Client Advisory · Tracking-Technology Exposure · Substance Use Treatment
What every treatment center needs to know about the tracking pixels on their website
A plain-language guide to the lawsuits, settlements, and federal rules that affect substance use disorder treatment centers running advertising pixels on their websites. Prepared by your marketing agency to help you make informed decisions about your digital presence.
Settled So Far
$152M+
Healthcare pixel settlements 2022–2026
Lawsuits Filed in 2024
~4,000
Up from ~200 in 2023 · 1,900% growth
Unique Defendants
3,512
Across 45 states + DC · 315 courts
Breach Risk Increase
46%
Hospitals with third-party pixels · Rutgers 2026
Data-Privacy Class Actions Filed Per Year
Source: Duane Morris Class Action Review 2026 (consistent methodology, court-filed class actions)
The Iceberg Below the Chart
The bars above count class actions filed in court only. A separate Stinson LLP analysis found nearly 4,000 total tracking-technology claims in 2024 when including demand letters, arbitration filings, and pre-litigation notices — roughly 2.5x the class-action-only count. The visible docket is the tip. Demand letters that never reach a courtroom are the bulk of the enforcement activity, and those are not captured in any public filing database.
Methodology. 2022–2025 figures from Duane Morris LLP Class Action Review 2026: 1,822 data-privacy class actions filed in 2025 (18% over 2024, 200%+ over 2022). 2024 and 2022–2023 back-calculated from reported growth rates. 2026 projected at 150+/month pace (matching 2025 reported rate); YTD solid fill represents ~750 filings through May 2026. Troutman Pepper separately tracked 197 ECPA-specific complaints in 7 months (Sept 2025–Mar 2026) at 2–4x prior-year rate, suggesting the actual 2026 pace may exceed the 2025 baseline.
Total Claims (2024)
~4,000
Statutory Damages · Per Violation
California's wiretap statute (CIPA) allows $5,000 per violation with no requirement to prove actual damages. Multiply by call volume and it becomes existential.
Under Cal. Penal Code § 637.2(a)(1), any person injured by a CIPA violation may recover the greater of $5,000 per violation or three times actual damages. Critically, subsection (c) states: “It is not a necessary prerequisite to an action pursuant to this section that the plaintiff has suffered, or be threatened with, actual damages.” This means every single page view where a pixel fires on a health-intent URL is a separate violation with a $5,000 statutory floor — regardless of whether anyone was actually harmed. For a treatment center website receiving 10,000 monthly visits to condition-specific pages, that is $50 million in potential statutory exposure per month. Separately, the federal ECPA (Wiretap Act) carries statutory damages of $10,000 or $100 per day of violation, whichever is greater — and can be filed in any state.
What the numbers mean
This is no longer a tail risk. Nearly 4,000 tracking-technology privacy lawsuits were filed in 2024 — up from just over 200 in 2023. The plaintiff bar has named 3,512 unique defendants across 45 states.
According to a January 2026 analysis by Stinson LLP, lawsuits related to online tracking privacy increased approximately 1,900% in a single year (2023 to 2024). Over the three-year period 2023–2025, plaintiff firms filed tracking-technology claims in 315 courts across 45 states plus the District of Columbia, targeting 3,512 unique defendants. A separate Duane Morris Class Action Review found that 1,822 data-privacy class actions were filed in 2025 alone — an average of more than 7 filings per business day — representing 18% growth over 2024 and 200%+ growth since 2022. A peer-reviewed Rutgers study (PNAS Nexus, May 2026) found that 66% of U.S. hospitals deploy the same third-party tracking pixels driving these lawsuits, and those hospitals are 46% more likely to experience a data breach. First-party analytics (where data stays in your own systems) show no breach correlation. The technology is not the problem. Sending the data to outside companies is.
