Two Health Systems, $14 Million, One Month: Pixel Lawsuits Didn't Get the Memo

Two Health Systems, $14 Million, One Month: Pixel Lawsuits Didn't Get the Memo

On June 30, HIPAA Journal reported that Allina Health System had agreed to pay $12.5 million to settle a class action lawsuit over tracking pixels on its website. Seventeen days later, it reported the next one: Atrium Health had agreed to pay up to $1.8 million to settle a class action over tracking pixels on its patient portal.

Two health systems. Roughly $14.3 million. One month.

If you work in healthcare marketing, there’s a decent chance your reaction is confusion. Didn’t a federal court throw out the government’s tracking rules back in 2024? Didn’t the American Hospital Association win that fight?

Yes, and yes. The problem is that the ruling didn’t do what most people think it did, and that misunderstanding is expensive.

What happened at Allina

Allina Health is a nonprofit health system based in Minneapolis serving patients across Minnesota and western Wisconsin. Like thousands of healthcare organizations, its website ran tracking tools from companies like Meta and Google. The lawsuit alleged those tools sent personally identifiable information and protected health information to those third parties.

The first complaint was filed in September 2024 in federal court in Minnesota. More plaintiffs joined, the cases were consolidated, and the claims stacked up: invasion of privacy, breach of implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, negligence, plus violations of the federal Electronic Communications Privacy Act, the Minnesota Health Records Act, and Minnesota’s consumer protection statute.

Not one of those claims is a HIPAA claim.

The settlement covers roughly 2.5 million people, split into two groups. The first is patients who used Allina’s patient portal, online bill pay, or online scheduling between September 2018 and May 2026; it gets $10.3 million of the fund. The second group gets $2.2 million, and it covers Allina patients who used none of those tools.

That’s nearly eight years of exposure from tools that were almost certainly installed with no ill intent by a marketing team doing what marketing teams do. Allina denies any wrongdoing, which is standard, and settled to avoid the cost and risk of continuing to fight. The deal received preliminary court approval in May, with a final approval hearing scheduled for late September.

What happened at Atrium

Atrium Health operates a dozen hospitals and more than 900 care facilities across North and South Carolina. Its case centered on the MyAtriumHealth patient portal, where tracking technologies ran on authenticated pages between 2015 and 2019. After an investigation, Atrium determined that the protected health information of up to 585,959 patients may have been disclosed to third parties, and when it reported the breach, it assumed every portal user was affected.

The data at issue included IP addresses and third-party cookies, and for anyone who filled out a form, potentially names, email addresses, phone numbers, locations, gender, and anything else typed into a field. Multiple lawsuits were consolidated in state court in Mecklenburg County, North Carolina. The claims: breach of contract, breach of fiduciary duty, negligence, unjust enrichment. The settlement is awaiting final approval there too, with a fairness hearing set for the end of September.

Again, no HIPAA claim. Again, a settlement instead of a trial.

About that court ruling

In June 2024, a federal judge in Texas sided with the American Hospital Association and vacated the core of HHS’s online tracking guidance. HHS briefly appealed, then dropped it. Healthcare marketing teams across the country exhaled. Plenty of them re-enabled their pixels.

Here’s what that ruling actually covered: it struck down OCR’s position that combining a visitor’s IP address with a visit to a public, unauthenticated webpage about a health condition creates protected health information.

It did not touch authenticated pages. Patient portals, bill pay, scheduling tools, logged-in anything. Data flowing off those pages was PHI before the guidance, during the guidance, and after the ruling. The Atrium case is entirely about a patient portal. The vacated guidance was never going to help.

More importantly, the ruling constrained one agency’s interpretation of one law. Class action attorneys don’t sue under HIPAA, because HIPAA has no private right of action. They sue under wiretap statutes, state health records laws, consumer protection acts, and plain old common law theories like negligence and breach of fiduciary duty. Look at the Allina claim list. A Texas judge limiting OCR’s reach does nothing to a Minnesota Health Records Act claim in a Minnesota courtroom.

And go back to Allina’s second settlement group: $2.2 million set aside for patients who never logged into a portal, never paid a bill online, never scheduled an appointment. Their claims rest on ordinary website visits, the exact activity the court said OCR couldn’t call PHI. The plaintiffs recovered for it anyway, because their claims never ran through HIPAA in the first place.

The AHA won its case. Allina and Atrium still wrote the checks.

The math nobody runs

Here’s the uncomfortable exercise. Free analytics from Google. Free pixel from Meta. Total savings: whatever a compliant analytics platform would have cost, which for most organizations is a few thousand dollars a year.

Against that: $12.5 million for Allina. Up to $1.8 million for Atrium, plus the cost of a breach notification to more than half a million patients, plus years of litigation, plus every hour of leadership attention it consumed. And both of these are settlements, meaning they’re the discounted price. Neither number includes what a jury might have done.

The free tools were never free. The bill just arrives years later, with interest, addressed to legal.

What this means for your organization

If you run a healthcare website and you’re still relying on the 2024 ruling as your compliance strategy, these two settlements are the correction. A few things worth doing this week:

Audit what’s actually firing. Not what you think is installed. What’s actually sending data, on which pages, to which domains. Pixels have a way of accumulating, and tag managers make it easy for things to run long after anyone remembers adding them. Anatomy of a PHI Leak walks through how to watch it happen in your browser’s network tab.

Treat authenticated pages as radioactive. Portals, bill pay, scheduling, intake forms. No third-party tracking scripts without a Business Associate Agreement, and most ad platforms will not sign one. The Atrium settlement is what portal tracking costs.

Stop assuming HIPAA is the only exposure. Every claim in these two cases came from somewhere else: state law, federal wiretap statutes, common law. The plaintiffs’ bar has a working playbook, and the AHA ruling isn’t a defense against any page of it.

Replace, don’t just remove. Marketing still needs data. The answer isn’t flying blind, it’s measurement built for this environment: first-party, no data sharing with ad platforms, and a vendor that will actually sign a BAA.

That is what Ghost Metrics was built for. The protection isn’t a compliance certificate, it’s the architecture: your data stays first-party and never reaches Meta or Google, so there’s no third-party disclosure for a plaintiff to point to. We’ll sign a BAA, and we’re built for HIPAA, but the real defense is simpler than that. The data never leaves. If you’d like to see what your current setup is leaking, our free HIPAA guide and audit walks through exactly how to check.

Nothing about the 2024 ruling stopped either of these cases, and nothing about it will stop the next one. The question is whether your site is currently generating the evidence.

Chris Wathen
Co-Founder & CTO at Ghost Metrics. Writes about HIPAA, privacy, and the architecture behind compliant analytics.
Try Ghost Metrics

Stop betting compliance on a TOS promise.

Get analytics that sign a BAA and keep PHI out of the pixel, live in minutes.