The $1.55M Mistake Healthcare Marketers Are Making Outside HIPAA
Por David A. Prado, Esq., The Prado Law Firm, LLC
There is a category of company that has spent a decade believing it sits in a regulatory quiet zone. It handles health-adjacent data every day but is not a hospital, not a health plan, not a business associate. It runs HCP engagement programs, pharmaceutical brand media, condition-education publishing, patient-finder campaigns, and the advertising technology that measures all of it. Its privacy program, if it has one, was built around a single question: are we a HIPAA covered entity? The answer was no, and the analysis stopped.
California has ended that quiet zone. Over roughly six months in 2025, the California Privacy Protection Agency and the California Attorney General brought four enforcement actions that share a common allegation: the company transferred personal information to vendors and partners without the written contract that Civil Code Section 1798.100(d) requires. The fourth of those actions, and the largest, targeted a health publisher. Nothing about the underlying conduct was unusual for the healthcare marketing industry. That is the point.
Four cases, one theme
Honda (March 2025). The CPPA's first public enforcement action fined American Honda $632,500. The headline issues involved opt-out friction and verification requirements for opt-out requests. But the agency also found that Honda had no contracts, or inadequate ones, with the advertising technology companies receiving data from its website, and ordered it to fix them.
Todd Snyder (May 2025). A menswear retailer paid $345,178. The CPPA found that the company's consent management platform had been misconfigured for months and that the company had not contracted properly with the third parties receiving consumer data through tracking technologies. The agency's message was that a business owns its compliance even when a privacy tool fails.
Tractor Supply (September 2025). The CPPA's largest fine to date, $1.35 million, resolved allegations that the retailer failed to notify consumers and job applicants of their rights, failed to provide a functional opt-out, and offered inadequate service provider contracts.
Healthline Media (July 2025). The Attorney General secured $1.55 million, the largest CCPA settlement on record. Healthline is one of the most visited websites in the world, and the AG estimated 6.5 million California visitors per month. The complaint alleged three violations. Healthline continued to share data with advertising partners after consumers opted out, including through Global Privacy Control signals. It violated the purpose limitation principle in Section 1798.100(c) by sharing article titles that signaled a likely diagnosis, such as content written for people newly diagnosed with multiple sclerosis, tied to a persistent identifier. And its contracts with the recipients of that data did not contain the terms Section 1798.100(d) requires.
The contract finding in Healthline deserves attention because of how it happened. Healthline relied on the IAB Multi-State Privacy Agreement to cover its advertising partners. The AG found that several partners were not MSPA signatories. For those partners, the framework was simply not in effect, so the AG went to Healthline's own agreements and found them deficient. The consent order allows Healthline to keep using the MSPA but requires an annual review of the signatory list to confirm every partner is still covered.
What Section 1798.100(d) actually requires
The CPRA amendments added the contract requirement effective January 1, 2023. A business that sells, shares, or discloses personal information to a third party, service provider, or contractor must enter into a written agreement that:
specifies that the personal information is sold or disclosed only for limited and specified purposes;
obligates the recipient to comply with applicable CCPA obligations and to provide the same level of privacy protection the statute requires;
grants the business the right to take reasonable and appropriate steps to help ensure the recipient uses the personal information in a manner consistent with the business's own obligations;
requires the recipient to notify the business if it determines it can no longer meet its obligations; and
grants the business the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use.
The CPPA regulations layer on more. Regulation Section 7051 governs service providers and contractors and requires, among other things, an express prohibition on selling or sharing the data, a prohibition on combining it with data from other sources outside the permitted business purposes, and a requirement that the recipient permit compliance audits. Regulation Section 7053 governs third parties and requires the contract to identify the limited and specified purposes and to require the third party to check for and honor opt-out signals.
Two practical lessons come out of the enforcement record. First, generic language fails. A contract that permits use for "any business purpose" or "internal operations" does not identify limited and specified purposes. Second, the classification matters. Whether a recipient is a service provider or a third party determines which regulation applies, which terms are required, and whether the transfer is a "sale" or "share" that triggers opt-out rights. Most advertising technology relationships in healthcare media are third-party relationships, not service provider relationships, and the contracts need to reflect that.
