Legal News about HIPAA Compliance

Valley Oaks Health Data Breach Settlement Gets First Nod from Court

Valley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated lawsuit has recently been settled. Hackers accessed the Valley Oaks Health network between June 8, 2023, and June 13, 2023, and potentially obtained files containing names, Social Security numbers, driver’s license numbers, state ID numbers, credit/debit card numbers, access codes/passwords, biometric data, and other sensitive information.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In re: Valley Oaks Data Incident Litigation – as the lawsuits had overlapping claims and classes. The consolidated lawsuit is pending in the Superior Court for Tippecanoe, Indiana. The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, and unjust enrichment, all of which are denied by Valley Oaks Health, which maintains there was no wrongdoing.

Valley Oaks Health sought to have the lawsuit dismissed; however, the motion to dismiss was rejected by the court. A full day of mediation did not result in a settlement; however, after several months of negotiations, a settlement was agreed to avoid the cost, delay, and risks of protracted litigation.  The settlement has recently received preliminary approval from the court.

Valley Oaks Health has agreed to pay attorneys’ fees and expenses, settlement notification and administration costs, and service awards for the seven class representatives (total of $17,500). Attorneys’ fees are capped at $450,000. Claims may be submitted for reimbursement of up to $500 in documented, unreimbursed ordinary losses due to the data breach, including up to four hours of lost time at $20 per hour. A claim may also be submitted for up to $5,000 as reimbursement for documented, unreimbursed extraordinary losses. If claims are not submitted for reimbursement of losses or lost time, a claim may be submitted for an alternative $40 cash payment. All class members are entitled to enroll in two years of medical data monitoring services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The deadline for opting out, objecting to the settlement, and submitting a claim is November 9, 2026. The final fairness hearing has been scheduled for December 10, 2026.

The post Valley Oaks Health Data Breach Settlement Gets First Nod from Court appeared first on The HIPAA Journal.

Laboratory Services Cooperative Agrees to Pay $6.1 Million to Settle Data Breach Litigation

Laboratory Services Cooperative, a Seattle, Washington-based nonprofit clinical laboratory that provides diagnostic and analytical testing services for Planned Parenthood affiliates in 31 U.S. states, has agreed to settle class action litigation arising from a 2024 data breach that affected approximately 1.6 million current and former patients and employees.

The data breach

On October 27, 2024, Laboratory Services Cooperative identified unauthorized network activity. The forensic investigation determined that a hacker accessed its network and removed data. The compromised information includes names, dates of birth, contact information, medical information, claims information, billing information, health insurance information, Social Security numbers, and other government- and state-issued identifiers. The notification letters did not state how long hackers had access to its network. The affected individuals started to be notified on or around April 10, 2025. The HHS’ Office for Civil Rights was notified on November 20, 2024. The OCR breach portal still lists the incident as affecting 501 individuals.

The litigation

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Several class action lawsuits were filed in response to the data breach, which were consolidated as they asserted similar claims and had overlapping classes. The consolidated lawsuit – In re Laboratory Services Cooperative Data Breach Litigation – is pending in the U.S. District Court for the Western District of Washington.

The plaintiffs allege that the data breach occurred because the defendant’s data security systems were completely inadequate, and the company failed to follow industry-standard cybersecurity practices. Further, the breach notifications were delayed, and the notices failed to include important information about the breach. The lawsuit asserted claims for negligence, breach of contract, unjust enrichment, invasion of privacy, and declaratory and injunctive relief.

The defendant disagrees with the claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability. The parties agreed to a settlement to avoid the cost, delay, distraction, and risks associated with a trial and related appeals.

The settlement

Laboratory Services Cooperative has agreed to establish a $6,100,000 settlement fund to resolve the litigation, from which costs and expenses will be deducted, and the remaining funds will be used to pay benefits to the class members. Costs and expenses include attorneys’ fees (up to one-third of the settlement fund) and expenses, notice and settlement administration costs, and service awards of up to $2,500 for the class representatives.

