Blog|Articles|September 24, 2026

The intersection of privacy, AI, data tracking and enforcement

Fact checked by: Keith A. Reynolds

A $20.5 million CVS settlement over web tracking shows how AI and data tracking without patient consent invite lawsuits and enforcement.

It is well established that patients have an expectation of privacy related to their medical records and how the information is shared. The U.S. Department of Health and Human Services (HHS) and the Federal Trade Commission (FTC), as well as states and class action attorneys, have expressed concerns about the use of data tracking technologies in violation of security and privacy considerations. At the heart of government enforcement actions and civil cases: lack of patient consent. Artificial intelligence (AI) adds another dimension.

Case in point. In September 2026, CVS Health and Criteo, a digital advertising firm, agreed to settle a class action case involving allegations that CVS unlawfully disclosed patients' personally identifiable information (PII) and individually identifiable health information (IIHI) to Criteo via web tracking technology, which was embedded in CVS websites and apps. See Alex Sisti, et al. v. CVS Pharmacy, Inc. Criteo Corp. and Medallia, Inc., Case No. CACE-26-008094, Dkt. 253 (July 24, 2026) and the related notice issued by the court on July 27, 2026.

The $20.5 million settlement will not be finalized until after the court holds the final approval hearing at 9:30 a.m. ET on Dec. 1, 2026, virtually by Zoom. At its core, the First Amended Complaint (FAC) alleged the following items, which led to the settlement:

  • "By failing to receive the requisite consent, CVS breached its duty of confidentiality and aided the third-party trackers in unlawfully intercepting plaintiff's private information."
  • "Egregious violations" of patients' "reasonable expectation of privacy."
  • Instead of adhering to the HIPAA Privacy Rule and FTC consumer protection requirements, CVS engaged in "aiding, employing, agreeing, and conspiring with Adobe, Inc. ("Adobe"), Criteo, Medallia, Quantum Metric, Inc. ("QM") (collectively, "Third-Party Trackers") and others to intercept, eavesdrop, and/or record sensitive and confidential personal and medical communications of Website users via third-party code embedded on the Website."
  • "QM's service includes many features such as data analytics, AI analysis, and session replay. Each of these features is employed by CVS on the Application and is discussed in turn."

In essence, downstream remuneration without patient or consumer consent. All patients are consumers; however, not all consumers are patients. An important distinction when implicating FTC only or HHS (coupled with potential FTC) purview.

The FAC expressly mentions "AI analysis." According to the HHS Office of the National Coordinator for Health Information Technology (ONC), AI means, "[e]nabl[ing] computer systems to perform tasks normally requiring human intelligence – for example, recognizing patterns, learning from experience, drawing conclusions, making predictions, etc." By way of contrast, "machine learning" is a subset of AI that "enables computers to learn without being programmed by humans." There is also generative AI, agentic AI and large language models, all of which fall under the broader AI umbrella.

AI raises a host of other issues with HIPAA and other laws in terms of privacy and security. Using AI for downstream remuneration or to enhance and sell packets of individuals' information, especially sensitive information, including biometrics, has caught the attention of the Texas Attorney General's Office. In July 2024, a press release was issued that Meta paid $1.4 billion to settle allegations of its unauthorized capture of personal biometric data. In sum, ensuring that the deployment of AI and tracking technology is ethical and legal is paramount, which includes data privacy and security considerations, is crucial in avoiding downstream government enforcement actions and class action lawsuits.

Rachel V. Rose, J.D., MBA, advises clients on compliance, transactions, government administrative actions and litigation involving health care, cybersecurity, corporate and securities law, as well as False Claims Act and Dodd-Frank whistleblower cases. She also teaches bioethics at Baylor College of Medicine in Houston. Rose can be reached through her website, www.rvrose.com.


Related to this article