The HIPAA exemption is narrower than the industry assumes
Section 1798.145(c) exempts protected health information collected by a HIPAA covered entity or business associate, and medical information governed by California's Confidentiality of Medical Information Act. It also exempts data de-identified under HIPAA standards, subject to conditions.
That exemption is data-specific and entity-specific. It does not exempt a company because it works in healthcare. It does not exempt health-signaling data that never passed through a covered entity. And it does not exempt information about healthcare professionals.
Consider what falls outside the exemption and inside the CCPA:
HCP engagement data. A physician is a California consumer. The CCPA's temporary exemptions for business-to-business contacts and employee data expired on January 1, 2023 and were not renewed. A platform holding an HCP's name, NPI, specialty, practice address, prescribing behavior, email opens, content views, and predicted receptivity to a brand message holds personal information subject to every CCPA right and every contract requirement. That data typically flows among pharmaceutical manufacturers, agencies, data providers, and engagement platforms under agreements written for a different era. Many of those agreements have never been reviewed against Section 1798.100(d).
Pharmaceutical brand and disease-awareness media. Unbranded condition sites, branded product sites, copay and patient support enrollment, and patient-finder advertising all collect data from people who are not anyone's patient. A visit to a page about a specific therapy, tied to a cookie or a hashed email, is the Healthline fact pattern. The AG called that data "highly intimate" without ever deciding whether it qualifies as "sensitive personal information" under the statute, and imposed the largest penalty in the law's history anyway.
Health publishers, marketplaces, and wellness apps. Symptom checkers, telehealth lead generation, pharmacy price comparison, fitness and nutrition apps, and health content publishers operate entirely in this space. Their monetization model depends on transferring audience data to advertising and measurement partners. Every one of those transfers requires a compliant contract.
The instinct in this industry is to reach for a business associate agreement. That is the wrong instrument. A BAA governs PHI between a covered entity and its vendor. It does not satisfy Section 1798.100(d), and in most healthcare marketing transactions there is no covered entity in the chain to sign one.
The wider enforcement environment
The contract cases are not happening in isolation. Pixel litigation against healthcare providers has produced more than $100 million in settlements since 2023, and plaintiffs' firms have moved to template complaints aimed at smaller operators. California's risk assessment regulations took effect January 1, 2026, requiring documented assessments for high-risk processing including selling or sharing personal information and processing sensitive data. Automated decision-making technology rules follow in 2027. The CPPA now has a track record, a budget, and a demonstrated willingness to audit contracts rather than take a privacy policy at face value.
For a company that sells or shares health-signaling data, a missing or generic vendor contract is no longer a technical gap. It is an enforcement finding waiting for an investigator.
A practical program for HCP engagement and pharma media companies
Inventory every transfer. Pixels, tags, SDKs, server-side integrations, clean rooms, list uploads, data appends, and reporting feeds. Each one has a counterparty and a data set.
Classify each counterparty. Service provider, contractor, or third party. Be honest. A demand-side platform that uses your data to build audiences for other clients is a third party regardless of what the order form says.
Paper every transfer. Confirm a signed agreement containing all Section 1798.100(d) terms and the applicable Regulation 7051 or 7053 terms. Where you rely on an industry framework such as the MSPA, verify the counterparty is on the current signatory list and calendar an annual re-check. Where it is not, execute your own addendum.
Treat health-signaling and HCP data as sensitive. The statute's definition of sensitive personal information may or may not capture a condition-level page view. Regulators have shown they will enforce on purpose limitation grounds either way. Build purpose restrictions into the contract and into the data flow.
Test opt-out end to end. Confirm that a Global Privacy Control signal actually stops the transfer at the tag, at the server, and at the partner. Honda, Todd Snyder, and Healthline all failed here.
Document the risk assessment. California now requires it for selling and sharing. Use it to record the contract review, the classification decisions, and the purpose limitations.
Conclusion
The healthcare marketing industry built its privacy posture around a HIPAA question that, for most of the industry, was never the right question. California has now answered the right one. Health-signaling data and HCP data are personal information, transfers of that data require specific written contracts, and regulators will ask to see them. Companies in HCP engagement and pharmaceutical media should assume they are the next Healthline and paper their data flows accordingly.
