CVS and Criteo Pay $20.5 Million Over Pixels (09/24/2026)
- › CVS and Criteo agreed to pay $20.5 million to settle claims that tracking pixels sent users' health data to advertising and analytics companies.
- › The class covers everyone who used the CVS website or pharmacy app before July 27, 2026.
- › The FTC is asking whether platforms should be required to vet advertisers and remove impersonation scam ads.
- › EU AI Act enforcement is under way, with the Commission's first formal investigations opened in June.
- › Astrana is the latest healthcare technology company to report a breach to the SEC, after attackers impersonated its staff.
The tracking pixel settlements keep arriving, and the size of this one makes a useful benchmark for anybody still running third-party scripts on pages where people look up prescriptions. A pixel is a few lines of code a marketing team added to measure a campaign, and from a liability standpoint it is a disclosure of whatever the page knew about the visitor to whichever companies the script reports to. Alongside that, the FTC is considering whether the platforms that carry impersonation scam ads should carry some of the obligation to stop them.
Top 5 Critical Compliance Alerts
1. CVS and Criteo Settle Tracking Claims for $20.5 Million
CVS Health and Criteo agreed to pay $20.5 million to resolve claims that web tracking technologies on the CVS website and CVS Pharmacy app collected users’ sensitive data and sent it to companies including Criteo, Adobe, Medallia, and Quantum Metric without consent, per the HIPAA Journal. The case, Brewer v. CVS Pharmacy and Criteo, is in the Circuit Court of the 17th Judicial Circuit in Broward County, Florida, and the class covers everyone who used the site or app before July 27, 2026.
Operator Note: Run an inventory of every third-party script on your authenticated and health-related pages, along with the data each one sends. Marketing added most of them, and your organization carries the disclosure regardless of who added them.
2. The FTC Asks Whether Platforms Must Stop Impersonation Ads
The FTC is seeking comment on updating its rule on impersonation of government and businesses to address how platform ad optimization helps scammers, including whether platforms should vet advertisers, monitor ads, investigate suspected impersonation ads, remove confirmed ones, and act against the advertisers behind them, per the FTC. Consumers reported more than $2.1 billion lost to imposter scams in 2025, with nearly 30% of victims first contacted on social media. Comments are due 60 days after the notice appears in the Federal Register.
3. EU AI Act Enforcement Is Under Way
Prohibited practices under the EU AI Act have been enforceable since February 2025 and general-purpose AI obligations since August 2025, and the Commission opened its first formal investigations in June 2026 into uses in hiring, credit scoring, and student assessment, per JD Supra. The second part of the series covers the Digital Omnibus and the current timeline, per JD Supra.
Operator Note: Hiring and credit scoring are the first targets, and many US companies run AI screening tools across EU applicants without having classified them. Find those tools before an investigator asks about them.
4. Astrana Reports an Impersonation Breach to the SEC
Healthcare firm Astrana told regulators that attackers accessed confidential information by impersonating company personnel, making it the latest healthcare technology company to disclose a breach to the SEC, per The Record. Public healthcare companies now face the SEC’s disclosure clock alongside HIPAA’s, and the two run on different triggers.
5. Oculus Pathology Notifies More Than 20,000 Patients
Texas-based Oculus Pathology disclosed a breach affecting more than 20,000 patients tied to an April 2026 incident, per the HIPAA Journal, while a gastroenterology practice and hospice companies announced breaches of their own, per the HIPAA Journal. Specialty labs and home care providers hold the full clinical record with a fraction of a hospital’s security budget.
Additional Compliance Alerts
Policy & Governance Updates
- UK government moves to service-led cyber governance after a critical audit: Whitehall is shifting away from mandated controls after an audit found failures in its 2022 cyber strategy. Infosecurity Magazine
- Your employee handbook may say more than you meant under the NLRB standard: A legitimate business purpose no longer settles whether a handbook rule is lawful. JD Supra
Regulatory Updates
- SEC staff grants no-action relief for zero cash balance brokerage models: Staff relief clarifies the treatment of brokerage accounts that hold no cash balance. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.