Treatment Center Compliance Monitor
Prepared for your clients · Updated June 2026
Client Advisory · Tracking-Technology Exposure · Substance Use Treatment

What every treatment center needs to know about the tracking pixels on their website

A plain-language guide to the lawsuits, settlements, and federal rules that affect substance use disorder treatment centers running advertising pixels on their websites. Prepared by your marketing agency to help you make informed decisions about your digital presence.

01

The Landscape

Settled So Far
$152M+
Healthcare pixel settlements 2022–2026
Lawsuits Filed in 2024
~4,000
Up from ~200 in 2023 · 1,900% growth
Unique Defendants
3,512
Across 45 states + DC · 315 courts
Breach Risk Increase
46%
Hospitals with third-party pixels · Rutgers 2026
Data-Privacy Class Actions Filed Per Year
Source: Duane Morris Class Action Review 2026 (consistent methodology, court-filed class actions)
2.5K
2K
1.5K
1K
500
0
~607
2022
~950
2023
~1,543
2024
1,822
2025
~2,150
projected
2026
The Iceberg Below the Chart
The bars above count class actions filed in court only. A separate Stinson LLP analysis found nearly 4,000 total tracking-technology claims in 2024 when including demand letters, arbitration filings, and pre-litigation notices — roughly 2.5x the class-action-only count. The visible docket is the tip. Demand letters that never reach a courtroom are the bulk of the enforcement activity, and those are not captured in any public filing database.
Methodology. 2022–2025 figures from Duane Morris LLP Class Action Review 2026: 1,822 data-privacy class actions filed in 2025 (18% over 2024, 200%+ over 2022). 2024 and 2022–2023 back-calculated from reported growth rates. 2026 projected at 150+/month pace (matching 2025 reported rate); YTD solid fill represents ~750 filings through May 2026. Troutman Pepper separately tracked 197 ECPA-specific complaints in 7 months (Sept 2025–Mar 2026) at 2–4x prior-year rate, suggesting the actual 2026 pace may exceed the 2025 baseline.
3-Year Growth
200%+
2024 → 2025
+18%
Total Claims (2024)
~4,000
ECPA Filing Rate
2x–4x
Statutory Damages · Per Violation
California's wiretap statute (CIPA) allows $5,000 per violation with no requirement to prove actual damages. Multiply by call volume and it becomes existential.
Under Cal. Penal Code § 637.2(a)(1), any person injured by a CIPA violation may recover the greater of $5,000 per violation or three times actual damages. Critically, subsection (c) states: “It is not a necessary prerequisite to an action pursuant to this section that the plaintiff has suffered, or be threatened with, actual damages.” This means every single page view where a pixel fires on a health-intent URL is a separate violation with a $5,000 statutory floor — regardless of whether anyone was actually harmed. For a treatment center website receiving 10,000 monthly visits to condition-specific pages, that is $50 million in potential statutory exposure per month. Separately, the federal ECPA (Wiretap Act) carries statutory damages of $10,000 or $100 per day of violation, whichever is greater — and can be filed in any state.
What the numbers mean
This is no longer a tail risk. Nearly 4,000 tracking-technology privacy lawsuits were filed in 2024 — up from just over 200 in 2023. The plaintiff bar has named 3,512 unique defendants across 45 states.
According to a January 2026 analysis by Stinson LLP, lawsuits related to online tracking privacy increased approximately 1,900% in a single year (2023 to 2024). Over the three-year period 2023–2025, plaintiff firms filed tracking-technology claims in 315 courts across 45 states plus the District of Columbia, targeting 3,512 unique defendants. A separate Duane Morris Class Action Review found that 1,822 data-privacy class actions were filed in 2025 alone — an average of more than 7 filings per business day — representing 18% growth over 2024 and 200%+ growth since 2022. A peer-reviewed Rutgers study (PNAS Nexus, May 2026) found that 66% of U.S. hospitals deploy the same third-party tracking pixels driving these lawsuits, and those hospitals are 46% more likely to experience a data breach. First-party analytics (where data stays in your own systems) show no breach correlation. The technology is not the problem. Sending the data to outside companies is.
Filing rate still accelerating. An analysis by Troutman Pepper Locke tracked 197 federal ECPA wiretap complaints filed between September 2025 and March 2026 — a rate two to four times higher than the same months the prior year. Washington State's My Health My Data Act adds a private right of action, meaning plaintiffs do not need a regulator to sue — they file directly. Treatment centers carrying 42 CFR Part 2 obligations face the highest per-violation statutory exposure of any healthcare vertical.
Sources. Stinson LLP, “A New Era of Comprehensive Privacy Laws and the Surge in Data Privacy Litigation: Important Updates for 2026,” JD Supra, Jan. 26, 2026. Duane Morris LLP, Class Action Review 2026 (Trend #6: Data Breach Filings Continued to Grow). Troutman Pepper Locke, “The ECPA: A Federal Private Right of Action for Privacy Policy Inaccuracies?,” Apr. 28, 2026. Rutgers Business School, PNAS Nexus, May 2026. Cal. Penal Code § 637.2 (CIPA statutory damages). 18 U.S.C. § 2520 (ECPA statutory damages).
02

