TL;DR
- Atrium Health, a public hospital authority in Charlotte, North Carolina, ran third-party tracking pixels from Meta and Google on its website and patient portal, allegedly leaking patient health-related information to those tech companies.
- The alleged tracking on the patient portal ran from January 1, 2015 through July 31, 2019, and the class covers everyone who had a MyAtriumHealth or MyCarolinas portal account through April 10, 2024.
- Atrium agreed to pay up to $1,800,000 total to settle. The core Settlement Fund is $1,500,000, with a separate cap of $300,000 for a second group of claimants.
- Class Counsel can take up to $500,000 in fees plus $25,000 in expenses off the top of the fund. The four named plaintiffs get $2,500 each.
- Atrium admits no wrongdoing. Patients who did the least (never even logged in during the tracking window) are capped at a $10 payout each.
Atrium Health Fed Your Patient Portal Data to Facebook. The Fix Is a $10 Check.
The Charlotte-Mecklenburg Hospital Authority, operating as Atrium Health, is a North Carolina public hospital authority. According to a class action complaint, it embedded third-party tracking tools on the very web pages where sick people log in to manage their care.
The Non-Financial Ledger
When you log into a hospital patient portal, you are doing one of the most private things a person can do online. You are checking test results, messaging doctors, and managing conditions you may not have told your own family about. The complaint alleges Atrium Health placed tracking pixels from Meta and Google on those pages, meaning that intimate activity could travel to advertising giants without patients ever agreeing to it.
The class here is defined by a single act of trust: creating a MyAtriumHealth or MyCarolinas account to handle personal health matters. That trust is the thing allegedly breached. People who believed they were communicating privately with a health provider were, per the allegations, part of a data flow that reached companies whose entire business is targeting and profiling.
Atrium only posted a Privacy Notice about its prior use of tracking technologies on December 4, 2024, years after the alleged portal tracking window that ran from 2015 to mid-2019. For most of that time, patients had no way to know.
Legal Receipts
The following passages come directly from the settlement documents. They show, in the parties’ own words, what was alleged and how little the company conceded.
“Plaintiffs claim that Defendant’s implementation and use of Tracking Tools resulted in the invasion of Plaintiffs’ and Class Members’ privacy and other alleged common law and statutory violations.”
- This is the core accusation: the tracking tools themselves are alleged to have caused a privacy invasion, not some accidental side effect.
- It confirms the claims include both common law and statutory violations, meaning the alleged conduct potentially broke multiple legal protections.
“the alleged disclosure of personal and/or health-related information of Plaintiffs and Class Members to any third party, including but not limited to Meta (formerly known as Facebook) and Google as a result of any use of Tracking Tools in Defendant’s Web Properties.”
- The document names the recipients: Meta and Google. This was not a vague data leak; the allegation points at two of the largest ad-tech companies on earth.
- It confirms the disclosed data allegedly included “health-related information,” the most sensitive category of personal data there is.
“neither this Settlement Agreement, nor the Settlement it represents, shall be construed as an admission by Defendant of any wrongdoing whatsoever, including an admission of a violation of any statute or law or of liability on the claims or allegations in the Litigation.”
- Atrium pays up to $1.8 million while conceding nothing. This is the standard corporate exit: money changes hands, but no fault is ever recorded.
- Because there is no admission, the settlement cannot be used against Atrium as evidence in any other proceeding, including regulatory matters.
“For the avoidance of doubt, Defendant’s liability to Class Members shall not exceed the financial obligations described in Paragraphs 19 through 31 below.”
- Atrium capped its total exposure in advance. No matter how many patients were harmed, the company’s maximum payout is locked.
- This converts an open-ended privacy harm into a fixed, budgeted line item for the hospital.
Public Deception: The Portal Promised Privacy, The Pixels Delivered Data
The gap here is between what a patient portal represents and what the complaint says was happening behind the login screen.
