In Re Meta Pixel Healthcare Litigation

District Court, N.D. California·Decided January 29, 2024·No. 3:22-cv-03580·Unknown

Opinion

Case No. 22-cv-03580-WHO

ORDER ON MOTION TO DISMISS LITIGATION Re: Dkt. Nos. 387, 388

In my September 7, 2023 Order, I denied defendant Meta Platform, Inc.’s motion to dismiss certain claims, but granted it with leave to amend plaintiffs’ claims for invasion of privacy/intrusion on seclusion, California’s Comprehensive Computer Data Access and Fraud Act (“CDAFA”), negligence per se, trespass, larceny, Unfair Competition Law (“UCL”), and California’s Consumers Legal Remedies Act (“CLRA”). Doe v. Meta Platforms, Inc., No. 22-CV- 03580-WHO, 2023 WL 5837443, at *17 (N.D. Cal. Sept. 7, 2023). In their First Amended Consolidated Class Action Complaint (“FAC,” Dkt. No. 334-3) plaintiffs did not reallege their negligence per se, larceny, or UCL claims and amended and realleged their privacy/intrusion of seclusion, CDAFA, trespass and CLRA claims. Meta moves again to dismiss. Plaintiffs voluntarily withdraw their CLRA claim, but contest dismissal of the other claims. Meta’s motion is DENIED. 1 In the September 2023 Order, I rejected most of Meta’s challenges to plaintiffs’ privacy claims but recognized:

1 The factual and procedural background have been outlined in my prior Orders and will not be Given the nature of this case – where plaintiffs allege that both unprotected and constitutionally protected information was captured by Meta's Pixel – plaintiffs are required to amend to describe the types or categories of sensitive health information that they provided through their devices to their healthcare providers. That basic amendment (which can be general enough to protect plaintiffs’ specific privacy interests) will allow these privacy claims to go forward. September 2023 Order, 2023 WL 5837443 at *8. In the FAC, plaintiffs identify the specific types of information they provided to their healthcare providers that they believe Meta collected without their consent. FAC ¶¶ 24-38. For the most part, plaintiffs identify the health conditions for which they sought treatment or services, as well as examples of their queries, appointment requests, or other information and services about which they communicated with their providers. Meta takes another pass at arguing that these disclosures are insufficient to plausibly plead their privacy-based claims. Mot. at 1, 4. But the allegations suffice at this juncture because they identify generally the types of sensitive information plaintiffs shared with their healthcare providers that was plausibly collected by Meta. Meta also attacks on these claims because the plaintiffs transmitted some or all of their healthcare information to their providers’ websites through “publicly accessible” URLs, meaning URLs that were accessible without a user logging in. It contends that its retrieval of plaintiffs’ information from those unprotected or public pages cannot support an invasion of privacy claim. Smith v. Facebook, Inc., 745 F. App'x 8, 9 (9th Cir. 2018) (“The data show only that Plaintiffs searched and viewed publicly available health information that cannot, in and of itself, reveal details of an individual’s health status or medical history. Moreover, many other kinds of information are equally sensitive. We conclude that the practice complained of falls within the scope of Plaintiffs’ consent to Facebook’s Terms and Policies. . . . Information available on publicly accessible websites stands in stark contrast to the personally identifiable patient records and medical histories protected by these statutes—information that unequivocally provides a window into an individual’s personal medical history. . . . Put simply, the connection between a person’s browsing history and his or her own state of health is too tenuous to support Plaintiffs’ In the Preliminary Injunction Order, I distinguished the Smith district court decision:

Meta does not challenge plaintiffs’ assertion that patient status is protected information under HIPAA, but instead relies on Smith v. Facebook, 262 F. Supp. 3d 943 (N.D. Cal. 2017). But Smith does not forestall my conclusion that patient status is protected health information. It dealt with the question of whether Facebook users had consented to Facebook collecting information about them via their browsing through certain health-related websites (such as http://www.cancer.net) that had an embedded Facebook “Like” button. Smith, 262 F. Supp. 3d at 948. Smith concluded that there was no protected health information because the information transmitted to Facebook when a user visited the http://www.cancer.net page was the same kind of information transmitted to Facebook any time a user visited any page on the internet that contained a Facebook button. Id. at 954. In other words, the URLs did not “relate[ ] specifically to Plaintiffs’ health.” Id. at 954. Smith further explained:

The URLs at issue in this case point to pages containing information about treatment options for melanoma, information about a specific doctor, search results related to the phrase “intestine transplant,” a wife's blog post about her husband's cancer diagnosis, and other publicly available medical information. These pages contain general health information that is accessible to the public at large. The same pages are available *793 to every computer, tablet, smartphone, or automated crawler that sends GET requests to these URLs. Nothing about the URLs, or the content of the pages located at those URLs, relates “to the past, present, or future physical or mental health or condition of an individual.” 45 C.F.R. § 160.103 (emphasis added). As such, the stricter authorization requirements of HIPAA (as well as Cal. Civ. Code § 1798.91) do not apply.

Id. at 954–55 (underline in original).

Free access — add to your briefcase to read the full text and ask questions with AI

In Re Meta Pixel Healthcare Litigation, (N.D. Cal. 2024).

In Re Meta Pixel Healthcare Litigation (In Re Meta Pixel Healthcare Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Hill v. National Collegiate Athletic Assn.
865 P.2d 633 (California Supreme Court, 1994)
eBay, Inc. v. Bidder's Edge, Inc.
100 F. Supp. 2d 1058 (N.D. California, 2000)
Intel Corp. v. Hamidi
71 P.3d 296 (California Supreme Court, 2003)
Perrin Davis v. Facebook, Inc.
956 F.3d 589 (Ninth Circuit, 2020)
Smith v. Facebook, Inc.
262 F. Supp. 3d 943 (N.D. California, 2017)
Ticketmaster L.L.C. v. Prestige Entm't W., Inc.
315 F. Supp. 3d 1147 (C.D. California, 2018)
In re Apple Inc. Device Performance Litig.
347 F. Supp. 3d 434 (N.D. California, 2018)
In re Apple Inc.
386 F. Supp. 3d 1155 (N.D. California, 2019)
In re iPhone Application Litig.
844 F. Supp. 2d 1040 (N.D. California, 2012)
Fair v. Kirk
317 F. Supp. 12 (N.D. Florida, 1970)