Class members are entitled to submit a claim for reimbursement of documented, unreimbursed losses due to the data breach, a pro rata cash payment, and two years of credit and medical information monitoring services. Reimbursement claims are capped at $5,000 per class member, and the pro rata cash payments will be up to $1,000 per class member but may be lower depending on the number of claims received. Cash payments will be affected by the number of reimbursement claims and the number of individuals signing up for credit monitoring services.

Laboratory Services Cooperative has made changes to its business practices and implemented security enhancements to reduce the risk of similar incidents in the future. The deadline for objection and exclusion is October 26, 2026. The deadline for filing a claim is November 24, 2026, and the final fairness hearing is scheduled for January 4, 2027.

The post Laboratory Services Cooperative Agrees to Pay $6.1 Million to Settle Data Breach Litigation appeared first on The HIPAA Journal.

Jefferson-Blount-St. Clair Mental Health Authority Pays $700K to Settle Data Breach Lawsuit

Jefferson-Blount-St. Clair Mental Health Authority has agreed to settle a consolidated class action lawsuit stemming from a 2025 security incident that affected more than 30,000 individuals. Unauthorized network activity was identified on November 25, 2025, and its forensic investigation determined that a ransomware group accessed its network the same day and potentially obtained the personal information of employees and protected health information of 30,434 patients. Data compromised in the incident included names, Social Security numbers, health insurance information, dates of birth, medical information, Medicare/Medicaid information, and billing or claims information.

Multiple putative class action lawsuits were filed in response to the breach, alleging the defendant was responsible for the data breach due to a failure to implement appropriate cybersecurity measures and follow industry-standard best practices. The lawsuits were consolidated into a single action – Meyer, et al. v. Jefferson-Blount-St. Clair Mental Health Authority – which is pending in the Circuit Court of Jefferson County, Alabama, Birmingham Division.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, breach of third-party beneficiary contract, breach of fiduciary duty, breach of confidence, invasion of privacy, fraud, misrepresentation, unjust enrichment, bailment, wantonness, failure to provide adequate notice, in violation of federal and state notification statutes. Jefferson-Blount-St. Clair Mental Health Authority disagrees with all claims and contentions in the lawsuit and maintains that there was no wrongdoing.

Jefferson-Blount-St. Clair Mental Health Authority agreed to a settlement to avoid the risk, delay, and uncertainty of continued litigation. Jefferson-Blount-St. Clair Mental Health Authority has agreed to establish a $700,000 settlement fund, from which attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be used to pay for class member benefits.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Class members are entitled to claim three years of credit monitoring and identity theft protection services. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. If a reimbursement claim is not submitted, class members may claim an alternative flat cash payment, estimated to be $100 per class member. The cash payments are subject to a pro rata increase or decrease.

Jefferson-Blount-St. Clair Mental Health Authority has also undertaken or will undertake changes to its business practices to ensure the security of its digital environment. The deadline for opting out and objection is November 23, 2026. Claims must be submitted by December 23, 2026, and the final fairness hearing has been scheduled for February 16, 2027.

The post Jefferson-Blount-St. Clair Mental Health Authority Pays $700K to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.

Fairchild Medical Center & Boone Health Settle Pixel Lawsuits

Fairchild Medical Center and Boone Health have agreed to settlements to resolve complaints alleging they impermissibly disclosed patient data to third parties via the use of pixels and other website tracking tools.

Fairchild Medical Center Pixel Settlement

Fairchild Medical Center in Yreka, California, has agreed to settle a class action lawsuit over its use of third-party tracking tools such as Meta Pixel on its website, which allegedly resulted in disclosures of patient data to third parties without patients’ knowledge or consent.

