PrivacySignal
Healthcare

Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits

HIPAA Journal · · US Federal · Healthcare Privacy

Banner Health and LifeStance Health Group have each agreed to settle lawsuits stemming from their use of tracking pixels and similar technologies on their websites. The tools allegedly collected and shared patient data with third parties without proper authorization under HIPAA.

Why this matters: When you visit a health provider's website to look up symptoms, find a therapist, or book an appointment, you probably assume that information stays private. Tracking pixels can send it to ad platforms before you ever speak to a doctor. Two settlements do not end this practice across healthcare. They just confirm the legal exposure is real. Health systems that kept using these tools after earlier warnings cannot claim they did not know the risk. The question now is whether settlements change behavior, or just become a cost of doing business.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Healthcare
HIPAA Journal · · US Federal

House Committee Advances Bill Preventing OSHA From Implementing Heat Standard

A House committee has advanced legislation that would block OSHA from finalizing or enforcing a federal heat safety standard for workers. The bill targets a rulemaking effort the agency has been developing to protect employees from heat-related illness on the job.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
Nextgov/FCW · · US Federal

HHS continues health tech initiative with 7 new industry pledges

The Department of Health and Human Services has added seven new industry pledges to its ongoing health technology initiative, which the Trump administration says has expanded app-based access to personal medical records to roughly 60% of Americans.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

How to Become HIPAA Compliant

The HIPAA Journal has published a practical guide outlining how organizations can work toward HIPAA compliance, centering on the Department of Health and Human Services' seven-element compliance framework as a structured starting point following a risk assessment.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure

A Government Accountability Office report found that federal cyber incident reporting requirements for critical infrastructure operators may overlap across agencies, creating redundant obligations. The findings come as CISA prepares to finalize its rule implementing mandatory cyber incident reporting under the CIRCIA legislation.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack

AnMed, a nonprofit health system operating across upstate South Carolina and Northeast Georgia, has shut down close to 80 facilities while responding to a cyberattack. The scale of the closure points to serious disruption across a regional system that serves a wide patient population.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, a healthcare management and revenue cycle services company based in Augusta, Georgia, has disclosed a cybersecurity incident affecting approximately 1.26 million individuals. The company works in revenue cycle management, meaning it processes sensitive patient financial and health data on behalf of healthcare providers.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →