CVS Health and Criteo Settle $20.5M Class Action Over Unconsented Web‑Tracker Disclosure of Patient Health Data
What Happened – CVS Health’s website and mobile apps embedded third‑party tracking code from advertising firm Criteo. The trackers captured and transmitted visitors’ personal and health information—including prescription details, immunization status, and searches for sensitive healthcare products—to Criteo without obtaining user consent. A Florida class‑action lawsuit alleged violations of the Electronic Communications Privacy Act and related state statutes; the parties agreed to a $20.5 million settlement.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of insufficient third‑party oversight: a control objective that requires continuous monitoring of vendor‑supplied code and evidence of consent management.
- Highlights the need for privacy‑by‑design consent mechanisms (e.g., CookiePLUS) that capture, store, and audit user consent for data collection across web properties.
- Provides a concrete audit‑ready artifact: a documented consent‑capture process that can be mapped to privacy controls in frameworks such as HIPAA.
Who Is Affected – Retail pharmacy & health‑service providers, digital advertising firms, and any organization that deploys third‑party web trackers on consumer‑facing platforms.
Recommended Actions
- Conduct an inventory of all third‑party scripts on web and mobile assets; classify them by data‑handling impact.
- Deploy a consent‑management solution that logs user choices, timestamps, and the specific data elements collected.
- Integrate continuous monitoring of third‑party code changes into your control‑assurance program and retain audit‑ready evidence. Source: https://www.databreachtoday.com/cvs-criteo-settle-web-tracker-data-privacy-suit-for-205m-a-32845
Technical Notes
- Attack vector: Third‑party dependency – embedded advertising script captured form fields and URL parameters containing health data.
- Data types exposed: Personal identifiers, prescription details, immunization records, search queries for health products. Source: https://www.databreachtoday.com/cvs-criteo-settle-web-tracker-data-privacy-suit-for-205m-a-32845