Allina Health Settled Patient Privacy Class-Action Lawsuit
The $12.5 million settlement resolves claims that website tracking tools improperly shared sensitive patient data.
Updated on Sept. 25, 2026 in Healthcare

Live Poll
Do you trust that your health provider keeps your digital medical information private and secure?
Allina Health has agreed to a $12.5 million settlement to resolve a federal class-action lawsuit involving the disclosure of private patient data to third-party marketers. The settlement affects more than 120,000 patients whose information was transmitted via web tracking pixels.
Why it matters
The case highlights the significant operational and liability risks associated with using digital marketing tools on patient-facing web portals. The settlement addresses a 2023 disclosure where technical issues allowed for the unauthorized sharing of diagnostic and personal details.
Allina Health has reached a $12.5 million settlement agreement, with more than 120,000 patients eligible to participate. The total amount resolves a 2024 class-action filing regarding data privacy practices.
The players
Allina Health
A major non-profit healthcare system operating hospitals and clinics across Minnesota.
U.S. District Court of Minnesota
The federal judicial body that presided over the class-action litigation.
The details
The litigation centered on the use of tracking pixels on Allina Health's web portal, which automatically transmitted patient names, birth dates, insurance numbers, and diagnostic data to third-party advertisers. Allina Health self-reported the technical glitch in 2023, noting that the tracking tools recorded website visits without proper data safeguards. The company has not admitted to any wrongdoing as part of the legal resolution.
Timeline
2023: Allina Health self-reported the tracking pixel data collection.
2024: Lawsuit filed in U.S. District Court of Minnesota.
September 24, 2026: Federal judge approved the settlement.
Market Landscape
This settlement follows a broader industry trend where healthcare providers face class-action liability for the unauthorized data sharing caused by third-party tracking software. The case reflects the heightened legal scrutiny surrounding digital privacy compliance in medical web portals.
Operators in the healthcare sector should audit all third-party marketing scripts and analytics tools embedded on patient-facing digital properties. Ensure that any data transmission complies with privacy standards and verify that vendors have strictly defined limitations on data use.
The takeaway
The case emphasizes the operational necessity of strict technical oversight for all marketing software integrated into sensitive web environments. Managers should review their current digital vendor agreements to ensure they specifically prohibit the retention or utilization of PII or PHI.
Further reading
For more on industry regulatory shifts, visit the Healthcare section.
Source note: This article includes information reported by Star Tribune.
Live Poll
Do you trust that your health provider keeps your digital medical information private and secure?










