ANNABEL KADY, et al., Case No. 4:25-cv-05037-KAW
Plaintiffs, ORDER GRANTING IN PART AND DENYING IN PART MOTION TO v. DISMISS FIRST AMENDED CLASS ACTION COMPLAINT Re: Dkt. No. 33 Defendant.
On January 14, 2026, Defendant Opencare, Inc. filed a motion to dismiss the first amended class action complaint (“FAC”). (Def.’s Mot., Dkt. No. 33.) Upon review of the moving papers, the Court finds this matter suitable for resolution without oral argument pursuant to Civil Local Rule 7-1(b), and, for the reasons set forth below, GRANTS IN PART AND DENIES IN PART the motion to dismiss. Defendant Opencare, Inc. (“Opencare” or “Defendant”) connects patients across the United States to local dental providers through their website, https://www.opencare.com/ (“Website”). (First Am. Class Action Compl., “FAC,” Dkt. No. 31 ¶ 2.) To use this service, Website users provide various pieces of information, including their location, email addresses, IP addresses, unique identifiers (for their devices and for certain internet accounts), date of visit to the Website, URLs visited, insurance information, when they last visited a dentist, whether they are experiencing a dental emergency, and the nature of their dental problem(s). (FAC ¶¶ 7, 63, 86, 97- 99, 102, 105.) Unbeknownst to users, Opencare allegedly implemented invisible third-party tracking tools (“Tracking Technologies”) that simultaneously collect and transmit the information The data divulged to the Information Recipients is then connected back to a user’s profile with the respective Information Recipients, or, if a user lacks such a profile, a shadow profile assembled by the Information Recipients. (FAC ¶¶ 88-89, 91.) As a result, the Information Recipients are able to identify the user’s real-world identity (e.g., through the user’s unique TikTok account identifier, accessible via a cookie in the user’s browser, or digital “fingerprints”) and use their Private Information to sell targeted digital advertising, including ads targeted to Plaintiffs, based on their medical conditions. (See FAC ¶¶ 108-109.) This process occurs whether or not a user has an account with Defendant. (See FAC ¶¶ 97-107.) Plaintiff Kady used Defendant’s Website beginning in July of 2023 to research conditions, find dentists, and book appointments. (FAC ¶ 30.) Plaintiff Taylor began using the Website in or around March of 2025 to research dental conditions and treatments and to find local dentists. (FAC ¶ 38.) As a result of using the Website for these purposes, each of the Plaintiffs’ Private Information was shared with the Information Recipients. (FAC ¶¶ 34, 35, 42, 43.) Immediately after using Defendant’s Website, each Plaintiff began receiving unsolicited advertisements related to their disclosed medical conditions. (FAC ¶¶ 108-109.) In its privacy policy (“Privacy Policy”), Defendant promised not to disclose users’ Private Information without consent, stating: “If you do schedule an appointment through Opencare, that information is considered Protected Health Information, and we will not sell that to third parties.” (FAC ¶ 114.) The Privacy Policy explains that Opencare may receive PHI as a HIPAA “business associate” and that this “prohibits us from using or disclosing the Protected Health Information in ways that are not permissible by the health care provider itself, and requires us to implement certain measures to safeguard the confidentiality, integrity, and availability of the Protected Health Information.” (FAC ¶ 116.) On June 13, 2025, Plaintiffs filed this lawsuit. On January 2, 2026, Plaintiffs filed the first amended complaint. On January 14, 2026, Defendant filed the motion to dismiss. (Def.’s Mot., Dkt. No. 33.) On January 28, 2026, Plaintiffs filed an opposition. (Pls.’ Opp’n, Dkt. No. 36.) On February 4, 2026, Defendant filed a reply. (Def.’s Reply, Dkt. No. 37.) Under Federal Rule of Civil Procedure 12(b)(6), a party may file a motion to dismiss based on the failure to state a claim upon which relief may be granted. A motion to dismiss under Rule 12(b)(6) tests the legal sufficiency of the claims asserted in the complaint. Navarro v. Block, 250 F.3d 729, 732 (9th Cir. 2001). In considering such a motion, a court must “accept as true all of the factual allegations contained in the complaint,” Erickson v. Pardus, 551 U.S. 89, 94 (2007) (per curiam) (citation omitted), and may dismiss the case or a claim “only where there is no cognizable legal theory” or there is an absence of “sufficient factual matter to state a facially plausible claim to relief.” Shroyer v. New Cingular Wireless Servs., Inc., 622 F.3d 1035, 1041 (9th Cir. 2010) (citing Ashcroft v. Iqbal, 556 U.S. 662, 677-78 (2009); Navarro, 250 F.3d at 732) (internal quotation marks omitted). A claim is plausible on its face when a plaintiff “pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 556 U.S. at 678 (citation omitted). In other words, the facts alleged must demonstrate “more than labels and conclusions, and a formulaic recitation of the elements of a cause of action will not do.” Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007). “Threadbare recitals of the elements of a cause of action” and “conclusory statements” are inadequate. Iqbal, 556 U.S. at 678; see also Epstein v. Wash. Energy Co., 83 F.3d 1136, 1140 (9th Cir. 1996) (“[C]onclusory allegations of law and unwarranted inferences are insufficient to defeat a motion to dismiss for failure to state a claim.”). “The plausibility standard is not akin to a probability requirement, but it asks for more than a sheer possibility that a defendant has acted unlawfully . . . When a complaint pleads facts that are merely consistent with a defendant's liability, it stops short of the line between possibility and plausibility of entitlement to relief.” Iqbal, 556 U.S. at 678 (quoting Twombly, 550 U.S. at 557) (internal citations omitted). Generally, if the court grants a motion to dismiss, it should grant leave to amend even if no request to amend is made “unless it determines that the pleading could not possibly be cured by the allegation of other facts.” Lopez v. Smith, 203 F.3d 1122, 1127 (9th Cir. 2000) (citations omitted). Defendant moves to dismiss on the grounds that Plaintiffs lack Article III Standing and that Plaintiffs separately fail to state a claim under Federal Rule of Civil Procedure 12(b)(6), in part, because they misclassify the information as individually identifiable health information (“IIHI”) and protected health information (“PHI”). (Def.’s Mot. at 1, 5, 17.) A. Article III Standing As an initial matter, Defendant moves to dismiss on the grounds that Plaintiffs lack Article III standing because they fail to allege a concrete injury, their allegations of future harm are speculative and not imminent, and they lack standing for injunctive relief. (Def.’s Mot. at 17.) Article III standing requires the demonstration of three elements: (1) the plaintiff suffered an “injury in fact” that is concrete and particularized and actual or imminent, not conjectural or hypothetical; (2) the injury is fairly traceable to the challenged action of the defendant; and (3) it is likely, as opposed to merely speculative, that the injury will be redressed by a favorable decision. Lujan v. Defenders of Wildlife, 504 U.S. 555, 560-61 (1992). Absent this showing, the action must be dismissed. See Steel Co. v. Citizens for a Better Env’t, 523 U.S. 83, 109-10 (1998). Here, Defendant largely relies on Popa v. Microsoft Corporation, in which the Ninth Circuit recently held that a plaintiff had not established a concrete injury-in-fact stemming from Microsoft’s “session-replay technology,” which enables businesses to track users’ browsing activity. 153 F.4th 784 (9th Cir. 2025). In sum, the plaintiff failed to establish “how the tracking of her interactions… caused her to experience any kind of harm that is remotely similar to the ‘highly offensive’ interferences or disclosures that were actionable at common law.” Id. at 791. “[T]he kind of harm and not the degree” is relevant to determining whether an alleged injury-in- fact is sufficiently concrete and comparable “to a specific common-law tort,” such that the injury is one “that has traditionally been actionable in our nation’s legal system.” Id. In opposition, Plaintiffs argue that they have adequately alleged injury in fact caused by courts in this district. See, e.g., Lineberry v. AddShopper, Inc., No. 23-CV-01996-VC, 2025 WL 551864, at *1 (N.D. Cal. Feb. 19, 2025) (The court found injury in fact based on website tracking when allegations involved misappropriation of browsing activity by using it to “barrage that person’s devices with unwanted email communications.”); Shah v. MyFitnessPal, Inc., No. 25- CV-04430-PCP, 2026 WL 216334, at *3 (N.D. Cal. Jan. 27, 2026) (Claims regarding misuse of nutrition and fitness tracking information sufficient qualified as “embarrassing, invasive, or otherwise private information,” which was sufficient for standing under Popa.). Namely, Plaintiffs allege facts showing they used Defendant’s Website, submitted Private Information, and Defendant invaded their privacy rights by disclosing such information to third parties without consent through the Tracking Technologies. (Pls.’ Oppp’n at 4 (citing FAC ¶ 33 (detailing Defendant’s unauthorized disclosure of confidential medical information concerning dental surgery required after a traumatic accident).) Moreover, to the extent that Defendant contends that Plaintiffs’ allegations of future harm are speculative and not imminent and that they lack standing for injunctive relief, those arguments are not well taken. (See Def.’s Mot. at 18-19.) As Plaintiffs argue in opposition, their claims are based on harms that have already occurred, such as the invasion of privacy rights by disclosing their information to third parties without their consent. (See Pls.’ Opp’n at 5.) Furthermore, the allegations of ongoing harm support standing for injunctive relief. Campbell v. Facebook, Inc., 951 F.3d 1106, 1120 (9th Cir. 2020) (quoting she Friends of the Earth, Inc. v. Laidlaw Env't Servs. (TOC), Inc., 528 U.S. 167, 191-92 (2000) (threat of future harm sufficiently alleged despite voluntary cessation of using data from personal messages to populate users’ Recommendations Feed due to formidable burden of showing that wrongful behavior could not reasonably be expected to recur). Accordingly, Plaintiffs’ allegations are sufficient to establish standing at the pleadings stage. B. Whether the information at issue is individually identifiable health information (“IIHI”) and protected health information (“PHI”). cannot state any valid claim because the information shared never became IIHI or PHI. (Def.’s Mot. at 5.) Specifically, Defendant argues that Opencare is akin to a receptionist, and, upon calling a receptionist, a person may provide demographic, insurance, and location information in order to schedule an appointment, which is not IIHI or PHI under federal or California statutory definitions. Id. In opposition, Plaintiffs argue that HIPAA applies to receptionists in healthcare offices. (Pls.’ Opp’n at 6.) Specifically, Plaintiffs contend that HIPAA applies to Defendant as a “business associate” of the dentists to which it connects users of its Website. Id. (citing 45 C.F.R. § 160.103.) 45 C.F.R. § 160.103 provides that “[a] covered entity may be a business associate of another covered entity,” and that “business associate” includes: (i) persons that provide “data transmission services with respect to protected health information to a covered entity”; (ii) persons that offer a personal health record to an “individual[] on behalf of a covered entity”; and (iii) subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate. 45 C.F.R. § 160.103(3). The Court notes that the operative complaint quotes Defendant’s acknowledgement in its Privacy Policy that it might be subject to HIPAA: “[w]hen we act as a Business Associate, we may be subject to certain laws and regulations, including certain HIPAA rules, that govern our use and disclosure of Protected Health Information.” (FAC ¶ 116.) Additionally, the Privacy Policy allegedly explained that, in its role as a Business Associate, Opencare is prohibited from “using or disclosing the Protected Health Information in ways that are not permissible by the health care provider itself and requires us to implement certain measures to safeguard the confidentiality, integrity, and availability of the Protected Health Information.” Id. Perhaps tellingly, Defendant does not argue that the information provided would not qualify as PHI or IIHI if it were a covered entity under HIPAA. Based on the foregoing, Plaintiffs sufficiently plead that Defendant qualifies as a Business Associate under HIPAA, so, at the pleading stage, the information transmitted and obtained by the Tracking Technologies qualifies as PHI or IIHI. Thus, the Court declines to dismiss the complaint on this basis. // C. Whether Plaintiffs consented to disclosure through the Privacy Policies of Opencare, Facebook, TikTok, and Google Alternatively, Defendant argues that Plaintiffs consented to disclosure through the privacy policies of Opencare, Facebook, TikTok, and Google. (Def.’s Mot. at 5.) In opposition, Plaintiff alleges that users are not asked to consent to the Privacy Policy until after they provide their Private Information through the Website, and the notice itself is inconspicuous. (Pls.’ Opp’n at 7.) As a result, Plaintiffs contend that they had no reason to opt out as they were not aware of the Privacy Policy. Id. Specifically, the operative complaint alleges:
