HomeMalware & ThreatsCVS and Criteo Reach $20.5 Million Settlement in Web Tracker Data Privacy...

CVS and Criteo Reach $20.5 Million Settlement in Web Tracker Data Privacy Lawsuit

Published on

spot_img

Class Action Suit Settled: CVS and Criteo Agree to Pay $20.5 Million Over Patient Data Breach

In a landmark decision reflecting the increasing scrutiny over data privacy in the healthcare sector, retail pharmacy giant CVS Health and digital advertising firm Criteo have reached a settlement of $20.5 million. This settlement stems from a class action lawsuit alleging that CVS unlawfully disclosed personal and health information of patients to Criteo through embedded web tracking technologies on its websites and mobile applications. The implications of this case highlight the ongoing concerns surrounding data privacy and the ethical use of technology within the healthcare industry.

The proposed class action litigation was initiated in May 2026 in a Florida state court. It contended that both CVS and Criteo had violated several laws, including the Electronic Communications Privacy Act. The lawsuit also included state statutory claims, breach of confidence, invasion of privacy, and negligence against the companies. According to court documents, the plaintiffs claimed that through the implementation of third-party tracking codes on its digital platforms, CVS enabled these trackers to eavesdrop on and unlawfully record sensitive information about patients. This included details regarding their medical conditions, immunizations, prescriptions, and searches for healthcare products, all without the patients’ consent.

The lawsuit asserted that CVS had breached its duty of confidentiality and, furthermore, had facilitated third-party trackers in unlawfully intercepting private information. The plaintiffs characterized this failure as “egregious violations” of the patients’ reasonable expectation of privacy. The ramifications of this case extend beyond the monetary settlement; they underscore the critical importance of maintaining patient confidentiality in an era where digital technologies permeate health services.

As part of the settlement, CVS and Criteo will not acknowledge any wrongdoing. Although details regarding the specific contributions of each company to the settlement fund are not revealed, the terms of the proposed settlement offer some relief to class members. Individuals eligible for the settlement include "all living individuals who accessed the CVS Digital Properties in the U.S. prior to July 27, 2026.” A final approval hearing for the settlement is scheduled for December 1, 2026.

Eligible class members can submit a valid claim to receive a cash payment of up to $5 without needing documentation, or up to $10 if they provide proof of membership in the settlement class. This proof could include third-party documentation, such as browser search history or email receipts for online purchases made through CVS’s digital platforms.

In the related context of digital privacy, this case is just one of many emerging within the healthcare sector, which has increasingly faced scrutiny over its use of web technologies. The lawsuit against CVS and Criteo follows other notable cases, including a recent settlement involving Atrium Health, which agreed to pay $1.8 million over similar allegations linked to pixel tracking codes on its patient portal. Patients in that instance claimed that sensitive information was unlawfully shared with third-party firms for marketing purposes, violating patient trust and federal regulations.

Moreover, one of the more significant settlements occurred with Kaiser Permanente, which was ordered to pay up to $47.5 million for similar claims related to the unauthorized use of web trackers across its platforms. Kaiser Permanente reported a substantial HIPAA breach affecting 13.4 million patients due to its previous use of such technologies. These cases signify a broader trend, spotlighting the ethical dilemmas faced by healthcare organizations caught in the web of digital advertising technologies that may infringe on patient privacy.

Regulatory bodies like the Federal Trade Commission (FTC) and various state regulators have ramped up actions against firms in the healthcare sector that employ tracking technologies without proper user consent. Recent actions include a lawsuit against telehealth firm Hims & Hers, indicating a more aggressive stance toward protecting consumer health information.

The growing number of lawsuits and settlements focused on data privacy within healthcare underscores the crucial need for organizations to implement robust data privacy measures. It raises essential questions about how patient data is used within the healthcare ecosystem and the ethical responsibilities of organizations entrusted with sensitive information. As technology continues to evolve, ongoing vigilance and adherence to data privacy norms will be paramount for both consumer trust and legal compliance in this ever-changing landscape of digital health.

Source link

Latest articles

16 Governance Tools to Secure Your AI Fleet

In today's rapidly evolving digital landscape, organizations implementing artificial intelligence (AI) face a myriad...

RatHat Exploits Android Wireless Debugging for Shell Access and Banking PIN Theft

New Android Banking Malware: RatHat Emerges with Advanced Threat Capabilities Recently, cybersecurity experts have unveiled...

NCSC and Allies Issue Warning on Iranian Spyware Campaign

The United Kingdom, alongside its allies, has issued a stark warning to individuals opposing...

Robinhood Engineers Indicted in $50K Crypto Fraud Case

Two engineers from Robinhood Markets have been charged with federal crimes, specifically commodities fraud...

More like this

16 Governance Tools to Secure Your AI Fleet

In today's rapidly evolving digital landscape, organizations implementing artificial intelligence (AI) face a myriad...

RatHat Exploits Android Wireless Debugging for Shell Access and Banking PIN Theft

New Android Banking Malware: RatHat Emerges with Advanced Threat Capabilities Recently, cybersecurity experts have unveiled...

NCSC and Allies Issue Warning on Iranian Spyware Campaign

The United Kingdom, alongside its allies, has issued a stark warning to individuals opposing...