In a landmark case that could reshape how dental practices handle online data, Aspen Dental Management Inc. has agreed to an $18.4 million settlement to resolve claims that it illegally tracked patient data through its website using pixel technology without proper consent.
The case, which accused Aspen of violating state and federal privacy laws, is a timely reminder for all dental professionals: just because a tool is available doesn't mean it's compliant.
01What happened?
The class action lawsuit alleged that Aspen Dental used Meta pixels and similar tracking technologies to collect patients' sensitive data during website visits — including information typed into forms and potentially PHI (Protected Health Information) — and shared it with third parties like Facebook and Google without HIPAA-compliant safeguards or patient consent.
This kind of passive data tracking is increasingly common in healthcare websites, but it's also increasingly risky.
02Why it matters
Under HIPAA and various state privacy laws, collecting, storing, or transmitting PHI without proper authorization is a violation — period. Tools like tracking pixels, analytics platforms, and ad tech integrations often fly under the radar for dental practices, but they can:
Including names, phone numbers, and treatment details.
And location data.
With third-party advertisers.
To lawsuits, regulatory fines, and loss of patient trust.
Aspen's multi-million-dollar settlement proves that regulators and courts are no longer ignoring this.
03What your practice should do right now
Whether you're a single-practice dentist or a growing DSO, here's how you can stay ahead of similar risk:
- 1Audit your website for tracking technologyReview every third-party tool on your site: analytics platforms, form builders, chatbots, marketing integrations. Tools like Facebook Pixel or Google Tag Manager should be reviewed and documented.
- 2Get a HIPAA website compliance checkIf your website collects any patient information — appointment requests, contact forms, treatment inquiries — it must meet HIPAA standards. That includes end-to-end encryption, secure storage of form submissions, and signed Business Associate Agreements (BAAs) with all vendors.
- 3Don't trust web developers aloneMany agencies don't understand HIPAA compliance in a dental setting. They may add tracking tech to improve marketing without realizing it exposes your practice legally.
- 4Partner with experts who know dental + HIPAAAt Darkhorse Tech, we specialize in securing dental practices from the front desk to the firewall.
We offer:
Aspen Dental's story isn't unique — it's just the first of many to make headlines.
Concerned about your website's data tracking risks?
Schedule a HIPAA website audit with Darkhorse Tech today.
The bottom line
You can't afford to treat patient data like marketing data. It's time to take control of your online presence, ensure your tools are compliant, and protect your practice from becoming the next cautionary tale.

