SMART v. MAIN LINE HEALTH

District Court, E.D. Pennsylvania·Decided April 14, 2026·No. 2:22-cv-05239·Unknown

Opinion

LIN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF PENNSYLVANIA

DAVID SMART, : Plaintiff, : Vv. . CIVIL NO. 22-5239 MAIN LINE HEALTH, . Defendant. : MEMORANDUM Scott, J. April 14, 2026 In his Second Amended Class Action Complaint (“SAC”), ECF No. 39, Plaintiff David Smart alleges that Defendant Main Line Health told patients that it would protect their health information and personally identifiable information (collectively, “private information”). Smart further alleges that Main Line Health backtracked on its privacy policy by commercializing the private information through installing Meta Pixel and Meta Conversions API, two pieces of software that allow a website owner to study website user behavior and to collect private information (collectively, the “Meta Collection Tools”). Smart asserts claims for (1) violation of the Electronic Communications Privacy Act, 18 U.S.C. § 2510 et seq. ““ECPA”), (2) negligence, and (3) invasion of privacy — intrusion upon seclusion. Presently before the Court is Main Line Health’s Motion to Dismiss the Second Amended Complaint. ECF No. 42. Smart filed a Response in Opposition. ECF No. 43. Main Line Health filed a Reply. ECF No. 45. Smart filed, without seeking permission from the Court, a Sur-Reply. ECF No. 46. Afterwards, Main Line Health submitted four Notices of Supplemental Authority. ECF Nos. 48, 49, 50, and 53. Smart likewise filed four Notices of Supplemental Authority. ECF Nos. 47, 51, 52, and 54.

For reasons explained below, the Court grants in part and denies in part Main Line Health’s Motion to Dismiss. I. BACKGROUND Smart brings this putative class action against Main Line Health, a nonprofit health system that operates a public-facing website where users can search for medial providers, research conditions and treatments, and schedule appointments. Sec. Am. Compl. § 4. Additionally, when a website user wishes to schedule an appointment online, the user is directed to a log-in page on Main Line Health’s MyChart portal. Jd. § 67. Throughout its website, Main Line Health installed Meta Pixels and the Meta Conversions API, technologies that collect information about users’ interactions with the website and transmit that information to Meta, who in turn, sells the information to marketers and advertisers. Jd. {§ 12—15, 21-22, 29. Smart alleges that Main Line’s Health use of the Meta Collection Tools captured information about Smart’s medical profile, including his research into “conditions and treatments,” “providers,” and scheduling of medical appointments. SAC § 184. Smart also alleges that Main Line Health captured certain URLs that contain “communications about Plaintiff's prospective healthcare” that were sent to Meta through Meta Pixels, including URLs that Smart visited on the Main Line Health website when making an appointment and logging-in to Main Line Health’s MyChart page. /d. § 184(g)-(h). Other information captured by these tools are website users’ “names, dates they sought treatments, computer IP addresses, device identifiers, [Facebook] IDs, ... web URLs [visited by users], services selected, patient statuses, medical conditions, treatments, provider information, and appointment information.” /d. § 82. According to the Complaint, Main Line Health informed patients that it was collecting their data in its privacy policy. SAC 4 2. But Main Line Health “never informed patients of its intention to disclose their private information to Meta, never received signed authorizations from patients

allowing it to disclose their Private Information to Meta, and never told patients it shared their Private Information with Meta.” /d. § 115. On Smart’s view, this failure to inform and to receive permission prior to installing the Meta Collection Tools means that Main Line Health violated its own privacy policy, which represented to patients that Main Line Health will only disclose personal health information with patients’ written permission and that Main Line Health would “seek [patients’] written permission prior to using or sharing [patient] information for marketing purposes or selling [patient] information.” /d. § 134. This failure also, on Smart’s telling, has led to a variety of HIPAA violations concerning requirements to safeguard patient health information. Id. 4 112-13. II. LEGAL STANDARD To survive a Rule 12(b)(6) motion, “a complaint must contain sufficient factual matter, accepted as true, to ‘state a claim to relief that is plausible on its face.’” Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007)). “Plausibility means ‘more than a sheer possibility that a defendant has acted unlawfully.’” Tatis v. Allied Interstate, LLC, 882 F.3d 422, 426 (3d Cir. 2018) (quoting /gbal, 556 U.S. at 678). A claim is plausible “when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” /gbal, 556 U.S. at 678 (citing Twombly, 550 U.S. at 556). ‘““Threadbare recitals of the elements of a cause of action, supported by mere conclusory statements, do not suffice.” Jd. In considering a motion to dismiss under Rule 12(b)(6), all well-pleaded allegations in the complaint are accepted as true and interpreted in the light most favorable to the plaintiff, and all inferences are drawn in the plaintiff's favor. See McTernan v. City of York, 577 F.3d 521, 526 (3d Cir. 2009) (quoting Schrob v. Catterson, 948 F.2d 1402, 1408 (3d Cir. 1991)).

Il. DISCUSSION A. Plaintiff Alleges Sufficient Facts to State an ECPA Claim To state a claim for relief under the ECPA, Smart must plead sufficient facts to make plausible that Main Line Health “‘(1) intentionally (2) intercepted, endeavored to intercept or procured another person to intercept or endeavor to intercept (3) the contents of (4) an electronic communication, (5) using a device.’” Jn re Google Inc. Cookie Placement Consumer Priv. Litig., 806 F.3d 125, 135 (3d Cir. 2015) (quoting /n re Pharmatrak, Inc., 329 F.3d 9, 18 (1st Cir. 2003)). The “party exception” to the ECPA states that it is not “unlawful to intercept the communication when party to a communication.” § 18 U.S.C. 2511(2)(d). This exception, however, has its own exception, known as the “crime-tort exception:” a party to the communication cannot intercept communications “for the purpose of committing any criminal or tortious act.” Jd. To invoke the crime-tort exception at the motion-to-dismiss stage, a plaintiff must not only allege that a defendant intercepted the communications with a criminal and tortious purpose but also allege that the criminal or tortious conduct is something other than the interception itself or that there is a “tortious or criminal use” of the intercepted contents. /n re Google, Inc., 806 F.3d at 145 (emphasis in original). Smart alleges that Main Line Health intercepted sensitive communications—including attempts by users to schedule appointments and to log-in to a patient portal—by installing the Meta Collection Tools, and that Main Line Health put these intercepted communications to criminal use by effectively selling users’ private information to marketers. See, e.g., SAC ¥§ 110-17. Why is selling this information to marketers criminal? Smart’s answer is that it violates the Health Insurance Portability and Accountability Act (“HIPAA”), which imposes federal criminal liability when an entity discloses individually identifiable health information without prior authorization

and with the intent to use the information for commercial advantage. 42 U.S.C. § 1320(d)(6); see also SAC § 110.

Free access — add to your briefcase to read the full text and ask questions with AI

SMART v. MAIN LINE HEALTH, (E.D. Pa. 2026).

SMART v. MAIN LINE HEALTH (SMART v. MAIN LINE HEALTH) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

§ 2510
18 U.S.C. § 2510
§ 1320
42 U.S.C. § 1320