The lawsuit – Delgado v. Siskiyou Hospital, Inc. d/b/a Fairchild Medical Center – was filed in the Superior Court for Siskiyou County, California, and asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, violations of the California Constitution, California Invasion of Privacy Act, California Confidentiality of Medical Information Act, the Comprehensive Computer Data Access and Fraud Act, and Cal. Bus. & Prof. Code. The defendant disagrees with the claims and contentions in the lawsuit and maintains there was no wrongdoing, and the plaintiffs believe their claims have merit. To avoid the cost, delay, and risks of continued litigation, all parties agreed to settle the lawsuit.

Fairchild Medical Center has agreed to pay attorneys’ fees and expenses, settlement administration costs, a service award to the class representative, and benefits to the class members. The class consists of all California citizens whose information was disclosed to third parties – approximately 1,000 individuals. Those individuals are eligible to enroll in a one-year membership to the CyEx Privacy Shield Pro product and may claim a one-time cash payment of $25.00. The deadline for exclusion and opting out has passed. Claims must be submitted by November 2, 2026, and the final approval hearing has been scheduled for October 15, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Boone Health and CH Allied Services Pixel Settlement

Boone Health, a healthcare network that includes Boone Hospital Center in Columbia, Missouri, and its parent company, CH Allied Services, have agreed to settle class action litigation stemming from the use of the Meta Pixel tracking tool, Google Analytics code, and related tools which are alleged to have collected and disclosed sensitive patient data to third parties without patients’ knowledge or consent.

The first lawsuit was filed on December 5, 2022, and was refiled – Doe, et al. v. Boone Health, Inc., et al. – in the Circuit Court of Cole County, 19th Judicial Circuit, State of Missouri, adding further plaintiffs to the action. The lawsuit alleged that the plaintiffs and class members were harmed as a result of the disclosure of their personal and health information, and that their data was collected without their knowledge or consent. The defendants deny wrongdoing and disagree with all claims and contentions in the lawsuit and filed a motion to dismiss the action; however, that attempt was unsuccessful.

Following the court’s decision to deny the motion to dismiss, the parties agreed to settle the lawsuit to avoid the cost, distraction, and risks associated with a trial and related appeals. The defendants have agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and benefits for the class members.

The class consists of Boone Health patients who reside in Missouri and logged into the patient portal between April 1, 2021, and December 5, 2022. A claim may be submitted for a cash payment of $20.00, and class members will be automatically enrolled in a 12-month membership to the CyEx Privacy Shield Pro product. The deadline for exclusion is October 9, 2026, and the deadline for objection is November 9, 2026. Claims must be submitted by November 9, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

The post Fairchild Medical Center & Boone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.

CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit

CPAP Medical Supplies and Services, a Jacksonville, Florida-based provider of durable medical equipment for treating sleep apnea, has agreed to pay up to $500,000 in benefits to individuals affected by a December 2024 cyberattack and data breach.

The cybersecurity incident was identified in late December 2024, and the forensic investigation determined that an unauthorized third party accessed its network between December 13, 2024, and December 21, 2024, and potentially obtained the personal and protected health information of current and former patients and employees. The HHS’ Office for Civil Rights was notified that the electronic protected health information of 90,133 individuals was compromised in the incident. The affected individuals were notified around August 15, 2025.

Four class action complaints were filed in response to the data breach in the District Court for the Middle District of Florida. Since the lawsuits asserted similar claims and had overlapping classes, they were consolidated into the first complaint filed. The defendant denies wrongdoing, fault, and liability, disagrees with all claims and contentions in the lawsuit, and sought to have the lawsuit dismissed. The motion to dismiss was granted in part and denied in part, and the lawsuit was allowed to proceed. The plaintiffs maintain that the defendant was at fault for failing to implement sufficient cybersecurity measures and should have prevented the cyberattack and data breach.

