Henry Ford Health Settles Tracking Technology Lawsuit
Another settlement has been reached to resolve a class action lawsuit over the use of third-party tracking tools on healthcare websites. Henry Ford Health, a not-for-profit health system in Detroit and the second-largest health system in Michigan, used tracking technologies on its website that collected information from web visitors. According to the complaint, tracking tools such as Meta Pixel, Google Analytics, Google Tag Manager, and Google DoubleClickAds, were installed on its website. Those tools collected visitor information, including protected health information (PHI), which was transferred to third parties such as Meta and Google Inc. without website users’ knowledge or consent. The tools were even used on web pages that required authorization to access, such as the MyChart Patient Portal. Henry Ford Health encouraged patients to use the website and patient portal to submit information, review their health records, book appointments, schedule visits, pay bills, and communicate with providers. From the information collected, third parties could infer that a patient was...
Ransomware Attacks Fall in Q2 as Ecosystem Reshuffles
Ransomware attacks declined by 23% from the previous quarter, although they are up 43% on this time last year, with the dip only partially explained by normal seasonal variations. In Q2 of 2025, 1,591 new victims of ransomware attacks were posted publicly on data leak sites, at an average of 17.5 per day, compared to 22.9 per day in Q1 of 2025 and 12.2 per day in Q2 of 2024. Compared to last year, Alphv/BlackCat – a major player in the ransomware ecosystem – has shut down, LockBit has been subject to law enforcement action, and there has been significant disruption to the RansomHub operation, all of which have contributed to the fragmentation of the ransomware ecosystem. Compared to last year, there are more small groups and lone wolves operating, who find it much easier to stay under the radar of law enforcement. In Q2, 2024, there were 41 active ransomware groups, and 71 in Q2, 2025, according to the quarterly Ransomware & Cyber Threat Report from the GuidePoint Research and Intelligence Team (GRIT), a 45% year-over-year increase. The United States is still the primary target...
HHS Publishes New General Policy on Criminal Referrals for Regulatory Violations
When individuals and entities violate Health and Human Services (HHS) regulations, HHS may choose to make a criminal referral to the Department of Justice (DoJ). For instance, when a healthcare employee accesses patient data without authorization for financial gain or in order to inflict harm on an individual, there may be criminal charges for the violation. The HHS has recently published its plans to address regulations that impose criminal liability, following on from President Trump’s Executive Order on Fighting Overcriminalization in Federal Regulations (Executive Order 14294). The Executive Order is intended to reduce the regulatory burden on everyday Americans and ensure that no American faces criminal charges for violating a regulation that they have no reason to know exists. The Executive Order states that the policy of the United States is criminal enforcement of criminal regulatory offenses is disfavored, and the prosecution of criminal regulatory offenses is most appropriate “for persons who know or can be presumed to know what is prohibited or required by the regulation...
Gardner Orthopedics Ransomware Attack Affects 47,000 Patients
Data breaches have been announced by Gardner Orthopedics in Florida, Blue Cross and Blue Shield of Massachusetts, Health Care and Rehabilitation Services of Southeastern Vermont, Retina Associates of Cleveland, and Clement Manor in Wisconsin. Gardner Orthopedics, Florida Gardner Orthopedics in Fort Myers, Florida, has recently determined that the protected health information of 47,000 patients was potentially compromised in a recent cyberattack. While not described as a ransomware attack, the Inc Ransom ransomware group claimed responsibility and added Gardner Orthopedics to its dark web data leak site on May 15, 2025, along with samples of the stolen data. Gardner Orthopedics detected the intrusion on April 29, 2025, and engaged third-party cybersecurity experts to contain the incident and determine the nature and scope of the unauthorized activity. The company also rebuilt the affected systems and strengthened security. Data had been backed up, and the backups were unaffected, so data could be recovered, and the network was rebuilt and restored within a week. Information...
MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit
MarinHealth has agreed to a $3 million settlement to resolve claims related to its use of the Meta Pixel tracking tool on its website between 2019 and 2025. MarinHealth is the operator of Marin Health Medical Center and various outpatient clinics in Marin County and Sonoma County in California. Like many other healthcare providers, MarinHealth used Meta Pixel and other tracking tools on its website to collect visitor information. Meta Pixel, similar to other website tracking tools, gathers data from individuals who visit a website where the tool is installed. The tool collects information about website usage, including information that could be used to identify that individual. That information is then transmitted to Meta and can potentially be used to serve personalized ads elsewhere on the web. If Meta Pixel collects information from dropdown menus, button click data, and the pages an individual visits on a healthcare website, advertisements could be served related to a health condition the user has, believes they have, or has researched. The lawsuit against MarinHealth –...



