If you run the Meta Pixel on a healthcare website, you’re almost certainly sharing patient data with Facebook. That’s exactly what’s landed hospital after hospital in court. The Pixel is Meta’s tracking code, and on a healthcare site it can quietly send protected health information (PHI) to Meta without a patient ever knowing. Meta won’t sign a Business Associate Agreement (BAA), so there’s no compliant way to hand it that data. The result has been a steady stream of class-action lawsuits and multi-million-dollar settlements.
We, at Sounder, know how frustrating that is to hear. The Meta Ads is one of the most effective advertising platforms ever built, and for a healthcare practice trying to fill its schedule, walking away from it feels like walking away from reliable patient acquisition. You can compliantly run Meta Ads, but not with the standard setup using their Pixel.
So let’s unpack what’s really going on: what the Pixel sends, why it keeps triggering lawsuits, where the regulators stand, and, the part we care about most, how you can keep advertising on Meta without putting your patients or your practice at risk.
Why Is the Meta Pixel a HIPAA Problem?
It comes down to the same document that trips up so many marketing tools: the BAA. HIPAA only lets you share PHI with a vendor that has signed a Business Associate Agreement agreeing to protect it. Meta does not sign BAAs for its Pixel. So the moment the Meta Pixel transmits anything that qualifies as PHI, you’ve made an unauthorized disclosure.
And PHI is a much wider net than most people expect. It isn’t just names and record numbers: there are 18 different identifiers, including IP addresses and condition-revealing URLs, that can turn ordinary web data into PHI once it’s tied to someone seeking care. The Meta Pixel scoops up several of those automatically. (If you want the fuller picture of where the line sits, our guide to what constitutes a HIPAA violation on a website walks through it.)
On a healthcare site, the Meta Pixel doesn’t need a patient to type their name to create a violation. A single visit to the wrong URL, tied to a Facebook cookie, and through it to a real Facebook or Instagram account, can be enough.
Why Are Healthcare Sites Getting Sued Over It?
Because plaintiffs’ attorneys have realized just how common this is, and how well-documented. Once you know the Meta Pixel is on a patient portal or an appointment page, the disclosure is right there in the network traffic. That’s turned into a wave of class actions, and the settlements are not small:
- Advocate Aurora Health agreed to a $12.225 million settlement after allegedly disclosing the information of more than 2.5 million people to Meta and Google through tracking pixels on its website and patient portal.
- Novant Health settled for $6.6 million over a Meta Pixel that allegedly shared the data of roughly 1.3 million patients with Facebook.
- Duke Health reached a $3.7 million settlement over similar allegations.
- Closer to home for Sounder, The Christ Hospital in Cincinnati (where we have an office) settled for a reported $4.5–7.0 million. It’s one of the cases that kicked off our warning that the HIPAA lawsuit avalanche is coming.
There’s also a massive consolidated case, In re Meta Pixel Healthcare Litigation, currently (2026) moving through federal court in California. Plaintiffs there say they’ve identified hundreds of hospital systems and provider web properties sending patient data to Meta. In 2025 the court even ordered Mark Zuckerberg to sit for a limited deposition. This isn’t a fringe issue affecting a handful of careless organizations; it’s the standard Meta setup, running on a huge share of healthcare websites.
Here’s the part that should get every practice’s attention: the size of your organization doesn’t protect you. Law firms filing these suits don’t need a regulator to act first, and a small practice with the Meta Pixel on its scheduling page carries the same core exposure as a 27-hospital system.
It’s Not Just Lawsuits: Regulators Are Watching Too
Even setting the class actions aside, two federal agencies have made their position clear.
The HHS Office for Civil Rights (OCR) issued guidance on online tracking technologies stating that sending PHI to third parties like Meta requires a HIPAA authorization or a BAA. OCR and the FTC then jointly warned roughly 130 hospitals and telehealth providers specifically about the Meta Pixel and Google Analytics.
The FTC has also gone after companies directly, and there’s now a clear pattern:
- GoodRx (2023): a $1.5 million penalty in the FTC’s first-ever Health Breach Notification Rule enforcement action, for sharing users’ health information with Facebook and Google.
- BetterHelp (2023): $7.8 million returned to consumers, plus a ban on sharing health data with advertisers, over information allegedly shared with Facebook, Snapchat, and others.
- Cerebral (2024): more than $7 million, tied to the data of nearly 3.2 million consumers disclosed to third parties through tracking technologies on its site and apps.
- Monument (2024): banned from disclosing health information for advertising.
What the FTC’s Hims & Hers Lawsuit (2026) Means for Your Website
The most recent case is also the clearest warning yet, and website tracking sits right at the center of it.
In July 2026, the FTC, joined by Utah and California, sued telehealth company Hims & Hers, alleging it shared consumers’ sensitive health information about their medical conditions with third-party advertising platforms including Meta, despite promising to protect patient privacy. (The complaint covers billing and cancellation practices too, but the data-sharing allegations are what should concern every healthcare marketing department.)
The mechanism should sound extremely familiar. Per the complaint, Hims shared health information two ways:
- by handing lists of certain customers directly to those platforms
- through third-party tracking technologies that automatically shared “Events” (the actions visitors took on the Hims website) with the ad platforms.
