Back to Intelligence

Fairchild Medical Center & Boone Health Pixel Settlements: Detecting and Removing Patient Portal Trackers Before OCR Does

SA
Security Arsenal Team
October 2, 2026
12 min read

Fairchild Medical Center and Boone Health have agreed to settle class action lawsuits alleging they impermissibly disclosed patient data to Meta and other third parties through tracking pixels embedded in their websites and patient portals. These are not isolated events — they are the latest entries in a growing line of pixel litigation and OCR enforcement that has already cost healthcare organizations tens of millions of dollars collectively. If your organization operates a public website, a scheduling page, or — worst case — an authenticated patient portal with third-party tracking code on it, you are carrying the same regulatory and litigation exposure these two systems just paid to resolve.

What Happened

Fairchild Medical Center, a California-based provider, and Boone Health, a Missouri-based system, both faced complaints alleging that tracking technologies deployed on their web properties transmitted patient information to Meta Platforms and other advertising technology companies without authorization and without a Business Associate Agreement (BAA) in place. The alleged disclosures followed the pattern we've seen across dozens of similar complaints since 2022: a patient logs into a portal, searches for a provider, views a condition-specific page, or schedules an appointment — and the pixel quietly transmits the page URL, button interactions, IP address, device identifiers, and in some cases form-field content to Meta's servers.

The settlements resolve the complaints without admission of wrongdoing, as is standard — but the financial and operational fallout is real: settlement funds, mandatory notification, credit monitoring in some pixel-adjacent cases, and the near-certainty of OCR scrutiny following public litigation. The plaintiffs' bar has industrialized these claims, frequently leveraging state wiretap statutes (California's CIPA chief among them) and consumer protection laws alongside HIPAA theories. Every health system marketing team that dropped a pixel on a scheduling page three years ago is a potential defendant today.

Technical Analysis: How the Disclosure Actually Works

There is no CVE here — no software vulnerability, no exploit chain. The 'attack surface' is a feature working exactly as designed, deployed in the wrong place. Understanding the mechanics matters because remediation requires knowing precisely what to hunt.

The Meta Pixel is a JavaScript snippet that loads fbevents.js from connect.facebook.net and initializes with a pixel ID via fbq('init', '<PIXEL_ID>'). From that point forward:

  • Automatic PageView events fire on every page load, transmitting the full URL (which on portals often contains condition-specific paths like /oncology/appointment or query strings with search terms), the referrer, timestamp, IP address, and browser fingerprint.
  • Standard and custom events (fbq('track', 'Schedule'), fbq('track', 'CompleteRegistration')) fire on button clicks and form submissions — exactly the actions that constitute an individual's interaction with healthcare services.
  • Automatic Advanced Matching can scrape form fields — names, emails, phone numbers — hash them, and transmit them to Meta for identity resolution. If this was enabled on a portal login or appointment form, identifiable patient data left your environment.
  • The Meta cookie (_fbp, _fbc) ties the session to a persistent identifier, meaning subsequent visits are correlated into a longitudinal profile of a patient's interaction with your health system.

The critical distinction defenders and privacy officers must internalize: OCR's December 2022 bulletin (and its subsequent updates) draws a line between unauthenticated public pages and authenticated portals. On authenticated pages, the disclosure of IP address plus health-service interaction is essentially per se an impermissible disclosure of PHI without a BAA — and Meta will not sign a BAA. On unauthenticated pages, OCR's position was partially vacated in the June 2024 AHA v. HHS ruling, but state wiretap claims (CIPA), FTC unfairness theories, and common-law privacy claims remain fully alive. The litigation pipeline did not slow down after AHA; it shifted legal theories.

Other trackers in scope for the same exposure: Google Analytics (gtag.js, analytics.js), Google Tag Manager containers, TikTok Pixel (analytics.tiktok.com), Snap Pixel, and any session-replay tooling (Hotjar, FullStory, Microsoft Clarity) that records form interactions.

Detection & Response

Your detection strategy has two surfaces: (1) the source code surface — find tracker code in your web properties — and (2) the network egress surface — find endpoints and servers talking to ad-tech collection endpoints. Do both. Source scans tell you what marketing deployed; egress hunting tells you what's actually firing, including trackers injected by third-party tag managers you didn't know were loading.

Sigma Rules

YAML
---
title: Outbound Connection to Meta Pixel Collection Endpoint
title_note: Detects browsers or processes reaching Meta tracking infrastructure from corporate/clinical networks
id: 9f2b7c41-3a58-4e1d-b6c3-7d0e5f8a2b14
status: experimental
description: Detects network connections to Meta Pixel collection and script delivery endpoints. Clinical workstations and hospital VLANs should have no business reason to contact ad-tech infrastructure. Hits may indicate tracker-laden internal web apps, shadow browsing, or pixel code firing from intranet portals.
references:
  - https://www.hipaajournal.com/fairchild-medical-center-boone-health-pixel-settlements/
  - https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
author: Security Arsenal
date: 2026/02/10
tags:
  - attack.collection
  - attack.exfiltration
logsource:
  category: network_connection
  product: windows
detection:
  selection_meta:
    DestinationHostname|contains:
      - 'connect.facebook.net'
      - 'facebook.com/tr'
      - 'graph.facebook.com'
  selection_tiktok:
    DestinationHostname|contains:
      - 'analytics.tiktok.com'
  filter_cdn:
    DestinationHostname|endswith:
      - '.fna.fbcdn.net'
  condition: (selection_meta or selection_tiktok) and not filter_cdn
falsepositives:
  - Marketing department workstations with legitimate social media access
  - General user browsing on guest networks (scope to clinical/server VLANs to reduce noise)
level: medium
---
title: Meta Pixel or Ad Tracker Request Observed in Proxy Logs from Healthcare Web Servers
id: 2c8e4a97-61d3-4b5f-9e02-8a1c6d3f5b77
status: experimental
description: Detects HTTP requests to advertising pixel collection endpoints observed in proxy/firewall logs. Use to discover which internal endpoints and user segments are triggering ad-tech beacons, and to validate that tracker remediation actually took effect. A drop to zero hits after pixel removal from portal code confirms remediation.
references:
  - https://www.hipaajournal.com/fairchild-medical-center-boone-health-pixel-settlements/
  - https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
author: Security Arsenal
date: 2026/02/10
tags:
  - attack.collection
logsource:
  category: proxy
detection:
  selection_uri:
    c-uri|contains:
      - 'facebook.com/tr?'
      - 'facebook.com/tr/'
      - '/en_US/fbevents.js'
      - 'analytics.tiktok.com/i18n/pixel'
      - 'google-analytics.com/g/collect'
  selection_host:
    c-hostname|contains:
      - 'connect.facebook.net'
  condition: selection_uri or selection_host
falsepositives:
  - Consumer devices on guest Wi-Fi
  - Marketing-managed campaign landing pages where tracking is intentionally deployed and documented
level: low

Two notes on tuning: scope rule one to clinical VLANs and server subnets — on general user networks it will fire constantly and get disabled. Rule two is deliberately low-severity and is best used as a hunting/baselining rule to enumerate exposure and verify remediation, not as an alerting rule.

KQL — Microsoft Sentinel / Defender

This hunt enumerates every device in your environment generating beacon traffic to ad-tech collection endpoints over the last 14 days, pivots on the initiating process, and flags devices in clinical OU naming conventions. Run it, export the results, and hand the device list to your web/privacy team as the authoritative exposure inventory.

KQL — Microsoft Sentinel / Defender
let AdTechEndpoints = dynamic([
    "connect.facebook.net",
    "graph.facebook.com",
    "analytics.tiktok.com",
    "tr.snapchat.com",
    "google-analytics.com",
    "googletagmanager.com",
    "script.hotjar.com",
    "clarity.ms"
]);
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (AdTechEndpoints) or RemoteUrl contains "facebook.com/tr"
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
            ConnectionCount = count(),
            RemoteUrls = make_set(RemoteUrl, 10)
        by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine
| extend IsServerProcess = InitiatingProcessFileName in~ ("w3wp.exe", "nginx.exe", "httpd.exe", "node.exe", "java.exe")
| extend RiskNote = case(
    IsServerProcess, "HIGH: Server-side process emitting ad-tech traffic - check for server-side tagging or injected code",
    InitiatingProcessFileName has_any ("chrome", "msedge", "firefox"), "Browser session - identify which internal site loaded the tracker",
    "Investigate process")
| order by IsServerProcess desc, ConnectionCount desc

If you ingest proxy or firewall logs into Sentinel via CommonSecurityLog, this companion query gives you the URL-level view — critical for identifying which pages (e.g., /portal/oncology/appointments) are leaking:

KQL — Microsoft Sentinel / Defender
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where RequestURL contains "facebook.com/tr" or RequestURL contains "fbevents.js" or RequestURL contains "google-analytics.com/g/collect"
| extend RefererPage = extract(@"referer=([^&]+)", 1, RequestURL)
| summarize Hits = count(), SampleURLs = make_set(RequestURL, 5)
        by SourceIP, DeviceHostName, RefererPage
| order by Hits desc

Velociraptor VQL — Web Root Tracker Sweep

Use this as a hunt across your web servers (IIS, Apache, Nginx) to find tracker references embedded in site content, templates, and JavaScript bundles. This catches what marketing deployed directly; combine with egress data to catch what tag managers inject at runtime.

VQL — Velociraptor
-- Hunt: Sweep web roots for third-party tracking pixels and tag manager references
-- Targets Meta Pixel, Google Tag/Analytics, TikTok, Snap, and session replay tools
LET tracker_regex = '(fbevents\.js|connect\.facebook\.net|fbq\(|googletagmanager\.com|gtag\(|analytics\.tiktok\.com|tr\.snapchat\.com|hotjar|clarity\.ms)'

SELECT FullPath,
       Mtime,
       Size,
       String AS MatchedContent
FROM foreach(
    row={
        SELECT FullPath, Mtime, Size
        FROM glob(globs=[
            'C:/inetpub/wwwroot/**/*.html',
            'C:/inetpub/wwwroot/**/*.js',
            'C:/inetpub/wwwroot/**/*.cshtml',
            'C:/inetpub/wwwroot/**/*.aspx',
            '/var/www/**/*.html',
            '/var/www/**/*.js'
        ])
        WHERE Size < 10000000
    },
    query={
        SELECT FullPath, Mtime, Size,
               read_file(filenames=FullPath, length=10000000) AS String
        FROM scope()
        WHERE read_file(filenames=FullPath, length=10000000) =~ tracker_regex
    })
ORDER BY Mtime DESC

Adjust the glob roots to your actual document roots. For large estates, scope the hunt to portal and scheduling properties first — that's where the regulatory exposure concentrates.

Remediation / Audit Script

Run this on web servers and against exported site source to produce a tracker inventory with page-level attribution. The -ReportPath output goes directly to your privacy officer and legal counsel — treat this as a litigation-hold-quality artifact, not a scratch scan.

PowerShell
# TrackerSweep.ps1 - Audit web content for third-party tracking technologies
# Run elevated on web servers; point -WebRoot at each site's document root

param(
    [Parameter(Mandatory=$true)][string]$WebRoot,
    [string]$ReportPath = ".\TrackerAudit_$(Get-Date -Format 'yyyyMMdd_HHmm').csv"
)

$TrackerPatterns = @{
    'Meta Pixel'            = 'fbevents\.js|connect\.facebook\.net|fbq\s*\('
    'Google Tag Manager'    = 'googletagmanager\.com/(gtm\.js|gtag/js)'
    'Google Analytics'      = 'google-analytics\.com|gtag\s*\('
    'TikTok Pixel'          = 'analytics\.tiktok\.com|ttq\.'
    'Snap Pixel'            = 'tr\.snapchat\.com|snaptr\('
    'Hotjar'                = 'static\.hotjar\.com|hj\s*\('
    'Microsoft Clarity'     = 'clarity\.ms'
    'LinkedIn Insight'      = 'snap\.licdn\.com'
}

$FileTypes = @('*.html','*.htm','*.js','*.cshtml','*.aspx','*.php','*.jsp','*.json')
$results = foreach ($file in (Get-ChildItem -Path $WebRoot -Recurse -Include $FileTypes -ErrorAction SilentlyContinue)) {
    $content = Get-Content -Path $file.FullName -Raw -ErrorAction SilentlyContinue
    if ($null -eq $content) { continue }
    foreach ($tracker in $TrackerPatterns.GetEnumerator()) {
        if ($content -match $tracker.Value) {
            # Flag high-risk paths: authenticated portal, scheduling, condition-specific
            $risk = if ($file.FullName -match 'portal|patient|schedule|appointment|mychart|login|results') { 'HIGH - Patient-facing/authenticated context' }
                    else { 'Review - Public page (AHA v. HHS narrowed OCR scope, CIPA/state claims still apply)' }
            [PSCustomObject]@{
                File        = $file.FullName
                Tracker     = $tracker.Key
                LastWrite   = $file.LastWriteTime
                RiskContext = $risk
            }
        }
    }
}

$results | Sort-Object RiskContext, Tracker | Export-Csv -Path $ReportPath -NoTypeInformation
Write-Host "[+] Scan complete. $($results.Count) tracker references found. Report: $ReportPath" -ForegroundColor Cyan
$results | Where-Object { $_.RiskContext -like 'HIGH*' } | Format-Table -AutoSize

Anything returned with the HIGH flag is an incident, not an audit finding — treat it as a potential impermissible disclosure and invoke your breach determination process under 45 CFR §§ 164.400–414.

Remediation

  1. Remove trackers from authenticated experiences immediately. No pixel, tag manager container, or session replay tool belongs on any page behind a login, any scheduling flow, any provider search that implies a condition, or any page whose URL or content reveals a health service interaction. There is no configuration of Meta Pixel that makes it HIPAA-compliant on an authenticated page — Meta does not offer a BAA, and the data transmitted cannot be adequately de-identified client-side.

  2. Audit your tag managers, not just your source. Google Tag Manager and similar containers can inject pixels at runtime that never appear in your source control. Export your GTM containers, enumerate every tag and trigger, and reconcile against what marketing believes is deployed. The gap between those two lists is your incident queue.

  3. Implement a Content Security Policy as a technical control. A restrictive script-src and connect-src CSP blocks unauthorized tracker injection even if a marketing team or compromised CMS tries to add one. This converts a policy problem into an enforced control:

    • connect-src 'self' on portal properties prevents any outbound beacon from authenticated pages.
    • Deploy in Content-Security-Policy-Report-Only mode first, review violations, then enforce.
  4. Establish a data-governance gate for web properties. Any new third-party script on a healthcare web property requires privacy office sign-off and a documented determination of whether the page is authenticated, what identifiers are transmitted, and whether a BAA exists. Vendors who will not sign a BAA do not get code on patient-facing pages. Full stop.

  5. Preserve evidence and assess historical exposure. Before deleting anything, snapshot the deployed configuration (GTM exports, CMS revision history, server logs). If trackers were present on authenticated pages, you owe your legal counsel a retrospective analysis: what data elements were transmitted, for what time period, and to how many individuals. That analysis drives the breach determination and notification obligations. Deleting the pixel before preserving evidence is spoliation risk.

  6. Baseline network egress and alert on regression. Deploy the detection content above, remediate to zero hits on portal-originated traffic, then convert the hunt into an alerting rule. Trackers have a way of coming back — a CMS update, a new marketing agency, a tag manager push. The control that matters is the one that's still watching in six months.

  7. Monitor the regulatory landscape actively. OCR's tracking technology guidance remains in flux following AHA v. HHS, but OCR has signaled continued enforcement interest, the FTC continues to act against health-adjacent data sharing under Section 5, and state legislatures (Washington My Health My Data, and CIPA wiretap claims in California) have created private rights of action that bypass HHS entirely. The plaintiffs' bar is scanning hospital websites with automated tooling. Your external properties are being audited right now — by people looking for standing to sue you.

The Bottom Line

Fairchild Medical Center and Boone Health join a list that already includes some of the largest health systems in the country. The consistent thread across every one of these cases: the exposure was discovered by plaintiffs' attorneys or journalists before it was discovered by the organization's own security and privacy teams. That is a detection gap, and it is entirely closable with the source sweeps, egress hunting, and CSP enforcement described above. Run the scan this week. What you find will either be reassuring or urgent — but either way, you need to know before someone else does.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.