All parties engaged in negotiations, and on September 4, 2026, the terms of a settlement were agreed upon by all parties.  The federal complaint was dropped, and the consolidated lawsuit – Brett Conner v. CPAP Medical Supplies and Services, Inc. – was refiled and is pending in the Circuit Court for Broward County, Florida. The defendant has agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and up to $500,000 in benefits for the class members.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The benefits are two years of medical data monitoring services, and claims may also be submitted for up to $5,000 as reimbursement for documented, unreimbursed losses due to the data breach. If that total is exceeded, claims will be paid pro rata. There is no alternative cash payment. The deadline for opting out and objecting to the settlement is October 30, 2026. Claims must be submitted by November 26, 2026, and the final fairness hearing was scheduled for December 1, 2026.

The post CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit appeared first on The HIPAA Journal.

The Mental Health Association Data Breach Settlement Agreed

The Mental Health Association, a Chicopee, Massachusetts-based human services agency that provides substance use recovery and support services for developmental disabilities, has agreed to a settlement to resolve class action litigation over a November 2024 cyberattack and data breach that affected 12,633 individuals.

Cybercriminal actors breached its network in November 2024 and potentially obtained personal and protected health information such as names, addresses, dates of birth, Social Security numbers, driver’s license numbers, diagnoses, medications, other medical information, and medical record numbers. The company notified affected individuals about the data breach on May 30, 2025.

The first class action lawsuit was filed in June 2025, alleging that the plaintiff had suffered injuries as a result of the exposure of his sensitive personal and health information, and that the data breach occurred due to the negligence of the defendant due to the failure to implement reasonable cybersecurity measures. The defendant sought to have the lawsuit dismissed; however, the court allowed the action to proceed. Two additional plaintiffs were added to the complaint – Campbell et al. v. Mental Health Association, Inc. – which is pending in the Superior Court of Hampden County, Massachusetts.

The complaint asserted claims for negligence, negligence per se, breach of implied contract, and breach of fiduciary duty. All claims and contentions in the lawsuit continue to be denied by the defendant; however, to avoid the cost, risk, and distraction of continued litigation, all parties agreed to settle the lawsuit. The defendant has agreed to pay attorneys’ fees, legal expenses, settlement administration costs, and benefits for the class members. All class members are entitled to claim three years of complimentary credit monitoring services and may submit a claim for up to three hours of lost time spent responding to the data breach at $25.000 per hour.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Class members may submit a claim for reimbursement of documented, unreimbursed losses incurred due to the data breach up to a maximum of $5,000 per class member or may instead claim an alternative one-time $40 cash payment. The benefits have been capped at $300,000 and will be paid pro rata if that total is exceeded. The deadline for objecting to the settlement, opting out, and submitting a claim is November 19, 2026. The final fairness hearing has been scheduled for December 15, 2026.

The post The Mental Health Association Data Breach Settlement Agreed appeared first on The HIPAA Journal.

WPM Pathology Laboratory; Salina Regional Health Center Settle Class Action Litigation

A settlement has been agreed to resolve class action litigation over a November 2024 targeted cyberattack on the information systems of WPM Pathology Laboratory. The cyberattack occurred on or around November 4, 2024, and resulted in unauthorized access to sensitive personally identifiable information (PII) and protected health information (PHI). Data compromised in the incident included names, dates of birth, Social Security numbers, diagnosis information, medical record numbers, and health insurance claims information.

WPM Pathology Laboratory is based in Salina, Kansas, and provides anatomic pathology, cytology, and molecular testing services to hospitals and clinics, including Salina Regional Health Center, which is also named as a defendant in the lawsuit. The lawsuit – Steinle v. WPM Pathology Laboratory and Salina Regional Health Center, Inc. – was filed in the District Court of Saline County, Kansas, by plaintiff Shawn Steinle, who alleged that the cyberattack was due to the failure of the defendants to implement reasonable cybersecurity safeguards. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and invasion of privacy, all of which were denied by the defendants.