A user of the Website is not asked to review Defendant’s privacy practices until well after Defendant has shared copious amounts of IIHI and PHI about that user. Specifically, a user is only asked to consent to Defendant’s privacy policy after that user has completed the entire questionnaire on Defendant’s Website, imputing highly sensitive information about the user’s medical conditions, insurance information, geographic location, dental history, and more. After Opencare has shared all of this sensitive information, users are provided with a small reference to the Defendant’s privacy policy page below the form in which they input their email. The form claims that a user consents to Opencare’s privacy policy by inputting their email. Many users are likely to miss this as it is in a small font in a grey color. (FAC ¶ 113.) Once users process and book an appointment, they are promised that “[i]f you do schedule an appointment through Opencare, that information is considered Protected Health Information, and we will not sell that to third parties.” Id. ¶ 114 (citing Opencare Privacy Policy). Even after, Plaintiffs contend that users are deceived and misled by the Privacy Policy, which, while it mentions that third parties may collect information about your activity, it provides assurances that “[i]f you do schedule an appointment through Opencare, that information is considered Protected Health Information, and we will not sell that to third parties.” (FAC ¶ 115 (quoting Opencare Privacy Policy).) Moreover, whether “users could have taken additional measures to prevent cookies from tracking their browsing” is not relevant at the pleading stage, because that “is a fact-based defense to be developed and asserted at a later stage of the litigation.” In re Facebook, Inc. Internet Tracking Litig., 956 F.3d 589, 605 (9th Cir. 2020). Accordingly, the Court finds that Plaintiffs’ allegations are sufficient to plead that they did D. Individual Claims i. Negligence Plaintiffs’ first cause of action is for negligence. (FAC ¶¶ 201-210.) To plead negligence, Plaintiffs must show that Defendant “owed [Plaintiffs] a legal duty, that it breached the duty, and that the breach was a proximate or legal cause of [Plaintiffs’] injuries.” Merrill v. Navegar, Inc., 26 Cal. 4th 465, 477 (2001). Defendant moves to dismiss on the grounds that HIPAA does not create a private right of action and cannot be used to define a tort duty enforceable under state common law. (Def.’s Mot. at 6.) In opposition, Plaintiffs contend that they are not alleging negligence under HIPAA. (Pls. Opp’n at 17.) Rather, Plaintiffs allege that Defendant had a common law duty “to exercise reasonable care to secure, safeguard and protect their highly sensitive Private Information.” (Pl.’s Opp’n at 16 (citing FAC ¶¶ 131, 141-145, 150, 202, 205).) While this claim mentions Defendant’s duty to safeguard this information under HIPAA, the negligence claim itself does not plead that HIPAA is the source of the common law duty. (See FAC ¶ 206.) Thus, Defendant’s argument is unavailing. California courts consider several factors when deciding whether a duty of care exists, including the foreseeability of harm to the plaintiff, the degree of certainty that the plaintiff suffered injury, the closeness of the connection between the defendant's conduct and the injury suffered, the moral blame attached to the defendant's conduct, the policy of preventing future harm, the extent of the burden to the defendant and the consequences to the community of imposing a duty to exercise care with resulting liability for breach, and the availability, cost, and prevalence of insurance for the risk involved. Regents of Univ. of Cal. v. Superior Court, 4 Cal. 5th 607, 628 (2018) (quoting Rowland v. Christian, 69 Cal. 2d 108 113 (1968)). These factors “must be evaluated at a relatively broad level of factual generality.” Id. (quotation omitted). Courts in this district have found a duty in data breach cases because “[t]he lack of reasonable care in the handling of personal information can foreseeably harm the individuals providing the information.” Bass v. Facebook, Inc., 394 F. Supp. 3d 1024, 1039 (N.D. Cal. 2019). The harm is even more foreseeable when the information “would create perverse incentives for businesses who profit off the use of consumers' personal data to turn a blind eye and ignore known security risks.” Id. (quoting In re Equifax, Inc., Customer Data Sec. Breach Litig., 362 F. Supp. 3d 1295, 1325 (N.D. Ga. 2019) (internal quotations omitted)). Here, Defendants collected private, medical information from Plaintiffs and used Tracking Technologies to collect other information about Plaintiffs. Thus, the Court finds that Plaintiffs’ allegations are sufficient to state a common law duty for negligence. Next, Defendant argues that the harm to is too speculative to constitute a breach of duty. (Def.’s Mot. at 7.) The Court disagrees. As discussed above, the Court finds that the harms are not speculative, as they have both occurred and remain ongoing. See discussion, supra, Part III.A. Finally, to the extent that Defendant argues that Plaintiffs could have opted out of targeted advertising pursuant to Opencare’s Privacy Policy, that argument is also not availing. (Def.’s Mot. at 8.) As discussed above, Plaintiff alleges that users are not asked to consent to the Privacy Policy until after they provide their Private Information through the Website, and the notice itself is inconspicuous. See discussion, supra, Part III.C. Accordingly, the motion is denied as to the negligence cause of action. ii. Invasion of Privacy Plaintiffs’ second cause of action is for invasion of privacy. (FAC ¶¶ 211-224.) Defendant moves to dismiss on the grounds that this claim in not cognizable because the use of tracking pixels or analytics is not offensive as a matter of law. (Def.’s Mot. at 8.) To state a claim for common law invasion of privacy, Plaintiffs “must allege: (1) intrusion into a private place, conversation or matter (2) in a manner highly offensive to a reasonable person.” Low v. LinkedIn Corp., 900 F. Supp. 2d 1010, 1025 (N.D. Cal. 2012) (citing Shulman v. Group W Prods., Inc., 18 Cal.4th 200, 231, 74 Cal.Rptr.2d 843, 955 P.2d 469 (1998) (emphasis in original). Similarly, to state a claim for invasion of privacy under the California Constitution, “Plaintiffs must show that (1) they possess a legally protected privacy interest, (2) they maintain a reasonable expectation of privacy, and (3) the intrusion is ‘so serious ... as to constitute an egregious breach of the social norms’ such that the breach is ‘highly offensive.’” In re Facebook, Inc., 47 Cal. 4th 272, 287 (2009)). In opposition, Plaintiffs claim to submit claims for invasion of privacy under both common law and the California Constitution. (Pls.’ Opp’n at 20.) As previously discussed, at this juncture, the Court finds that Plaintiffs have sufficiently alleged that the information transmitted was private information, and that the opt-out procedure was not sufficient to confer consent. See discussion, supra, Parts III.B-C. In accordance with other courts in this district, the Court finds that Plaintiffs had a reasonable expectation that the information shared would remain private, and the Tracking Technologies installed to share that information is highly offensive. See, e.g., Shah v. MyFitnessPal, Inc., No. 25-CV-04430-PCP, 2026 WL 216334, at *5 (N.D. Cal. Jan. 27, 2026) (third-party data collection and disclosure was highly offensive based on the information transmitted and the misrepresentation that it would be kept private). In reply, however, Defendant argues that the operative complaint does not mention the California Constitution. (Def.’s Reply at 6.) This argument is well taken. Plaintiffs, however, did request leave to amend to clearly allege both claims, and the Court grants them that opportunity. (See Pls.’ Opp’n at 20.) Thus, while the motion is denied as to the invasion of privacy claim, Plaintiffs are granted leave to amend to allege separate invasion of privacy claims under common law and the California Constitution. iii. Breach of Confidence Plaintiffs’ third cause of action is for breach of confidence under California law. (FAC ¶¶ 225-231.) To state a claim for breach of confidence, a plaintiff must adequately allege “(1) the plaintiff conveyed ‘confidential and novel information’ to the defendant; (2) the defendant had knowledge that the information was being disclosed in confidence; (3) there was an understanding between the defendant and the plaintiff that the confidence be maintained; and (4) there was a disclosure or use in violation of the understanding.” Berkla v. Corel Corp., 302 F.3d 909, 917 (9th Cir. 2002) (quoting Ent. Rsch. Grp., Inc. v. Genesis Creative Grp., Inc., 122 F.3d 1211, 1227 (9th Cir. 1997)). Defendant moves to dismiss on the grounds that “California does not recognize a standalone tort for breach of confidence outside of a traditional, confidential professional relationship such as a physician-patient relationship.” (Def.’s Mot. at 10.) As a result, Defendant contends that Plaintiffs’ failure to allege the existence of a special relationship beyond a duty to keep medical information confidential is fatal to this claim. Id. Defendant’s interpretation of SocialApps is much narrower than the order itself, which merely states that such a claim requires that the plaintiff “plead the existence of a confidential relationship and [Defendant’s] voluntary assumption thereof,” but it is “not limited to fiduciary relationships, nor to the existence of a contract.” SocialApps, 2012 WL 381216, at *3 (citing Faris v. Engberg, 97 Cal.App.3d 309, 321, 158 Cal.Rptr. 704 (1979)). In opposition, Plaintiffs argue that their allegations satisfy the elements of this claim. (Pls.’ Opp’n at 21.) Plaintiffs allege that they had reasonable expectations of privacy in the responses and communications entrusted through the Website, which included highly sensitive health information, and, while Defendant made express promises to keep the information confidential, Opencare installed Tracking Technologies to disclose the Private Information regarding Plaintiffs’ health. (FAC ¶¶ 227-228.) This is sufficient to state a claim for breach of confidence. Accordingly, the motion is denied as to this cause of action. iv. Unjust Enrichment Plaintiffs fourth cause of action is for unjust enrichment. (FAC ¶¶ 232-238.) While California does not have a standalone cause of action for “unjust enrichment,” “[w]hen a plaintiff alleges unjust enrichment, a court may construe the cause of action as a quasi-contract claim seeking restitution.” Astiana v. Hain Celestial Grp., Inc., 783 F.3d 753, 762 (9th Cir. 2015); see also Hartford Cas. Ins. Co. v. J.R. Mktg., L.L.C., 61 Cal. 4th 988, 998 (2015). “To allege unjust enrichment as an independent cause of action, a plaintiff must show that the defendant received and unjustly retained a benefit at the plaintiff's expense.” ESG Cap. Partners, LP v. Stratos, 828 F.3d 1023, 1038–39 (9th Cir. 2016) (citing Lectrodryer v. SeoulBank, 77 Cal. App. 4th 723, 726 (2000)). purported information provided, nor do Plaintiffs explain how Opencare has been able to monetize said information.” (Def.’s Mot. at 10.) Additionally, Defendant argues that Plaintiffs plead no facts that Opencare retained the benefit and the retention is unjust. Id. at 10-11. In opposition, Plaintiffs contend that they specifically allege that the benefit conferred was in the form of valuable Private Information in the expectation that their Private Information would remain confidential. (Pls.’ Opp’n at 22 (citing FAC ¶¶ 234-235.) Plaintiffs allege that Defendant unjustly retained those benefits at the expense of Plaintiffs and Class without providing any commensurate compensation to Plaintiffs or Class members. (FAC ¶ 236.) Defendant accepted Plaintiffs’ Private Information, but it did not provide the confidentiality promised, and, instead, it used Plaintiffs’ Private Information for its own benefit. (FAC ¶¶ 114, 237.) There appears to be no dispute that Plaintiffs have sufficient facts to plead this cause of action, but the current allegations set forth under the claim itself constitute the type of threadbare recitals and conclusory statements not permitted by Federal Rule of Civil Procedure 8. See Gibson v. City of Portland, 165 F.4th 1265, 1288 (9th Cir. 2026) (“Incorporation by reference is permitted by Rule 10(b) and (c), but when it is used indiscriminately, it becomes a shortcut by counsel that violates Rule 8.”) Accordingly, the unjust enrichment claim is dismissed with leave to amend. v. Violations of the Electronic Communications Privacy Act (“ECPA”) and the California Invasion of Privacy Act (“CIPA”) The fifth cause of action is for violations of the ECPA, 18 U.S.C. § 2511(1), et seq. (FAC ¶¶ 239-252.) The sixth cause of action is for violation of CIPA, California Penal § 631. (FAC ¶¶ 262-270.) These are both wiretapping claims and the courts treat them similarly, so the Court will address them together. See Shah v. MyFitnessPal, Inc., No. 25-CV-04430-PCP, 2026 WL 216334, at *6 (N.D. Cal. Jan. 27, 2026). Defendant moves to dismiss these claims on three independent grounds: “(i) the content at issue is not covered by the narrow statutory definition; (ii) Opencare was a party to the communication and cannot intentionally intercept its own communication (18 U.S.C. § 2511(2)(c)); and (iii) Plaintiffs consented to the communication….” (Def.’s Mot. at 11-12.) As an initial matter, the consent argument is not well taken for the same reasons set forth above. See discussion, supra, Part III.C. As far as whether the contents requirement is satisfied, Plaintiffs allege that the Tracking Technologies unlawfully disclosed Private Information, IIHI, PHI, IP addresses, Google account information, and health information to Information Recipients. (FAC ¶¶ 252-254.) The Ninth Circuit has held that to satisfy the statutory definition of “contents,” the information must be “a person's intended message to another (i.e., the ‘essential part’ of the communication, the ‘meaning conveyed,’ and the ‘thing one intends to convey’).” In re Zynga Priv. Litig., 750 F.3d 1098, 1106 (9th Cir. 2014). Thus, the allegations are sufficient to satisfy the content requirement. The only meritorious argument is the second one. Courts perform the same analysis for both the ECPA and CIPA regarding the party exemption. In re Facebook, Inc. Internet Tracking Litig., 956 F.3d 589, 607 (9th Cir. 2020). The ECPA prohibits the unauthorized “interception” of an “electronic communication.” 