomware attack that could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit alleged that basic cybersecurity measures had not even been implemented and that there was insufficient monitoring of network activity, since the unauthorized access was not detected for almost five months. A second class action lawsuit was filed, and the two actions were consolidated – Nelson et al. v. Vasindas’ Around the Clock Care, Inc. – in the Superior Court for Kern County, California.

All parties explored an early resolution to the litigation, and while mediation was not successful, an agreement was reached, and a settlement has now been finalized and approved by the court, with no admission of wrongdoing or liability by the defendant. The defendant continues to deny all allegations and claims in the lawsuit, and maintains that the plaintiffs did not suffer any damages as a result of the data incident.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Under the terms of the settlement, the defendant will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members are entitled to claim a two-year membership to a medical data monitoring service and may also claim one of two cash payments. A claim may be submitted for compensation for documented, unreimbursed losses due to the data breach up to a maximum of $2,500, or they may claim an alternative one-time cash payment of $70. The deadline for objection and opting out is October 26, 2026. The deadline for submitting a claim is November 23, 2026, and the final fairness hearing is scheduled for December 3, 2026.

The post Vasindas’ Around the Clock Care Settles Data Breach Litigation appeared first on The HIPAA Journal.

Albany College of Pharmacy and Health Sciences Data Breach Settlement

Albany College of Pharmacy and Health Sciences in New York State has agreed to settle a class action lawsuit stemming from a 2024 cybersecurity incident involving unauthorized access to systems containing the personal and protected health information of employees, patients, applicants, and students.

Suspicious activity was identified within its network on September 14, 2024. The forensic investigation determined that a hacker had access to its network between August 31, 2024, and September 14, 2024, and potentially obtained names, Social Security numbers, financial information, birth and marriage certificates, passport numbers, driver’s license numbers, health insurance information, medical information, and student information. Notification letters were mailed to the 26,411 affected individuals on June 16, 2025, and September 8, 2025.

The first class action lawsuit was filed in June 2025, followed by a further three putative class action lawsuits. The four lawsuits were consolidated into a single action – Levin, et al. v. Albany College of Pharmacy and Health Sciences – which is pending in the Supreme Court of Albany County, New York. Another plaintiff was later added to the consolidated complaint.

The lawsuit asserted claims for negligence, invasion of privacy-intrusion upon seclusion, breach of implied contract, unjust enrichment, and violation of New York’s Information Security Breach and Notification Act. All claims and contentions in the lawsuit were denied by the defendant. Mediation was unsuccessful; however, in the following weeks, the material terms of a settlement were agreed upon, and the terms have now been finalized and received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The defendant has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards of $2,500 for each of the five class representatives. Class members are entitled to claim a two-year membership to a credit, fraud, and identity theft monitoring service. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $5,000 per class member, and/or compensation for up to four hours of lost time at $20 per hour.

An alternative cash payment of $25 is available for class members who choose not to submit a claim for reimbursement of losses or lost time. The deadline for objection and opting out is October 16, 2026. The deadline for submitting a claim is November 16, 2026, and the final fairness hearing is scheduled for December 10, 2026.

The post Albany College of Pharmacy and Health Sciences Data Breach Settlement appeared first on The HIPAA Journal.

Settlement Resolves Class Action Data Breach Complaint Against Community Dental Care

Community Dental Care, a nonprofit Medicaid dental provider in the state of Minnesota, has agreed to settle class action litigation over a 2024 cyberattack and data breach that exposed patients’ personal and protected health information.

The cyberattack and data breach that sparked the litigation occurred on or around December 20, 2024. A cybercriminal actor accessed its network and potentially exfiltrated the personal and protected health information of more than 130,000 individuals, including their names, health insurance information, dates of birth, medical information, and Social Security numbers. Approximately 7,100 of the affected individuals had their Social Security numbers exposed in the incident. Notification letters started to be mailed to the affected individuals on March 28, 2025.

A few days after mailing notifications, a class action lawsuit was filed in the District Court for Ramsey County in the state of Minnesota. A further four class action complaints were filed in response to the data breach, which were consolidated into a single complaint. The consolidated lawsuit alleged that the data breach was due to negligence, as the defendant failed to implement reasonable and appropriate cybersecurity measures. All claims were denied by the defendant, who sought to have the lawsuit dismissed. The motion to dismiss was granted in part and denied in part by the court, with the claims for negligence, negligence per se, and breach of implied contract allowed to proceed. The consolidated class action complaint, In re Community Dental Care, is pending in the District Court for Ramsey County, Minnesota.

