No hacker broke into Concord Hospital’s systems. Instead, a class-action lawsuit alleged that the New Hampshire health system’s own websites quietly shared visitors’ information with outside technology companies through tracking code embedded in the pages. The hospital agreed to an $800,000 settlement to resolve the claims, and people who used its sites over a five-year span can file for a cash payment. The deadline is September 11, 2026.
Tracking pixels, not a hacker, drove the lawsuit
The case centers on tracking pixels, small pieces of code that websites embed to measure traffic and target advertising. The lawsuit alleged that as visitors browsed Concord Hospital’s websites and apps, those tools transmitted identifying information to third parties, including Google and the web-services vendor Geonetric, without adequate consent. Plaintiffs argued that because the sites dealt with medical services, the data amounted to protected health information that should never have been shared.
Federal regulators have warned health providers about exactly this practice; the Department of Health and Human Services maintains guidance on HIPAA and protected health information that governs how patient data must be safeguarded, including on websites. Concord Hospital, which operates facilities in Laconia and Franklin under the Capital Region Healthcare umbrella, denied wrongdoing but agreed to settle rather than continue litigating.
The theory in the case is spreading across the health sector. Dozens of hospitals and health systems have faced similar suits alleging that advertising and analytics pixels on patient-facing pages relayed information, such as the pages a visitor viewed or the provider they searched for, to outside companies including Google and Meta. Because that browsing can reveal a person’s medical concerns before they ever speak to a clinician, plaintiffs contend it should have been handled with the same care as a medical record rather than treated as ordinary website traffic.
Free retirement updates: Every year, billions in settlements and unclaimed money go unclaimed. Our free Retirement Shield newsletter sends the real ones — with deadlines — a couple times a week. Get the free newsletter.
Who used a Concord Hospital site between 2021 and 2026
Eligibility is defined by website use over a specific window. According to a summary of the case by ClassAction.org, the settlement covers people who used a Concord Hospital website or mobile app between May 9, 2021 and June 12, 2026. Unlike a data-breach settlement tied to a single intrusion, this class is defined by ordinary interaction with the sites across that five-year period. That interaction includes routine actions many people would not think twice about, such as looking up a physician, paying a bill, or scheduling an appointment online, which means a large share of the region’s residents may fall within the class without realizing it.
That broad definition means many class members took no unusual action and suffered no obvious harm; the alleged injury is the disclosure itself, not a fraudulent charge or a stolen identity. As a result, the settlement does not ask claimants to document losses, and it does not require proof that any specific piece of information was misused before a payment can be made.
The absence of a documentation requirement follows directly from the nature of the alleged harm. There is no fraudulent charge to itemize and no stolen identity to prove, so the settlement compensates class members simply for having used the sites during the covered window. That design also means the payment is built to be modest and shared broadly rather than to make any single person whole for a specific loss, and the more people who file, the smaller each share becomes.
A pro-rata payment and the September 11 deadline
Payments will be made on a pro-rata basis, meaning the $800,000 fund, after costs, is divided among valid claimants, so the individual amount depends on how many people file. Claims are submitted through the official Concord pixel settlement site, and no proof is required to receive a share. The claim deadline is September 11, 2026, and it is open now.
A final approval hearing is scheduled for November 3, 2026, when the court will decide whether to authorize the settlement. As with most class actions, payments follow that approval rather than the claim deadline, so filing by September 11 secures a claimant’s place even though the money arrives later. Because the payout is pro-rata, the number of claims filed will shape the size of each individual check.
Class members who would rather not participate have a parallel set of choices. Objecting to the settlement, or opting out to sue Concord Hospital independently, must be done by the deadlines the administrator sets, and opting out means giving up a share of the $800,000 fund. Given the small, no-proof nature of the payment, most eligible visitors have little practical reason to do anything other than confirm their dates of use and file before September 11.
The settlement reflects a wave of litigation over website tracking by hospitals and health systems, a practice that turned routine analytics tools into a legal liability once medical context was involved. For former visitors to Concord Hospital’s sites, the requirement is minimal: confirm the dates of use and file before September 11. The settlement administrator’s page remains the authoritative source for eligibility and the November approval timeline.
This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.
More Financial Reading