Federal Judge Rules that Online Tracking Technologies Guidance Exceeded HHS’ Authority
Time 2 Minute Read

On June 20, 2024, the U.S. District Court for the Northern District of Texas Fort Worth Division ruled that guidance issued by the U.S. Department of Health and Human Services (“HHS”) relating to online tracking technologies exceeded HHS’ authority and ordered that it be vacated. 

As previously reported, on December 1, 2022, HHS released a Bulletin on the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security and Breach Notification Rules when using online tracking technologies. The Bulletin provided several hypotheticals that trigger HIPAA obligations, including when an online technology connects (1) an individual’s IP address with (2) a visit to a unauthenticated public webpage addressing specific health conditions or healthcare providers (the “Proscribed Combination”). The American Hospital Association and other plaintiffs viewed the Proscribed Combination as a new rule and sued to stop enforcement of the rule. Both parties moved for summary judgement and, days before HHS’ brief was due, HHS revised the bulletin, softening its language and stating that it does not have the force and effect of law.

In the case, American Hospital Association v. Becerra, No. 4:23-cv-01110-P, the Court began the quippy decision by stating “Congress passed the Health Insurance Portability and Accountability Act (“HIPAA”) in 1996 because health information needed more protections and the world needed more acronyms.” The Court then went on to agree with the plaintiffs, ruling that HHS exceeded its authority because the bulletins improperly created substantive legal obligations for covered entities with respect to the Proscribed Combination.

The Court rejected the plaintiffs’ request for a permanent injunction to enjoin HHS from enforcing the Proscribed Combination. Instead, the Court declared the Proscribed Combination unlawful and ordered that it be vacated.

You May Also Be Interested In

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page