Williams v. TMC Health

District Court, D. Arizona·Decided September 30, 2024·No. 4:23-cv-00434·Unknown

Opinion

WO

George Williams, et al., No. CV-23-00434-TUC-SHR

Plaintiffs, Order Granting Motion to Dismiss

v.

TMC Health,

Defendant. Pending before the Court is Defendant’s “Motion to Dismiss Amended Complaint” (Doc. 19). The Motion to Dismiss is fully briefed and the Court held oral argument on August 14, 2024. (Docs. 19-1, 20, 23, 36.) For the following reasons, the Court grants the Motion to Dismiss. I. Background Defendant TMC Health is a healthcare system in Southern Arizona serving patients via several hospitals and clinics. (Doc. 13 ¶ 1.) Plaintiffs are people who have visited TMC’s public website and have used the website to access the patient portal. (Id. ¶¶ 21– 24.) This putative class action raises six claims based on Defendant’s use of online tracking technologies from Meta, LinkedIn, Snapchat, Google, CallRail, and potentially other third parties (collectively, “tracking technologies”) on its public website, www.tmcaz.com (the “Website”). (Id. ¶¶ 1, 9.) . . . . A. The Website & Technologies Involved Defendant’s Website allows visitors “to search for doctors, research conditions and symptoms,” “sign up for classes and events,” and “seek further information” related to sensitive healthcare topics. (Doc. 13 ¶¶ 1, 82.) “The Website’s landing page has a drop- down menu of options, including ‘request my medical records.’” (Id. ¶ 76.) TMC patients can also access the patient portal from Defendant’s Website, but the patient portal is a “user-authenticated webpage[],” which means patients are required to log in by providing a user name and password before they are able to access the patient portal. (Id. ¶¶ 21–24, 120, 191.)1 Unbeknownst to the Website’s visitors, Defendant embeds code on its Website, allowing third-party technology companies to “intercept and record the visitors’ activities on the Website in real-time, including specific searches for sensitive health-related topics.” (Doc. 13 ¶ 2.) These technologies include the Meta Pixel (“Pixel”) and similar tracking technologies.2 (Id. ¶ 7.) When Pixel code is embedded on a third-party website, like Defendant’s Website, Pixel “tracks the website visitor’s activity on that website and sends that data,” including “mouse clicks, words typed into search bars, and pages visited on the website,” to Meta. (Id. ¶ 6.) Generally, Pixel and related technologies interact with communications between a browser and a server. “Web browsers are software applications that allow consumers to navigate the web and view and exchange electronic information and communications over the internet.” (Doc. 13 ¶ 50.) “Each ‘client device’ (such as computer, tablet, or smart phone) accesses web content through a web browser (e.g., Google’s Chrome browser, Mozilla’s Firefox browser, Apple’s Safari browser, and Microsoft’s Edge browser).” (Id.) “Every website is hosted by a computer ‘server’ that holds the website’s contents and through which the entity in charge of the website exchanges communications with Internet

1 Plaintiffs do not allege any disclosure of data related to how they used Defendant’s private patient portal. 2 Although Plaintiffs include detailed descriptions of how each technology operates in their Amended Complaint, the Court will not restate those details in full here because nothing about the specifics of each technology involved changes the legal analysis. Therefore, the Court will treat these technologies together for its analysis. users’ client devices via their web browsers.” (Id. ¶ 51.) A user’s web browser communicates with a website’s server by sending an HTTP Request, most commonly in the form of a GET Request, and the server communicates back by sending an HTTP Response. (Doc. 13 ¶ 52.) “In addition to specifying a particular URL (i.e., web address), GET Requests can also send data to the host server embedded inside the URL, and can include cookies.” (Id.) Other types of HTTP Requests send even more data. For example, a POST Request “can send a large amount of data outside of the URL (for instance, uploading a PDF for filing a motion to a court).” (Id.) Cookies are small text files “used to store information on the client device that can later be communicated to a server or servers.” (Id.) “Cookies are sent with HTTP Requests from client devices to the host server.” (Id.) After receiving an HTTP Request asking the server to retrieve certain information (such as a webpage), the “HTTP Response sends the requested information in the form of ‘Markup.’” (Id. ¶ 53.) “This is the foundation for the pages, images, words, buttons, and other features that appear on the individual’s screen as they navigate” a website. (Id.) “Every website is composed of Markup and ‘Source Code.’ Source Code is a set of instructions that commands the website visitor’s browser to take certain actions when the web page first loads or when a specified event triggers the code.” (Id. ¶ 54.) Specifically, when a person visits Defendant’s Website, i.e. the person’s web browser sends an HTTP Request to Defendant’s server, “the server sends an HTTP Response including the Markup that displays the webpage visible to the user along with the invisible Source Code that includes the Pixel.” (Doc. 13 ¶ 56.) After this initial communication, the source code containing Pixel then operates to transmit data back to Meta’s servers and Defendant’s server. (Id.) This data “is also linked to a specific IP address, which Meta may use in combination with other cookies and tracking technologies to associate the web activity to a specific Facebook user.” (Id. ¶ 57.) “Meta does this by placing cookies,” like the “c_user” cookie, which “contains a numerical value known as the Facebook ID” that “uniquely identifies a Facebook user,” in the web browsers of users logged into their services. (Id. ¶ 58.) Therefore, “[w]hen a Facebook user visits the Defendant’s Website while logged-in to their Facebook account,” Pixel sends the user’s “web communications with the Defendant along with the ‘c_user’ cookie” to Meta. (Id.) “Meta can then use this information to match the web communications with the user’s Facebook ID.” (Id.) By embedding these technologies into the Website’s source code, data about a user’s visits to the Website, “including the URL, referrer, IP address, device and browser characteristics (User Agent),” and searched terms, are shared with third parties including Meta, LinkedIn, Snapchat, Google, and CallRail. (Doc. 13 ¶¶ 56, 70–76, 80–84, 86–89, 91–94.) Defendant embedded these technologies into the Website and shared the data with third parties “to increase its own profits through sophisticated and targeted advertising and to improve its website analytics.” (Id. ¶ 2; see also id. ¶¶ 12, 73, 83, 89, 108, 187.) Plaintiffs never consented to share their data with these third parties. (Id. ¶¶ 65, 77, 85, 90, 95.) B. Regulatory Landscape Pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Secretary of the Department of Health and Human Services has promulgated various regulations to ensure the confidentiality of individuals’ health information and protect against “unauthorized uses or disclosures of the information.” 42 U.S.C. § 1320d- 2; see also 45 C.F.R. §§ 160, 164. The Standards for Privacy of Individually Identifiable Health Information (the “Privacy Rule”), (Doc. 13 ¶ 118), establishes standards for the protection of certain health information, broadly defining “[p]rotected health information” (PHI) as “individually identifiable health information” (IIHI) that is “[t]ransmitted by electronic media,” “maintained in electronic media,” or “transmitted or maintained in any other form or medium.” 45 C.F.R. §

Williams v. TMC Health, (D. Ariz. 2024).

Williams v. TMC Health (Williams v. TMC Health) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
State Ex Rel. Horne v. Autozone, Inc.
275 P.3d 1278 (Arizona Supreme Court, 2012)
Gipson v. Kasey
150 P.3d 228 (Arizona Supreme Court, 2007)
John sullivan/susan Sullivan v. Pulte Home Corp
306 P.3d 1 (Arizona Supreme Court, 2013)
John A. Artukovich & Sons, Inc. v. Reliance Truck Co.
614 P.2d 327 (Arizona Supreme Court, 1980)
Hart v. Seven Resorts Inc.
947 P.2d 846 (Court of Appeals of Arizona, 1997)
Carroll v. Lee
712 P.2d 923 (Arizona Supreme Court, 1986)
Nataros v. Fine Arts Gallery of Scottsdale, Inc.
612 P.2d 500 (Court of Appeals of Arizona, 1980)
Murdock-Bryant Construction, Inc. v. Pearson
703 P.2d 1197 (Arizona Supreme Court, 1985)
Amanda Watts v. Medicis Pharmaceutical Corporation
365 P.3d 944 (Arizona Supreme Court, 2016)
First American Title Insurance v. Johnson Bank
372 P.3d 292 (Arizona Supreme Court, 2016)
Ernest Quiroz Et Ux v. Alcoa Inc
416 P.3d 824 (Arizona Supreme Court, 2018)
Wang Electric, Inc. v. Smoke Tree Resort, LLC
283 P.3d 45 (Court of Appeals of Arizona, 2012)
Sullivan v. Pulte Home Corp.
290 P.3d 446 (Court of Appeals of Arizona, 2012)
Camreta v. Greene
179 L. Ed. 2d 1118 (Supreme Court, 2011)