Doe v. Integris Health

123 F.4th 1189
Court of Appeals for the Tenth Circuit·Decided December 20, 2024·No. 23-6209·Published·Cited by 2 cases

Opinion

FILED

United States Court of Appeals PUBLISH Tenth Circuit

UNITED STATES COURT OF APPEALS December 20, 2024

Christopher M. Wolpert

FOR THE TENTH CIRCUIT Clerk of Court

JOHN DOE, Individually and on behalf of all others similarly situated,

Plaintiff - Appellee, v. No. 23-6209 INTEGRIS HEALTH, INC.,

Defendant - Appellant.

Appeal from the United States District Court for the Western District of Oklahoma (D.C. No. 5:23-CV-00728-HE)

Kyle T. Cutts, Baker & Hostetler LLP, Cleveland, Ohio (Paul G. Karlsgodt, Baker & Hostetler LLP, Denver, Colorado; Lisa A. Houssiere, Baker & Hostetler LLP, Houston, Texas; Larry D. Ottaway and Andrew M. Bowman, Foliart, Huff, Ottaway & Bottom, Oklahoma City, Oklahoma, on the briefs), for Defendant – Appellant.

Michael C. Iadevaia, Stranch, Jennings & Garvey, PLLC, Nashville, Tennessee (J. Gerard Stranch IV, Stranch, Jennings & Garvey, PLLC; Lynn A. Toops, Cohen & Malad, LLP, Indianapolis, Indiana; Matthew Dean Alison and Jason Bjorn Aamodt, Indian & Environmental Law Group, Tulsa, Oklahoma, with him on the briefs), for Plaintiff – Appellee.

Before TYMKOVICH, McHUGH, and ROSSMAN, Circuit Judges.

McHUGH, Circuit Judge.

Plaintiff John Doe filed a putative class action lawsuit against Defendant Integris Health, Inc. In his complaint, Mr. Doe alleges that Integris collected confidential health information from people who visited its website and unlawfully shared that information with third parties, like Google and Facebook.

Mr. Doe brought his suit in Oklahoma state court and asserted only state law claims. Integris responded by removing the case to federal court under the federal officer removal statute, asserting it was “acting under” the direction of a federal officer. See 28 U.S.C. § 1442(a)(1). Integris argued it acted under a federal officer because it created its website to help the federal government achieve its objective of ensuring patients can access and use electronic health records (“EHR”).

The federal district court remanded the case, concluding Integris had not shown it was “acting under” the direction of a federal officer. We agree with this conclusion and affirm.

I. BACKGROUND

A. Factual History1

In 2004, President George W. Bush issued an executive order directing the Secretary of Health and Human Services (HHS) to establish the position of National Health Information Technology Coordinator (the “National Coordinator”). Exec.

1 “When courts review a notice of removal for jurisdiction, they may consider the complaint as well as documents attached to the notice of removal.” Bd. of Cnty. Comm’rs v. Suncor Energy (U.S.A.) Inc., 25 F.4th 1238, 1247 n.1 (10th Cir. 2022). Accordingly, these facts are drawn from Mr. Doe’s complaint as well as the documents attached to Integris’s Notice of Removal.

Order No. 13,335, 69 Fed. Reg. 24059 (Apr. 27, 2004). The National Coordinator’s purpose is “to provide leadership for the development and nationwide implementation of an interoperable[2] health information technology infrastructure to improve the quality and efficiency of health care.” App. Vol. II at 231.

In 2009, Congress codified the position of National Coordinator in the Health Information Technology Act (the “HITECH Act” or the “Act”). See Am. Recovery & Reinvestment Act, Pub. L. No. 111-5, 123 Stat. 115, 230 (2009) (codified at 42 U.S.C. § 300jj-11(a)). The Act directs the National Coordinator to act “in a manner consistent with the development of a nationwide health information technology infrastructure that allows for the electronic use and exchange of information.” 42 U.S.C. § 300jj-11(b). Additionally, the HITECH Act directed HHS to make incentive payments to healthcare providers for their “adoption and meaningful use of certified EHR technology.” Id. § 1395w-4(o). Starting in 2015, healthcare providers that were not “meaningful EHR user[s]” received reduced Medicare reimbursements. Id. § 1395w-4(a)(7)(A)(i).