Prior to discovery, all parties engaged in discussions about a potential settlement, and after mediation, the terms of a settlement were agreed to by all parties. Class members may submit a claim for reimbursement of documented, unreimbursed losses fairly traceable to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time cash payment of $50 per class member.  In addition to one of those cash payments, class members are eligible to claim a two-year membership to a medical data monitoring service. The deadline for objection and opting out is September 24, 2026. Claims must be submitted by October 19, 2026, and the final fairness hearing has been scheduled for November 23, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The post Settlement Resolves Class Action Data Breach Complaint Against Community Dental Care appeared first on The HIPAA Journal.

Modernizing Medicine Agrees to $3M Data Breach Settlement

Modernizing Medicine, a Boca Raton, Florida-based company that provides cloud-based, AI-powered software and electronic health record systems for healthcare providers, has agreed to pay almost $3 million to settle class action data breach litigation.

The litigation stems from a July 2025 cybersecurity incident in which a criminal hacker gained access to two of its computer servers between July 9, 2025, and July 10, 2025. The servers were used for the conversion of data from retiring EHR platforms to the current Modernizing Medicine EHR platform. Data compromised in the incident included names, addresses, dates of birth, phone numbers, email addresses, limited Social Security numbers, health insurance information, and medical information. The affected individuals were notified on or around October 17, 2025. The HHS Office for Civil Rights was informed that 198,795 individuals had been affected.

A class action lawsuit – Cavallaro-Kearins v. Modernizing Medicine, Inc. – was filed on November 19, 2025, in the U.S. District Court for the Southern District of Florida by plaintiff Patricia Cavallaro-Kearins, individually and on behalf of similarly situated individuals. The lawsuit alleged that the data breach occurred as a result of insufficient cybersecurity measures, and asserted claims for negligence, breach of implied contract, invasion of privacy, unjust enrichment, and breach of fiduciary duty. Modernizing Medicine denies wrongdoing and liability.

All parties opted to explore opportunities for early resolution of the litigation, and after a full day of mediation on April 2, 2026, the material terms of a settlement were agreed upon by all parties. The settlement has now been finalized and has received preliminary approval from the court. Under the terms of the settlement, Modernizing Medicine has agreed to establish a $2,999,750.00 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration costs, and service awards have been deducted.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All class members are entitled to claim a two-year membership to the CyEx Medical Shield Complete medical data monitoring service, plus one of two cash payments. A claim may be submitted for reimbursement of documented losses fairly traceable to the data breach up to a maximum of $5,000 per class member. Alternatively, class members may claim a one-time pro rata cash payment, which is expected to be approximately $75 per class member, but may be higher or lower depending on the number of valid claims received. Claims must be submitted by November 2, 2026, and the final fairness hearing has been scheduled for November 17, 2026. Individuals wishing to object to the settlement or opt out have until October 19, 2026, to do so.

The post Modernizing Medicine Agrees to $3M Data Breach Settlement appeared first on The HIPAA Journal.

Brevard Skin and Cancer Center Settles Class Action Complaint

The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming from a 2025 cyberattack and data breach.

Unauthorized activity was identified within its network on October 14, 2025. The forensic investigation confirmed unauthorized network access starting on September 28, 2025, and the exposure of patient data including names, phone numbers, e-mail addresses, dates of birth, Social Security numbers, diagnoses, clinical information, and billing and claims information. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 54,570 individuals. A threat group called PEAR claimed responsibility for the attack and threatened to publish the data unless a ransom was paid.

The first class action lawsuit was filed on October 20, 2025, and similar class action lawsuits were filed by other individuals affected by the data breach. The lawsuits were consolidated into a single action as they had overlapping claims and classes. The consolidated lawsuit – In Re: Brevard Skin & Cancer Center Data Breach Litigation – was filed on February 5, 2026, in the Circuit Court for Brevard County, Florida, where it is currently pending.

The plaintiffs alleged that Brevard Skin and Cancer Center was at fault for the incident and data breach, as it failed to implement appropriate cybersecurity measures, and that if those measures had been implemented, the data breach could have been prevented. The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, invasion of privacy, breach of fiduciary duty, and violation of the Florida Deceptive and Unfair Trade Practices Act. All claims and contentions in the lawsuit were denied by Brevard Skin and Cancer Center, including fault, wrongdoing, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties agreed to a settlement to avoid the delay, risk, and uncertainty of continued litigation. Under the terms of the settlement, Brevard Skin and Cancer Center has agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and multiple benefits for the class members.

All class members may claim a one-year membership to the CyEx Medical Shield Complete medical data monitoring service. Class members may also claim up to $2,500 as reimbursement for documented, unreimbursed losses due to the data breach. If a claim for reimbursement of losses is not submitted, class members may claim an alternative one-time $45 cash payment. Class members have until November 2, 2026, to object or opt out. Claims must be submitted by November 16, 2026, and the final fairness hearing has been scheduled for November 30, 2026.

The post Brevard Skin and Cancer Center Settles Class Action Complaint appeared first on The HIPAA Journal.

Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits

Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data security incidents that exposed patient information.

Central Maine Medical Center Data Breach Settlement

Central Maine Medical Center, a Lewiston, Maine-based nonprofit healthcare provider, has agreed to pay $1,368,025 to settle a consolidated class action lawsuit stemming from a 2025 cyberattack and data breach.

The attack was identified on June 1, 2026, and caused the shutdown of IT systems, network servers, and its phone system. The forensic investigation determined that hackers had access to its network between March 19, 2025, and June 1, 2025, and potentially obtained personal and protected health information. According to the lawsuit, notification letters were mailed to 218,884 individuals.

Six putative class action lawsuits were filed in response to the data breach, alleging that Central Maine Healthcare was at fault as reasonable and appropriate cybersecurity measures had not been implemented. The lawsuits were consolidated into a single complaint – In re Central Maine Data Security Litigation – naming the defendants Central Maine Healthcare Corporation and Central Maine Medical Center. The defendants deny all claims and contentions in the lawsuit, including claims of fault, wrongdoing, and liability. The lawsuit was settled to avoid the time, cost, and uncertainty of continued litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement fund will be used to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The remainder of the settlement fund will be used to pay benefits to the class members. Class members may claim one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be around $60 per class member.  In addition to one of those payments, class members may claim a one-year membership to a medical record monitoring service. The deadline for objection and opting out is September 13, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 28, 2026.

Susan B. Allen Memorial Hospital Data Breach Settlement

A settlement has been agreed to resolve class action litigation against the Butler, Kansas acute-care medical facility, Susan B. Allen Memorial Hospital, to resolve claims stemming from a July 2025 cyberattack and data breach. Hackers gained access to its network and potentially obtained personal and protected health information. The data breach was initially reported to the HHS’ Office for Civil Rights as affecting up to 12,097 individuals, although the HHS’ Office for Civil Rights breach portal has since been updated to indicate that only 11,866 individuals had protected health information compromised in the incident.

Four putative class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims and classes. The consolidated lawsuit, In Re: Susan B. Allen Data Security Litigation, is pending in the District Court of Butler County, Kansas. The plaintiffs allege that the hospital was at fault for the data breach as it failed to implement appropriate cybersecurity measures, and the defendant maintains there was no wrongdoing. A settlement was agreed to avoid the cost, time, distraction, and uncertainty of continued litigation.

The settlement provides two years of credit monitoring and identity theft protection services for all class members. In addition, a claim may be submitted for reimbursement of out-of-pocket losses due to the data breach up to a maximum of $100 per class member. In addition, a claim may be submitted for reimbursement of up to four hours of lost time at $25 per hour. Claims have been capped at an aggregate of $100 per class member. Claims must be submitted by November 12, 2026. Individuals wishing to object to the settlement or exclude themselves must do so by October 13, 2026. The final fairness hearing has been scheduled for December 7, 2026.

The post Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits

Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit Medical Group in Tennessee.

Palomar Health Medical Group Data Breach Settlement

Palomar Health Medical Group, a non-profit healthcare organization serving patients at 20 locations in North San Diego County and South Riverside County in Southern California, has agreed to settle class action litigation stemming from a Spring 2024 cybersecurity incident involving the protected health information of 1,140,221 individuals. The incident was identified on May 5, 2024, and the forensic investigation confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Data potentially stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, medical histories, health information, health insurance information, and other sensitive data.

Several class action lawsuits were filed in response to the data breach, all of which alleged that the data breach could have been prevented and occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. On September 16, 2024, the lawsuits were consolidated into a single complaint – Castro et al. v. Arch Health Partners, Inc. d/b/a Palomar Health Medical Group – which is pending in the Superior Court for the State of California, County of San Diego. The consolidated lawsuit asserted claims for negligence, negligence per se, invasion of privacy, and violations of the California Consumer Privacy Act, California Confidentiality of Medical Information Act, and California Customer Records Act. All claims and contentions in the lawsuit were denied by Palomar Health Medical Group; however, all parties agreed to settle the litigation to avoid the costs and risks associated with continued litigation.

Under the terms of the settlement, Palomar Health Medical Group has agreed to establish a $3,100,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be used to pay benefits to the class members.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement provides two years of complimentary single-bureau credit monitoring services to all class members. Class members may also claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a claim may be submitted for an alternative pro rata cash payment, estimated to be $60 per class member. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

Summit Medical Group Data Breach Settlement

Summit Medical Group, a Tennessee-based medical group with more than 90 locations in Tennessee, has settled class action litigation stemming from a November 2024 cybersecurity incident that exposed the personal and protected health information of more than 464,000 patients and employees. Data exposed in the incident included names, contact information, demographic information, medical record numbers, provider names, dates of services, facilities of service, treatment information, and/or health insurance information. The affected individuals were notified about the breach in March 2025.

