PrivacySignal
Healthcare

CVS Health; Criteo Agree to Pay $20.5 Million to Resolve Website Tracking Litigation

HIPAA Journal · · US Federal · Healthcare Privacy

CVS Health, Criteo, and American Wellness Corp have agreed to pay $20.5 million to settle class action lawsuits tied to website tracking practices. The settlements resolve litigation that appears to center on how user data was collected and shared through tracking tools on health-related websites.

Why this matters: When you visit a pharmacy or health website, you probably assume your activity stays private. These lawsuits say it did not. Tracking tools quietly collected and shared that data with ad-tech companies. Health browsing is not ordinary browsing. It can reveal conditions, medications, and personal struggles you never consented to share. A $20.5 million settlement sounds large, but the real number to watch is how many people were affected and how little each one gets. The money matters less than whether the behavior stops.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Gastroenterology Practice and Hospice Companies

Data breaches have been announced by Gastroenterology & Hepatology of Central New York, Three Oaks Hospice, and Doctor’s Choice Home […] The post Data Breaches Announced by Gastroenterology Practice and Hospice Companies appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

California Seeks to Implement AI Guardrails for Mental Health Treatment

The California Senate has unanimously passed a bill to establish guardrails on the use of artificial intelligence in mental health treatment. The legislation moves forward amid broader national debate over how AI tools should be regulated in clinical and therapeutic settings.

Who should care: Healthcare professionals · Privacy officers · Compliance · AI governance · Lawyers · Administrators · General readers · Policy

#healthcare#ai-governance#ai Read original →
Healthcare
HIPAA Journal · · US Federal

What a Healthcare Compliance Attorney Heard at the OCR’s HIPAA Security Conference

A healthcare compliance attorney attended a two-day HIPAA Security Conference hosted by the Office for Civil Rights at the NIST campus in Gaithersburg, sharing observations from the event. The conference brought together regulators and compliance professionals to discuss healthcare data security requirements.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

Cybersecurity Awareness Month 2026: Critical Infrastructure Urged to Adopt Cybersecurity 3Rs

October is Cybersecurity Awareness Month, a global effort to promote online safety and digital security. Launched in 2024 by the […] The post Cybersecurity Awareness Month 2026: Critical Infrastructure Urged to Adopt Cybersecurity 3Rs appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud

Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment, […] The post HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity […] The post Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →