Allina Sent Your Medical Website Clicks to Facebook and Google. The Price Tag: $12.5 Million
The Non-Financial Ledger
When you log into a hospital’s website to pay a bill, schedule surgery, or read your test results, you assume you are alone with your doctor’s institution. The lawsuit alleges Allina broke that assumption. Every click, every page you visited about a condition, may have been quietly copied and handed to Facebook and Google without your knowledge or consent.
This is not about a stolen password. It is about the most intimate category of information a person has, their health, being turned into advertising signal. Patients trusted a healthcare provider with their bodies and their fears. The complaint says that trust was routed through invisible code embedded in the pages they were told were safe.
The betrayal here is structural. People did not choose to share their medical browsing with the two largest ad-tech companies on earth. They were never asked. They found out because a lawyer did, years after the alleged disclosures began.
Legal Receipts
“Defendant disclosed information about Plaintiffs and Class Members, including personally identifiable information (‘PII’), protected health information (‘PHI’), and sensitive medical information… to third parties including, but not necessarily limited to, Meta Platforms, Inc. d/b/a Meta (‘Facebook’) and Google LLC (‘Google’) via tracking pixels, cookies, and other tracking technologies.”
- This is the core allegation in Allina’s own settlement document: sensitive medical data flowed to Facebook and Google.
- The disclosure vehicle was tracking technology embedded directly in Allina’s own websites and patient portal.
“Defendant denies each and every one of the allegations, contentions, and claims that have been or could have been alleged against it in the Action and all charges of wrongdoing or liability of any kind.”
- Allina pays $12.5 million while formally denying it did anything wrong.
- The settlement is engineered so that writing the check never becomes an admission of guilt.
“Neither the Final Approval Order and Judgment, the Settlement, nor the Settlement Agreement shall constitute an admission of liability or wrongdoing by any of the Parties.”
- The no-admission clause is baked into the order the court is asked to sign, not just the private deal.
- It means no legal precedent of wrongdoing is created, protecting Allina from being cited in future cases.
“Class Counsel may petition the Court for an award of attorneys’ fees in an amount not to exceed $4,166,666.67, which is approximately one third of the Settlement Fund.”
- One-third of the total recovery is earmarked for the attorneys before class members are paid.
- This deduction comes out of the same pot meant to compensate 2.5 million exposed patients.
Public Deception: The Gap Between the Portal and the Pixel
The documents show a contradiction between what a hospital website implies and what the complaint alleges was running behind it.
- Patients were presented with a secure-looking patient portal to manage bills, scheduling, and records; the complaint alleges tracking pixels simultaneously transmitted their activity to Facebook and Google.
- Allina publicly denies “all charges of wrongdoing or liability of any kind”; it simultaneously agreed to pay $12,500,000 to make the case go away.
- The settlement notice tells patients the case concerns “certain personal or health-related information may have been disclosed”; the underlying complaint asserts nine distinct legal violations including breach of fiduciary duty and invasion of privacy.
The Relationship Map: How Your Data Left the Building
The alleged harm depended on a simple chain: patients trusted Allina, Allina embedded third-party tracking code, and that code fed data to advertising giants.
The Anatomy of the Class: Who Got Exposed
The single “settlement class” of 2,531,323 people is actually two groups with very different alleged exposure and very different pieces of the money.
How Capitalism Exploits Delay: Time as a Corporate Weapon
The timeline of this case shows how long the alleged conduct ran and how the settlement machinery stretches payout even further into the future.
- The class period runs from September 16, 2018 through preliminary approval, meaning the alleged data-sharing continued for roughly seven years.
- The lawsuit was filed September 16, 2024, exactly six years after the start of the class period, before any accountability began.
- Two full-day mediation sessions were needed, on November 18, 2025 and February 4, 2026, before a deal was reached.
- Even after final approval, payments are not sent until 60 days after the settlement becomes “Final,” which itself waits out any appeal window.
- Checks expire 90 days after issuance; unclaimed money becomes “Residual Funds” that go to a charity, not back to class members.
The Contractor Shield: A Sprawling Web of Released Parties
The settlement does not just release Allina. It wraps a legal shield around a wide ring of connected entities.
- “Released Parties” covers Allina plus its past and present parents, subsidiaries, divisions, and affiliated entities.
- The release extends to owners, “religious sponsor,” directors, officers, employees, agents, attorneys, insurers, and reinsurers.
- “Defendant Related Entities” explicitly names St. Francis Regional Medical Center and “its sponsors, members, and directors” as protected.
- The release bars any class member who does not opt out from suing any of these parties over the tracking claims, now or in the future, including “Unknown Claims.”
Societal Impact Mapping
Public Health
The alleged conduct strikes at the confidentiality that makes healthcare function.
- An estimated 2,531,323 people had their interactions with a healthcare provider’s web properties allegedly exposed.
- The information at issue includes protected health information (PHI) and “sensitive medical information,” the most guarded category of personal data.
- The complaint asserts a breach of fiduciary duty, the special trust a patient places in a medical institution.