After considering the likely cost, delay, and risk associated with continued litigation, all parties explored the opportunity of an early resolution. Negotiations were conducted at arm’s length without mediation, and a settlement has been agreed upon and has received the first nod from the court. The defendants have agreed to pay benefits to the class members, as well as attorneys’ fees and expenses, settlement administration costs, and a service award to the class representative.

Class members are entitled to claim a two-year membership to the CyEx Identity Defense Complete credit monitoring service, plus a cash payment. A claim may be submitted for reimbursement of documented, unreimbursed ordinary losses up to $400.00 incurred between November 4, 2024, and October 19, 2026 and/or extraordinary losses up to $4,000.00 incurred between the same dates. A claim may also be submitted for reimbursement of up to four hours of lost time at $20.00 per hour. Individuals who do not submit a claim for any of those cash payments may claim an alternative $45.00 cash payment, in addition to the credit monitoring services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Individuals wishing to opt out of the settlement or file an objection must do so by October 19, 2026, and claims must be submitted by the same date. The final fairness hearing has been scheduled for December 16, 2026.

The post WPM Pathology Laboratory; Salina Regional Health Center Settle Class Action Litigation appeared first on The HIPAA Journal.

Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits

Settlements have been agreed to resolve class action complaints against Wayne Memorial Hospital in Georgia and Regional Urology in Louisiana stemming from breaches of patients’ personal and protected health information.

Wayne Memorial Hospital Data Breach Settlement

Wayne Memorial Hospital Auxiliary, Inc. d/b/a Wayne Memorial Hospital, a Georgia healthcare provider, has agreed to settle a class action lawsuit over a 2024 data breach. Wayne Memorial Hospital identified a cybersecurity incident on or around June 3, 2024. The forensic investigation determined that an unauthorized third party had access to its network between May 30, 2024, and June 3, 2024, and potentially obtained patients’ personal and protected health information. Notification letters were mailed to the affected individuals in late August 2025.

Multiple class action lawsuits were filed in response to the data breach, alleging that the hospital was at fault for the data breach, as insufficient measures had been implemented to protect against unauthorized access to systems containing patient information. The lawsuits were consolidated as they all made similar claims. The consolidated lawsuit – Bates v. Wayne Memorial Hospital – is pending in the Superior Court of Wayne County, State of Georgia. The parties participated in mediation in May 2026 and reached agreement on the terms of a settlement that were acceptable to all parties. The settlement has now received preliminary approval from the court.

Wayne Memorial Hospital has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards from the class representatives. Class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket expenses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be $25 per class member. The cash payments may be adjusted depending on the number of valid claims received. The deadline to object to the settlement and opt out is November 7, 2026. Claims must be submitted by December 7, 2026. The final fairness hearing has been scheduled for January 27, 2027.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Regional Urology Data Breach Settlement

Regional Urology, a private urology clinic in Northern Louisiana that operates under the name Ochsner LSU Health – Regional Urology, has agreed to settle class action litigation stemming from a data security incident first identified in October 2025. Regional Urology was a victim of a targeted cyberattack that exposed patients’ personal and protected health information. Data compromised in the incident included names, dates of birth, Social Security numbers, medical record numbers, and information related to the care provided.

The first class action lawsuit was filed by plaintiff Cathy Cowden on October 17, 2025. Three further class action lawsuits were filed over the data breach, which were consolidated as they made similar claims and had overlapping classes. The consolidated lawsuit – Clark, et al., v. Regional Urology, LLC, et al. – is pending in the District Court for the Parish of Caddo, Louisiana.

The plaintiffs alleged that the data breach should have been prevented and was due to the failure to implement reasonable and appropriate cybersecurity measures. The consolidated lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, and declaratory judgment. The defendant denies all claims in the lawsuit, including fault, liability, and wrongdoing.

The parties agreed to attend mediation, and the terms of a settlement were agreed. The settlement has now been finalized and has received preliminary approval from the court. Under the terms of the settlement, class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses due to the data breach up to a maximum of $5,000 per class member. The expenses must have been incurred between October 5, 2025, and November 16, 2026. In addition, a claim may be submitted for one year of medical data monitoring services.

