Fairchild Medical Center and Boone Health have agreed to settle class action lawsuits alleging that Meta Pixel tracking code on their patient portals disclosed protected health information to third parties without consent. The settlements underscore the ongoing HIPAA enforcement and litigation risk tied to website tracking technologies on healthcare platforms.
Fairchild Medical Center and Boone Health have reached settlements in class action litigation stemming from their use of Meta Pixel tracking technology on patient-facing websites and portals. The lawsuits alleged that when patients interacted with these platforms—such as scheduling appointments, logging into patient portals, or searching for health information—the Pixel code transmitted protected health information (PHI) to Meta without patient authorization.
The Meta Pixel is a JavaScript tracking snippet widely used for advertising analytics. In healthcare contexts, however, its deployment has drawn intense regulatory scrutiny because the data captured can include IP addresses, page URLs, appointment types, provider names, and even clinical conditions—information that falls squarely within the definition of PHI under HIPAA.
The Fairchild and Boone Health cases are part of a broader wave of litigation that began after investigative reporting in 2022 revealed that dozens of hospital systems had installed the Pixel on their websites. Since then, the HHS Office for Civil Rights (OCR) issued guidance clarifying that tracking technologies on authenticated patient portals generally require HIPAA-compliant authorizations, and multiple health systems have faced both regulatory investigations and private class actions.
The settlements affect patients of Fairchild Medical Center, a rural critical access hospital in Yreka, California, and Boone Health, a healthcare system based in Columbia, Missouri. Individuals who used the organizations' websites or patient portals during the period when the Pixel was active may be included in the settlement classes. Affected patients potentially had information such as the pages they visited, appointment scheduling details, and in some cases medical condition identifiers disclosed to Meta.
While the specific financial terms of the settlements have not been fully detailed at the time of reporting, class action settlements of this nature have historically ranged from hundreds of thousands to several million dollars, depending on class size and the scope of data exposed. Beyond direct financial costs, both organizations have presumably agreed to implement corrective measures, including removal or reconfiguration of tracking technologies and enhanced privacy controls.
The broader impact extends to every HIPAA-covered entity that maintains a public website or patient portal. OCR has made clear that it views the use of tracking technologies on authenticated pages as a potential impermissible disclosure of PHI absent a valid authorization, signaling continued enforcement risk for non-compliant organizations.
The Fairchild and Boone settlements reinforce several critical compliance lessons for HIPAA-covered entities:
Under OCR's December 2022 bulletin and subsequent updates, tracking technologies like Meta Pixel collect identifiable information that, when tied to a user's interaction with a health-related website, constitutes PHI. On authenticated pages—where a user is logged into a patient portal—the collected data almost certainly falls under HIPAA protection. Covered entities cannot rely on website terms of service or general privacy policies alone; they must obtain HIPAA-compliant authorization before deploying these tools on authenticated surfaces.
If an organization chooses to use third-party analytics or tracking vendors, OCR guidance requires a Business Associate Agreement (BAA) when the vendor will have access to PHI. Meta has historically declined to sign BAAs for the Pixel product, which creates a fundamental compliance obstacle for healthcare providers seeking to use it on PHI-bearing pages.
The settlements demonstrate that even before or without an OCR enforcement action, private plaintiffs' attorneys are actively pursuing healthcare organizations over Pixel deployments. Class action claims often proceed under state privacy laws, common law invasion of privacy, and breach of fiduciary duty theories, creating a parallel liability track to federal HIPAA enforcement.
Organizations must conduct thorough security risk assessments that specifically evaluate website and application tracking technologies. This includes maintaining a complete inventory of all scripts and pixels deployed across digital properties, understanding what data each script captures, and documenting the legal basis for any PHI transmission.
Healthcare organizations should take immediate, concrete steps to mitigate similar exposure:
1. Inventory all tracking technologies. Conduct a comprehensive audit of all websites, patient portals, and mobile apps to identify every third-party script, pixel, or beacon currently deployed. Document the vendor, purpose, data collected, and pages where the technology is active.
2. Remove or reconfigure non-compliant tracking. For any tracking technology that collects PHI without a valid authorization or BAA, remove the script immediately from authenticated pages. On unauthenticated pages, carefully evaluate whether the data collected could reasonably be tied to an individual's health status, which would trigger HIPAA protections.
3. Establish a tracking technology governance process. Create formal policies and procedures requiring privacy, legal, and security review before any new tracking script is deployed. Document approvals and maintain a regularly updated inventory.
4. Review vendor contracts. Ensure that any vendor receiving PHI through digital channels has a signed, current BAA. If a vendor refuses to sign a BAA—as Meta has for Pixel—do not deploy the technology on pages that transmit PHI.
5. Update patient-facing privacy notices. Ensure Notices of Privacy Practices accurately describe any tracking or analytics activities, and provide patients with clear mechanisms to exercise their rights.
6. Monitor regulatory developments. Track OCR guidance and enforcement activity, as well as ongoing litigation, to stay current on evolving expectations for website privacy in healthcare.
The Fairchild and Boone settlements serve as a clear reminder that the HIPAA compliance landscape now extends well beyond traditional data security measures to encompass the digital marketing and analytics tools that organizations use every day.
The Meta Pixel is a JavaScript tracking code used for advertising analytics. It becomes a HIPAA risk when deployed on healthcare websites or patient portals because it can transmit protected health information—such as IP addresses, page URLs, and appointment details—to Meta without patient authorization, constituting an impermissible disclosure.
Settlement agreements typically do not require an admission of wrongdoing. Fairchild Medical Center and Boone Health agreed to resolve the litigation to avoid protracted legal costs and uncertainty, but the settlement terms do not constitute an admission that they violated HIPAA or other privacy laws.
A healthcare provider can use analytics tools if they avoid transmitting PHI. This means removing tracking scripts from authenticated pages, ensuring unauthenticated page tracking does not capture health-related identifiers, signing a Business Associate Agreement with analytics vendors that will receive PHI, and obtaining HIPAA-compliant authorizations where required.
Patients who believe their data was exposed through a tracking pixel should contact the healthcare provider's privacy officer to request information about the disclosure, file a complaint with the HHS Office for Civil Rights at hhs.gov/hipaa, and consider whether they may be eligible to join an existing class action settlement.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started FreeHIPAA civil monetary penalties range from $137 to $68,928 per violation, with annual caps ranging from $34,464 to $2,067,813 depending on the level of culpability. In addition, healthcare organizations face class action settlement costs, remediation expenses, notification costs, and reputational harm that often exceed regulatory penalties.