Reporting on the complaint also notes trackers from a whole host of platforms beyond Meta: Snap, Microsoft, Pinterest, Reddit, and X among them. In other words, this wasn’t one rogue script. It was an ordinary marketing stack doing what marketing stacks do. (Hims & Hers calls the claims “baseless” and says it will defend itself; as the FTC notes, the case will be decided by the court.)
Read that description again and notice how ordinary it is: a tracker on the site, firing automatically, reporting what visitors did. That’s not an exotic misconfiguration by a careless company. That’s the default setup on an enormous number of healthcare websites, and quite possibly yours.
This isn’t isolated to Hims & Hers, it’s widespread
We don’t have to guess at how widespread this is. A 2023 study published in Health Affairs found that nearly all U.S. non-federal acute care hospital websites contained third-party trackers. Nearly all of them. More sobering still, research published in PNAS Nexus found that hospitals using third-party tracking pixels were 46% more likely to experience a data breach.
So if you’re reading this thinking “surely we’re not doing that,” the odds are honestly not in your favor. And that’s not a knock on your team. These trackers get added by marketers, agencies, and platform wizards doing exactly what the documentation tells them to do. The tooling makes it easy; nobody warns you it’s a HIPAA problem.
The through-line from Washington is consistent, and getting louder: sharing health data with ad platforms without consent is not a gray area.
“But We Need Meta Ads to Fill Our Schedule.” Can We Run Them Compliantly?
Yes, and this is the part we most want you to hear. The goal was never to make you abandon Meta, TikTok, or LinkedIn. It’s to make sure PHI never reaches them in the first place, while the useful conversion signal still gets through.
That’s exactly what Sounder’s HIPAA-Compliant Analytics & Ads is built to do. Instead of letting the raw Meta Pixel fire straight from a patient’s browser to Meta, Sounder routes your tracking data through a HIPAA-compliant server that strips the problematic data first. The clean, PHI-free conversion signal goes out to Meta (and TikTok, and LinkedIn, etc.); the protected health information never does. So you can keep optimizing your Meta, TikTok, and LinkedIn campaigns, without the liability that has cost other providers millions.
How Do I Know If the Meta Pixel Is on My Site Right Now?
Honestly, if you’ve ever run Facebook or Instagram ads, there’s a good chance it’s there, and possibly on pages you’d never want it, like your scheduler or patient portal. The reassuring news is you don’t have to guess.
Run a free HIPAA website scan. It checks your pages in a few minutes for the Meta Pixel and other trackers that put PHI at risk, with no commitment and no sales pressure.
Frequently Asked Questions
Is the Meta Pixel HIPAA compliant?
No. Meta will not sign a Business Associate Agreement (BAA) for the Meta Pixel, so there is no compliant way to send it protected health information. On a healthcare website, the Meta Pixel routinely transmits data that qualifies as PHI, making it a HIPAA risk.
What patient information does the Meta Pixel collect?
By default it can capture the pages and URLs a visitor views (including condition-specific ones), button and form interactions, IP address, device details (fingerprinting data), and Meta cookies that link the activity to a person’s Facebook or Instagram account.
Why are hospitals being sued over the Meta Pixel?
Class-action lawsuits allege that hospitals disclosed patients’ protected health information to Meta without consent by running the Meta Pixel on their websites and patient portals. Settlements have included $12.225 million (Advocate Aurora Health), $6.6 million (Novant Health), and $3.7 million (Duke Health).
Has the FTC taken action over health data and tracking pixels?
Yes, repeatedly. The FTC fined GoodRx $1.5 million in its first Health Breach Notification Rule case, secured $7.8 million from BetterHelp, and reached a $7 million-plus settlement with Cerebral over data from nearly 3.2 million consumers. In July 2026, the FTC and state partners sued telehealth company Hims & Hers, alleging it shared consumers’ health information with advertising platforms including Meta through tracking technologies on its website. That case is ongoing.
How common are tracking pixels on hospital websites?
Very. A 2023 Health Affairs study found that nearly all U.S. non-federal acute care hospital websites contained third-party trackers. Research in PNAS Nexus also found that hospitals using third-party tracking pixels were 46% more likely to experience a data breach.
Can a small practice get sued over the Meta Pixel?
Yes. Plaintiffs’ attorneys don’t need a regulator to act first, and a small practice using social media pixels on its scheduling or contact pages carries the same core HIPAA exposure as a large hospital system.
Can I still advertise on Facebook and Instagram as a healthcare provider?
Yes, if PHI never reaches Meta. You can keep running and optimizing ads compliantly by using a HIPAA-compliant, server-side setup like Sounder’s that strips protected health information before forwarding the “clean” conversion signal to Meta.
How do I check whether the Meta Pixel is on my website?
Run a website scan that inspects your pages for tracking code. Sounder’s free HIPAA website scan checks in a few minutes for the Meta Pixel and other trackers that put PHI at risk.
Reviewed for HIPAA accuracy by the Sounder compliance team. Sounder is a Pilot company helping healthcare organizations keep their marketing data while staying compliant. This article is for informational purposes and is not legal advice.
Worried the Pixel is already on your site?