18 U.S.C. § 2511(1)(a)–(e). Similarly, California Penal Code Section 631(a) prohibits “willfully and without the consent of all parties to the communication, or in any unauthorized manner, read[ing], or attempt[ing] to read, or to learn the content or meaning of any message, report, or communication while the same is in transit.” “Both statutes contain an exemption from liability for a person who is a ‘party’ to the communication, whether acting under the color of law or not.” In re Facebook, Inc. Internet Tracking Litig., 956 F.3d at 607. Here, however, Defendant was a party to the communications, and, therefore, cannot intercept its own communications. To adequately plead the wiretapping claims, Plaintiffs would need to allege that a third party intercepted their communications with Opencare’s website. Shah v. MyFitnessPal, Inc., No. 25-CV-04430-PCP, 2026 WL 216334, at *7 (N.D. Cal. Jan. 27, 2026) (failure to allege that communications were intercepted by a third party fatal to wiretapping claim.) Alleging mere tracking is not sufficient. See id. Accordingly, the fifth and sixth causes of action for wiretapping are dismissed with leave to amend. If Plaintiffs cannot in good faith allege interception by a third-party, they should not include these claims in the second amended class action complaint. vi. Pen Register violation of California Penal Code § 638.51. (FAC ¶¶ 271-276.) California Penal Code Section 638.51(a) prohibits “install[ing] or us[ing] a pen register” without a court order under specific circumstances. Section 638.50(b) defines a “pen register” as “a device or process that record or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication.” Defendant argues that this claim should be dismissed, because consent of the user is an exception to the use of these devices. (Def.’s Mot. at 13.) Defendant further contends that Plaintiff Kady’s claim is barred by the applicable one-year statute of limitations, because Plaintiff Kady accessed Opencare in July 2023. Id. at 13-14. In opposition, Plaintiffs acknowledge that the pen register claim is being pled in the alternative to the wiretapping claims. (Pls.’ Opp’n at 16.) Plaintiffs also argue that Plaintiff Kady’s claim is not time-barred due to the delayed discovery rule, because she did not discover Opencare’s violations until shortly before the initial complaint was filed. (See Pls.’ Opp’n at 13, 16.) Again, the Court finds the consent argument unavailing for the reasons set forth above. See discussion, supra, Part III.C. Defendant’s statute of limitations argument, however, appears well taken. (Def.’s Mot. at 13-14; Def.’s Reply at 5.) Indeed, Plaintiff Kady alleges that she received unwanted advertisements almost immediately after visiting the Website in July 2023, and this lawsuit was not filed until June 2025. (See FAC ¶¶ 30-31.) “Generally speaking, a cause of action accrues at the time when the cause of action is complete with all of its elements.” Fox v. Ethicon Endo-Surgery, Inc., 35 Cal. 4th 797, 806, 27 Cal.Rptr.3d 661, 110 P.3d 914 (2005) (cleaned up). The statute of limitations will begin to run so long as the plaintiff knows the facts underlying the claim even if they did not know that the conduct is illegal. Wakefield v. Wells Fargo & Co., No. C 13-05053-LB, 2014 WL 5077134, at *12 (N.D. Cal. Oct. 9, 2014). “The discovery rule is an exception to the accrual rule and postpones ‘accrual of a cause of action until the plaintiff discovers, or has reason to discover, the at *4 (N.D. Cal. June 5, 2026) (quoting Fox, 35 Cal. 4th at 807.) Here, the operative complaint does not allege any specific facts to support the imposition of the delayed discovery rule, and, instead, relies on a threadbare recital that tolling applies. (See FAC ¶ 186.) Thus, the pen register claim is dismissed with leave to amend to allege facts to support delayed discovery as to Plaintiff Kady. If Plaintiffs cannot do so, they shall amend this claim to apply only to Plaintiff Taylor, who utilized the Website within the statutory period. (See FAC ¶ 38.) vii. Violation of the California Confidentiality of Medical Information Act (“CMIA”) The eighth cause of action is for violation of CMIA, California Civil Code § 56, et seq. (FAC ¶¶ 277-283.) The CMIA states that “[a] provider of health care… shall not disclose medical information regarding a patient of the provider of health care… without first obtaining an authorization.” Cal. Civ. Code § 56.10(a)-(c). A health care provider “who negligently creates, maintains, preserves, stores, abandons, destroys, or disposes of medical information” is subject to liability. Cal. Civ. Code § 56.101(a). “The Legislature enacted the CMIA to ‘protect the confidentiality of individually identifiable medical information obtained from a patient by a health care provider, while at the same time setting forth limited circumstances in which the release of such information to specified entities or individuals is permissible.’” J.M. v. Illuminate Educ., Inc., 19 Cal. 5th 705, 714, 588 P.3d 611, 615 (2026) (quoting Loder v. City of Glendale, 14 Cal. 4th 846, 859 (1997)). The California Supreme Court recently clarified that “confidentiality is breached when the information is exposed to a significant risk of unauthorized access or use.” J.M., 19 Cal. 5th at 711. Here, Defendant moves to dismiss on the grounds that it is not a provider of health care under the CMIA. (Def.’s Mot. at 15.) Section 56.06, however, broadly defines a “provider of health care” to include “[a]ny business organized for the purpose of maintaining medical information in order to make the information available to an individual or to a provider of health care at the request of the individual or a provider of health care.” Cal. Civ. Code § 56.06(a). In businesses that offer software or hardware to consumers, including mobile applications and websites, that “make the information available to an individual or a provider of health care at the request of the individual or a provider of health care, for purposes of allowing the individual to manage the individual's information, or for the diagnosis, treatment, or management of a medical condition of the individual….” Cal. Civ. Code § 56.06(b); see also J.M., 19 Cal. 5th at 714 (noting the expansion of the provider definition). In opposition, Plaintiffs contend that Defendant is provider of healthcare under the statute, because it falls within the definition of a “contractor” under Section 56.05(d), but they concede that additional facts could be included to sufficiently plead the elements of this cause of action. (Pls.’ Opp’n at 15 & n. 131.) In reply, Defendant argues that Plaintiffs’ categorization of Opencare as “any other entity” and a “contractor” in the opposition should not be entertained, because those terms have distinct definitions under CIMA. (Def.’s Reply at 7.) While Defendant is correct that the claim is subject to dismissal for failure to adequately allege that it is a provider, the Court will grant Plaintiffs leave to amend. To the extent that Defendant argues that Plaintiffs are not “patients” or that the Private Information does not constitute “medical information,” these arguments must be addressed after amendment. (See Def.’s Mot. at 15.) The CMIA defines “patient” as “a natural person, whether or not still living, who received health care services from a provider of health care and to whom medical information pertains.” Cal. Civ. Code § 56.05(m). “Medical information” is defined as “any individually identifiable information, in electronic or physical form, in possession of or derived from a provider of health care, health care service plan, pharmaceutical company, or contractor regarding a patient’s medical history, mental health application information, reproductive or sexual health application information, mental or physical condition, or treatment.” Cal. Civ. Code § 56.05(i). In the motion, Defendant concedes that whether Plaintiffs qualify as
1 Generally, the parties are dissuaded from including legal argument in footnotes, because the Court is under no obligation to consider them. See Indep. Towers of Wash. v. Washington, 350 F.3d 925, 929 (9th Cir. 2003). As the Seventh Circuit observed in its now familiar maxim, “judges ] “patients” or that the information qualifies as “medical information” depends on whether 2 Opencare is a “provider.” (Def.’s Mot. at 15.) 3 Accordingly, the eighth cause of action is dismissed with leave to amend. 4 viii. Violation of the California Customer Records Act 5 The ninth cause of action is for violation of the California Customer Records Act, 6 California Civil Code § 1798.80, et seq. (FAC 9 284-295.) Plaintiffs explicitly abandoned this 7 claim in their opposition, so it is dismissed with prejudice. (See Pls.” Opp’n at 9 n. 6.) 9 For the reasons set forth above, Defendant’s motion to dismiss is GRANTED IN PART 10 AND DENIED IN PART. Specifically, the fourth, fifth, sixth, seventh, and eighth causes of 1] action are dismissed with leave to amend, while the ninth cause of action is dismissed without 12 leave to amend. The motion is denied in all other respects, but Plaintiffs are GRANTED leave to 13 amend to separately allege invasion of privacy under common law and the California Constitution. 14 IfPlaintiffs cannot in good faith allege sufficient facts to satisfy all of the elements of the 15 dismissed claims, they are encouraged to forego amendment of those claims. a 16 Plaintiffs shall file a second amended class action complaint within 21 days of this order. 18 Dated: August 31, 2026
20 Unitéd States Magistrate Judge 21 22 23 24 25 26 27 28