What Makes Treatment Centers Different

The Part 2 Problem
Substance use disorder treatment records carry stricter federal protections than standard medical records. Most treatment centers do not realize their website tracking violates those protections.
Under a federal rule called 42 CFR Part 2, substance use disorder treatment records are protected even more strictly than regular HIPAA-protected health information. Part 2 was originally written to encourage people to seek treatment without fear that their records would be shared with employers, insurers, or law enforcement.

What this means for your website: When a prospective patient visits a treatment center's website and views pages like /detox, /rehab, /treatment, /addiction, or /suboxone, the URL itself reveals they are seeking substance use treatment. If a Meta Pixel or Google Analytics tag is running on that page, it transmits that URL — along with the visitor's IP address and device information — to Facebook or Google servers. Under Part 2, that transmission is an unauthorized disclosure of substance use treatment information to a third party who has no right to receive it.

This is not just a HIPAA problem. This is a HIPAA problem plus a Part 2 problem plus a state-law problem. Treatment centers carry more layers of legal exposure than almost any other type of healthcare provider.

Treatment centers face five layers of legal exposure from a single tracking pixel:

42 CFR Part 2 — Substance Use Confidentiality
Strictest
HIPAA — Health Information Privacy
Federal
State Consumer Health Privacy (e.g., WA MHMDA)
State CHP
State Wiretap Statutes (e.g., CIPA, IL Eavesdropping)
State
FTC Act / Health Breach Notification Rule
Federal
Why the stacking matters. A standard healthcare provider might face two or three of these layers. A substance use treatment center faces all five simultaneously. Each layer has its own enforcement mechanism — some through private lawsuits, some through state attorneys general, some through federal agencies. A single tracking pixel on a single page can trigger liability under all five at once.
03

How Treatment Centers Get Sued

Layer 1 · 42 CFR Part 2
Substance use records disclosed without specific written consent
Part 2 requires specific written consent before SUD treatment information can be shared with anyone — even other healthcare providers. There is no exception for analytics platforms or advertising networks. When a pixel transmits a URL like /addiction-treatment along with a visitor's IP address to Facebook, that is a disclosure Part 2 prohibits. The consent forms your clients currently use for treatment intake do not cover advertising analytics.
Layer 2 · HIPAA
Protected health information sent to a company without a Business Associate Agreement
Meta and Google are not your clients' business associates. There is no BAA between a treatment center and Facebook covering the Meta Pixel. When the pixel fires on a patient-facing page, HIPAA-protected information (IP address combined with health-intent URL) goes to a company with no contractual obligation to protect it. This is the same fact pattern that produced the $46 million Kaiser Permanente settlement in 2025.
Layer 3 · State Health Privacy Laws
Washington, Nevada, Connecticut, and more are passing laws specifically about health data
Washington State's My Health My Data Act treats the transmission of health data to an advertising platform as a "sale" of consumer health information — and requires a specific written authorization that no website visitor has ever signed. If your clients' treatment center serves anyone in Washington State (even via telehealth), this law applies. Nevada and Connecticut have similar statutes. More states are following.
Layer 4 · State Wiretap Laws
Recording what someone does on a website without their real consent
In California, Illinois, Massachusetts, Pennsylvania, Florida, and other states, intercepting someone's online activity and sending it to a third party can be treated as wiretapping. The largest healthcare settlement to date — Kaiser Permanente at $46 million — was brought primarily under California's wiretap statute. A cookie banner or terms-of-service page does not provide the kind of consent these statutes require.
Layer 5 · FTC Enforcement
The federal government is actively pursuing healthcare companies for tracking-pixel violations
The Federal Trade Commission has already settled enforcement actions against three behavioral-health platforms for sharing patient data through tracking pixels: BetterHelp ($7.8 million), Cerebral ($7 million), and Monument ($2.5 million). Monument is an alcohol-use-disorder platform — directly analogous to substance use treatment centers. In each case, the company promised in its privacy policy not to share health data for advertising, but the pixels did exactly that. The FTC has made clear that mental health and substance use treatment are enforcement priorities.
04

