What happened
CVS Health and advertising technology firm Criteo have agreed to pay $20.5 million to settle claims that the pharmacy chain shared patients' personal and health information with Criteo through tracking technology built into its websites and apps.
The proposed class action was filed in a Florida state court in May. It alleged violations of the Electronic Communications Privacy Act, state statutory claims, breach of confidence, invasion of privacy and negligence by both companies. The complaint said third-party code let trackers intercept and record information about medical conditions, immunizations, prescriptions, and the search and purchase of sensitive healthcare products, all without patients knowing. Plaintiffs called the lapse an "egregious" breach of the duty of confidentiality that a pharmacy owes its customers.
Court documents do not disclose how much each company is contributing. The settlement class covers people in the United States who accessed the CVS digital properties before July 27, 2026, the date the court approved the preliminary settlement. Eligible claimants can receive up to $5 without documentation, or up to $10 with proof of interaction with the sites. A final approval hearing is set for December 1. CVS and Criteo deny any wrongdoing, and the advertising firm Medallia, also named as a defendant, is not part of the settlement.
The case is the latest in a run of class actions over tracking pixels and similar code in the healthcare sector, where plaintiffs argue that third-party marketing technology sees data that patients never agreed to share.
Why this is a GRC story
Nothing about this failure looks like a breach in the usual sense. No perimeter was crossed. A tag was added to a page, and the page carried health information. The control that failed was governance of third-party code, not network security.
That distinction matters because tag management usually sits with marketing or product teams, while data protection sits with compliance. Any organisation that relies on that split is exposed. Someone needs to own the inventory of what code runs on customer-facing properties, what each script can read, and which data flows were ever approved. Consent terms, vendor contracts that prohibit secondary use of the data, and a review step that catches new tags when a page changes all sit inside that same gap.
The settlement also sets an expected value on the exposure. A $20.5 million payment, class member awards in single digits, and a litigation timeline measured in years is a familiar shape now. For a GRC team, the useful reading is straight comparison: the cost of knowing where patient or customer data travels through your own web estate is trivial next to the headline number here.
What to watch
Watch the final approval hearing on December 1, and whether the low per-claimant payments draw the same objections that other digital privacy settlements have faced.
Watch whether state regulators open parallel inquiries. Private class actions rarely end an issue that a data protection authority can also act on.
Watch where the next wave lands. The same tracking pattern exists well beyond healthcare, in financial services, insurance and government services, and the theories tested here travel easily.
Attribution: Analysis based on DataBreachToday's reporting and related public reporting. This article is original commentary, not a repost of the source material.
