Advertising and analytics code tucked into a pharmacy’s website can quietly carry away more than a shopping cart. A proposed $20.5 million settlement would resolve claims that code planted across CVS digital properties shipped shoppers’ health, personal, and browsing details to Criteo and other outside vendors.
Payouts reach $5 with no paperwork and $10 with documentation, limited to one per household. To qualify, a person had to use a CVS digital property before July 27, 2026, whether the flagship site, CVSHealth.com, or the mobile app. The claim window shuts November 16, and final approval arguments are set for December 1. Both CVS and Criteo deny the allegations.
The stakes reach past retail pharmacy. A person’s prescriptions and the conditions they manage can be inferred from where they click, and courts have treated that blend as sensitive even when a company argues it is not a HIPAA covered entity. Health systems have absorbed the same lesson through pixel-tracking suits that cost Allina Health $12.5 million, a Georgia system $4.5 million, and Cone Health $1.76 million. Marketing tags, session-replay scripts, and analytics pixels deserve the vendor review any system touching patient data gets, and a consent banner does not close the question.