Allina Health Settled Patient Data Privacy Lawsuit
A federal judge approved a $12.5 million settlement regarding the improper sharing of patient data with marketers.
Updated on Sept. 25, 2026 in Healthcare

Live Poll
Do you trust that your health provider keeps your digital medical information private and secure?
Allina Health has agreed to pay $12.5 million to settle a federal class-action lawsuit involving the unauthorized sharing of private patient information. The agreement, approved by a judge, concludes a case brought after the healthcare provider self-reported a tracking pixel error.
Why it matters
The settlement addresses concerns over digital privacy in healthcare, specifically how website tracking tools can inadvertently expose sensitive medical data to third-party marketers. It highlights the growing legal risks institutions face when their digital infrastructure fails to protect patient confidentiality.
The settlement provides $12.5 million in total compensation for over 120,000 patients whose information was shared. Allina Health did not admit to any wrongdoing as part of the legal agreement.
The players
Allina Health
This is a non-profit health system based in Minnesota that provides care through various hospitals and clinics.
U.S. District Court of Minnesota
This is the federal trial court that presided over the class-action lawsuit filed against the healthcare provider.
The details
The litigation stemmed from Allina Health utilizing website tracking pixels that captured and shared patient names, birth dates, IP addresses, diagnostic details, and insurance numbers. These tools were originally meant to record website visits but caused a technical glitch that leaked the data to third-party marketing firms.
Timeline
2023: Allina Health self-reported the tracking pixel data collection incident.
2024: A class-action lawsuit was filed against the health system in the U.S. District Court of Minnesota.
September 24, 2026: A federal judge formally approved the final settlement agreement.
Market Landscape
The settlement follows a pattern of heightened regulatory and legal scrutiny regarding the intersection of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and modern digital marketing technologies. This resolution underscores a broader industry shift toward stricter oversight of how third-party tracking tools integrate with hospital digital portals.
Patients who were affected by the data breach may be eligible for financial compensation as part of the settlement process. Individuals should monitor their mail or official communications from the court for instructions on how to submit a claim for their share of the fund.
The takeaway
Healthcare providers are increasingly vulnerable to data privacy litigation due to the complex integration of third-party tracking software on patient-facing websites. Patients should remain vigilant by reviewing privacy notices and opting out of non-essential website tracking whenever possible.
Further reading
For more on how medical systems are addressing data security, visit the Healthcare section.
Source note: This article includes information reported by Star Tribune.
Live Poll
Do you trust that your health provider keeps your digital medical information private and secure?