Filing rate still accelerating. An analysis by Troutman Pepper Locke tracked 197 federal ECPA wiretap complaints filed between September 2025 and March 2026 — a rate two to four times higher than the same months the prior year. Washington State's My Health My Data Act adds a private right of action, meaning plaintiffs do not need a regulator to sue — they file directly. Treatment centers carrying 42 CFR Part 2 obligations face the highest per-violation statutory exposure of any healthcare vertical.
Sources. Stinson LLP, “A New Era of Comprehensive Privacy Laws and the Surge in Data Privacy Litigation: Important Updates for 2026,” JD Supra, Jan. 26, 2026. Duane Morris LLP, Class Action Review 2026 (Trend #6: Data Breach Filings Continued to Grow). Troutman Pepper Locke, “The ECPA: A Federal Private Right of Action for Privacy Policy Inaccuracies?,” Apr. 28, 2026. Rutgers Business School, PNAS Nexus, May 2026. Cal. Penal Code § 637.2 (CIPA statutory damages). 18 U.S.C. § 2520 (ECPA statutory damages).
02
What Makes Treatment Centers Different
The Part 2 Problem
Substance use disorder treatment records carry stricter federal protections than standard medical records. Most treatment centers do not realize their website tracking violates those protections.
Under a federal rule called 42 CFR Part 2, substance use disorder treatment records are protected even more strictly than regular HIPAA-protected health information. Part 2 was originally written to encourage people to seek treatment without fear that their records would be shared with employers, insurers, or law enforcement.
What this means for your website: When a prospective patient visits a treatment center's website and views pages like /detox, /rehab, /treatment, /addiction, or /suboxone, the URL itself reveals they are seeking substance use treatment. If a Meta Pixel or Google Analytics tag is running on that page, it transmits that URL — along with the visitor's IP address and device information — to Facebook or Google servers. Under Part 2, that transmission is an unauthorized disclosure of substance use treatment information to a third party who has no right to receive it.
This is not just a HIPAA problem. This is a HIPAA problem plus a Part 2 problem plus a state-law problem. Treatment centers carry more layers of legal exposure than almost any other type of healthcare provider.
Treatment centers face five layers of legal exposure from a single tracking pixel:
42 CFR Part 2 — Substance Use Confidentiality
Strictest
HIPAA — Health Information Privacy
Federal
State Consumer Health Privacy (e.g., WA MHMDA)
State CHP
State Wiretap Statutes (e.g., CIPA, IL Eavesdropping)
State
FTC Act / Health Breach Notification Rule
Federal
Why the stacking matters. A standard healthcare provider might face two or three of these layers. A substance use treatment center faces all five simultaneously. Each layer has its own enforcement mechanism — some through private lawsuits, some through state attorneys general, some through federal agencies. A single tracking pixel on a single page can trigger liability under all five at once.
05
Cases That Set the Benchmark
These are the settlements and enforcement actions that define the financial reality. Treatment centers are in the same category as these defendants — the same tracking tools, the same legal theories, the same plaintiff firms.
