This project started with a conversation I had in 2025 at a state-level healthcare conference. Two marketers from two different small critical access hospitals chatted together with me after I gave a presentation on how to make healthcare websites HIPAA compliant. They told me their hospitals were in adjoining rural counties and they worked together a lot. Then they let me know they wished they’d known about Sounder sooner because both of their hospitals had just been sued for having tracking pixels on their sites. They continued on, saying that all their digital marketing was on hold because of the lawsuits and neither hospital could afford this whole situation. I didn’t want to press them too much on the details and just listened to what they were willing to share.
But I was curious, so when I got home I went looking.
I found a couple of short news articles from local sources in what I figured was the area they were from. From those I was able to track down the actual case filings. And that is when it got interesting. Both hospitals, in different towns but near each other, were being sued by the same out-of-state law firm, over the same kinds of tracking pixels, with complaints that read like they came off the same template.I was really surprised to find that each suit had been filed on behalf of a single named plaintiff.
That got me wondering. If two small hospitals I happened to bump into were both being sued, how many other hospitals and clinics were in the same spot? And why wasn’t this in the news?
The answer to the second question turned out to be the reason Sounder’s lawsuit database exists. The information was out there, but it was scattered across court dockets, settlement administrator websites, law firm press pages, and the occasional trade publication. There was no single list. The big cases (Kaiser, Advocate Aurora, Mass General Brigham) got headlines. The critical access hospital in a town of 8,000 got a paragraph in the local paper, and that was it.
So we decided to build the list. Today we’re making it public, and we’re giving it away.
If you follow that link, you will see that we have found 207 lawsuits and enforcement actions (together they’re called “matters”,) filed from 2019 through September 2026. We don’t want to give the impression this is the exact number of tracking lawsuits that have been filed in the US as of September, 2026. We were able to find 207 of them. There may be more, and if you know of others, we’d love to get the information.
What’s in the database
Each row in the database is one matter (a lawsuit or an enforcement action). To keep things clear, if a health system has been sued twice, each matter has its own row and the health system/practice shows up twice.
For each matter we record:
- the defendant
- what kind of organization it is
- the court and docket number
- five key dates (filed, settlement agreement, preliminary approval, final approval, and ruling)
- the current status
- how the settlement is structured and for how much
- the estimated payment per claimant
- the digital marketing tracking tools named in the complaint
- the plaintiff law firms
- A link to the source with a note on how well we were able to verify it.
Most of these are class action lawsuits, but not all of them.

What makes a case qualify? The complaint or order has to allege that some kind of web or app tracking technology (a pixel, a tag, a software development kit, a session-replay tool, or something similar) sent health-related information to a third party. If the matter meets that test, we included it in the database. Ordinary data breaches, ransomware attacks, and lost-laptop cases are not in our data. We are focused on websites sending data to third parties.
How we built it (and how much you should trust it)
We started with a list of 86 cases that I put together by hand over the course of about a year, mostly from web searches, news coverage, and settlement websites. Then we expanded it using AI-assisted research. The AI tools dug into health system content, settlement administrator sites, and federal and state court dockets. Every case the AI research turned up was then double checked by our team.
Our sources, in order of how much we trust them:
- Court dockets and orders. The complaint, the motion to dismiss ruling, the settlement approval order. These are the gold standard.
- Settlement administrator websites. If you’ve ever received a postcard about a class action, the website on it was built by one of these companies (Simpluris, Kroll, Angeion, Epiq, and A.B. Data are the common ones). Their job is to notify everyone in the class, process the claims, and send out the payments. Their FAQ pages are often the clearest public record of what a settlement actually covers.
- Regulator press releases. The FTC, HHS Office for Civil Rights, and state attorneys general.
- Law firm and trade press coverage. We use these as leads to find a primary document, not as the final word.
Every row is tagged with a verification level. Primary means we found a court document, an administrator site, or a regulator release. Secondary means we read a reliable report but not the underlying document. Unverified means we found a credible mention and nothing more yet. As of this writing, that’s 92 Primary, 111 Secondary, and 4 Unverified.
A few definitions also keep the numbers honest, and they’re worth knowing before you use the data:
- The filing date is the date of the original complaint, not the amended one.
- A final approval hearing is not a final approval order. We wait for the order.
- Fees requested are not fees awarded.
- A claims-made cap is not a settlement fund. If a settlement says “up to $5 million,” that is not $5 million.
- The settlement amount field never holds a theoretical maximum.
That last group matters more than it sounds. A lot of the press coverage of these cases (and, frankly, a lot of the law firm press releases) report the biggest number available, which is often not verifiable or correct.
What the numbers say
Here are the big takeaways that jumped out at us.

The wave crested in 2023 with 85 filings. That followed The Markup’s investigative reporting on hospital websites in June 2022 and the HHS bulletin (since partly vacated) on tracking technologies that December. Since then it has settled into a steady 20 to 45 new cases a year. So far in 2026 we count 19, which puts this year on pace with last year. Four matters don’t have a confirmed filing date yet.

