Nashville/ Crime & Emergencies

Nashville Patients Sue CareNow, Say Cookie Walls Leaked Health Data to Google

AI Assisted Icon
Published on September 04, 2026
Nashville Patients Sue CareNow, Say Cookie Walls Leaked Health Data to GoogleSource: Google Street View

Three patients suing HCA Healthcare's CareNow urgent care chain say they couldn't book an appointment online without first accepting cookies that funneled their personal and health information to Google. The class action, filed in Davidson County, claims the scheduling website repeatedly threw up CAPTCHA verification screens whenever a user disabled first-party cookies, effectively forcing them to accept tracking tools just to see a doctor.

According to the lawsuit, the CareNow scheduling page would not properly load unless those cookies were enabled, and patients who tried to opt out kept getting bounced back to CAPTCHA checks. As reported by WKRN News 2, three of the patients behind the suit used pseudonyms rather than their real names in court filings. Attorneys for the plaintiffs say protected health information and personally identifiable information were shared with Google once those trackers were switched on, and they argue the practice violates Tennessee HIPAA laws.

What the Lawsuit Says Was Shared

The lawsuit alleges the CareNow website shared patients' information with Google as part of its scheduling process. Cybersecurity expert and national security advisor Ricoh Danielson, speaking with WKRN, said the kind of data exposed in incidents like this can include addresses, phone numbers, next of kin, and dates of birth. Danielson warned that a data breach involving that scope of information could put patients' details up for sale.

Danielson also told the station that patients caught up in this kind of tracking might notice unusual or redirected advertisements, or simply a different experience using the site than they expected. Attorneys still have to prove their claims to a judge before the case moves forward, and no ruling has been issued.

HCA Healthcare's Response

HCA Healthcare has disagreed with the claims made in the lawsuit and said it plans to defend itself vigorously. The company also said it takes its obligation to safeguard patients' information seriously. The Nashville-based health system is one of the country's largest, operating 185 hospitals and expanding its CareNow urgent care division past 430 clinics nationwide as of last month, according to Healthcare Dive.

This isn't HCA's first brush with patient data controversy. The company disclosed a cybersecurity incident in July 2023 in which an external storage exposure affected the non-clinical personal data of more than 11.2 million patients across 20 states, triggering multiple class actions, per UpGuard. That earlier incident involved automated email formatting servers rather than direct clinical records.

A Legal Gray Area Around Web Tracking

The CareNow case lands in a murky corner of health privacy law. A June 2024 federal court ruling in AHA v. Becerra vacated federal guidance that treated an IP address captured on a public healthcare webpage as automatically constituting protected health information, a decision HHS declined to appeal, according to ArentFox Schiff. But HHS Office for Civil Rights guidance reaffirmed in July 2024 maintains that tracking technologies on interactive patient tools, like appointment schedulers, do expose protected health information and violate HIPAA when data is shared without explicit consent or a business associate agreement.

That distinction matters because Google explicitly excludes Google Analytics from its HIPAA-eligible services and won't sign business associate agreements with healthcare providers for standard web analytics tools, per Improvado. That leaves providers who embed native Google tracking code on scheduling portals exposed to compliance risk. Tennessee's own consumer privacy law, the Tennessee Information Protection Act, took effect in mid-2025 but explicitly exempts HIPAA-covered entities and protected health information, pushing disputes like this one toward federal HIPAA standards and state common law claims instead.

Part of a Broader Wave of Health Data Suits

The CareNow filing isn't happening in isolation. Middle Tennessee courts saw a surge in healthcare data privacy litigation this year, with the Davidson County suit arriving alongside a dozen federal lawsuits against Franklin-based analytics firm XSolis over a breach affecting 1.4 million patients, according to the Tennessee Bar Association. Nationally, hospital tracking-pixel litigation has ballooned, with Kaiser Permanente exposing up to 13.4 million member records to third parties in 2024 and New York's Mount Sinai Health System agreeing this year to a $5.3 million settlement over similar tracking claims.

Industry groups have pushed back against expanding legal theories in these cases. In an amicus brief filed before the Washington Supreme Court, the Interactive Advertising Bureau argued that treating standard browser cookie requests as illegal wiretapping would disrupt routine website operations, click logging, and basic ad measurement nationwide, a fight Hoodline detailed in its coverage of a similar Seattle case.

Protecting Yourself Online

For patients worried about their own exposure, Danielson recommended several basic precautions, including using a password manager, relying on a VPN, and installing endpoint detection and response or malware mitigation software. Cyber experts more broadly say there are concrete steps people can take to limit what gets shared when they interact with medical websites. For now, the CareNow case remains in its early stages, with attorneys still needing to prove their claims before a judge.