FINDING 01 · PRIVACY & COMPLIANCE
A class-action waiting to happen.
Meta Pixel, LinkedIn Insight Tag, and Google Ads remarketing all fire on harborviewcare.org pages that collect program-of-interest data — including the Request Info form where users specify which condition or care type they need.
Context: In the past four years, the U.S. Department of Health and Human Services Office for Civil Rights, the FTC, and several state Attorneys General have specifically targeted hospital and provider websites that load Meta Pixel on pages collecting condition-related data. Multiple peer healthcare organizations have settled class-action complaints in the eight-figure range. This site was loading these pixels before the user had even responded to the cookie consent banner.
impact
Significant HIPAA / OCR enforcement exposure. Class-action precedent at peer providers. Pre-consent firing also creates GDPR/CCPA non-compliance for any visitor in those jurisdictions.
recommendation
Engage privacy counsel immediately. Gate marketing pixels behind explicit opt-in consent. Strongly consider removing them from /request-info/ and condition-specific pages entirely.