PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher

Posted on July 3, 2025 by Dissent

Jennifer L. Mitchell, Taylor A. Bloom, and Danielle A. A. Richardson of Baker Hostetler write:

On July 1, the California attorney general (CA AG) announced the largest CCPA settlement to date, $1.55 million, and the first settlement against a website publisher, Healthline Media LLC (Healthline). The settlement (pending court approval) resolves allegations against Healthline, a health and wellness information website, for violating the California Consumer Privacy Act (CCPA) and the California Unfair Competition Law (UCL) and would involve novel injunctive requirements. This is the first CCPA enforcement action focused on health-related data, following years of heightened federal enforcement trends triggered by healthcare entities’ treatment and disclosure of this category of sensitive personal information.

The California Department of Justice (DOJ) investigation into Healthline was triggered by a finding that the opt-out functionality on its website was not functioning as required under the CCPA, namely that consumers could not effectively opt out of numerous behavioral advertising cookies that were allegedly used to transmit health information to third-party advertising vendors. In CA AG Rob Bonta’s press release accompanying this settlement, Bonta emphasized the DOJ’s authority under the CCPA to “fight online surveillance,” as well as the sensitive nature of the underlying data, which “could have revealed consumers’ private medical diagnosis.”

Read more at BakerHostetler.

Related posts:

  • Attorney General Bonta Announces Settlement with Sephora as Part of Ongoing Enforcement of California Consumer Privacy Act
Category: CourtFeatured NewsLawsOnlineSurveillanceU.S.

Post navigation

← Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
German court awards Facebook user €5,000 for data protection violations →

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Department of Justice Subpoenas Doctors and Clinics Involved in Performing Transgender Medical Procedures on Children
  • Google Settles Privacy Class Action Over Period Tracking App
  • ICE Is Searching a Massive Insurance and Medical Bill Database to Find Deportation Targets
  • Franklin, Tennessee Resident Sentenced to 30 Months in Federal Prison on Multiple Cyber Stalking Charges
  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher

RSS Recent Posts on DataBreaches.net

  • Avantic Medical Lab hacked; patient data leaked by Everest Group
  • Integrated Oncology Network victim of phishing attack; multiple locations affected (2)
  • HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with Deer Oaks Behavioral Health for $225k and a Corrective Action Plan
  • HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
  • Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined
©2025 PogoWasRight.org. All rights reserved.