Making a doctor’s appointment and then learning that your private health information may have been disclosed to an advertising platform is a bit unsettling. Not by means of a hack. not via a conventional data breach. simply by means of the silent, everyday functioning of website tracking cookies, which are the same devices that follow you around the web after you view a pair of sneakers.
In a class-action lawsuit brought against HCA Healthcare in September 2026, three patients essentially make that claim. HCA’s CareNow urgent care network is named as the defendant in the case, which was filed in Nashville, Tennessee’s Davidson County Circuit Court. The plaintiffs’ use of pseudonyms—identified as Jane Does in court documents—indicates the delicate nature of their claims.
The main accusation is that patients had to have first-party cookies enabled on their devices in order to make an urgent care appointment via CareNow’s online portal. The scheduling page did more than just issue a warning or reroute if they rejected or blocked those cookies. The lawsuit claims that it put users in a never-ending cycle of CAPTCHA verification with no way out. Don’t schedule your appointment, or accept the tracking. For someone who needs to see a doctor, that is a limited option.
The more important aspect is what transpired with the information gathered by those cookies. According to the complaint, the website’s tracking tools gave Google and outside advertisers access to protected health information, or PHI as it is known in legal and regulatory parlance. That goes beyond names and email addresses. A variety of information is described in the lawsuit, including IP addresses, clinic locations, doctor names, appointment details, and patient status. the type of information that, under federal privacy law, would need to be handled carefully and with express consent in a different situation.
The case was presented clearly by national security advisor and cybersecurity specialist Ricoh Danielson. He pointed out that health data is for sale when it is released in this manner. Although it may sound direct, it is worthwhile to sit with. The specifics of a patient’s online appointment for an X-ray or strep test may have been converted into advertising inventory. For most people, the practical impact might seem insignificant—a targeted advertisement, an odd suggestion. However, the underlying idea is different. For good reason, medical information carries a particular, legally recognized expectation of privacy.
The claims have been refuted by HCA Healthcare, which has stated that it will vigorously defend the lawsuit. In a statement, the company said it “takes its obligation to safeguard patients’ information seriously.” This is the kind of language used by all corporations, and courts will now have to compare it to actual behavior. The technical difference between what its cookies collected and what is legally protected health information may be the main focus of the company’s defense. This argument has been made in other healthcare privacy cases, with varying degrees of success.

This is not a stand-alone lawsuit. The use of tracking pixels, session recorders, and third-party analytics tools on patient-facing websites has resulted in an increasing number of lawsuits against healthcare providers across the nation. In the tech and marketing sectors, the tools are standard. They encounter HIPAA and a patchwork of state-level privacy laws in the healthcare industry, which were drafted with hospitals, not advertising networks, in mind.
The purported CAPTCHA mechanism—the notion that declining data collection was not only inconvenient but actually prevented access to a health service—makes the HCA case feel especially acute. It remains to be seen if a court determines that coercion is severe enough to violate the law. However, it’s difficult to ignore the imbalance when a patient, ill or anxious, sits at a computer at a strange hour, clicking repeatedly before giving up and clicking accept.
Not because HCA is particularly evil in the field of healthcare technology, but rather because the case’s outcome might establish a significant benchmark for what healthcare websites are truly permitted to do with the data they covertly gather on a daily basis.