HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Atrium Health Settles $1.8 M Over Unauthorized Web‑Tracker Data Sharing on Patient Portal

Atrium Health will pay up to $1.8 million to settle claims that pixel trackers on its patient portal sent protected health information to third‑party advertisers without consent. The breach highlights the need for documented consent and continuous monitoring to satisfy SOC 2 privacy requirements.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

Atrium Health Settles $1.8 M Over Unauthorized Web‑Tracker Data Sharing on Patient Portal

What Happened – Atrium Health agreed to pay up to $1.8 million to resolve a class‑action lawsuit alleging that pixel‑tracking code embedded in its patient portal (2015‑2019) transmitted protected health information to third‑party advertising firms such as Meta and Google without patient consent. The breach was reported to HHS as affecting roughly 586,000 individuals.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure to meet SOC 2 CC5 (Confidentiality) and privacy‑related criteria that require documented consent and strict controls over third‑party data flows.
  • Continuous evidence of consent management and third‑party script inventories is essential to demonstrate due diligence during a SOC 2 audit.
  • Verisq’s CookiePLUS capability provides the automated consent capture and audit‑ready logs needed to close this gap.

Who Is Affected – Large health systems, hospitals, and any organization that hosts patient‑facing web applications.

Recommended Actions

  • Perform an inventory of all third‑party scripts on patient‑facing sites and map them to privacy controls.
  • Implement a consent‑management solution that records, stores, and can produce audit‑ready evidence of patient opt‑in/opt‑out.
  • Update privacy policies and SOC 2 documentation to reflect the new controls and retain logs for the required retention period. Source: DataBreachToday

Technical Notes – The exposure stemmed from embedded web‑tracker pixels (JavaScript) that automatically sent HTTP requests containing PHI to advertising networks. No specific CVE is involved; the issue is a misconfiguration/privacy‑policy gap. Source: same article

📰 Original Source
https://www.databreachtoday.com/atrium-health-to-pay-18m-to-settle-web-tracker-lawsuit-a-32170

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →