Banner Health and LifeStance Settle Tracking-Tech Lawsuits
July 31, 2026
On this page
Ready to be survey-ready?
What the Banner Health and LifeStance settlements mean for your compliance program
Two health systems just paid to make website tracking lawsuits go away, and every compliance officer should treat that as a prompt to open their own website in an incognito window and see what fires. Banner Health and LifeStance Health Group agreed to settle class actions over their use of pixels and other website tracking tools that plaintiffs said sent patient information to Meta and Google without consent. This is not a data breach story. It is a consent, disclosure, and vendor-management story.
The specifics are worth knowing. The Banner settlement covers roughly 1,028,000 people who logged into a Banner patient account between June 1, 2020 and November 22, 2023, and the tracking tools were alleged to have disclosed sensitive information to Meta Platforms (Facebook) and Google LLC. On the behavioral health side, LifeStance agreed to pay $3,027,874.44 to settle a class action alleging it used third-party tracking pixels on its public website to collect and disclose personal patient information to third parties without authorization. If your organization runs a patient portal, an online scheduler, or a symptom checker, the operational question is simple: do you know every script running on those pages, and can you prove it?
Why behavioral health carries extra exposure here
Behavioral health data is not the same as a lab result for a sprained ankle, and juries know it. LifeStance runs around 600 locations with more than 5,200 therapists and psychiatrists treating conditions like depression, PTSD, and bipolar disorder, and the information allegedly sent to Meta and Google was not just names and emails, but signals tied to mental health treatment itself, including appointment bookings, page visits, and Facebook IDs that could be traced back to a real person. That is the reputational multiplier that pushes settlements higher and makes plaintiffs’ counsel more motivated.
The legal theories are broad. The LifeStance lawsuit asserted claims for violation of the California Invasion of Privacy Act, California Confidentiality of Medical Information Act, Electronic Communications Privacy Act, California Unfair Competition Law, Arizona Consumer Fraud Act, New York General Business Law, and common law invasion of privacy. Plaintiffs are not waiting for OCR to act. They are stacking state wiretap statutes, consumer protection laws, and common-law privacy torts on top of HIPAA. If you serve behavioral health patients across multiple states, your risk profile stretches to every one of those state laws, not just federal rules.
What the OCR guidance still says, and what a court threw out
Federal guidance on this is live, but partially clipped. HHS-OCR reiterates that covered entities and business associates must comply with the HIPAA privacy, security and breach notification rules when using third-party online tracking technologies to collect and analyze ePHI, and regulated entities are prohibited from using tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking vendors or others, including disclosures for marketing purposes, without an individual’s HIPAA compliant authorization. OCR also reminds covered entities that they may only disclose health information to digital tracking vendors who first sign a business associate agreement.
A Texas court then narrowed one piece of that. The court vacated the guidance to the extent it provides that HIPAA obligations are triggered in “circumstances where an online technology connects (1) an individual’s IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers,” and HHS is evaluating its next steps. Read the room, though. The court trimmed the unauthenticated-page theory. It did not touch authenticated portals, scheduling tools, or symptom checkers where a patient identity is already tied to the session. That is exactly where Banner and LifeStance got hit. And on July 20, 2023, HHS OCR and the FTC sent a joint letter to approximately 130 hospital systems and telehealth providers warning them of their obligations to comply with the HIPAA rules when using tracking technology. Enforcement attention has not gone away.
The operator playbook: what compliance officers should audit this quarter
Here is the practical work. First, inventory every tracking script on every patient-facing property. Marketing teams add pixels for campaign attribution. Analytics teams add tags for A/B testing. IT adds monitoring scripts. Nobody keeps a single list. Ask your web team to pull a full tag inventory from your tag manager and pair it with a live scan of each domain, then map every third party receiving data against your business associate agreements. If a vendor is receiving anything that could be tied back to a patient and does not have a signed BAA, that is your Monday morning conversation.
Second, tighten the pages that matter most. Patient portals. Online scheduling. Provider directories filtered by condition. Behavioral health intake forms. These are the pages where pixel exposure creates the biggest liability. Third, review your Notice of Privacy Practices and your online consent language against what the site actually does. If your NPP says you do not share PHI for marketing and your Meta pixel is firing on an appointment confirmation page, the two are in conflict. Fourth, run a documented risk analysis specifically for tracking technologies and keep the artifact. Fifth, look at your incident and grievance queues. Patient complaints about targeted ads after a portal visit are often the first signal, and they should route straight into your compliance workflow with the same seriousness as any other privacy incident. In AccrediCulture, we help operators keep this kind of vendor inventory, BAA tracking, policy versioning, and grievance intake in one place so the audit trail exists before anyone asks for it.
Frequently asked questions
Does the Texas court ruling mean my organization can go back to using pixels freely?
No. The ruling narrowed one specific theory tied to unauthenticated public pages and IP addresses. Authenticated portals, logged-in scheduling tools, and any page where a patient identity is already established are still squarely within HIPAA analysis. State wiretap and consumer protection claims, which drove much of the Banner and LifeStance litigation, were not affected at all.
What did LifeStance actually agree to change going forward?
LifeStance denies doing anything wrong, settled anyway, and agreed to stop using non-HIPAA-compliant tracking pixels on its website for five years. That is the practical injunctive floor other plaintiffs’ firms will point to when they negotiate future settlements.
What is the fastest way to reduce exposure without shutting down analytics entirely?
Move analytics behind authentication walls only when necessary, use server-side tagging for anything patient-related, execute BAAs with any vendor touching identifiable data, and strip PHI at the source rather than trusting a vendor to filter it downstream. Then document the decisions. Your defense in a future lawsuit is the paper trail you built before the complaint was filed.
Where should this work live inside a compliance program?
Treat tracking technology as a joint responsibility across compliance, privacy, IT, and marketing, with compliance owning the register of vendors, BAAs, and risk assessments. A single source of truth beats four spreadsheets in four departments every time a surveyor or a plaintiff’s attorney asks who approved what.
References
- HIPAA Journal: Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits
- HHS Office for Civil Rights: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
- Official Settlement Website: McCulley, et al. V. Banner Health
- Official Settlement Website: Strong v. LifeStance Health Group
- American Hospital Association: OCR Updates HIPAA Guidance on Use of Online Tracking Technologies
- Norton Rose Fulbright: Applying HIPAA to Online Tracking Technologies, Court Finds HHS Guidance Exceeds Authority