What Your Clients Need to Know

Current as of June 2026
The docket is moving faster than most treatment centers realize. Here are the developments that matter right now.
California Supreme Court lowers the bar for lawsuits (May 14, 2026). In a unanimous ruling, the California Supreme Court held that plaintiffs do not need to prove their health data was actually viewed by an unauthorized party. It is enough to show the data was exposed to a "significant risk of unauthorized access." This makes it easier to sue any healthcare company running third-party pixels in California.

First lawsuits against health insurers (May 2026). A major plaintiff firm filed four simultaneous class actions against Humana, Cigna, Elevance Health, and Blue Cross Blue Shield of Michigan for tracking-pixel data harvesting. The docket has now expanded from hospitals and providers to insurers — treatment centers that accept insurance from these companies should pay attention.

First Big Pharma class action (March 2026). A breast-cancer patient sued Novartis for tracking pixels on branded drug websites. This signals the docket is reaching every corner of healthcare, not just hospitals.

Appellate decision pending that could reshape the entire landscape. The First Circuit Court of Appeals heard oral argument in April 2026 on whether website operators face federal wiretapping liability for using tracking tools. A decision is expected mid-2026 and will affect every healthcare provider in the country.
05

Cases That Set the Benchmark

These are the settlements and enforcement actions that define the financial reality. Treatment centers are in the same category as these defendants — the same tracking tools, the same legal theories, the same plaintiff firms.

Who was sued Category Settlement What happened
Kaiser PermanenteCalifornia · Dec 2025 Health system $46.0M Meta Pixel on patient portal transmitted patient names, appointment data, and search terms to Facebook. Largest healthcare tracking settlement on record.
Adena Health SystemOhio · 2026 Regional nonprofit $17.8M Meta Pixel and Google Analytics on patient portal. 89,000 patients. Approximately $200 per affected patient — one of the highest per-person settlement rates.
BetterHelpFTC enforcement · 2023 Mental health $7.8M Meta Pixel transmitted users' mental-health intake answers (anxiety, depression, suicidal ideation) to Facebook for ad targeting. Permanent ban on health-data sharing.
CerebralFTC enforcement · 2024 Mental health $7.0M Meta Pixel and TikTok pixel disclosed mental-health information of 3.2 million users. Permanent ban. Tied to stimulant-prescribing controversies.
MonumentFTC enforcement · 2024 · TOTAL BAN Alcohol use disorder $2.5M PERMANENTLY BANNED from sharing ANY health data with ANY third party for advertising — not even sanitized conversion signals. Monument's entire attribution pipeline was killed. No pixel, no CAPI, no hashed data, no anonymized events. The FTC did not give Monument the option to remediate and continue — the order is a total, permanent prohibition. This is the FTC's template for substance use treatment platforms.
GoodRxFTC + DOJ · 2023 DTC pharmacy $1.5M First-ever FTC Health Breach Notification Rule enforcement. Facebook Pixel shared medication data for advertising. Falsely displayed HIPAA seal on website.
Shields Health Care GroupMassachusetts · 2024 Health system $15.35M Imaging-services provider. Meta Pixel on appointment and portal pages. Massachusetts wiretap statute + consumer protection (treble damages).
Advocate Aurora HealthWisconsin · 2024 Health system $12.3M Self-disclosed Meta Pixel breach affecting 3 million patients. The case that started the wave in 2022.
Duke University Health SystemNorth Carolina · 2026 Academic med center $3.74M Pixels on MyChart patient portal AND mobile app. 872,634 affected patients. Both web and app tracking vectors addressed.
Premom (Easy Healthcare)FTC + 3 state AGs · 2023 Health app $200K Ovulation and menstrual data shared with China-based companies via SDKs. First case where device identifiers (IMEI) were ruled identifiable health information.
Why Monument Is the Case Your Clients Need to Understand
Monument did not lose a lawsuit. They were ordered by the FTC to permanently stop sending ANY health data to ANY advertising platform. Their attribution pipeline is gone. Not reduced — gone.
Monument was an alcohol-use-disorder telehealth platform — the closest publicly-settled analog to a residential rehab, detox, IOP, or MAT clinic. The FTC found that Monument shared substance-use treatment data to Meta and Google via tracking pixels despite privacy-policy promises not to.