Individuals who do not submit a claim for losses and/or medical monitoring services may claim a one-time $40.00 cash payment. The deadline to object to the settlement and opt out is October 16, 2026. Claims must be submitted by November 16, 2026. The final fairness hearing has been scheduled for October 19, 2026.

The post Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation

Settlements have been agreed to resolve class action litigation against CVS Health & Criteo and American Wellness Corp. The lawsuits stem from their use of tracking technologies on their websites and mobile apps.

CVS Health & Criteo Corp. Pixel Settlement

A $20.5 million settlement has been agreed to resolve class action litigation against the U.S. healthcare company CVS Health and the digital advertising company Criteo to resolve claims related to the use of web tracking technologies. The tracking tools are alleged to have resulted in the unlawful disclosure of web users’ personal and protected health information to third parties, without the knowledge or consent of web users.

Multiple class action lawsuits were filed in response to the alleged disclosures. The lawsuits were consolidated into a single complaint as the lawsuits had overlapping claims and classes. The consolidated lawsuit – Brewer, et al. v. CVS Pharmacy, Inc. and Criteo Corp. – is pending in the Circuit Court of the 17th Judicial Circuit in and for Broward County, Florida.

According to the lawsuit, tracking tools were added to the CVS Health website and CVS Pharmacy mobile application, which collected users’ sensitive data and transmitted the information to companies such as Criteo, Adobe Inc., Medallia, and Quantum Metric. Web users were unaware that the tools were used and that their sensitive data was being collected and shared with third parties for advertising and marketing purposes, in an egregious violation of their privacy. The lawsuit asserted claims for negligence, breach of confidence, invasion of privacy, and violations of the Electronic Communications Privacy Act. The defendants deny that they violated any law and disagree with the claims in the lawsuit.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties attended mediation on March 17, 2026, and negotiations continued for several weeks thereafter. The terms of the settlement have now been agreed to by all parties, and the settlement has received preliminary approval from the court. The defendants have agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and cash payments to the class members. The settlement class consists of all individuals who accessed the CVS Health website or application prior to July 27, 2026.

Class members who can submit documentation proving they are a member of the class may submit a claim for up to $10.00. Individuals who submit a claim and cannot provide proof that they are a class member may claim up to $5.00. Claims are subject to a pro rata decrease if the cap is exceeded. The deadline for opting out and objection is November 1, 2026. Claims must be submitted by November 16, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

American Wellness Corp. Web Tracking Settlement

A settlement has been agreed to resolve class action litigation against American Wellness Corp. (AmWell) stemming from the use of website tracking technologies such as pixels, which are alleged to have resulted in web users’ personally identifiable medical information and confidential communications being transmitted to third-party companies without their knowledge or consent.

The lawsuit – Polk vs American Well Corp. – was filed in the Superior Court for the State of California, County of Sacramento, by Virginia Polk, individually and on behalf of similarly situated individuals. The lawsuit alleged violations of the Federal Wiretap Act, California Invasion of Privacy Act, California Confidentiality of Medical Information Act, California Constitution, and common law.

During mediation, all parties agreed to the terms of a settlement, which has now received preliminary approval from the court, with no admission of fault, wrongdoing, or liability by the defendant. The settlement class consists of all U.S. based persons who used the appointment booking tool on the LiveHealth Online website or the LiveHealth Online iOS or Android Apps between October 2024 and August 2025.

AmWell has agreed to establish a $2,037,751.46 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and a service award to the class representative will be deducted. The remainder of the fund will be divided pro rata between individuals submitting a valid claim. The cash payments are anticipated to be between $51.14 and $102.29, depending on the number of valid claims received. The deadline for objection, opting out, and submitting a claim is October 30, 2026. The final fairness hearing has been scheduled for January 15, 2027.

The post CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation appeared first on The HIPAA Journal.