
The intersection of privacy, AI, data tracking and enforcement
A $20.5 million CVS settlement over web tracking shows how AI and data tracking without patient consent invite lawsuits and enforcement.
It is well established that
Case in point. In September 2026, CVS Health and Criteo, a digital advertising firm, agreed to settle a class action case involving allegations that CVS unlawfully disclosed patients' personally identifiable information (PII) and individually identifiable health information (IIHI) to Criteo via web tracking technology, which was embedded in CVS websites and apps. See Alex Sisti, et al. v. CVS Pharmacy, Inc. Criteo Corp. and Medallia, Inc., Case No. CACE-26-008094, Dkt. 253 (July 24, 2026) and the related
The $20.5 million settlement will not be finalized until after the court holds the final approval hearing at 9:30 a.m. ET on Dec. 1, 2026, virtually by Zoom. At its core, the First Amended Complaint (FAC) alleged the following items, which led to the settlement:
- "By failing to receive the requisite consent, CVS breached its duty of confidentiality and aided the third-party trackers in unlawfully intercepting plaintiff's private information."
- "Egregious violations" of patients' "reasonable expectation of privacy."
- Instead of adhering to the HIPAA Privacy Rule and FTC consumer protection requirements, CVS engaged in "aiding, employing, agreeing, and conspiring with Adobe, Inc. ("Adobe"), Criteo, Medallia, Quantum Metric, Inc. ("QM") (collectively, "Third-Party Trackers") and others to intercept, eavesdrop, and/or record sensitive and confidential personal and medical communications of Website users via third-party code embedded on the Website."
- "QM's service includes many features such as data analytics, AI analysis, and session replay. Each of these features is employed by CVS on the Application and is discussed in turn."
In essence, downstream remuneration without patient or consumer consent. All patients are consumers; however, not all consumers are patients. An important distinction when implicating FTC only or HHS (coupled with potential FTC) purview.
The FAC expressly mentions "AI analysis." According to the HHS Office of the National Coordinator for Health Information Technology (ONC),
AI raises a host of other issues with HIPAA and other laws in terms of privacy and security. Using AI for downstream remuneration or to enhance and sell packets of individuals' information, especially sensitive information, including biometrics, has caught the attention of the Texas Attorney General's Office. In July 2024, a press release was issued that
Related to this article








