Doe v. County of Santa Clara
- William Orrick
- 3:23-cv-04411
- U.S. District Court · Northern District of California
- 15
In Jane Doe v. County of Santa Clara, Judge Orrick granted in part and denied in part the County’s dismissal motion, allowing amendment of several privacy-related claims.
Jane Doe and the proposed classes of patients and prospective patients, as well as the County of Santa Clara. The order dismissed some claims, left the CCRA claim in place at this stage, and allowed Doe to amend several claims; it did not decide class certification.
What happened
Jane Doe brought a proposed class action against the County of Santa Clara, alleging that tracking pixels on Santa Clara Valley Medical Center websites and its patient portal sent patients’ health and identifying information to third parties. The County argued that website policies and portal terms showed consent or waived liability.
The court rejected the consent and waiver defense at this stage. It dismissed the California Invasion of Privacy Act claim with prejudice, dismissed the computer-access claim and privacy claims while allowing amendment, and denied dismissal of the California consumer-records claim without prejudice. The court also allowed Doe to add a federal wiretap claim.
Judge William H. Orrick granted in part and denied in part the motion to dismiss. Doe had 21 days to file a further amended complaint, and the order did not decide whether the proposed classes should be certified.
The detailed version
- Doe v. County of Santa Clara · No. 3:23-cv-04411
- William Orrick
- July 8, 2024
Background
Jane Doe sued the County of Santa Clara on behalf of proposed classes of patients and prospective patients who exchanged communications with Santa Clara Valley Medical Center or its affiliates through their websites and patient portal. She alleged that the County used tracking pixels that sent information about patient interactions, including personal health information and information that could identify patients, to third parties including Meta/Facebook and Google.
The second amended complaint asserted claims under the California Invasion of Privacy Act (CIPA), the Confidentiality of Medical Information Act (CMIA), the Comprehensive Computer Data Access and Fraud Act (CDAFA), the California Consumers Records Act (CCRA), the California Information Practices Act, and California common law for intrusion upon seclusion. The County moved to dismiss every claim.
Legal standard
The court applied Federal Rule of Civil Procedure 12(b)(6), which requires dismissal when a complaint does not allege enough facts to state a legally plausible claim. At this stage, the court generally accepts the complaint’s factual allegations as true and draws reasonable inferences for the plaintiff, but it need not accept conclusory allegations or unreasonable inferences.
Consent and waiver
The County argued that Doe’s claims were barred by a website privacy policy and the portal’s terms and conditions. The court held that Doe’s reference to the website privacy policy in her complaint did not establish that she personally knew of the policy at the relevant time. The disclosures also did not clearly tell users that personally identifiable information, much less personal health information, would be sent to third parties.
The court also held that the County had not shown that Doe affirmatively agreed to the portal terms when she began using the portal in 2018. The County’s evidence concerned a current account-creation page and later materials, without establishing when affirmative consent became required. The County also did not show that the linked terms constituted a binding browsewrap agreement—that is, terms binding a user merely through continued website use. The motion to dismiss based on consent and waiver was denied.
The court granted the County’s request for judicial notice of Exhibits D through K and granted Doe’s request to take judicial notice of the County’s Notice of Privacy Practices. It denied the County’s request to take judicial notice of litigation documents from the American Hospital Association and other nonparties. The court also denied the County’s motion to strike Doe’s declaration.
CIPA and proposed federal wiretap claim
The County argued that it could not be sued under CIPA because a public entity is not a qualifying “person” under that statute. Doe did not oppose dismissal of the CIPA claim but requested permission to replace it with a claim under the federal Wiretap Act. The court dismissed the CIPA claim with prejudice. It nevertheless gave Doe leave to allege a federal Wiretap Act claim. The opinion contains an inconsistent reference to the proposed federal claim as section 2250(a) in one passage, while the surrounding discussion identifies section 2520(a).
CDAFA
The County argued that it was not a proper defendant under CDAFA. The court did not decide that issue because it found that Doe had not alleged the type of loss or damage required by CDAFA. The court rejected a theory based on the lost or diminished value of personal health information. It therefore granted the motion to dismiss the CDAFA claim, while giving Doe leave to amend if she could allege a viable damages theory not based on the value of the health information.
CCRA
The County argued that it was not a proper defendant under the CCRA. The court declined to resolve that state-law issue on the existing record. The motion to dismiss the CCRA claim was denied without prejudice, meaning the issue could be raised again. The court stated that the County could move again after a further amendment or raise the issue at summary judgment.
Common-law privacy claim
The County argued that California’s Government Code generally prevents public entities from being liable for common-law tort claims. Doe argued that another Government Code provision creates liability when a public entity violates a mandatory duty designed to protect against the type of injury alleged. The court found that the complaint did not assert a claim under that provision or identify the mandatory duty the County allegedly violated.
The court therefore granted the motion to dismiss the common-law invasion-of-privacy claim and gave Doe leave to amend to state a claim based on a mandatory duty, if she could identify one. The court deferred arguments about whether the cited medical-privacy laws could supply that duty until a later amended complaint.
Disposition
The court’s conclusion states that the motion to dismiss was denied as to the consent and waiver defenses and the CCRA claim, and granted as to the CIPA claim, CDAFA claim, and privacy claims. Doe was given leave to amend the CDAFA and privacy claims and to state a federal Wiretap Act claim. Any further amended complaint had to be filed within 21 days of the order. The provided text lists CMIA and Information Practices Act claims but does not separately explain their individual dispositions; the conclusion’s reference to “privacy claims” is not further broken down in the text provided.
Read the full 15-page opinion on CourtListener, the free public archive maintained by the Free Law Project.