Google and Meta must reveal internal data policies in telehealth lawsuit
A federal judge ruled that Google and Meta must proceed with discovery in a class-action lawsuit concerning their collection of health data through tracking pixels on telehealth websites. The court rejected the companies' consent defense, ruling that standard privacy policy language is insufficient for protecting sensitive health information under the California Invasion of Privacy Act.
Key Takeaways
- Court ruled that buried privacy policy language fails to meet the 'all-party consent' standard for health data under the California Invasion of Privacy Act.
- Discovery will force Google and Meta to produce internal communications regarding what they knew about sensitive health data flowing through their pixel tools.
- Technical allegations state the Facebook Pixel transmitted unique Facebook IDs alongside medication SKUs, effectively deanonymizing specific prescription choices.
- Industry-wide pixel adoption in hospitals fell from 98% in 2021 to 30% in 2025 as litigation risks and regulatory pressure intensified.
Why It Matters
The ruling shifts the legal focus from the healthcare providers who deploy pixels to the ad-tech giants that provide the underlying code. By piercing the 'consent' defense, courts are signaling that generic terms of service cannot bridge the gap between ad-supported business models and stringent health privacy mandates. For the streaming and digital media ecosystem, this case highlights the growing liability of third-party trackers in sensitive contexts and the risk of 'wiretap' claims for standard JavaScript tools. Watch for the discovery phase to reveal whether these platforms had internal flags for medical SKUs that were ignored for monetization purposes.
Additional Context
The BlueChew case is part of a broader wave of pixel-related litigation that has already cost the healthcare industry hundreds of millions of dollars. Per Paubox and ClassAction.org in June and July 2026, several health systems have reached multi-million dollar settlements, including Duke University Health System for $3.7 million and Christ Hospital for $7 million. These cases focused on the transmission of patient portal data and appointment details to social media platforms through embedded scripts. Collectively, an analysis by Feroot Security indicates the industry has paid more than $100 million in penalties and settlements since 2023. Regulators have simultaneously increased pressure on healthcare platforms and the ad-tech ecosystem. In March 2024, the Department of Health and Human Services (HHS) issued updated guidance clarifyng that sharing individually identifiable health information (IIHI) with third parties via tracking technologies generally constitutes a HIPAA violation regardless of a user’s lack of an existing relationship with the entity. This regulatory stance has been mirrored by Federal Trade Commission (FTC) enforcement; per FTC reports, platforms like BetterHelp and Cerebral paid over $20 million in combined fines between 2023 and 2024 for sharing mental health and prescription data without explicit consent. Looking ahead, the legal landscape for digital tracking continues to shift toward stricter definitions of personal data. According to reports from Cookie-Script in May 2026, the FTC has entered a new era of enforcement following the April 2026 compliance deadline for updated COPPA rules, which expanded data definitions to include neural and biometric information. As state-level privacy laws in 20 states mature, the use of tracking pixels before explicit, affirmative consent is becoming a primary target for both regulatory audits and private class-action litigation.
Read full article at techtimes.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source