| Who was sued |
Category |
Settlement |
What happened |
| Kaiser PermanenteCalifornia · Dec 2025 |
Health system |
$46.0M |
Meta Pixel on patient portal transmitted patient names, appointment data, and search terms to Facebook. Largest healthcare tracking settlement on record. |
| Adena Health SystemOhio · 2026 |
Regional nonprofit |
$17.8M |
Meta Pixel and Google Analytics on patient portal. 89,000 patients. Approximately $200 per affected patient — one of the highest per-person settlement rates. |
| BetterHelpFTC enforcement · 2023 |
Mental health |
$7.8M |
Meta Pixel transmitted users' mental-health intake answers (anxiety, depression, suicidal ideation) to Facebook for ad targeting. Permanent ban on health-data sharing. |
| CerebralFTC enforcement · 2024 |
Mental health |
$7.0M |
Meta Pixel and TikTok pixel disclosed mental-health information of 3.2 million users. Permanent ban. Tied to stimulant-prescribing controversies. |
| MonumentFTC enforcement · 2024 · TOTAL BAN |
Alcohol use disorder |
$2.5M |
PERMANENTLY BANNED from sharing ANY health data with ANY third party for advertising — not even sanitized conversion signals. Monument's entire attribution pipeline was killed. No pixel, no CAPI, no hashed data, no anonymized events. The FTC did not give Monument the option to remediate and continue — the order is a total, permanent prohibition. This is the FTC's template for substance use treatment platforms. |
| GoodRxFTC + DOJ · 2023 |
DTC pharmacy |
$1.5M |
First-ever FTC Health Breach Notification Rule enforcement. Facebook Pixel shared medication data for advertising. Falsely displayed HIPAA seal on website. |
| Shields Health Care GroupMassachusetts · 2024 |
Health system |
$15.35M |
Imaging-services provider. Meta Pixel on appointment and portal pages. Massachusetts wiretap statute + consumer protection (treble damages). |
| Advocate Aurora HealthWisconsin · 2024 |
Health system |
$12.3M |
Self-disclosed Meta Pixel breach affecting 3 million patients. The case that started the wave in 2022. |
| Duke University Health SystemNorth Carolina · 2026 |
Academic med center |
$3.74M |
Pixels on MyChart patient portal AND mobile app. 872,634 affected patients. Both web and app tracking vectors addressed. |
| Premom (Easy Healthcare)FTC + 3 state AGs · 2023 |
Health app |
$200K |
Ovulation and menstrual data shared with China-based companies via SDKs. First case where device identifiers (IMEI) were ruled identifiable health information. |
Why Monument Is the Case Your Clients Need to Understand
Monument did not lose a lawsuit. They were ordered by the FTC to permanently stop sending ANY health data to ANY advertising platform. Their attribution pipeline is gone. Not reduced — gone.
Monument was an alcohol-use-disorder telehealth platform — the closest publicly-settled analog to a residential rehab, detox, IOP, or MAT clinic. The FTC found that Monument shared substance-use treatment data to Meta and Google via tracking pixels despite privacy-policy promises not to.
The FTC's order is a permanent, total ban on sharing health data for advertising purposes. Not "fix your consent flow and you can continue." Not "sanitize the data first." Not "use a server-side API instead of a pixel." The order prohibits any sharing of health information with any third party for advertising — period. Monument's entire ad-attribution pipeline was killed. They cannot run Meta ads with conversion tracking. They cannot run Google Ads with conversion tracking. They cannot send even anonymized, sanitized, or hashed conversion events to any advertising platform. Their digital marketing capacity was permanently crippled.
This matters because of how FTC enforcement works. When a class-action plaintiff sues your client in court, the treatment center can fight back — file motions to dismiss, challenge standing, negotiate a settlement, appeal a ruling. There is a process. When the FTC comes after your client, the dynamic is fundamentally different. The FTC is an administrative agency with its own in-house judges (Administrative Law Judges). The agency investigates, the agency prosecutes, and the agency's own judges decide the case. There is no jury. The burden of proof is lower. The defendant's ability to fight is structurally limited compared to a courtroom. The FTC can issue consent orders (like Monument's) that impose permanent behavioral restrictions — and violating a consent order carries civil penalties of up to $50,120 per violation per day.
The FTC has publicly stated that substance use treatment is an enforcement priority. BetterHelp ($7.8M), Cerebral ($7M), and Monument ($2.5M) were settled within 14 months of each other. The agency is not slowing down. Every residential rehab, detox, IOP, and MAT clinic running a Meta Pixel or Google Analytics on treatment-intake pages faces the same fact pattern that triggered the Monument order. The question is not whether the FTC is looking at substance use treatment centers — it is whether your client's treatment center is next.
Compliance Infrastructure Partner
APEX VAULT.
Apex Vault provides compliance infrastructure for healthcare organizations. The architecture replaces third-party tracking pixels with private, self-hosted analytics and sanitized conversion signals — preserving marketing attribution while preventing health data from reaching outside advertising platforms.
Learn more at apexvaultcompliance.com →