PogoWasRight.org

Menu
  • About
  • Privacy
Menu

California Attorney General Announces $1.55M CCPA Settlement with Healthline.com

Posted on July 29, 2025 by Dissent

Libbie Canter, Lindsey Tonsager, Olivia Vega, Natalie Maas, and Bryan Ramirez of Covington and Burling write:

On July 1, 2025, California Attorney General Bonta announced a $1.55 million settlement, pending court approval, related to allegations that Healthline.com, a website where consumers can read informational articles about medical and health topics, violated the California Consumer Privacy Act (“CCPA”) and the California Unfair Competition Law.

As summarized in the complaint and proposed settlement, the AG alleges Healthline committed the following violations:

  • Failed to Honor Consumer Opt-Outs of Sell or Share for Targeted Advertising. The AG alleges that even after Healthline readers exercised their right to opt out of the sale or sharing of their personal information for targeted advertising, Healthline continued to transmit identifying data to Healthline’s advertising partners for such purposes. The complaint alleges that Healthline misconfigured one opt-out mechanism and failed to test whether it worked. After being contacted by the AG, Healthline reported that its “privacy compliance vendor may not have properly identified and blocked all relevant online trackers after the vendor detected that a consumer had opted out.” Earlier this year, the AG’s Office published a press release reminding businesses and consumers about the right to opt out.
  • Violated the CCPA’s Purpose Limitation Principle. Under the CCPA’s purpose limitation principle, businesses are restricted to processing personal information for the purposes for which the data was collected (or for a compatible purpose). The AG alleges that Healthline violated this principle by disclosing article titles that suggested a possible medical diagnosis (e.g., “Newly Diagnosed with HIV? Important Things to Know.”) with advertisers and their vendors, which these recipients could add to their consumer profiles. The AG alleges that Healthline’s privacy policy did not indicate that Healthline would share article titles and that consumers would not reasonably expect that those titles were being shared.
  • Failed to Maintain Contracts with Third Parties that Contain CCPA-Required Terms. After reviewing Healthline’s contracts with advertising companies, the AG found that many of those contracts did not contain CCPA-mandated terms.
  • Deceived Consumers about their Ability to Disable Tracking Cookies. Healthline’s cookie banner allowed users to select a “more information” link where consumers could uncheck the box that allowed targeted/advertising cookies. However, the AG alleges that Healthline’s cookie banner deceived consumers because it purported to allow users to disable cookies but failed to do so in practice.

Read more at Inside Privacy.

Related posts:

  • Attorney General Bonta Announces Settlement with Sephora as Part of Ongoing Enforcement of California Consumer Privacy Act
Category: BusinessLawsOnlineU.S.

Post navigation

← Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance
White House ordered to restore Medicaid funding to Planned Parenthood clinics →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
  • Oh Great, Smart Glasses That Record Everything You Say
  • CBP Agents Held This U.S. Citizen for Hours Until He Agreed To Let Them Search His Electronic Devices
  • U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
  • ANNOUNCEMENT: EFF Launches Age Verification Hub as Resource Against Misguided Laws
  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend

RSS Recent Posts at DataBreaches.net

  • Virginia Urology Silent on Possible Data Breach as Purported Patient Data Begins to Leak
  • Village of Golf Manor considering paying ransom amid cyberattack (1)
  • Teen who allegedly stole millions of personal data records arrested in Spain
  • Akira ransomware: FBI tallies 250 million in payouts
  • IE: HSE confirms second ransomware attack but ‘no evidence’ patient data was stolen
©2025 PogoWasRight.org. All rights reserved.