PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Novant Health Settles $6.6 Million Pixel Privacy Breach Lawsuit

Posted on January 17, 2024 by pogowasright.org

Steve Alder writes:

Novant Health has agreed to settle a class action lawsuit that stemmed from its use of tracking pixels on its MyChart patient portal. The pixel code on the patient portal collected the personally identifiable information of users with the goals of “improving access to care through virtual visits and to provide increased accessibility to counter the limitations of in-person care,” however the information collected was also transferred to third-party technology companies that were not authorized to receive the data.

The North Carolina Health System was the first healthcare provider to report a pixel-related HIPAA violation to the HHS Office for Civil Rights (OCR).

Read more at HIPAA Journal.

The problem of tracking pixels was first revealed publicly by The Markup in June 2022.  Novant was one of the hospital systems that The Markup reported on specifically in that piece. Novant’s disclosure to HHS was in August 2022. Since then, HHS published guidance in December of 2022, and other entities have also self-reported trackers.

But it is not just HHS OCR and class action lawyers who have been pursuing entities over this. Last month, NYS Attorney General James secured $300,000 from NewYork-Presbyterian Hospital over the trackers issue.

Category: BreachesBusinessHealthcareLawsSurveillanceU.S.

Post navigation

← Each Facebook User is Monitored by Thousands of Companies
How a 27-year-old busted the myth of Bitcoin’s anonymity →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

RSS Recent Posts on DataBreaches.net

  • CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
  • Montana Attorney General launches investigation into Lee Enterprises data breach
  • AT&T gets preliminary approval for $177 million data breach settlement
  • Aflac notifies SEC of breach suspected to be work of Scattered Spider
  • Former JBLM soldier pleads guilty to attempting to share military secrets with China
©2025 PogoWasRight.org. All rights reserved.