Of the 207 matters, 89 (43%) have settled, 78 (38%) are still active, 20 ended without a settlement (dismissed, withdrawn, or sent to arbitration), 11 are regulatory actions, and 6 are on appeal or were decided on appeal. That means about 40% of defendants have paid or agreed to pay, and roughly 10% got out without paying.

Of the 89 settlements, 54 are still at preliminary approval, which means a lot of the settlement money you read about hasn’t actually gone anywhere yet.

California leads with 20, then Illinois (18), Pennsylvania (12), and Massachusetts (10). This is not a map of where the hospitals are. It’s a map of where the friendliest state laws are: California’s wiretap and medical confidentiality statutes, Illinois’ long history with privacy class actions, Pennsylvania’s wiretap act, and the Massachusetts wiretap act. Forty-six matters are against national defendants (insurers, platforms, pharmacies, and agencies) with no single home state, and 10 rows still need a state assigned. Both groups are left off this chart.

Large or integrated health systems make up 26% of defendants, community hospitals 15%, and academic medical centers 12%. That’s the part you’d expect.
The interesting part is the long tail: 13 specialty practices, 11 telehealth companies, 9 public or district hospitals, 6 rural or critical access hospitals, 5 behavioral health providers, 5 fertility clinics, and 4 physician groups. This does away with the idea that only large companies or organizations are targets of lawsuits.

Meta shows up in 169 of 207 complaints (81%). Google shows up in 114 (55%). After that it drops off fast: ad-tech networks such as Criteo and The Trade Desk (20), TikTok (17), Microsoft Clarity and Bing (17), Pinterest (9), LinkedIn (8), X (7), and Snap (7). Fourteen complaints don’t name a specific tool at all. Keep in mind that most complaints name more than one vendor, so these add up to over 100%.

Among the 89 settled matters, 44 are common funds (a fixed pot of money that gets divided up) and 36 are claims-made (the defendant pays only for the claims that actually come in, usually up to a cap), with a handful of floor-and-maximum, hybrid, and voucher-only deals. This matters because only a common fund has a real total. You can’t average a claims-made cap against a common fund and get a meaningful number, which is why the next chart only uses common funds.

Forty-five common fund settlements disclose an amount. The median is $2.45 million, and half of them fall between $1.4 million and $5 million. Twenty-three of the 45 are under $2.5 million. Eight are over $10 million. The largest are the co-defendant settlements in the Flo Health case ($59.5 million from Google, Flo, and Flurry, with the case still going against Meta after the 2025 jury verdict), Kaiser Permanente ($46 million), the GoodRx private class action ($32 million), Sutter Health ($21.5 million), and Mass General Brigham ($18.4 million). Claims-made caps and civil penalties are intentionally left out of this chart.

Forty-seven settlements disclose an estimated or actual cash payment per person. The median is $20. The range is $10 to $90, and 79% pay under $30. You can draw your own conclusions from this, and I will write a blog post soon with my thoughts.
How to use it and how to cite it
The table lets you filter by matter type, provider type, tracker, status, state, plaintiff firm, and which parts of the website were involved (public pages, patient portal, or both). You can sort on any of the columns. After you have filtered the information how you like, you can download the data as a CSV.
The whole dataset is published under a Creative Commons Attribution 4.0 license (CC BY 4.0). That means you can use it, copy it, build on it, and publish from it, for free, as long as you say where it came from “SounderData healthcare web-tracking lawsuit database, [URL], accessed [date].”
If you find a mistake or a case we missed, please tell us at info@sounderdata.com. We keep a watch list, and we’d rather hear about a missing case from you than read about it six months from now. We plan to update the database quarterly.
What this database is not
Our database is not legal advice. I’m a digital marketer who has chosen to read a lot of court filings. I am definitely not a lawyer.
We also do not believe it is a complete census. We are sure we have most of the cases that have been publicly reported anywhere. However we are also confident there are some we haven’t found yet.
Lastly, the database is not a scorecard of who is compliant and who isn’t. A named defendant is an allegation, not a finding. Remember, quite a few of these cases have been dismissed.
Why we’re giving it away
The two marketers who started this whole project didn’t have anywhere to look for this type of information. It couldn’t be found in industry publications, and it couldn’t be found in the popular press. They found out about the risk when the lawsuit dropped and their hospitals’ lawyers told them to take all tracking off the website immediately. If this database means one clinic administrator or one hospital marketing director looks up their state, sees a pattern, and fixes their website before a law firm finds them, that’s a good outcome for everyone except the law firm. And we are fine with that!
If you’d like to know whether your own site has the kind of tracking that landed these websites in our database, we can tell you in a few minutes with a free scan.
This post is based on publicly available court records and industry reporting. It is for informational purposes only and is not legal advice. Consult qualified legal counsel about your organization’s specific obligations.



