HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

CVS Health and Criteo Settle $20.5M Class Action Over Unconsented Web Tracker Disclosure of Patient Health Data

CVS Health’s digital properties used Criteo’s advertising script, which captured and sent patients’ personal and health information to the ad firm without consent. The resulting privacy lawsuit settled for $20.5 million, underscoring the need for robust consent and third‑party oversight controls.

Verisq™ Intelligence · 📅 September 17, 2026 · 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

CVS Health and Criteo Settle $20.5M Class Action Over Unconsented Web‑Tracker Disclosure of Patient Health Data

What Happened – CVS Health’s website and mobile apps embedded third‑party tracking code from advertising firm Criteo. The trackers captured and transmitted visitors’ personal and health information—including prescription details, immunization status, and searches for sensitive healthcare products—to Criteo without obtaining user consent. A Florida class‑action lawsuit alleged violations of the Electronic Communications Privacy Act and related state statutes; the parties agreed to a $20.5 million settlement.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of insufficient third‑party oversight: a control objective that requires continuous monitoring of vendor‑supplied code and evidence of consent management.
  • Highlights the need for privacy‑by‑design consent mechanisms (e.g., CookiePLUS) that capture, store, and audit user consent for data collection across web properties.
  • Provides a concrete audit‑ready artifact: a documented consent‑capture process that can be mapped to privacy controls in frameworks such as HIPAA.

Who Is Affected – Retail pharmacy & health‑service providers, digital advertising firms, and any organization that deploys third‑party web trackers on consumer‑facing platforms.

Recommended Actions

  • Conduct an inventory of all third‑party scripts on web and mobile assets; classify them by data‑handling impact.
  • Deploy a consent‑management solution that logs user choices, timestamps, and the specific data elements collected.
  • Integrate continuous monitoring of third‑party code changes into your control‑assurance program and retain audit‑ready evidence. Source: https://www.databreachtoday.com/cvs-criteo-settle-web-tracker-data-privacy-suit-for-205m-a-32845

Technical Notes

  • Attack vector: Third‑party dependency – embedded advertising script captured form fields and URL parameters containing health data.
  • Data types exposed: Personal identifiers, prescription details, immunization records, search queries for health products. Source: https://www.databreachtoday.com/cvs-criteo-settle-web-tracker-data-privacy-suit-for-205m-a-32845
📰 Original Source
https://www.databreachtoday.com/cvs-criteo-settle-web-tracker-data-privacy-suit-for-205m-a-32845

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →