Health Privacy

California’s Healthline.com Enforcement Action Shows CCPA’s Teeth – and Sensitive Data Reach

The California Attorney General’s Office (“OAG”) announced an enforcement action against Healthline.com on July 1 that marks a significant development in California Consumer Privacy Act (CCPA) enforcement. This action, accompanied by the largest fine under CCPA yet at $1.55 million, highlights critical areas of consideration for any company engaging in the advertising ecosystem as well as any company that processes sensitive personal information.

Healthline is a popular website that hosts articles on various health conditions. According to the OAG’s complaint, Healthline collected browsing activity that constituted personal information and then disclosed the information via tracking technology with a litany of third-party advertising partners. The enforcement action is noteworthy because it:

  1. marks the first use of the CCPA’s purpose limitation requirement, a significant development in enforcement tools;

  2. raises a series of issues to consider with respect to sharing personal information with third parties, from a business’ own implementation considerations to critical contract terms; and

  3. is yet another datapoint to consider when defining what constitutes sensitive personal information, especially with respect to browsing activity.

We’ll discuss each in turn below.

(1) Purpose limitation is on the privacy enforcement menu.

To date, most OAG CCPA enforcement actions have focused on more narrow issues that do not address the substantive question of data use. For example, whether a disclosure was made, or whether a certain control was available to users. This enforcement shows the CCPA’s teeth with respect to the use of personal information for certain purposes. The CCPA’s “purpose limitation” principle states:

“A business’ collection, use, retention, and sharing of a consumer’s personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.”

The CCPA regulations clarify that, under this principle, secondary uses must be consistent with the “reasonable expectations of the consumer.” A number of factors are used to determine this, including the nature or sensitivity of the personal information, the “specificity, explicitness, prominence, and clarity of disclosures,” and the degree to which third parties’ role in processing that data is evident to the consumer.

The OAG used this use limitation principle to argue that processing data collected via Healthline’s tracking technology—including views on web pages with titles such as “Newly Diagnosed with HIV? Important Thing to Know”—violated the use limitation requirement and therefore violated the CCPA. The requirement was violated in two ways:

  1. When Healthline.com disclosed “health-related data” for advertising and,

  2. When Healthline.com disclosed personal information to third parties in order for the third party to create health-related inferences based on articles a consumer read.

Both of these uses were unexpected, according to the complaint, and therefore violated the use limitation principle.

The OAG did not allege that this browsing activity was sensitive data under the CCPA despite it being “health-related data.” However, the enforcement action does make it clear that the more sensitive the information shared, the less evident it would be to the average consumer that their information would be shared, especially for advertising purposes. Therefore, businesses should expect the OAG to more strictly limit the secondary use of sensitive types of personal information, whether defined under the CCPA as sensitive personal information or not.

The OAG’s novel use of this provision of the CCPA should be taken note of by any business subject to the CCPA. Businesses that engage in behavioral advertising in particular should perform purpose limitation analyses on their secondary uses and document their assessment justifying those secondary uses. This is especially critical for any business processing sensitive (or adjacent) personal information.

(2) Vendor and cookie contract management is not easy—nor should it be ignored.

At first look, Healthline’s website appeared to offer CCPA-compliant sharing and selling controls: the company had a Do Not Sell link on their site, claimed to respond to Global Privacy Control Signals, and, though not required (or often advisable), had a pop-up asking users to accept their privacy policy.

The OAG didn’t stop at accepting facial compliance. The investigators evaluated the efficacy of the controls. According to the complaint, Healthline’s controls weren’t actually effective, and personal information was still disclosed to advertising partners post opt-out. The complaint suggested—but did not specifically allege—that investigators were shown personalized ads using personal information from Healthline after they opted out via all three controls.

The allegations surrounding Healthline’s tracking technology controls—namely, that third-party advertising partners continued to receive and use data after individuals opted out—seems basic, but implementation requires constant upkeep. The intersection between cookie controls and contract terms is of particular note in this action. Incorporating the correct contract terms for third party data sharing is critical. Additionally, overreliance on plug-and-play solutions may lead to trouble, and cookie management programs need to regularly evaluate the efficacy of privacy controls.

According to the complaint, Healthline sent a “U.S. Privacy String” to its advertising vendors that should have communicated consumers’ opt-out from the sale or sharing of their personal information. Upon receipt of that string, vendors should not use that personal information where use would constitute a sale of personal information to the vendor. But as this enforcement action demonstrates, simply sending the privacy string to vendors is insufficient.

CCPA includes a safe harbor provision that shields businesses from liability when they pass a privacy string along to a third party and the party fails to adhere to the limitations associated with the string. The safe harbor only applies, however, when the business “does not have actual knowledge, or reason to believe, that the [recipient]” intends to not adhere to the privacy string. Here, the OAG claimed the safe harbor does not apply to Healthline because their contracts did not require third parties to adhere to the privacy string. Had the appropriate contract terms been in place, it’s likely the company would have met the safe harbor provision.

This enforcement action is an important reminder to businesses that advertising contracts—often presented as non-editable by opposing parties—need a hard look and should not be accepted off the shelf without thorough analysis.

(3) Sensitive personal information is still hard to define, for businesses and regulators

The OAG used phrases that should ring alarm bells. They described the data disclosed by Healthline as "highly intimate," "health-related," "potential health information," and "referencing current diagnoses of serious diseases.” There is one phrase, however, that was never used in the complaint: sensitive personal information. There was also never a reference to California’s Right to Limit Use and Disclosure of Sensitive Personal Information, which allows consumers to limit use of their sensitive personal information to a defined set of purposes.

California defines sensitive personal information, in relevant part, as personal information that reveals “personal information collected and analyzed concerning a consumer’s health.” It could be argued that “highly intimate” and “health-related” information “referencing current diagnoses of serious diseases” would fall within that definition.

However, in this enforcement action, it’s unclear why the OAG declined to address this in the complaint. It’s possible the OAG was worried about a statutory challenge, similar to what happened when the Department of Health and Human Services attempted to classify health-related browsing on unauthenticated webpages as Protected Health Information (PHI). The attempt was overturned in court, perhaps feeling there is a stronger case under the use limitation principle. California, unlike most states with comprehensive privacy laws, does not require consent to process sensitive personal information and did not need to raise the protections specific to sensitive personal information.

Furthermore, this enforcement action leaves businesses without additional direction or guidance regarding how to draw the line on what constitutes sensitive personal information. For Healthline, the lines are fuzzy; whereas in the familiar line of Federal Trade Commission (FTC) cases, there was a direct tie to a health condition. Now, there is a CCPA action where simply viewing an article is “health-related,” but not conclusively considered sensitive personal information.

While the OAG did not mention sensitive personal information in the complaint, it is mentioned in the proposed order with Healthline. The order includes a prohibition on disclosure of sensitive personal information for advertising purposes without providing notice that “clearly states that it uses and discloses” consumer’s “sensitive personal information for advertising purposes.” This is separate from the order’s outright prohibition on disclosing consumers’ browsing activity on “diagnosed medical condition article[s].”

The OAG’s approach on this may be confusing, but the message is clear: the lines drawing the definition of sensitive data are ever-moving, and regulators will continue to direct their focus on sensitive personal information—or, in this case, “health-related” personal information that does not meet the definition of sensitive personal information.

What businesses need to do

This is an important enforcement action that introduces new tools to regulators’ toolchest. If your business falls in scope of the CCPA, you need to:

  • Incorporate a purpose limitation test into the current privacy program, particularly with respect to the disclosure of personal information with advertising partners, and especially if it involves sensitive personal information or personal information relating to sensitive topics;

  • Perform regular audits of all privacy controls, including do not sell controls and opt outs of targeted advertising, and make sure the end-to-end process works as expected;

  • Audit contracts with all third parties to whom your business sells personal information to and make sure there are terms that prohibit the further use or sale of personal information upon a consumer’s opt out; and

  • Continue to re-evaluate how to define sensitive personal information and adjust the definition to incorporate this new data point.

Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on global privacy, data security, and AI law. Its attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of privacy, data security, and AI law.

Mason Fitch is Of Counsel at Hintze Law PLLC and a member of the firm’s Health & Biotech Team

 

Kate Black is a Partner at Hintze Law PLLC and is chair of the firm’s Health and Biotech Privacy Group, and co-chair of the Regulatory Defense Group, and Artificial Intelligence and Machine Learning Group.

