CVS Health and advertising technology company Criteo have agreed to pay $20.5 million to resolve class action litigation alleging that tracking pixels on CVS websites unlawfully disclosed patients' health information to third parties, including search terms and medication pages viewed, in potential violation of HIPAA and state privacy laws.
CVS Health and digital advertising firm Criteo have agreed to a combined $20.5 million settlement to resolve class action litigation stemming from the use of website tracking technologies on CVS digital properties. The lawsuit alleged that tracking pixels and similar technologies collected and transmitted sensitive health-related information—such as prescription medication searches, conditions viewed, and appointment scheduling activity—to third-party advertising networks without proper consent or authorization.
This settlement marks one of the largest website tracking resolutions in the healthcare sector and underscores the intensifying regulatory and legal scrutiny surrounding the use of analytics and advertising tools on health-related websites.
The litigation alleged that CVS Health deployed third-party tracking pixels, including those operated by Criteo, across its websites and patient portals. These tracking tools captured granular browsing data, including pages viewed about specific medications, health conditions, and treatment options. According to the complaint, this information could be combined with other identifiers such as IP addresses, device IDs, and cookie data to re-identify individual users.
Plaintiffs asserted that the data collected and transmitted to Criteo and potentially other advertising partners constituted protected health information (PHI) under HIPAA. The claims further alleged that the disclosure of this information occurred without patient authorization, violating HIPAA's Privacy Rule, various state consumer protection statutes, and common-law privacy doctrines.
The settlement class encompasses individuals who visited CVS Health websites—including CVS.com, Caremark.com, and related patient portal properties—and had their browsing activity captured by tracking technologies during the relevant class period. While CVS has not admitted liability, the settlement provides monetary relief to affected users and imposes corrective operational requirements.
This case directly impacts:
This settlement reinforces the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) guidance issued in December 2022 regarding the use of online tracking technologies by HIPAA-covered entities and business associates. Key compliance takeaways include:
The OCR guidance clarified that IP addresses, device identifiers, and browsing activity on unauthenticated public webpages can constitute PHI where there is a reasonable basis to believe the information relates to an individual's past, present, or future health condition or care. CVS's tracking practices fell squarely within this interpretation.
Sending health-related browsing data to advertising networks for targeted marketing purposes generally requires valid patient authorization under HIPAA. The absence of such authorization formed the core of the plaintiffs' claims.
Even where a tracking vendor signs a business associate agreement (BAA), the disclosure of PHI for marketing or advertising purposes that do not fall within HIPAA's permitted uses—such as treatment, payment, or healthcare operations—still requires individual authorization.
The settlement involved claims under state privacy statutes, including the California Invasion of Privacy Act (CIPA) and the California Confidentiality of Medical Information Act (CMIA), signaling that HIPAA compliance alone does not insulate organizations from state-level exposure.
The settlement arrives amid a wave of enforcement activity by regulators. The Federal Trade Commission (FTC) has pursued enforcement actions against digital health platforms for disclosing health information to advertising platforms such as Meta and Google. The OCR has also signaled that website tracking violations represent a priority area for future audits and corrective action plans.
Healthcare organizations, insurers, pharmacies, and telehealth providers should treat this settlement as a compliance wake-up call. Recommended actions include:
1. Conduct a Complete Tracking Technology Inventory — Document every pixel, script, SDK, and analytics tool deployed on each digital property, including patient portals, marketing sites, and mobile applications.
2. Map Data Flows to Third Parties — Identify precisely what data each vendor receives, how it is processed, and whether the vendor acts as a business associate or a data controller in its own right.
3. Review BAAs and Data Processing Agreements — Confirm that agreements address tracking data specifically and restrict secondary uses such as advertising.
4. Implement Consent Mechanisms — Where marketing disclosures are desired, deploy transparent, granular consent mechanisms that capture valid authorization in accordance with HIPAA and state requirements.
5. Evaluate Privacy-Enhancing Alternatives — Consider server-side analytics, cookieless measurement, and first-party data strategies that minimize third-party disclosure risk.
6. Establish Ongoing Monitoring — Website tag governance tools can alert compliance teams when unauthorized pixels or scripts are deployed by marketing or product teams.
The $20.5 million CVS-Criteo settlement adds to a growing body of website tracking litigation across healthcare, financial services, and e-commerce. With plaintiffs' firms actively recruiting plaintiffs in website tracking cases—and regulators issuing formal guidance—organizations that delay remediation face compounding legal, financial, and reputational exposure. The convergence of HIPAA enforcement, state privacy litigation, and FTC oversight makes website tracking governance a board-level risk issue for 2026 and beyond.
The CVS Health and Criteo settlement serves as a powerful reminder that website tracking technologies in healthcare settings carry meaningful regulatory and litigation risk under HIPAA and state law. Organizations that proactively inventory their tracking ecosystem, tighten vendor agreements, and implement robust consent mechanisms will be better positioned to navigate the evolving enforcement landscape. For compliance teams, the message is clear: advertising efficiency must not come at the expense of patient privacy.
CVS Health and Criteo agreed to the $20.5 million settlement to resolve class action claims that website tracking pixels on CVS digital properties disclosed patients' sensitive health information—such as medication searches and condition pages viewed—to third-party advertisers without valid HIPAA authorization, violating HIPAA and state privacy laws.
The lawsuit alleged that tracking pixels deployed by Criteo on CVS websites collected protected health information (PHI), including IP addresses and browsing activity related to specific medications and health conditions, and transmitted that data to advertising networks for marketing purposes without patient authorization, in violation of HIPAA's Privacy Rule.
Yes. Under the HHS Office for Civil Rights' December 2022 guidance, tracking data such as IP addresses, device identifiers, and browsing activity on health-related webpages can constitute protected health information (PHI) when there is a reasonable basis to believe it relates to an individual's health condition or care, even on unauthenticated public pages.
Healthcare organizations should inventory all tracking technologies on their websites and apps, map data flows to third parties, review business associate agreements, obtain valid patient authorization before sharing health data for marketing, implement tag governance tools, and consider privacy-enhancing alternatives like first-party analytics.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started FreeNo. A Business Associate Agreement (BAA) alone does not permit disclosure of protected health information to advertising vendors for marketing purposes. HIPAA requires specific patient authorization for disclosures used for marketing or advertising that fall outside permitted uses such as treatment, payment, or healthcare operations.