Skip to content

Menu

Jackson Lewis P.C.  logo
HomeAboutServicesContactSubscribe
Search
Close

Workplace Privacy, Data Management & Security Report

CCPA Compliance Alert: $1.55M Healthline Settlement

By Joseph J. Lazzarotti on August 6, 2025
Posted in California Consumer Privacy Act

On July 1, 2025, California Attorney General Rob Bonta announced the largest CCPA settlement to date, which included a $1.55 million penalty against Healthline Media LLC. This settlement sends a clear message to businesses that California Consumer Privacy Act (CCPA) enforcement is ramping up, and health-related data is in scope.

According to the complaint filed against Healthline, a popular health information website, the state alleged Healthline:

  • Shared sensitive health-related data with third parties without adequate user consent.
  • Failed to provide a clear opt-out mechanism for targeted advertising.
  • Lacked CCPA-compliant contracts with third parties, and assumed, but did not verify, that the third parties had agreed to abide by an industry contractual framework.
  • Transmitted article titles (e.g., “You’ve Been Newly Diagnosed with MS”) that could reveal a user’s medical condition, effectively disclosing personal health information.

This case marks the first time the California Department of Justice has enforced the CCPA’s protections around sensitive personal information.

Operating one of the top 40 most visited websites in the world, Healthline is a media company engaged in the use of use of online tracking technology on its website. The online trackers used on Healthline’s website, like cookies and pixels, communicate data about readers to advertisers and other third parties in order to maximize ad revenue. That data uniquely identified consumers along with, for example, titles of articles they were reading. Some titles indicated that the reader may have already been diagnosed with a serious illness, such as “You’ve Been Newly Diagnosed with MS. What’s Next?” In some cases, according to the allegation, consumers often had no idea how many online trackers might be running.

The settlement includes strict injunctive terms, such as:

  • A ban on sharing article titles that could imply a diagnosis.
  • Enhanced user opt-out mechanisms for data sharing.
  • Stronger contractual safeguards with service providers and third-party advertisers.

Key Takeaways for Business

For businesses that collect or share consumer data, especially when using online tracking technologies that share sensitive categories like health information, this case is just another reminder about the potential compliance and litigation risks. Here are some best practices for businesses subject to the CCPA.

  1. Audit data practices, including identifying what personal information, as well as sensitive personal information, the business is collecting and how it is being used and shared.
  2. Be familiar with what tracking technologies are being used on your websites, including what information they collect and share.
  3. Strengthen opt-out mechanisms, including ensuring that the “Do Not Sell or Share My Personal Information” link is prominent and functional.
  4. Review third-party contracts with advertisers and analytics providers, including CCPA-compliant data use restrictions.
  5. Avoid inadvertent disclosure by being cautious about URLs, article titles, or metadata that could reveal personal information.

Conducting an annual review of CCPA compliance, as required under the CCPA, is an obvious step to help ensure ongoing compliance.

Tags: CCPA, heatlh-related data, metadata, opt-out, sensitive personal information, third party contracts
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Joseph J. Lazzarotti Joseph J. Lazzarotti

Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm’s Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the…

Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm’s Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the International Association of Privacy Professionals. Trained as an employee benefits lawyer, focused on compliance, Joe also is a member of the firm’s Employee Benefits practice group.

In short, his practice focuses on the matrix of laws governing the privacy, security, and management of data, as well as the impact and regulation of social media. He also counsels companies on compliance, fiduciary, taxation, and administrative matters with respect to employee benefit plans.

Read more about Joseph J. Lazzarotti
Show more Show less
Related Posts
New CCPA Regulations Go Into Effect, Updated FAQs Summarize Key Compliance Requirements
January 22, 2026
Understanding California’s New CCPA Cybersecurity Audit Requirements
December 8, 2025
The CCPA and Automated Decision-Making Technologies (ADMT)
November 25, 2025
Jackson Lewis JacksonLewis.com

Stay Connected

Subscribe to this blog via RSS Follow Us on Twitter Add us on Facebook View Our LinkedIn Profile

Topics

Archives

Editors

  • Jason C. Gavejian
  • Joseph J. Lazzarotti

Contributors

  • Christopher E. Hoyme
  • Damon W. Silver
  • Michael R. Bertoncini
  • Marlo Johnson Roebuck
  • Nathan W. Austin
  • Nicky Jatana
  • Jeffrey M. Schlossberg

Blog Authors Show/Hide

  • Joseph J. Lazzarotti
  • Jason C. Gavejian
  • Maya Atrakchi
  • Jackson Lewis P.C.
  • Mary T. Costigan
  • Damon W. Silver
  • Jeffrey M. Schlossberg
  • Michael R. Bertoncini
  • Robert Yang
  • Christopher E. Hoyme
  • Eric J. Felsberg
  • Rachel E. Ehlers
  • Sean Paisan
  • Melissa Pascualini
  • Jody Kahn Mason
  • Frank J. Fanshawe
  • Gregory C. Brown Jr.
  • Delonie A. Plummer
  • Richard I. Greenberg
  • Michelle L. Duncan
  • Jerel Pacis Agatep
  • Cecilie E. Read
  • Catherine R. Tucciarello
  • Todd R. Dobry
  • Susan M. Corcoran
  • Phillip A. Baggett
  • Dorothy Parson McDermott
  • Ryan J. Soscia
  • Ronald V. Sgambati
  • Nathan W. Austin
  • Joshua D. Allen
  • Jason Selvey
  • Michelle T. Hackim
  • Daniel J. Moses
  • Amanda A. Simpson
  • Yvonne Arvanitis Fossati
  • Teri Wilford Wood
  • Shannon Bettis Nakabayashi
  • Paul A. Friedman
  • Nikolas S. Dean
  • Marlo Johnson Roebuck
  • Melissa Ostrower
  • Michael H. Neifach
  • Joseph J. Lynett
  • Kevin B. Hambly
  • Jennifer Shoaf Richardson
  • Jackson Biesecker
  • Francis P. Alvarez
  • Christopher T. Patrick
  • Cheyna Galloway
  • Amy L. Peck
  • Zachary A. Ahonen
  • John A. Snyder
  • Sierra Vierra
  • Stephanie L. Adler-Paindiris
  • Richard F. Vitarelli
  • Kathryn J. Russo
  • Rachel A. Jacob
  • Philip M. Duclos
  • Laura A. Mitchell
  • Michael D. Ridenour
  • Michael A. Giarratano
  • Maryam Shokry
  • Leo P. Norton
  • Kevin D. Holden
  • Kelly E. Eisenlohr-Moul
  • Julia Bover
  • Joshua M. Henderson
  • Jonathan J. Spitz
  • Jamie L. Levitt
  • Valerie K. Jackson
  • Howard M. Bloom
  • Greg Alvarez
  • Erik J. Winton
  • Ena T. Diaz
  • Elizabeth S. Walsh
  • David R. Golder
  • Craig W. Wiley
  • Clifford R. Atlas
  • Cindy Y. Huang
  • Chai Williams
  • Chad P. Richter
  • Brian L. McDermott
  • Ashley Solowan
  • Angelika Avagian
  • Alec Nealon
  • Theron Velazquez
  • Terri Bowman
  • Robert Pfeifer
  • Regan Harrison
  • Paige
  • Nicky Jatana
  • Nicole A. Trotta
  • Mei Fung So
  • Mariama Keita
  • lbarksdale
  • Lara Hamm
  • Kourtney Goebel
  • Kendall Melidosian
  • Gayla Kirkland
  • Kelly Heber
  • Katharine C. Weber
  • Joanne Marsh
  • Jessica Poot
  • Jenifer M. Bologna
  • Jen Starken
  • Jonathan L. Crook
  • Haley Nystrom
  • Camille​​​​ Garcia‑Mendoza
  • Ann Albertson

Recent Upates

  • Top 10 Privacy, AI & Cybersecurity Issues for 2026
  • Florida’s Digital Wiretapping Surge: What Businesses Need to Know About FSCA Litigation
  • New CCPA Regulations Go Into Effect, Updated FAQs Summarize Key Compliance Requirements
  • The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party AI Processing Risks
  • The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 3 –Privacy, Surveillance, and Labor Law Violations

Jackson Lewis

Subscribe to this blog via RSS Follow Us on Twitter Add us on Facebook View Our LinkedIn Profile
Privacy PolicyDisclaimer

About Jackson Lewis

Focused on employment and labor law since 1958, Jackson Lewis P.C.’s 1,100+ attorneys located in major cities nationwide consistently identify and respond to new ways workplace law intersects business. We help employers develop proactive strategies, strong policies and business-oriented solutions to cultivate high-functioning workforces that are engaged and stable, and share our clients’ goals to emphasize belonging and respect for the contributions of every employee.

Read More...
Copyright © 2026, Jackson Lewis P.C. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo