Two Health Systems Settle Pixel Suits & Breach Costs Climb to Nearly $5M (07/29/2026)

July 29, 2026
Two Health Systems Settle Pixel Suits & Breach Costs Climb to Nearly $5M (07/29/2026)
Key Intel / TL;DR
  • Banner Health and LifeStance Health Group agreed to settle lawsuits over their use of website pixels and other tracking technologies.
  • IBM's 2026 Cost of a Data Breach Study puts the global average at almost $5 million, up 12% in a year.
  • Soniva Dental Care disclosed a breach affecting at least 30,000 patients, alongside notifications from Optalis Management Solutions and CareCloud.
  • New Jersey's new privacy law extends compliance obligations to businesses that never considered themselves subject to privacy regulation.
  • The FCC proposed broadening filing obligations for the Robocall Mitigation Database.

Today’s compliance news is about the widening perimeter of who has to care. Two health systems are paying to settle claims over the tracking code on their websites. The average breach now costs close to $5 million. And a state privacy law is reaching businesses that assumed these rules were written for someone larger. The connective tissue is that the compliance floor keeps rising underneath organizations that were never watching it.

Top 5 Critical Compliance Alerts

1. Banner Health and LifeStance Settle Website Tracking Suits

Banner Health and LifeStance Health Group agreed to settle lawsuits over their use of pixels and other website tracking technologies (HIPAA Journal). Marketing code on a patient-facing page can transmit information about what someone was looking up, and in healthcare that turns an ordinary analytics decision into a disclosure question with a settlement attached.

Operator Note: Inventory every third-party script on any page where a patient, member, or client identifies themselves or searches for a condition. Most organizations cannot name what is running on their own site, and the marketing team that added the tag is rarely the team that will answer for it.

2. The Average Breach Now Costs Almost $5 Million

IBM’s 2026 Cost of a Data Breach Study found breach costs rose 12% in a year, bringing the global average to nearly $5 million (HIPAA Journal). A double-digit annual rise means the gap between the cost of prevention and the cost of an incident keeps widening, which is the number worth putting in front of a board that treats security spending as discretionary.

3. A Dental Practice Breach Hits At Least 30,000 Patients

Soniva Dental Care in Texas disclosed a data breach affecting at least 30,000 patients, alongside notifications from Optalis Management Solutions and CareCloud (HIPAA Journal). Small and mid-size practices hold the same regulated data as a hospital system with a fraction of the security staff, and the notification obligations do not scale down with the practice.

4. New Jersey’s Privacy Law Reaches Businesses That Never Complied

New Jersey’s new privacy law extends obligations to organizations that historically viewed privacy compliance as a problem for large technology companies, retailers, and data brokers (JD Supra). The threshold for being in scope keeps dropping across states, and the businesses most likely to be caught unprepared are the ones that concluded years ago that none of this applied to them.

5. The FCC Moves to Broaden Robocall Database Obligations

The FCC released a Further Notice of Proposed Rulemaking on July 23 seeking to improve the Robocall Mitigation Database by broadening the scope of who must file (JD Supra). Any organization that originates or transmits voice traffic should read the proposal now, because expanded filing obligations tend to arrive with deadlines that assume you were following the docket.

Additional Compliance Alerts

Employment

  • Minnesota Clarifies Earned Sick and Safe Time Rules: After a multi-year process, Minnesota’s Department of Labor and Industry adopted rules clarifying the state’s Earned Sick and Safe Time law, effective July 6, 2026. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)