A healthcare website may look like a simple digital front door. Patients use it to find a physician, request an appointment, complete a form, learn about a medical condition or read a patient success story.
Behind that convenience, however, may be a complicated collection of analytics software, advertising technologies, scheduling platforms, cloud services and third-party vendors. Recent government enforcement actions show why healthcare organizations should understand not only what appears on their websites, but also what information those websites collect, where that information goes and whether appropriate privacy controls are in place.
This is not a theoretical concern. Public records from the New York Attorney General, the U.S. Department of Health and Human Services Office for Civil Rights, and the Federal Trade Commission provide several important examples.
NewYork-Presbyterian: a $300,000 New York settlement
On December 27, 2023, the New York Attorney General announced a $300,000 settlement with NewYork-Presbyterian Hospital following an investigation involving third-party tracking technologies used on the hospital's website.
According to the Attorney General's office, tracking tools collected information when some visitors searched for physicians, researched medical conditions or scheduled appointments. The Attorney General reported that third-party companies received information that could include IP addresses and webpage URLs, and in some circumstances the URLs themselves contained information associated with a physician, medical specialty or health condition.
The Attorney General's investigation concluded that protected health information had been disclosed through tracking technologies and stated that the practices violated HIPAA. The office reported that the incident affected more than 54,000 individuals.
Under the settlement, NewYork-Presbyterian agreed to pay $300,000 and implement additional privacy safeguards, including policies governing third-party tools and regular audits, reviews and testing before certain technologies are deployed. The lesson is broader than one hospital: a website analytics or marketing technology can create a privacy issue when the information flowing through it is protected health information and the disclosure is not permitted.
Cadia Healthcare: patient stories and HIPAA authorization
Patient testimonials and success stories present a different type of website risk. In September 2025, the U.S. Department of Health and Human Services Office for Civil Rights announced a $182,000 settlement with five Cadia Healthcare facilities concerning potential violations of the HIPAA Privacy and Breach Notification Rules.
According to OCR, its investigation began after a complaint involving a patient's information appearing in a public-facing website success story. OCR reported that its investigation determined that protected health information involving 150 patients had been disclosed through facility websites as part of a success-story program without valid written HIPAA authorizations, and that it identified deficiencies involving safeguards and breach notification requirements.
Cadia agreed to pay $182,000 and implement a corrective-action plan monitored by OCR for two years. The case highlights an important distinction: a patient's relationship with a healthcare provider does not automatically give the provider permission to use that patient's protected health information for marketing or promotional purposes. HIPAA authorization requirements must be considered separately.
GoodRx: health information and advertising technologies
Healthcare privacy concerns are not limited to hospitals and physician practices. In February 2023, the Federal Trade Commission announced an enforcement action against GoodRx Holdings Inc.
The FTC alleged that GoodRx failed to provide required notifications concerning unauthorized disclosures of individually identifiable health information to companies including Facebook and Google. The FTC announced that GoodRx had agreed to pay a $1.5 million civil penalty as part of a proposed federal court order and would face restrictions on certain disclosures of user health information for advertising, calling it its first enforcement action under the Health Breach Notification Rule.
The case is important because healthcare data can move far beyond an electronic medical record. Websites, apps, analytics platforms and advertising systems can all become part of the information ecosystem.
BetterHelp: $7.8 million and sensitive health information
The Federal Trade Commission also pursued an enforcement action involving online counseling provider BetterHelp. The FTC alleged that BetterHelp disclosed information including email addresses, IP addresses and answers to health-related questionnaires to third parties for advertising purposes despite privacy representations made to consumers.
In July 2023, the FTC finalized an order requiring BetterHelp to pay $7.8 million, with the money designated for partial refunds to eligible consumers, and restricting the company's ability to share health data for advertising. The FTC continued distributing settlement-related refunds in subsequent years.
It is important to describe this case precisely: these statements reflect the FTC's allegations and the resulting consent order, rather than an independent conclusion by AABEAT TV.
The common thread
Taken together, these four cases point to the same underlying issue from different angles: tracking pixels, advertising integrations, testimonial programs and third-party vendors can each turn an ordinary healthcare website into a source of regulatory exposure. None of them required a traditional hack or breach in the way that term is usually understood. In each case, the risk came from how routine digital tools were configured and disclosed, not from an outside attacker breaking in.
For healthcare organizations, the practical takeaway is that website governance is now a compliance function as much as a marketing or IT one. That means knowing which third-party scripts and pixels run on patient-facing pages, confirming what those vendors do with the data they collect, obtaining valid HIPAA authorization before using patient stories for promotion, and auditing tools before they go live rather than after a complaint arrives.