The FTC's order is a permanent, total ban on sharing health data for advertising purposes. Not "fix your consent flow and you can continue." Not "sanitize the data first." Not "use a server-side API instead of a pixel." The order prohibits any sharing of health information with any third party for advertising — period. Monument's entire ad-attribution pipeline was killed. They cannot run Meta ads with conversion tracking. They cannot run Google Ads with conversion tracking. They cannot send even anonymized, sanitized, or hashed conversion events to any advertising platform. Their digital marketing capacity was permanently crippled.

This matters because of how FTC enforcement works. When a class-action plaintiff sues your client in court, the treatment center can fight back — file motions to dismiss, challenge standing, negotiate a settlement, appeal a ruling. There is a process. When the FTC comes after your client, the dynamic is fundamentally different. The FTC is an administrative agency with its own in-house judges (Administrative Law Judges). The agency investigates, the agency prosecutes, and the agency's own judges decide the case. There is no jury. The burden of proof is lower. The defendant's ability to fight is structurally limited compared to a courtroom. The FTC can issue consent orders (like Monument's) that impose permanent behavioral restrictions — and violating a consent order carries civil penalties of up to $50,120 per violation per day.

The FTC has publicly stated that substance use treatment is an enforcement priority. BetterHelp ($7.8M), Cerebral ($7M), and Monument ($2.5M) were settled within 14 months of each other. The agency is not slowing down. Every residential rehab, detox, IOP, and MAT clinic running a Meta Pixel or Google Analytics on treatment-intake pages faces the same fact pattern that triggered the Monument order. The question is not whether the FTC is looking at substance use treatment centers — it is whether your client's treatment center is next.
06

Your Website Right Now

If your treatment center's website has any of these URL paths AND runs a Meta Pixel, Google Analytics, Google Ads tag, or TikTok Pixel, the tracking tool is transmitting information about what the visitor is looking for to an advertising platform:

What the pixel sends
Every page view transmits data to an outside company
When someone visits yourfacility.com/opioid-treatment, the Meta Pixel sends Facebook: the full URL (revealing what condition they are researching), their IP address (revealing approximate location), a device fingerprint (identifying the specific phone or computer), and a cookie that links this visit to their Facebook account. Google Analytics sends similar data to Google. Neither company has a Business Associate Agreement with your treatment center. Neither is authorized under Part 2 to receive this information.
What a consent banner does not fix
Cookie banners and privacy policies do not cure this problem
A cookie consent banner addresses general data-collection preferences. It does not meet the specific written consent required under 42 CFR Part 2 (which requires naming the specific recipient and specific data being shared). It does not constitute a "Valid Authorization to Sell" under Washington State's MHMDA (which requires naming the buyer, the data, the purpose, and providing a 1-year expiration with right to revoke). The banner is legally irrelevant to the claims plaintiff firms are bringing.
07

What You Can Do Now

These are concrete steps your treatment center can take to understand and begin addressing tracking-pixel exposure. None of these are legal advice — consult counsel for your specific situation.

Compliance Infrastructure Partner
APEX VAULT.
Apex Vault provides compliance infrastructure for healthcare organizations. The architecture replaces third-party tracking pixels with private, self-hosted analytics and sanitized conversion signals — preserving marketing attribution while preventing health data from reaching outside advertising platforms.
Learn more at apexvaultcompliance.com →