Over the past few years, more than 20 privacy class action lawsuits have been filed against healthtech companies, from large hospital systems to small telehealth startups. The pattern is consistent enough to be instructive: the same handful of practices keep showing up as the trigger, regardless of company size.

The Practices Behind the Lawsuits

  1. Tracking pixels on patient-facing pages. Meta Pixel, Google Analytics, and similar tools are common across the web, but when they're placed on pages where someone schedules an appointment, searches symptoms, or logs into a patient portal, they can transmit details about that visit, such as page URLs, button clicks, sometimes form inputs, to the ad platform running the pixel. Several of the largest recent suits center on exactly this: a tracking tool installed for ordinary marketing analytics that ended up capturing health-related browsing activity.
  2. Data sharing with ad networks. Related to the above, but broader: some suits allege that patient data was shared with third-party advertising or analytics platforms as a matter of routine data flow, not through any single misconfigured tool. The complaints often hinge on whether patients were told this sharing was happening and whether they had a meaningful way to opt out.
  3. Session replay and analytics tools. Tools that record how a user moves through a site, like mouse movement, scrolling, keystrokes, have drawn scrutiny when deployed on portals where a user might be entering health information, even if the company never intended the tool to capture anything sensitive.
  4. Third-party vendor exposure. A number of cases don't stem from the healthtech company's own systems at all, but from a vendor or subprocessor with looser controls. The company is still named because the data originated with them, which puts vendor oversight squarely inside the risk perimeter, not outside it.

Why This Category Is Growing

Two things are compounding at once. First, plaintiffs' firms have gotten specific about what to look for. Tracking pixels are easy to detect from the outside, and a growing body of prior settlements gives them a template for the complaint. Second, health data sits at the intersection of two areas regulators and courts already treat carefully: sensitive personal information and consumer protection law. A practice that is common on a retail site, like a marketing pixel or an analytics script, carries more weight when the page underneath it is a symptom checker or an appointment scheduler.

Where the Gaps Tend to Hide

What makes this category particularly hard to manage is that the exposure often isn't the result of a deliberate decision. A pixel gets added by a marketing team for campaign attribution. A session-replay tool gets rolled out by a product team to reduce checkout friction. Neither team is thinking about health-data classification - they're solving a different problem entirely. The result is that the riskiest practices tend to accumulate quietly, through ordinary tool adoption, rather than through any single obvious misstep.

This is where ongoing monitoring earns its place. A one-time privacy review can catch what's on a site the day it's reviewed. It can't catch the pixel a marketing team adds six months later, or the new vendor a product team onboards without looping in the privacy team. Surfacing those gaps as they appear, rather than at the next scheduled audit, is what separates a practice that’s flagged and fixed from one that shows up first in a legal complaint.

Want to build patient trust and ensure your site meets the standard? See if your company qualifies for our Privacy Seal.