Congratulations to Mason Fitch on Promotion to Of Counsel

Hintze Law PLLC is pleased to announce Mason Fitch’s promotion to Of Counsel at the firm.

Mason is a member of the firm’s Health & Biotech Team and recently recognized by Chambers & Partners as an Associate to Watch in the 2025 USA Guide—Healthcare: Texas. Mason’s clients praise his “excellent knowledge of the industry and where the industry is going,” and for “provid[ing] practical advice.” Clients also said, “Mason is great to work with and fully delivers what we need him to.”

“We are excited to announce Mason as Hintze Law’s newest Of Counsel,” said Hintze Law Co-Managing Partner, Susan Hintze. “Mason stands out as a leading authority in AI and privacy law, demonstrating an exceptional grasp of both complex legal frameworks and the evolving landscape of data-driven business. His insightful, pragmatic guidance consistently benefits clients, making him an indispensable asset to the Hintze Law team and a trusted advisor to those navigating the intricacies of data protection.”

Mason has distinguished himself as a trusted advisor to a wide variety of clients ranging from dynamic startups to Fortune 100 corporations. Mason’s deep knowledge and pragmatic approach enable clients—both in the U.S. and internationally—to confidently address the challenges of an ever-evolving regulatory environment. Read Mason’s recent insights on the Hintze Law Blog and in recent coverage.

Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on global privacy, data security, and AI law. Its attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of privacy, data security, and AI law.

Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Texas District Court Vacates Majority of HIPAA Reproductive Privacy Rule

Texas District Court Vacates Majority of HIPAA Reproductive Privacy Rule

by Cameron Cantrell and Felicity Slater 

On June 19, 2025, the U.S. District Court in the Northern District of Texas vacated the vast majority of the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (the “HIPAA Reproductive Privacy Rule” or “Rule”). The Department of Health and Human Services (“HHS”) published the Rule in the Federal Register in April 2024 with a compliance date of December 23, 2024. The District Court’s decision to vacate the reproductive privacy aspects of the Rule has an immediate and nationwide effect.

Read More

Hintze & Partners Recognized by Chambers in 2025 USA Rankings

Hintze & Partners Recognized by Chambers in 2025 USA Rankings

Hintze Law PLLC is delighted to announce the Chambers & Partners recognition of Susan Hintze, Mike Hintze, Sam Castic, and Mason Fitch in its USA Guide 2025. These recognitions include the firm’s sixth year being nationally ranked in Privacy and Data Security, and third year in Privacy & Data Security: Healthcare.

Read More

Virginia Governor Signs Reproductive Health Data Restrictions into Law

Virginia Governor Signs Reproductive Health Data Restrictions into Law

by Cameron Cantrell and Felicity Slater 

On March 24, 2025, Governor Youngkin (R) of Virginia signed SB 754—which amends the Virginia Consumer Protection Act (VCPA) to restrict the collection and processing of “reproductive or sexual health information” and is enforceable through a private right of action—into law. The law will take effect July 1, 2025. 

Read More

Fourth Circuit Publishes Landmark Ruling on 21st Century Cures Act “Information Blocking”

By Cameron Cantrell and Kate Black

On March 12, 2025, the Fourth Circuit Court of Appeals ruled that (1) the information blocking prohibition in the federal 21st Century Cures Act (“Cures Act”) was plausibly violated when an Electronic Health Record (EHR) provider blocked bot access to its systems without sufficient justification, and (2) this violation may support a Maryland state law unfair competition claim, despite the Cures Act not having its own private right of action. This decision notably appears to be the first Circuit Court decision concerning the information blocking prohibition and, for parties subject to the rule, raises the risk that information blocking may be enforceable through a de facto state privacy right of action.

