Atrium Health Settles $1.8 M Over Unauthorized Web‑Tracker Data Sharing on Patient Portal
What Happened – Atrium Health agreed to pay up to $1.8 million to resolve a class‑action lawsuit alleging that pixel‑tracking code embedded in its patient portal (2015‑2019) transmitted protected health information to third‑party advertising firms such as Meta and Google without patient consent. The breach was reported to HHS as affecting roughly 586,000 individuals.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure to meet SOC 2 CC5 (Confidentiality) and privacy‑related criteria that require documented consent and strict controls over third‑party data flows.
- Continuous evidence of consent management and third‑party script inventories is essential to demonstrate due diligence during a SOC 2 audit.
- Verisq’s CookiePLUS capability provides the automated consent capture and audit‑ready logs needed to close this gap.
Who Is Affected – Large health systems, hospitals, and any organization that hosts patient‑facing web applications.
Recommended Actions
- Perform an inventory of all third‑party scripts on patient‑facing sites and map them to privacy controls.
- Implement a consent‑management solution that records, stores, and can produce audit‑ready evidence of patient opt‑in/opt‑out.
- Update privacy policies and SOC 2 documentation to reflect the new controls and retain logs for the required retention period. Source: DataBreachToday
Technical Notes – The exposure stemmed from embedded web‑tracker pixels (JavaScript) that automatically sent HTTP requests containing PHI to advertising networks. No specific CVE is involved; the issue is a misconfiguration/privacy‑policy gap. Source: same article