- When patients fear that browsing a hospital site leaks to advertisers, they may avoid seeking care information online.
Economic Inequality
The financial structure of the settlement shifts value away from the harmed and toward the professional class administering the deal.
- Up to $4,166,666.67 of the fund goes to attorneys, one-third of the total before patients are paid.
- Up to $1,000,000 goes to notice and administration costs, also drawn from the fund.
- After deductions, roughly $8 million is split among 2.5 million people, a small per-person payout that only reaches those who file a claim.
- Class members who never open the notice email or postcard get nothing, while the deductions are paid in full regardless.
The Cost of a Life Metric
Who Pays? Following the Cost
The settlement is structured so that the practical cost of the alleged harm lands on the very people who were exposed, while the deal is described as their compensation.
- The $12.5M fund originates with Allina and its insurers, but the litigation and administration costs are subtracted from the class recovery, not paid separately by Allina.
- Class members bear the burden of finding, reading, and acting on a notice within 90 days or forfeit any payment.
- Unclaimed and uncashed money becomes “Residual Funds” sent to a cy pres charity, meaning harmed individuals who miss the window subsidize a third party rather than being made whole.
The Settlement Isn’t Justice
A $12.5 million payment sounds large until you divide it by the harm and subtract what never reaches the harmed.
- The deal contains no admission of wrongdoing; the court order itself states it “shall not constitute an admission of liability or wrongdoing.”
- Nearly one-third of the fund, up to $4,166,666.67, is routed to attorneys before class members receive anything.
- Spread across 2,531,323 class members, the gross fund is worth about $4.94 per person, and less after fees and administration. Calculated from source figures: $12,500,000 ÷ 2,531,323.
- Only class members who submit a valid claim within 90 days are paid; the structure guarantees most of the class collects nothing.
- The release permanently bars future lawsuits over the tracking conduct, including “Unknown Claims” the class does not yet know about.
This Is the System Working as Intended
Every element of this settlement is legal, standard, and produces an outcome that protects the institution more than the people it allegedly harmed.
- Allina resolves nine legal claims across millions of people while denying every allegation and admitting nothing, a structure the court order explicitly preserves.
- The release shields not just Allina but its parents, subsidiaries, insurers, and named related entities like St. Francis Regional Medical Center from future claims.
- The claims-made structure means the effective cost to Allina drops every time a class member fails to file, since unclaimed value goes to a charity rather than expanding individual payouts materially.
- The one-third attorneys’ fee is described as “approximately one third of the Settlement Fund,” a routine benchmark that normalizes taking millions off the top of a privacy harm.
What a Legitimate Fix Looks Like
This case exposes a core failure: healthcare websites can deploy commercial surveillance code against patients with no meaningful consent, and the consequences arrive years late as a diluted cash pool. The following are editorial recommendations, not findings of the source document.
Regulatory Track
- The U.S. Department of Health and Human Services Office for Civil Rights should require healthcare providers to inventory and disclose every third-party tracking technology running on patient-facing web properties.
- The FTC should mandate that any transmission of health-related web activity to advertising platforms like Meta and Google require explicit, opt-in patient consent, with third-party audits of what pixels actually transmit.
- The Minnesota Attorney General should enforce the Minnesota Health Records Act against vendor and tracking arrangements that route patient data to advertisers without authorization.
Legislative Track
- Enact a federal health-data privacy statute that treats web-tracking disclosures of medical activity as a per-violation offense with statutory damages, removing the incentive to settle cheaply.
- Strengthen the Electronic Communications Privacy Act, cited in this complaint, to clearly bar interception of health-portal traffic by embedded third-party code.
- Require that class settlements involving health data direct unclaimed residual funds back to identifiable class members through supplemental distributions before any cy pres charity payout.
Corporate Governance Track
- Allina’s board should require sign-off from a privacy officer before any tracking or analytics code is deployed on patient-facing properties.
- Executive compensation for digital and marketing leadership should be tied to documented privacy compliance, not engagement or conversion metrics that reward surveillance.
- Implement mandatory, publicly reported annual audits of all data flowing from patient portals to third parties.
What Now?
Direct your attention to Allina Health System’s leadership and the agencies that let medical tracking run for years.
- If you used an Allina website, portal, or paid a bill online since September 16, 2018, file a claim before the deadline at the official settlement site rather than letting your share vanish into residual funds.
- Watchlist: the FTC (deceptive data practices), HHS Office for Civil Rights (HIPAA and PHI enforcement), and the Minnesota Attorney General (state health records law).
- Watchlist: the U.S. District Court for the District of Minnesota, Case No. 0:24-cv-03674, where final approval will be decided by Judge Susan Richard Nelson.
- Organize locally: push Minnesota healthcare systems to publish their third-party tracking inventories and demand opt-in consent at community health board meetings.
- Support digital-rights mutual aid: fund and share privacy tools like tracker blockers so patients can defend themselves while regulators lag behind.
The source document for this investigation is attached below.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →


