An empty, brightly lit clinical treatment room in the late afternoon.

One tracking pixel. A $6.6 million settlement.

Nobody there was careless. Somebody added a marketing pixel to a patient portal in 2020, the way every practice adds one. Two years later it was a 1.3 million person disclosure and a class action.1

Five companies arrive before anyone is asked anything.

Nobody has clicked. Nobody has agreed to anything. The address of the page alone carries the reason for the visit, and the address is the first thing that gets sent.

Loaded before consent was requestedElapsed
  • googletagmanager.com1.20s
  • google-analytics.com1.42s
  • connect.facebook.net2.14s
  • googleadservices.com2.96s
  • static.hotjar.com3.64s

This part is not hypothetical.

Every instance below started the same way: an ordinary marketing tag on an ordinary healthcare website. None of them started with anyone deciding to sell patient data.

Settled, no admission of liability $12.25M A 3-million-patient health system

Installed Meta Pixel and Google Analytics on its website, app and patient portal to better understand patient needs. IP addresses, locations, names and appointment information were exposed. Final approval July 2024.2

Notified Oct 2022, settled 2024
Largest health data breach of 2024 13.4M Members of one health plan

Tracking code on the websites and apps sent names, IP addresses, pages viewed, whether someone was signed in, and search terms typed into the health encyclopedia to Google, Microsoft and X.3

Reported April 2024
Settled, no admission of liability $6.6M 1.3 million people

A pixel added for a portal signup campaign, configured incorrectly, left in place for over two years.1

May 2020 to Aug 2022
Federal enforcement $1.5M Civil penalty, telehealth and discount platform

The first enforcement action ever brought under the Health Breach Notification Rule. Permanently barred from disclosing user health information to third parties for advertising.4

February 2023
Federal enforcement $7.8M Online counseling service

Barred from disclosing visitor and user information to third parties for targeted advertising, even with user consent.5

March 2023

Nobody in any of those instances set out to do harm. Somebody asked for a pixel so the ads could be measured. Somebody said yes. That is the whole mechanism. There is no villain in it. There is only the absence of a record.

One tag. Four separate bodies of law.

This is the part that surprises people. A single marketing tag, added in a single afternoon, can put a practice in front of four different regulators and a class action bar, none of which are looking at the same statute.

01

Health privacy

HIPAA, 45 CFR Part 164

Applies to covered entities and their business associates. The disputes above turned on whether a tracking transmission counts as a disclosure of protected health information.

02

Unfair or deceptive practices

FTC Act, Section 5

Reaches practices HIPAA does not, including health-adjacent businesses that are not covered entities at all. It is the authority behind the $7.8 million counseling matter.

03

Breach notification, outside HIPAA

Health Breach Notification Rule, 16 CFR Part 318

Covers health apps and platforms that fall outside HIPAA entirely. Its first ever enforcement action was a pixel case, and it carries civil penalties per violation.

04

State wiretapping and privacy statutes

State law, varies

The layer most practices never consider. Plaintiffs increasingly plead state wiretapping and interception claims over session recording and pixel transmissions, independent of any federal theory.

And the ground is still moving

On June 20, 2024, a federal court in the Northern District of Texas vacated part of the federal guidance on online tracking, specifically the position that HIPAA is triggered when a technology connects a visitor's IP address with a visit to an unauthenticated public page about a health condition or provider. The court held the rule was promulgated in clear excess of HHS's authority under HIPAA. The agency withdrew its appeal in August 2024.6

That narrowed one theory. It did not touch the FTC Act, the Health Breach Notification Rule, state wiretapping statutes, or the patient portal cases, which were never about unauthenticated public pages in the first place. Anyone telling you the tracking question is settled is selling something.

There are two kinds of practice owner. And one person it lands on.

An empty office corridor after hours.
The one who assumes

Assumes somebody is handling it

  • Usually the agency.
  • Usually nobody asked them to.

Neither one is smarter. It isn't a question of how careful you are. It's a question of whether the answer exists in writing on the day somebody asks for it, and of exactly which fields that writing holds.

So this is the thing we made.

It holds every outside company until the patient answers. The six below are real. Press one row to answer for that company on its own, or use the buttons underneath to answer for all six. A patient can allow some and refuse the rest.

Outside companies waiting to load6 held

    While it's watching the tags it also reads the site the way a patient using a screen reader would, notices when somebody adds something new, and flags a privacy policy that stopped matching the website.

    Watch it work on a real page — the decision it stores, the Google Consent Mode signal it sends, and the row the server actually kept.

    And on the first of the month, this arrives.

    One dated document with your domain on it. Every instance on this page turned on the same question: what was the website actually doing, and when. This is that answer, written down before anybody asks for it.

    yourpractice.comEvidence receipt, 01 to 31 Jul 2026
    Consent decisions recorded
    1,284
    Chain
    intact, 0 gaps
    Edits possible
    none
    Outside companies observed
    8
    Never declared by you
    2
    Accessibility
    66 / 100, grade C
    Blocking a screen reader
    2 serious
    Privacy policy version
    v4, 14 Jun 2026
    sha256 08bb7156, prev d519c384Kept, not overwritten

    The two flagged lines are the whole point. Two companies nobody declared, and two things stopping a screen reader from naming a button. Neither surfaces unless something goes looking every month.

    A clinician going through paperwork with a patient in an exam room.

    What we won't do.

    • Tell you you're compliant.
    • Install an overlay.
    • Send you a to-do list.

    Compliance is something a court decides, not a badge a vendor sells. Read the June 2024 decision above again if you want the reason. If you want a company that promises you're protected, they exist, and they're cheaper. We are narrow on purpose, and we publish what this product cannot reach.

    What it watches, every day.

    Four things, continuously, on every page you have. Not a one-time audit that ages the moment somebody edits the site.

    01

    Every third party, and its consent state

    What loaded, when it loaded, and whether a decision had been recorded before it did.

    02

    Anything new that appears

    A tag nobody declared is the finding in most of the instances above. It gets flagged the day it shows up, not at renewal.

    03

    The site as a screen reader reads it

    Graded monthly, with the specific elements that block a screen reader from naming a control.

    04

    Whether the privacy policy still matches

    Policies get written once and the website keeps changing. Drift between the two is the gap counsel asks about first.

    Don't believe me. Type in your website.

    Fifteen seconds. No call, no calendar, nobody phones you afterward. You'll get your own list instead of somebody else's.

    Most owners find something nobody told them about. Then it stops being a thing they carry around.

    Compliance isn't a promise. It's a paper trail.

    PS. The tracker timings and the sample receipt above are composites of what we find on practice websites. They aren't a report on yours. The litigation and enforcement matters are real and are sourced below. The scan is the part about you.

    Consential is consent enforcement and monitoring built for HIPAA-regulated practices. It documents findings and the fix path. It doesn't apply fixes, give legal advice, or replace your own counsel or a manual accessibility audit. Nothing on this page is legal advice.

    Sources

    1. $6.6M settlement, 1.3 million individuals, Meta Pixel on a patient portal, May 2020 to August 2022. HIPAA Journal, Bloomberg Law.
    2. $12.25M settlement, 3 million individuals notified October 2022, Meta Pixel and Google Analytics, final approval July 2024. National Law Review, HIPAA Journal.
    3. 13.4 million members, reported April 12 2024, tracking code transmitted data to Google, Microsoft and X. TechCrunch, Dark Reading.
    4. $1.5M civil penalty, February 2023, first enforcement action under the Health Breach Notification Rule. Davis Wright Tremaine.
    5. $7.8M, March 2023, order bars disclosure of visitor and user information for targeted advertising. Healthcare Dive, Wilson Sonsini.
    6. American Hospital Association v. Becerra, N.D. Tex., June 20 2024, vacating the proscribed combination portion of the OCR online tracking bulletin. Appeal withdrawn August 2024. Holland & Knight, American Hospital Association, HHS.