The Centers for Medicare and Medicaid Services (CMS)3 promulgated regulations explaining how providers qualify as meaningful EHR users. 42 C.F.R.

2 “Interoperability refers to the ability of IT systems to share and use electronic information.” C. Stephen Redhead, Cong. Rsch. Serv., R40161, The Health Information Technology for Economic and Clinical Health (HITECH) Act 1 n.2 (2009).

3 CMS is a federal agency within HHS and is responsible for administering Medicare, Medicaid, and related programs.

§ 495.2–.370. These regulations and the associated incentives are referred to as the “Promoting Interoperability Program” or the “Meaningful Use program” (“MUP”). Id. § 495.4. The MUP regulations require healthcare providers to certify annually that they are in compliance. Id. at § 495.40; 45 C.F.R. § 170.315. Certification requires providers to report on patients’ ability “to use internet-based technology to view, download, and transmit their health information to a 3rd party.” 45 C.F.R. § 170.315(e)(1)(i).

Integris is a private healthcare provider in Oklahoma that has been a MUP participant for years. Relevant to its MUP participation, Integris has a public-facing website that it encourages patients to use for, among other things, searching for physicians, researching health information, scheduling appointments, and paying bills. The public-facing website also links to Integris’s password-protected patient portal that patients use to access EHR. Some of Integris’s MUP funds went toward developing the patient portal.

Integris contends that for it to meet MUP requirements, and thus avoid reduced Medicare reimbursements, its “patients must be aware of the patient portal, understand the benefits and options that are available to them within the patient portal, and find the patient portal easy to use.” Id. Thus, Integris implemented tracking technology—called “trackers” or “pixels”—into its public-facing website to better understand the “usability” of its website and patient portal. App. Vol. I at 25; App. Vol. II at 223.

According to Mr. Doe, trackers or pixels are “a snippet of code embedded into a website that tracks information about its visitors and their website interactions.” App. Vol. I at 25–26. To illustrate, “[w]hen a person visits a website with an embedded pixel, the pixel tracks ‘events’ (i.e., user interactions with the site), such as pages viewed, buttons clicked, and information submitted.” Id. at 26. The pixel then “transmits the event information back to the website server and to third parties,” like Facebook, Google, and Microsoft.4 Id. at 26, 29. The third parties use the information “to create targeted advertisements based on the medical conditions and other information disclosed to [Integris].” Id. at 28. For example, if a patient researched hypertension on Integris’s website, Facebook could “sell a drug company targeted ad space for blood pressure medication” on the patient’s Facebook feed. Appellee’s Br. at 5. In exchange for patient information, the third parties provide Integris with “enhanced advertising services” that allow Integris to measure the impact of its advertisements. App. Vol. I at 49.

B. Procedural History Mr. Doe, an Integris patient, filed this class action lawsuit in Oklahoma state court. The complaint alleges that Integris’s use of trackers violates Health Insurance Portability and Accountability Act (HIPAA) standards, industry standards, the

4 Mr. Doe alleges that Integris has embedded several trackers, including Facebook Pixel (or “Meta Pixel”), Google Analytics, Google Tag Manager, Microsoft Universal Event Tracking, LinkedIn, Bidtellect, StackAdapt, Reddit Ads, DoubleClick, MediaMath, and Trade Desk.

Free access — add to your briefcase to read the full text and ask questions with AI

Doe v. Integris Health, 123 F.4th 1189 (10th Cir. 2024).

123 F.4th 1189 (Doe v. Integris Health) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related