Court Rules
All enforcement actions
SettlementHigh Risk

CA AG Settles Healthline for $1.55M Over CCPA Health Data Violations

Healthline Media LLCJuly 1, 2025California Attorney General

Penalty Amount

$1,550,000

Summary

California Attorney General Rob Bonta announced a $1.55 million settlement with health information website publisher Healthline Media LLC, resolving allegations that the company violated the CCPA and Unfair Competition Law. Violations included failing to honor consumer opt-out requests, sharing sensitive health data with third parties without required privacy protections, and using deceptive consent banners that did not disable tracking cookies. The settlement imposes injunctive terms, compliance requirements, and a civil penalty, marking the largest CCPA settlement to date.

Remedy

Healthline must pay $1.55 million in civil penalties and is permanently enjoined from sharing article titles that could reveal a consumer’s medical diagnosis. The company must ensure opt-out mechanisms (including Global Privacy Control) function properly, implement a CCPA compliance program that includes auditing third-party contracts for required privacy terms, and maintain accurate privacy policies and online disclosures.

Monetary PenaltyInjunctionCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams, especially at ad-supported online publishers or companies handling sensitive health data, should review vendor agreements with ad networks, tracking technology providers, and third-party data recipients to ensure they include all CCPA-mandated privacy terms, including requirements to honor opt-out requests (including via Global Privacy Control) and prohibitions on sharing sensitive health data without proper protections. Privacy policies and consent banners must be audited to confirm they accurately disclose tracking practices, that opt-out mechanisms function to disable all tracking cookies when selected, and that no deceptive dark patterns (like non-functional consent banners) are present. Companies should also review data sharing practices to comply with purpose limitation principles, specifically prohibiting transmission of data (such as article titles) that could link consumers to medical diagnoses, and update compliance programs to include regular audits of third-party contracts and privacy disclosures.

Contract Search Terms

Global Privacy ControlCCPA-required contract termsopt-out mechanismhealth data sharingpurpose limitation clauseconsent banner compliancethird-party data processing agreementprivacy policy accuracy

Laws Cited

CCPACalifornia Consumer Privacy ActCalifornia Unfair Competition Law

Violation Types

Entity Details

Entity

Healthline Media LLC

Also known as: Healthline

Industry

Media & Entertainment

Official Sources

Source Evidence

Entity Name
"website publisher Healthline Media LLC (Healthline)"
Fine Amount
"$1.55 million in civil penalties"
Event Date
"Tuesday, July 1, 2025"
Laws Cited
"violated the California Consumer Privacy Act (CCPA)"
Laws Cited
"violated the CCPA and the Unfair Competition Law"
Violation Types
"Failing to opt consumers out of the sharing of their personal information for targeted advertising."

Related Enforcement Actions

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

CA

California Privacy Protection Agency

The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.

CA

California Privacy Protection Agency

The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.

CA

Nexstar Media Group, Inc. and Tegna Inc.

California Attorney General Rob Bonta, joined by attorneys general from seven other states, filed a lawsuit to block the $6.2 billion merger between Nexstar Media Group and Tegna Inc. The lawsuit alleges the merger violates Section 7 of the Clayton Act by reducing competition in local TV markets, leading to higher prices, less local news, and job losses.