- The portal, MyAtriumHealth, is marketed as a secure account “that contained health information,” per the settlement’s own definition. The complaint alleges that same portal ran tracking pixels feeding data to third parties.
- Atrium did not post a Privacy Notice about its “prior use of Tracking Technologies” until December 4, 2024, according to the agreement. The alleged portal tracking ran from January 2015 to July 2019.
- Patients were given no contemporaneous disclosure during the 2015 to 2019 window that Meta Pixel and Google Analytics were operating on the health pages they used.
How Capitalism Exploits Delay: The Case Was Killed and Reborn to Settle Cheap
The path this litigation took shows how procedure can grind plaintiffs down before a single dollar is discussed.
- The federal Roberts Action was filed April 10, 2024. Atrium moved to dismiss on August 26, 2024, and the court threw out the single federal claim and ruled it lacked jurisdiction over the rest.
- Plaintiffs had to appeal to the Fourth Circuit. Two parallel state cases (Hill and Brown) were both voluntarily dismissed in early to mid 2025.
- A first mediation with a JAMS mediator on June 26, 2025 failed to produce a settlement. Only a second session on September 12, 2025 produced an agreement in principle.
- Under the deal, the Fourth Circuit appeal is dismissed with prejudice within 30 days of signing, with each side eating its own costs. The litigation is then refiled as a fresh state-court action purely to be settled.
The Contractor Shield: How Third-Party Tools Diffused the Liability
The alleged harm did not come from a product Atrium built alone. It came from third-party code Atrium chose to embed, and the recipients of the data were outside companies.
- The tracking was performed by third-party tools, specifically named as the Meta Pixel and Google Analytics, according to the settlement definitions.
- The data allegedly flowed outward from Atrium’s web properties to Meta and Google, meaning the most sensitive recipients of the information are entities that are not defendants in this case.
- The release protects not just Atrium but its “Related Parties,” a sweeping category including parents, subsidiaries, affiliates, insurers, and “providers,” insulating a wide corporate web from future claims.
- Atrium continued to operate the portal and its web properties throughout, meaning it retained the operational benefit of the analytics while the liability was spread across third-party vendors it selected.
Societal Impact Mapping
The documented harm here concentrates on privacy and on the unequal way this settlement compensates the people affected.
Public Health
- The alleged disclosures involved “health-related information” tied to a patient portal that “contained health information,” meaning the most sensitive category of personal data was implicated.
- The tracking allegedly ran on the tools patients use to manage care, which can chill people’s willingness to use digital health services when trust in confidentiality collapses.
- The class window runs from January 1, 2015 to April 10, 2024, covering roughly nine years of portal users exposed to the underlying privacy risk.
Economic Inequality
- Class Counsel may take up to $500,000 in fees, one-third of the entire $1.5 million Settlement Fund, plus $25,000 in expenses, before patients see a cent.
- The lowest tier of victims (Group 2) is capped at $10 per person, and even that can be reduced pro rata if too many people claim it, against a $300,000 ceiling.
- Actual per-person Group 1 payments are undefined in the documents; they depend on how many valid claims are filed after fees and costs are subtracted, so victims bear the uncertainty.
- Leftover money does not go back to patients as bigger checks; “Residual Funds” go to a charity via cy pres rather than boosting individual recoveries.
Who Pays? Following the Cost
The structure of this settlement moves value away from the injured patients and toward professionals and a charity.
- Up to $500,000 in attorneys’ fees and $25,000 in expenses come out of the $1,500,000 Settlement Fund, reducing what reaches patients before any claim is paid.
- Administration Costs for Group 1 claims (the settlement administrator Kroll, notice, mailing, call center, tax reporting) are also carved out of the same fund.
- Residual Funds left unclaimed are redirected as a cy pres distribution to the Charlotte Center for Legal Advocacy’s Carolinas Medical-Legal Partnership, not to class members.
The Settlement Isn’t Justice
This deal buys Atrium a permanent, sweeping release for a fixed price and admits nothing.
- Atrium’s total exposure is capped in advance at up to $1,800,000 and its liability “shall not exceed” the enumerated obligations, so the harm was converted into a budget line.
- The agreement states plainly it is not “an admission by Defendant of any wrongdoing whatsoever,” so no fault is ever recorded and it cannot be used in regulatory matters.
- The release covers all claims that “were or could have been asserted,” including “Unknown Claims,” a total waiver of even harms patients do not yet know about.
- The lowest tier of class members receives a maximum of $10 each, subject to reduction, for the alleged disclosure of their health-related information to Meta and Google.
- Atrium reserved the right to walk away entirely if just 1% or more of class members opt out, giving the company an escape hatch if too many people object with their feet.
The “Cost of a Life” Metric
Translate the alleged privacy invasion into what a patient in the lowest claim tier is actually offered.
This Is the System Working as Intended
Every element of this outcome was designed to be survivable for the institution and forgettable for the public.
- The federal claim was dismissed and jurisdiction was lost, so the case reached settlement not on the strength of the privacy claims but on the risk and cost of continuing, a dynamic Atrium’s own recitals cite.
- The company capped its liability at up to $1.8M in advance while denying “any wrongdoing whatsoever,” meaning the alleged conduct produces no legal finding and no precedent.
- Because the settlement “shall not be offered or be admissible” against Atrium in any regulatory proceeding, the deal actively insulates the hospital from broader accountability.
- The release sweeps in “Unknown Claims” and a broad web of “Related Parties,” ensuring the cheapest possible resolution closes the maximum number of doors.
What a Legitimate Fix Looks Like
The core failure this case exposes is that a public hospital could allegedly route patient portal activity to advertising companies for years with no contemporaneous disclosure and face only a capped, no-fault payout. The following is editorial analysis, not a finding of the source document.
- Health regulators should require any provider embedding third-party web tools to conduct and publish a mandatory third-party audit of what data those pixels transmit, since here the data allegedly reached Meta and Google unchecked.
- Enforcement should treat undisclosed tracking on health portals as a reportable breach at the time it occurs, not something a Privacy Notice can quietly acknowledge years later, as Atrium did in December 2024.
- Regulators should bar liability caps that let institutions pre-budget privacy harm below the scale of the affected population.
- State law should establish statutory damages for the disclosure of health-related data to third parties, so victims are not left with a $10 pro rata check for a genuine privacy invasion.
- Legislation should prohibit class settlements that release “Unknown Claims” for sensitive health data without heightened judicial scrutiny and clear per-person minimum recovery.
- Lawmakers should require affirmative, contemporaneous consent before any tracking technology operates on a patient portal.
- Atrium’s board should be required to adopt a data-vendor review process that documents every third-party script running on its web properties and the data each one collects.
- Executive compensation tied to digital engagement metrics should be decoupled from any tooling that transmits patient data externally.
- An internal compliance officer with independent reporting authority should sign off before any analytics or advertising pixel is deployed on health pages.
What Now?
Direct your attention to the entity responsible and to the agencies that should have caught this. If you had a MyAtriumHealth or MyCarolinas account between January 1, 2015 and April 10, 2024, your rights are affected whether you act or not.
- The responsible entity is The Charlotte-Mecklenburg Hospital Authority, operating as Atrium Health; if you are a class member, submit a claim before the deadline rather than letting the money default to fees and cy pres.
- Watchlist: the U.S. Department of Health and Human Services Office for Civil Rights (HIPAA enforcement) and the Federal Trade Commission (health data and tracking technologies) are the agencies with jurisdiction over this conduct.
- Support the Charlotte Center for Legal Advocacy’s Carolinas Medical-Legal Partnership, the named cy pres recipient, if you want unclaimed funds to do measurable local good.
- Organize locally to demand your health system publish a full list of every third-party tracker on its patient portal and website.
- Share this with anyone who used an Atrium portal so class members opt in with claims instead of leaving the settlement to expire in silence.
The source document for this investigation is attached below.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →


