Aspen Dental’s $18.4M Data Tracking Settlement: A Wake-Up Call for Dental Practices Everywhere

Aspen Dental's $18.4M Tracking Settlement | Darkhorse Tech
Compliance Watch

Aspen Dental's $18.4M Data Tracking Settlement: A Wake-Up Call for Dental Practices Everywhere

Tracking pixels on a dental website led to an eight-figure settlement. Here's what happened, why it matters, and how to check your own site.

4 MIN READHIPAA COMPLIANCEWEBSITE TRACKING
TL;DR

Aspen Dental Management Inc. agreed to an $18.4 million settlement over claims it used tracking pixels on its website to collect patient data, potentially including PHI, and share it with third parties like Facebook and Google without HIPAA-compliant safeguards or consent. Tracking pixels, analytics platforms, and ad tech can quietly put any practice at risk. Audit your website's tracking tools, get a HIPAA website compliance check, and make sure every vendor has signed a BAA.

In a landmark case that could reshape how dental practices handle online data, Aspen Dental Management Inc. has agreed to an $18.4 million settlement to resolve claims that it illegally tracked patient data through its website using pixel technology without proper consent.

The case, which accused Aspen of violating state and federal privacy laws, is a timely reminder for all dental professionals: just because a tool is available doesn't mean it's compliant.

$18.4M
Settlement amount
To resolve claims that Aspen Dental tracked patient data through its website without proper consent

01What happened?

Direct answerA class action lawsuit alleged that Aspen Dental used Meta pixels and similar tracking technologies to collect patients' sensitive data during website visits, including information typed into forms and potentially PHI, and shared it with third parties like Facebook and Google without HIPAA-compliant safeguards or patient consent.

The class action lawsuit alleged that Aspen Dental used Meta pixels and similar tracking technologies to collect patients' sensitive data during website visits — including information typed into forms and potentially PHI (Protected Health Information) — and shared it with third parties like Facebook and Google without HIPAA-compliant safeguards or patient consent.

This kind of passive data tracking is increasingly common in healthcare websites, but it's also increasingly risky.

02Why it matters

Direct answerUnder HIPAA and various state privacy laws, collecting, storing, or transmitting PHI without proper authorization is a violation. Tracking pixels, analytics platforms, and ad tech integrations can record form entries, capture IP addresses and location data, and share that data with third-party advertisers.

Under HIPAA and various state privacy laws, collecting, storing, or transmitting PHI without proper authorization is a violation — period. Tools like tracking pixels, analytics platforms, and ad tech integrations often fly under the radar for dental practices, but they can:

Record form entries

Including names, phone numbers, and treatment details.

Capture IP addresses

And location data.

Share this data

With third-party advertisers.

Leave your practice vulnerable

To lawsuits, regulatory fines, and loss of patient trust.

Aspen's multi-million-dollar settlement proves that regulators and courts are no longer ignoring this.

03What your practice should do right now

Direct answerAudit your website for tracking technology, get a HIPAA website compliance check, don't rely on web developers alone, and partner with experts who know both dentistry and HIPAA.

Whether you're a single-practice dentist or a growing DSO, here's how you can stay ahead of similar risk:

  1. 1
    Audit your website for tracking technologyReview every third-party tool on your site: analytics platforms, form builders, chatbots, marketing integrations. Tools like Facebook Pixel or Google Tag Manager should be reviewed and documented.
  2. 2
    Get a HIPAA website compliance checkIf your website collects any patient information — appointment requests, contact forms, treatment inquiries — it must meet HIPAA standards. That includes end-to-end encryption, secure storage of form submissions, and signed Business Associate Agreements (BAAs) with all vendors.
  3. 3
    Don't trust web developers aloneMany agencies don't understand HIPAA compliance in a dental setting. They may add tracking tech to improve marketing without realizing it exposes your practice legally.
  4. 4
    Partner with experts who know dental + HIPAAAt Darkhorse Tech, we specialize in securing dental practices from the front desk to the firewall.

We offer:

HIPAA-compliant website audits
Cybersecurity risk assessments
Vendor compliance management
Complete IT and compliance oversight

Aspen Dental's story isn't unique — it's just the first of many to make headlines.

Concerned about your website's data tracking risks?

Schedule a HIPAA website audit with Darkhorse Tech today.

The bottom line

You can't afford to treat patient data like marketing data. It's time to take control of your online presence, ensure your tools are compliant, and protect your practice from becoming the next cautionary tale.

Frequently asked questions

What was the Aspen Dental $18.4 million settlement about?
Aspen Dental Management Inc. agreed to an $18.4 million settlement to resolve claims that it illegally tracked patient data through its website using pixel technology without proper consent.
What did the Aspen Dental lawsuit allege?
The class action alleged that Aspen Dental used Meta pixels and similar tracking technologies to collect patients' sensitive data during website visits, including information typed into forms and potentially PHI, and shared it with third parties like Facebook and Google without HIPAA-compliant safeguards or patient consent.
Can tracking pixels on a dental website violate HIPAA?
Under HIPAA and various state privacy laws, collecting, storing, or transmitting PHI without proper authorization is a violation. Tracking pixels, analytics platforms, and ad tech can record form entries, capture IP addresses and location data, and share that data with third-party advertisers.
What does a HIPAA-compliant dental website need?
If a website collects any patient information, such as appointment requests, contact forms, or treatment inquiries, it must meet HIPAA standards, including end-to-end encryption, secure storage of form submissions, and signed Business Associate Agreements (BAAs) with all vendors.
What should dental practices do after the Aspen Dental settlement?
Audit the website for tracking technology, get a HIPAA website compliance check, don't rely on web developers alone, and partner with experts who understand both dentistry and HIPAA.

Darkhorse Tech is here for you.

Your dental technology should support your practice, not slow it down. Darkhorse Tech helps dental offices stay secure, connected, and productive with IT support built specifically for dentistry.

Schedule a Consultation Today

Back to Education

Looking to get dental IT support for the first time?

You’re in the right place.

Don’t hesitate to drop us a line, we look forward to connecting with you soon.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Want To Chat?

You can schedule an intro meeting online! Find a time on our calendar that works for you.

schedule today!