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night

Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night

By Felicity Slater and Kate Black

The Maryland Online Data Privacy Act (“MODPA” or the “Act”), which takes effect October 1, 2025, establishes a set of novel requirements that will have a particular impact for companies operating in the health and wellness sectors. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Hintze & Partners Recognized by Chambers in 2025 Global Rankings

Hintze & Partners Recognized by Chambers in 2025 Global Rankings

Hintze Law and its lawyers have once again been recognized in Chambers & Partners for expertise in Privacy and Data Security in the 2025 Chambers Global Guide. These recognitions include Hintze Law’s fifth year being ranked as an Elite Law Firm for Privacy and Data Security as well as the firm’s second year receiving recognition for Privacy and Data Security: Healthcare.

Read More

New York Legislature Passes Extraordinarily Restrictive Health Data Privacy Bill

New York Legislature Passes Extraordinarily Restrictive Health Data Privacy Bill

By Mike Hintze and Felicity Slater

Last year, we wrote about a proposed New York State law that would have significant impacts for entities that process health and wellness related data. That bill failed to pass before the 2024 legislative session ended. But today, in the early days of the 2025 session, the New York State legislature has passed Senate Bill S929 (SB S929), which is essentially unchanged from last year’s bill.  

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

In ‘Holy Redeemer’ Settlement Agreement, OCR Continues to Prioritize Privacy Protections for Reproductive Health Information

In ‘Holy Redeemer’ Settlement Agreement, OCR Continues to Prioritize Privacy Protections for Reproductive Health Information

by Felicity Slater and Kate Black

On November 26, 2024, the Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announced a resolution agreement and corrective plan with Pennsylvania’s Holy Redeemer Hospital (Holy Redeemer). The agreement settles OCR’s claim that Holy Redeemer disclosed a patient’s protected health information (PHI)—including intimate reproductive health details—without a permissible purpose or valid authorization from the patient in violation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule

Read More

A Last-Minute Push for a Reproductive Health Privacy Law in Michigan

A Last-Minute Push for a Reproductive Health Privacy Law in Michigan

By Mike Hintze and Felicity Slater 

On November 7, 2024, the Michigan legislature introduced Senate Bill 1082 / House Bill 6077, the Reproductive Data Privacy Act (the “RDPA” or the “act”). The act was introduced in the aftermath of the 2024 election cycle as Michigan Democrats brace to lose control of the House in 2025. At a hearing in the Senate Committee on Housing and Human Services, lawmakers backing the RDPA expressed a hope to pass the act before the year’s end. 

Read More

Washington My Health My Data Act - Part 4: Effective Dates

By Mike Hintze

Yesterday the amended Senate version of the Washington My Health My Data Act was approved by the Washington State Legislature. Now that it is a near certainty the Act will become law in its current form, entities subject to the Act need to start preparing to comply. The key factor in determining deadlines for having compliance measures in place is the effective date of the Act. The Act purports to come into effect on March 31, 2024 (and for small businesses, three months later on June 30, 2024). However, contrary to stated legislative intent, and due to what one can only conclude is, at least in part, a drafting error, some of the key substantive provisions of the Act may come into effect much sooner than expected - as soon as July 2023. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Washington My Health My Data Act - Part 3: The Scope of Entities and Consumers Captured by the Act

By Mike Hintze

The Washington My Health My Data Act applies to “regulated entities” that collect or process “consumer health information” from “consumers.” Part two of this series addressed the definition of “consumer health data” and how that definition results in a scope of applicability that is far beyond what we might typically think of as sensitive health data. But the other two above-quoted defined terms – “regulated entity” and “consumer” also result in a very broad (and in some ways surprising) scope and impact. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Washington My Health My Data Act - Part 2: The Scope of “Consumer Health Data”

By Mike Hintze

The substantive requirements of the Washington My Health My Data Act apply to collection, use, and disclosure of “consumer health data.” While there are a few important exclusions, the stunning breath of that term's definition, means that it will be difficult to safely conclude that any category of personal data is out of scope of the Act. As a result, it is inaccurate to refer to the Washington My Health My Data Act as a “health data privacy law.” On the contrary, it is, in effect, a generally-applicable privacy law. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

The Washington My Health My Data Act - Part 1: An Overview

By Mike Hintze

The Washington My Health My Data Act will become the most consequential privacy legislation enacted in 2023. The sweeping scope and extreme substantive obligations, combined with vague terms and with a full private right of action, make this Act extraordinarily challenging and risky for entities seeking to comply with its requirements.

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze