ELIA RAMIREZ, Case No. 5:24-cv-02012-EJD
Plaintiff, ORDER GRANTING IN PART AND DENYING IN PART MOTION TO v. DISMISS
Re: Dkt. No. 55 Defendant.
Plaintiff Elia Ramirez (“Ramirez”) brings individual and class action claims against Defendant, a telehealth company known as Trusper, Inc., d/b/a Musely (“Musely”), alleging that Musely embedded surveillance software known as the “Facebook Pixel” and “TikTok Pixel” into its website, which allowed Meta and TikTok to intercept users’ personally identifiable and protected health information in violation of various California privacy laws. First Am. Compl. (“FAC”), ECF No. 49. Before the Court is Musely’s motion to dismiss pursuant to Federal Rule of Civil Procedure 12(b)(6). Mot., ECF No 55. This motion is fully briefed. Opp’n, ECF No. 60; Reply, ECF No. 62. After carefully reviewing the relevant documents, the Court finds this motion suitable for decision without oral argument pursuant to Local Rule 7-1(b). For the reasons explained below, the Court GRANTS IN PART and DENIES IN PART Musely’s motion to dismiss. As the Court detailed in its prior order denying Musely’s motion to compel arbitration, ECF No. 25, Ramirez alleges that Musely disclosed its users’ confidential medical information to Meta and TikTok for advertising purposes by embedding the Facebook Pixel and TikTok Pixel on its website. See FAC. The Facebook Pixel and TikTok Pixel are pieces of JavaScript-based code that advertisers can install on their websites. Id. ¶¶ 66, 68. When a Facebook or TikTok user accesses the advertiser’s website, the codes cause the user’s internet browser to send information about their actions on the website to Meta and TikTok. Id. Meta and TikTok then use that data to identify the user and provide insights to the advertiser about its audience. Id. Musely is a nationwide telehealth services website that connects customers searching for prescription skin condition treatments to doctors. Id. ¶¶ 20–22. Ramirez alleges that she went to Musely’s website in or around August 2023 to purchase a prescription skin care treatment. Id. ¶ 5. Unbeknownst to her, Ramirez alleges that Musely had installed the Facebook Pixel on its website, and the personal information she submitted to receive a prescription was secretly sent to Meta without her consent. Id. ¶ 7. “To survive a motion to dismiss, a complaint must contain sufficient factual matter, accepted as true, to ‘state a claim to relief that is plausible on its face.’” Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007)). A plaintiff must “plead[] factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged,” which requires “more than a sheer possibility that a defendant has acted unlawfully.” Id. The Court must “accept factual allegations in the complaint as true and construe the pleadings in the light most favorable to the nonmoving party.” Manzarek v. St. Paul Fire & Marine Ins. Co., 519 F.3d 1025, 1031 (9th Cir. 2008). However, courts “are not bound to accept as true a legal conclusion couched as a factual allegation.” Ashcroft, 556 U.S. at 678. If the court concludes that a Rule 12(b)(6) motion should be granted, the “court should grant leave to amend even if no request to amend the pleading was made, unless it determines that the pleading could not possibly be cured by the allegation of other facts.” Lopez v. Smith, 203 F.3d 1122, 1127 (9th Cir. 2000) (en banc) (quotation omitted). III. DISCUSSION This case is not the first of its kind. The Court has issued several recent orders in cases alleging substantially similar CIPA, ECPA, CMIA, and California Constitution privacy claims— filed by largely the same counsel—arising out of the presence of LinkedIn’s Insight Tag and Meta’s Facebook Pixel on health-related websites. See, e.g., Doe, et al. v. LinkedIn Corp., No. 5:25-CV-03737-EJD, 2026 WL 2199526, at *1 (N.D. Cal. July 30, 2026); J.S. v. Spring Fertility Holdings, LLC, No. 5:24-CV-07374-EJD, 2026 WL 1483490, at *1 (N.D. Cal. May 27, 2026); L.B. v. LinkedIn Corp., Case No. 5:24-CV-06832-EJD, 2025 WL 2899514 (N.D. Cal. Oct. 10, 2025). The Court’s analysis below applies those same principles to the facts of this case. The Court will address in turn the threshold issues of consent and intent before examining Ramirez’s CIPA, CMIA, ECPA, and California Constitution claims. A. Consent Consent is a defense to each of Ramirez’s claims. See Calhoun v. Google LLC, 526 F. Supp. 3d 605, 619 (N.D. Cal. 2021) (collecting cases). Musely argues that Ramirez consented to the sharing of her data, including health-related information, through the Privacy Policy hyperlinked on the homepage of Musely’s website. Mot. 15. For a defendant to show consent through disclosures, the disclosures must “explicitly notify” users of the practice at issue and must have only one plausible interpretation. In re Facebook, Inc., Consumer Priv. User Profile Litig., 402 F. Supp. 3d 767, 794 (N.D. Cal. 2019); see also In re Google Location Hist. Litig., 428 F. Supp. 3d 185, 190 (N.D. Cal. 2019) (“Consent is only effective if the person alleging harm consented to ‘the particular conduct, or to substantially the same conduct’ and if the alleged tortfeasor did not exceed the scope of that consent.”). While there may be “subtle differences” among consent doctrines, “the question under [each] is essentially the same: Would a reasonable user who viewed [the defendant’s] disclosures have understood that [it] was collecting [the information at issue]?” Perkins v. LinkedIn Corp., 53 F. Supp. 3d 1190, 1212 (N.D. Cal. 2014); see also In re Google Inc., No. 13-MD-02430-LHK, 2013 WL 5423918, at *12 (N.D. Cal. Sept. 26, 2013) (“[C]onsent is not an all-or-nothing proposition.”). The parties spend a great deal of time in their pleadings disputing whether Ramirez had sufficient notice of the Privacy Policy, and whether the Court should grant Musely’s request to take judicial notice of a screenshot depicting what appears to be Muley’s Sign Up page.1 However, the Court finds it unnecessary to engage in that analysis at this time. Even if Ramirez had sufficient notice of the Privacy Policy, Musely has not established as a matter of law that the Privacy Policy disclosed Musely would send users’ health information to third parties such as Meta and TikTok. Musely’s motion presents the following argument, in its totality, regarding the disclosures in the Privacy Policy:
The Privacy Notice goes into great detail as to the type of information that Musely collects, including the very information Plaintiff alleges was improperly intercepted, i.e., “medical conditions,” “medical concerns,” “treatment,” prescription products for those conditions, and “physical condition.” Compare Doc. 49 at ¶¶ 107, 108 with Frey Decl., Ex. 2 at pp. 2-9. The FAC “fail[s] to plead facts sufficient to show a reasonable expectation that” Plaintiff’s information would not be shared. L.B., 2025 WL 2899514, at *11. Mot. 12. As an initial matter, several of these quotes do not exist in the Privacy Policy. See Privacy Policy, ECF No. 57-2. The terms “medical concerns” and “physical condition” do not appear in the seven pages cited, or any other page of Exhibit 2. Id. But regardless, Musely argues only that the Privacy Policy notifies users it collects the information at issue here; not that it discloses this information to third parties. In fact, the only provision in the Privacy Policy discussing disclosures suggests this information would be disclosed only to medical professionals for the purpose of determining diagnoses and treatments: If you purchase products that require an online consultation with a medical professional, you will be asked to submit during the online questionnaire process personal medical and health information,
1 The Court observes that it examined a different “Sign Up” page in its prior order denying Musely’s motion to compel arbitration. Regardless, because the Court need not reach these issues, the Court denies the request for judicial notice as moot. photographs of different angles of your face or other parts of your body, as well as demographic and other information relevant to diagnosis and treatment, such as skincare routines, lifestyle and general medical history (e.g., conditions, allergies, etc.) (collectively, "Medical Information"). With your consent, Musely will share your Medical Information via confidential channels to a doctor or other medical professional regarding your diagnosis and treatment. Privacy Policy 7 (emphasis added). There is also one section specifically discussing Musely’s use of “pixels” to “automatically record certain technical information about your interactions when you visit the Platform or otherwise engage with us.” Id. at 8. But again, this section says nothing about disclosing any information to third parties—let alone disclosing information users submit in pursuit of seeking a prescription from a medical professional. In other words, the Privacy Policy far from extinguishes a reasonable user’s expectation of privacy in their medical-related information. B. Intent Intent is also a requirement for liability under the ECPA, CIPA, and California Constitution privacy claims. To state these claims, Ramirez must plausibly allege that Musely’s violation of her privacy rights was intentional as opposed to inadvertent. See United States v. Christensen, 828 F.3d 763, 790 (9th Cir. 2015) (the Federal Wiretap Act requires that “the defendant acted intentionally, that is, purposefully and deliberately and not as a result of accident or mistake”); Doe I v. Google LLC, 741 F. Supp. 3d 828, 840, 844 (N.D. Cal. 2024) (extending Christensen's analysis of the intent requirement to claims under the ECPA and CIPA, as well as invasion of privacy under the California Constitution). Musely argues the mere fact that a defendant paid a vendor to intercept messages is insufficient to establish the necessary scienter for Ramirez’s claims. Mot. 14 (citing Heiting v. Taro Pharms. USA, Inc., 709 F. Supp. 3d 1007, 1019 (C.D. Cal. 2023) and Smith v. YETI Coolers, LLC, 754 F. Supp. 3d 933, 943 (N.D. Cal. 2024) (holding that allegations the defendant was aware that the third party collected consumers’ information and assisted the third party in doing so did “not contain sufficient facts for the Court to draw a plausible inference that Defendant knowingly agreed with or employed [the third party] to engage in conduct that violated the wiretapping statute”)). The Court disagrees. Ramirez pleads the following facts relevant to Musely’s knowledge and intent, among others: “Defendant chose to include the Facebook Pixel on its Website,” FAC ¶ 31; “Meta’s own documentation makes clear just how much tracking of private information the Facebook Pixel does,” id. ¶ 32; “[t]he Facebook Pixel code enables Meta not only to help Defendant with advertising to its own patients outside the Website,” id. ¶ 35; “[t]hrough the Facebook Pixel, Defendant shared its patients’ identities and online activity, including information and search results related to their private medical treatment,” id. ¶ 49; and “[t]he government has issued guidance warning that tracking code like the Facebook Pixel may violate federal privacy law when installed on healthcare websites,” id. ¶ 70. At this stage, the Court finds these allegations—that Musely chose to install the Facebook Pixel and TikTok pixel for advertising purposes despite Meta’s documentation making clear that the pixel would track the information at issue here and despite government warnings that installing pixels such as these on healthcare websites may violate federal privacy laws—sufficient to create a reasonable inference that Musely intentionally invaded Ramirez’s privacy rights for its own financial benefit. C. CIPA § 631 CIPA § 631 contains four independent clauses. Ramirez premises her claim on Clause Four, which imposes liability when a person “aids, agrees with, employs, or conspires with any person” to violate the statute. Cal. Penal Code § 631(a). Musely argues the Court should dismiss this claim because: (1) there are insufficient facts to show a predicate violation of § 631 by Meta or TikTok; (2) the party exception applies; and (3) there are insufficient facts to satisfy the “in- transit” requirement. 1. Predicate Violation A party is subject to derivative liability under Clause Four only where “a third party is liable for recording the communications in violation of the first, second or third clauses.” Martin v. Sephora USA, Inc., No. 1:22-CV-01355-JLT-SAB, 2023 WL 2717636, at *12 (E.D. Cal. Mar. 30, 2023), report and recommendation adopted, No. 122CV01355JLTSAB, 2023 WL 3061957 (E.D. Cal. Apr. 24, 2023). In other words, there must first be a predicate violation of one of § 631(a)’s first three clauses before liability may attach under the fourth clause. Gutierrez v. Converse Inc., No. CV 23-6547-KK-MARX, 2024 WL 3511648, at *8 (C.D. Cal. July 12, 2024), aff’d, No. 24-4797, 2025 WL 1895315 (9th Cir. July 9, 2025). Musely argues the allegations in the FAC relate only to Musely’s conduct, not the conduct of any third party. Mot. 13–15. For example, Musely cites to allegations that it was Musely who “chose to include the Facebook Pixel on its Website.” FAC ¶ 31. By focusing solely on allegations of Musely’s conduct, Musely argues Ramirez failed to plead Meta and TikTok themselves committed a predicate violation of § 631. Mot. 13–15. The Court finds Musely’s argument unpersuasive. Ramirez alleges the following facts relevant to showing a predicate violation: (1) the Facebook Pixel and TikTok Pixel operate by causing Musely to secretly duplicate Ramirez’s communications with Musely and transmit them contemporaneously to Meta and TikTok’s servers, id. ¶¶ 30, 38, 66, 68; (2) Meta and TikTok receive, process, analyze, and assimilate the incepted information, id. ¶¶ 39, 46, 48, 66; and (3) Meta and TikTok use this information for their own independent advertising purposes, id. ¶¶ 47, 128. At this early stage of litigation, the Court finds these allegations are sufficiently tailored to Meta and TikTok’s conduct for purposes of pleading their involvement in a predicate § 631 violation. 2. Party Exception Next, Musely argues that CIPA’s party exception dooms Ramirez’s § 631 claims. Mot. 15–16. Under this exception, a party to a conversation by definition cannot be liable for intercepting communications between them. In re Facebook, Inc. Internet Tracking Litig., 956 F.3d 589, 607 (9th Cir. 2020) (holding that CIPA applies “only to eavesdropping by a third party and not to recording by a participant to a conversation”) (citation omitted). Musely contends Meta and TikTok received information only to support Musely’s advertising business and therefore constitute a “party” to the communications between Musely and its website users. Mot. 15–16. As the Court has discussed in orders examining nearly identical complaints, there is a split among courts on this issue. See L.B., 2025 WL 2899514, at *14–15 (collecting cases). Some courts have found that, where the purpose of the tracking technology is to support the website operator’s advertising efforts, they act as an extension of the operators and therefore are protected by the party exception. See, e.g., Graham v. Noom, Inc., 533 F. Supp. 3d 823, 832 (N.D. Cal. 2021); Doe I v. Google LLC, 741 F. Supp. 3d 828, 843–44 (N.D. Cal. 2024); Love v. Ladder Fin., Inc., No. 23-CV-04234-VC, 2024 WL 2104497, at *1 (N.D. Cal. May 8, 2024); Williams v. What If Holdings, LLC, No. C 22-03780 WHA, 2022 WL 17869275, at *3 (N.D. Cal. Dec. 22, 2022). Other courts, however, have found that analytics providers such as Meta and TikTok are not mere extensions of a website operator if the providers have the “capability to use” communications for any other purpose other than supporting the operator. See, e.g., Javier v. Assurance IQ, LLC, 649 F. Supp. 3d 891, 900 (N.D. Cal. 2023); Jackson v. LinkedIn Corp., 744 F. Supp. 3d 986, 994 (N.D. Cal. 2024). As it did in L.B., the Court follows the logic of this second category of cases. Upon reviewing the facts alleged here, the Court finds sufficient allegations that Meta and TikTok can, and do, use the allegedly intercepted information to fuel their own advertising services and enable advertisers to reach target audiences. See, e.g., FAC ¶¶ 35, 46–47, 66, 68. The Court accordingly rejects Musely’s party exception argument at this time. 3. “In Transit” Finally, Musely argues Ramirez has failed to sufficiently allege Meta and TikTok intercept users’ data while “in transit.” Mot. 16. To meet the “in transit” requirement, Ramirez must allege that Meta and TikTok read communications between users and Musely during their transmission, as opposed to once the communications were placed in electronic storage. Heiting v. Taro Pharms. USA, Inc., 728 F. Supp. 3d 1112, 1125 (C.D. Cal. 2024). That is, Ramirez must plead specific facts about “when the interception occurs.” Swarts v. Home Depot, Inc., 689 F. Supp. 3d 732, 746 (N.D. Cal. 2023). Ramirez need not prove her theory of interception to survive dismissal, but she must at least “provide fair notice to [Musely] of when they believe [Meta and TikTok] intercepts their communications.” In re Vizio, Inc., Consumer Priv. Litig., 238 F. Supp. 3d 1204, 1228 (C.D. Cal. 2017); see also Esparza v. Gen Digital Inc., No. CV 23-8223- KK- AGRX, 2024 WL 655986, at *4 (C.D. Cal. Jan. 16, 2024) (dismissing CIPA claims where “Plaintiff fail[ed] to allege specific facts about . . . when the interception took place, and how the interception took place”). Musely contends that using the word “intercepted” in the complaint is insufficient without the addition of facts making it plausible that her data was intercepted in transit. Mot. 16. The Court finds Musely’s position unpersuasive at this time. Ramirez alleges in relevant part:
Transmissions from users’ browsers to Meta through the Facebook Tracking Pixel occur in the same manner on each website where the technology is loaded. When an action is taken on a website, the individual’s browser sends a GET request to Defendant’s server requesting that server to load the particular webpage …. The Facebook Tracking Pixel causes the browser to secretly and contemporaneously duplicate the communication with a website transmitting it to Meta’s servers, alongside additional information that transcribes the communication’s content and the individual’s identity. This transmission is initiated by Meta’s code and concurrent with the communications with the host website. Consistent with the way its technology is created, Meta immediately views and processes the information and adds it to advertising data sets, as described above. FAC ¶ 66; see also id. ¶ 68 (similar allegations regarding the TikTok Pixel). The Court finds these allegations that the pixels “contemporaneously duplicate” communications, “concurrent[ly]” transmit the communications to Meta and TikTok’s servers, and “immediately” view and process the information sufficient to survive Musely’s Rule 12(b)(6) challenge. Although the parties dispute the precise way and timing by which the pixels process the transmitted data, those issues are better addressed on a more developed factual record. The Court therefore DENIES the motion to dismiss Ramirez’s CIPA § 631 claim. D. CIPA § 632 CIPA § 632 prohibits “intentionally and without the consent of all parties to a confidential communication, us[ing] an electronic amplifying or recording device to eavesdrop upon or record the confidential communication.” Cal. Penal Code § 632(a). Musely argues that Ramirez’s § 632 claim fails in part because it does not contain a cause of action for derivative liability. Mot. 20; Reply 13. As it did in J.S., 2026 WL 1483490, at *5–6, the Court agrees. Ramirez does not allege that Musely eavesdropped on her communications; to the contrary, she alleges that she expected her communications “to be confined to [Musely].” FAC ¶ 124. Ramirez suggests that her § 632 claim against Musely could proceed nevertheless on a theory of derivative liability. However, unlike § 631, § 632 does not explicitly provide a cause of action for derivative liability. This omission is significant. See In re Eastport Assocs., 935 F.2d 1071, 1080 (9th Cir. 1991) (“[S]tatutes should be construed to give their terms meaning and effect, avoiding interpretive constructions which render some words surplusage.”) (quoting California Mfrs. Assn. v. Pub. Utilities Com., 24 Cal. 3d 836, 844 (1979)).2 Moreover, although Cal. Penal Code § 31 provides that “[a]ll persons concerned in the commission of a crime . . . whether they directly commit the act constituting the offense, or aid and abet in its commission . . . are principals in any crime so committed,” the Court is not persuaded that this same provision creates a cause of action for derivative civil liability under § 632. See J.S., 2026 WL 1483490, *5 n.5; see also Stoba v. Saveology.com, LLC, No. 13-cv-2925, 2014 WL 3573404, at *4 (S.D. Cal. July 18, 2014) (finding § 31’s “criminal standards do not apply to Plaintiffs’ §§ 632 and 632.7 civil causes of action”); see c.f. M.G. v. Therapymatch, Inc., No. 23-CV-04422-AMO, 2024 WL 4219992, at *4 (N.D. Cal. Sept. 16, 2024) (finding generally that criminal standard for aiding and abetting does not apply to civil right of action) (citing Stoba, 2014 WL 3573404, at *4). Therefore, the Court GRANTS Musely’s motion to dismiss the CIPA § 632 claim without leave to amend. California Civil Code § 56.10 provides that “[a] provider of health care . . . shall not disclose medical information regarding a patient . . . without first obtaining an authorization.” Cal. Civ. Code § 56.10(a). The CMIA defines “medical information” as:
2 Though not argued by Ramirez, Musely notes that any individually identifiable information, in electronic or physical form, in possession of or derived from a provider of health care, health care service plan, pharmaceutical company, or contractor regarding a patient's medical history, mental health application information, reproductive or sexual health application information, mental or physical condition, or treatment. Cal. Civ. Code § 56.05(j). The California Court of Appeal has explained that medical information under the CMIA consists of “substantive information regarding a patient’s medical condition or history that is combined with individually identifiable information.” Eisenhower Med. Ctr. v. Superior Ct., 226 Cal. App. 4th 430, 434 (2014). Musely argues the information it allegedly disclosed is both pled without sufficient detail and falls outside the CMIA’s definition of “medical information.” Mot. 17–19. According to Musely, Ramirez alleges to have only submitted demographic or numerical information, not information having to do with her medical condition or history. Id. at 18 (citing Gray v. Luxottica of Am., Inc., No. 8:24-CV-00160-MRA-DFM, 2024 WL 5689566, at *8 (C.D. Cal. Dec. 16, 2024)). The Court finds Musely’s argument unpersuasive. Ramirez alleges that she “answered a series of questions related to the condition of her skin for the purpose of having a doctor write a prescription for the medication she purchased,” and Musely transmitted this communication to Meta. FAC ¶ 5. Ramirez later specifically alleges that the information transmitted through the Facebook Pixel and TikTok pixel includes “information regarding prescription dermatology treatment,” id. ¶ 99, as well as: “patient medical conditions, medical concerns, treatment patients were seeking, and the fact that patients were seeking a prescription for treatment of those conditions,” id. ¶ 107. See also id. ¶123 (alleging disclosure of “prescription information”). These allegations fall squarely within the definition of “medical information” and are sufficient at this stage to state a plausible CMIA claim. See, e.g., St. Aubin v. Carbon Health Techs., Inc., No. 24-CV-00667-JST, 2024 WL 4369675, at *9 (N.D. Cal. Oct. 1, 2024) (finding long-form, full- string URLs revealing information about a patient’s medical conditions or treatment may constitute medical information under the CMIA); Castillo v. Costco Wholesale Corp., 2024 WL 4785136, at *13 (W.D. Wash. Nov. 14, 2024) (same). The Court therefore DENIES the motion to dismiss Ramirez’s CMIA claim. F. EPCA: Crime-Tort Exception The ECPA is a one-party consent statute, meaning there is no liability where “one of the parties to the communication has given prior consent” to the interception. 18 U.S.C. § 2511(2)(d). The statute contains a narrow exception where a communication is intercepted “for the purpose of committing any criminal or tortious act.” Id. This “crime-tort” exception requires “sufficient evidence to show ‘the purpose for the interception—its intended use—was criminal or tortious.’” Doe I v. Google LLC, No. 23-CV-02431-VC, 2023 WL 6882766, at *2 (N.D. Cal. Oct. 18, 2023) (quoting Sussman v. Am. Broad. Companies, Inc., 186 F.3d 1200, 1202 (9th Cir. 1999)) (emphasis in original). It is not enough that the interception itself allegedly violated the law; rather, the interception must have been undertaken “for the purpose of facilitating some further impropriety.” Id. In other words, a plaintiff must plausibly allege that “either the primary motivation or a determining factor” in the defendant’s actions was to injure the plaintiff through an independent tortious or criminal act. Zarif v. Hwareh.com, Inc., 789 F. Supp. 3d 880, 895 (S.D. Cal. 2025). Musely argues that it consented to sharing its users’ data with Meta and TikTok, and Ramirez fails to allege facts to invoke the crime-tort exception. Mot. 22–25. The Court finds Musely’s position persuasive. Other than reciting the requirements of the crime-tort exception—“[t]he third parties intentionally intercepted the contents of Plaintiff’s and Class members’ electronic communications for the purpose of committing a criminal or tortious act in violation of the Constitution or laws of the United States or of any state, namely, invasion of privacy, among others,” FAC ¶ 146—the only “purpose” Ramirez alleges throughout the FAC is financial gain. See, e.g., id. ¶ 62 (“for the purpose of sending targeted advertising”); ¶ 148 (“for financial gain”). The Court agrees with multiple others in this district that have found the crime- tort exception is inapplicable where the defendant’s primary motivation was to make money, not to injure plaintiffs tortiously. See In re Facebook Pixel Healthcare Litig., 647 F. Supp. 3d 778, 797 (N.D. Cal. 2022) (collecting cases). To be sure, the Court is not indicating that financial motives are completely insulated from the crime-tort exception, only that the complaint fails to allege any purpose other than financial motives. See, e.g., Riganian v. LiveRamp Holdings, Inc., 791 F. Supp. 3d 1075, 1090–91 (N.D. Cal. 2025) (“The existence of an underlying financial motivation does not mean that the act lacked a criminal or a tortious purpose.”). The Court therefore GRANTS the motion to dismiss Ramirez’s EPCA claim with leave to amend. G. California Constitution To state a claim for invasion of privacy under the California Constitution, plaintiffs must show: “(1) they possess a legally protected privacy interest, (2) they maintain a reasonable expectation of privacy, and (3) the intrusion is ‘so serious . . . as to constitute an egregious breach of social norms’ such that the breach is ‘highly offensive.’” In re Facebook, Inc., Internet Tracking Litigation, 956 F.3d at 601 (quoting Hernandez v. Hillsides, Inc., 47 Cal. 4th 272, 287 (2009)). Musely argues that Ramirez has failed to allege a sufficiently serious or highly offensive invasion of privacy, relying on Hammerling v. Google LLC, which observed that routine commercial data collection generally does not constitute a highly offensive intrusion.3 Mot. 19 (citing Hammerling v. Google LLC, 615 F. Supp. 3d 1069, 1090 (N.D. Cal. 2022), aff’d, No. 22- 17024, 2024 WL 937247 (9th Cir. Mar. 5, 2024)). Musely also contends that the FAC describes the allegedly disclosed information only in broad terms, such as “medical information,” “medical communications,” and “health information,” without alleging facts demonstrating the type of serious harm necessary to support a constitutional privacy claim. Id. The Court disagrees. Whether an intrusion is highly offensive requires consideration of several factors, including the likelihood of serious harm, the degree and setting of the intrusion, and the defendant’s motives and objectives. See Cousin v. Sharp Healthcare, 681 F. Supp. 3d 1117, 1126 (S.D. Cal. 2023); Hammerling v. Google LLC, No. 21-CV-09004-CRB, 2022 WL 17365255, at *8 (N.D. Cal. Dec. 1, 2022), aff’d, No. 22-17024, 2024 WL 937247 (9th Cir. Mar. 5,
3 Musely also argues that Ramirez lacked a reasonable expectation of privacy because she agreed to Musely’s Privacy Policy, but for all the reasons described above in Section III.A., the Court finds this unpersuasive. 2024). Courts have found unauthorized data sharing could possibly constitute a “highly offensive” intrusion in certain circumstances. See, e.g., In re Google Location Hist. Litig., 514 F. Supp. 3d 1147, 1157 (N.D. Cal. 2021) (“Whether Google’s collection and storage of location data when Location History was set to off was highly offensive to a reasonable person is a question of fact.”) (citing In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d at 606 (“The ultimate question of whether Facebook's tracking and collection practices could highly offend a reasonable individual is an issue that cannot be resolved at the pleading stage.”)). But courts have also found that certain data sharing practices do not rise to the level of highly offensive conduct as a matter of law. See, e.g., In re iPhone Application Litig., 844 F. Supp. 2d 1040, 1049–50 (N.D. Cal. 2012) (finding that permitting third-party application developers to access personally identifying information from users’ devices, including in some cases location data, did not rise to the level of highly offensive conduct); In re Google, Inc. Privacy Pol’y Litig., 58 F. Supp. 3d 968, 987–88 (N.D. Cal. 2014) (finding no highly offensive conduct in allegations that Google surreptitiously tracked users' browsing data while using Google's services); Ojeda v. Kaiser Permanente Int'l, Inc., No. EDCV221057MWFGJS, 2022 WL 18228249, at *6 (C.D. Cal. Nov. 29, 2022) (finding the disclosure of vaccination status not “highly offensive”). As it has found in cases concerning similar allegations, the Court finds the allegations here do not squarely fit into any of the cases cited above. See L.B., 2025 WL 2899514, at *20. Musely’s conduct may not be the same egregious systematic tracking and misrepresentations at issue in In re Facebook Internet Tracking Litigation and In re Google Location History Litigation; but the disclosure of information including the specific type of skin care prescription sought and/or purchased is medically-related and arguably more sensitive than the data at issue in In re iPhone Application Litigation, In re Google, Inc. Privacy Policy Litigation, and Ojeda. The Court therefore cannot conclude as a matter of law that no reasonable jury would find Musely’s conduct to be an egregious breach of social norms or incapable of creating serious harm. The Court therefore DENIES the motion to dismiss Ramirez’s California Constitution privacy claim. IV. CONCLUSION Based on the foregoing, the Court: 2 e GRANTS the motion to dismiss the ECPA claim with leave to amend; 3 e GRANTS the motion to dismiss the CIPA § 632 claim without leave to amend; 4 ¢ DENIES the motion to dismiss the CIPA § 631 claim’; 5 e DENIES the motion to dismiss the CMIA claim; and 6 e DENIES the motion to dismiss the California Constitution claim. 7 Should Ramirez wish to file an amended complaint, she must do so by September 3, 2026. 8 IT IS SO ORDERED. 9 Dated: August 13, 2026 10 " eM. EDWARD J. DAVILA United States District Judge 13 14
15 16
Z 18 19 20 21 22 23 24 25 26 27 * However, the Court directs Ramirez to file an amended complaint correcting the “scrivener’s error” referencing “memorialcare.org.” Opp’n 11 (citing FAC § 96). 28 Case No.: 5:24-cv-02012-EJD ORDER GRANTING IN PART AND DEN. IN PART MOT. TO DISMISS