Three putative class action lawsuits were filed in response to the data breach. The lawsuits had overlapping claims and putative classes, and were consolidated into a single lawsuit – Harris, et al. v. Summit Medical Group, PLLC, which is pending in the Circuit Court for Knox County, Tennessee. The consolidated lawsuit alleged that the data breach occurred as a result of insufficient security measures, and despite determining on September 19, 2024, that patient data was exposed, notifications were not mailed until March 2025. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, unjust enrichment, and invasion of privacy, all of which were denied by Summit Medical Group. Summit Medical Group sought to have the lawsuit dismissed; however, after considering the time, cost, and risks associated with continued litigation, all parties agreed to settle the litigation. The terms of the settlement have been finalized, and the proposed settlement has received preliminary approval from the court.

The settlement provides two years of medical data monitoring with the CyEx Medical Shield Complete service. In addition, class members may submit a claim for reimbursement of documented out-of-pocket losses due to the data breach up to a maximum of $2,500 per class member. A claim may also be submitted for reimbursement of up to three hours of lost time at $15 per hour (max $45). The cash payments have been capped at $500,000. Claims will be paid pro rata if claims exceed that total.

Summit Medical Group has also agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The deadline for objecting to the settlement and exclusion is October 10, 2026. Claims must be submitted by November 4, 2026, and the final fairness hearing has been scheduled for November 19, 2026.

The post Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Wellstar Health System & Cone Health Settle Pixel Lawsuits

Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating Corporation (Cone Health). The lawsuits stem from the defendants’ use of pixels and other website tracking tools, which are alleged to have resulted in impermissible disclosures of patient data to third parties such as Meta and Google.

Wellstar Health System Pixel Settlement

Wellstar Health System, a Marietta, Georgia-based health system with more than 400 care locations in the state, was sued over its use of tracking tools on its website that are alleged to have resulted in the disclosure of personally identifiable information and protected health information to third parties such as Alphabet Inc. (Google) and Meta Platforms (Facebook), without website users’ knowledge or consent.

The first lawsuit was filed on April 23, 2024, and an amended complaint was filed on August 2, 2024, adding three additional plaintiffs. The lawsuit – Doe v. Wellstar Health System, Inc. –  is pending in the United States District Court for the Northern District of Georgia. The lawsuit asserted claims for invasion of privacy – intrusion upon seclusion, breach of fiduciary duty, negligence, negligence per se, breach of implied contract, breach of express contract, unjust enrichment, and violations of the Electronic Communications Privacy Act. The defendant denies all claims and contentions in the lawsuit and maintains that there was no wrongdoing. A settlement was agreed to by all parties to avoid the time, expense, and uncertainty of a trial and related appeals.

Wellstar Health System has agreed to establish a $4,500,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be divided equally among all class members who submit a valid claim. The class consists of individuals whose personally identifiable information and/or protected health information was disclosed to third parties via the tracking tools between February 19, 2020, and July 22, 2026. Any remaining settlement funds, such as from uncashed checks, will be distributed to the Good Samaritan Health Center of Cobb.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The deadline for objection and opting out is October 26, 2026. Claims must be submitted by November 10, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

Moses H. Cone Memorial Hospital Operating Corporation (Cone Health) Pixel Settlement

Greensboro, North Carolina-based defendants The Moses H. Cone Memorial Hospital Operating Corporation, d/b/a Cone Health, and The Moses H. Cone Memorial Hospital, d/b/a Cone Health, were sued over the use of tracking tools such as pixels, which had been added to their public website without the knowledge or consent of website users. The lawsuit alleged that the use of the tracking code resulted in disclosures of users’ confidential health information and protected health information to third parties such as Alphabet Inc (Google) and Meta Platforms (Facebook).

The lawsuit, Singh v. The Moses H. Cone Memorial Hospital Operating Corp., et al., is pending in the United States District Court for the Middle District of North Carolina. The lawsuit asserted claims for violation of the Electronic Communications Privacy Act, breach of express contract, breach of implied duty of good faith and fair dealing, breach of implied contract, negligence, breach of fiduciary duty, and unjust enrichment. The defendants maintain that there was no wrongdoing; however, a settlement was agreed by all parties to avoid the costs, delays, and uncertainties of continued litigation.

Cone Health has agreed to establish a $1,765,000 settlement fund, which will be used to pay reasonable attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. After those costs have been deducted, the net settlement fund will be distributed equally among the class members. The value of each cash payment will depend on the number of valid claims received.

The settlement class consists of all individuals who accessed the MyChart patient portal on the defendants’ website between September 1, 2016, and November 3, 2022, as well as any individual who completed a submission form on the defendants’ website between the same dates. The settlement has received preliminary approval from the court. The deadline for opting out and objecting to the settlement is October 5, 2025. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for November 5, 2026.

The post Wellstar Health System & Cone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.