Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.OtherFiled Mar. 20, 2025

Doe I v. Google LLC

Judge
Vince Chhabria
Docket
3:23-cv-02431
Court
U.S. District Court · Northern District of California
Pages
6
Civil ProcedureContract
In one sentence

In Doe I v. Google LLC, Judge Chhabria tentatively outlined possible claims and requested supplemental briefs without issuing a final ruling.

Who this affects

The plaintiffs and Google LLC are affected because the court requested additional briefing on the plaintiffs’ allegations concerning Google’s collection and identification of private health information; the order does not finally decide their claims.

What happened

In Doe I v. Google LLC, the plaintiffs allege that Google received private health information from health-provider webpages and could link some of it to identifiable Google account holders through cookies. The court focused on whether the allegations adequately described that link.

The court tentatively viewed the allegations about Google account holders, the “gid” cookie, and conduct before Google’s 2023 health-information disclosure as potentially sufficient for some claims. It viewed the allegations about non-account holders and conduct after the 2023 disclosure less favorably, but did not make final decisions.

Judge Chhabria requested supplemental briefs from both sides. Google’s brief is due within seven days, the plaintiffs’ response within fourteen days, and Google’s reply within twenty-one days; the order does not grant or deny a motion or otherwise finally resolve the case.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Doe I v. Google LLC · No. 3:23-cv-02431
Judge
Vince Chhabria
Date
Mar. 20, 2025

Background

The plaintiffs’ lawsuit focuses on Google’s alleged receipt of private health information from communications between patients and health providers. The court said the key issue is whether Google obtained information that could be linked to an identifiable person. The plaintiffs invoke the Federal Wiretap Act, California’s Invasion of Privacy Act, and contract theories.

The court described the products at issue as tools that health providers place on their webpages. Those tools can use cookies to collect and transmit information to Google and the providers. The court’s discussion focused especially on two cookies:

- The “gid” cookie allegedly generates a unique identifier when a user is logged into a Google service on the same browser and can tie the website interaction to that user’s Google account. - The “cid” cookie appears, based on the court’s current understanding, to identify a user or browser without collecting information that identifies the person in the real world.

Tentative analysis

The court was tentatively inclined to conclude that the plaintiffs may have adequately alleged that Google collected private health information linked to identifiable Google account holders before Google’s 2023 health-information disclosure. The court also said the plaintiffs may have stated a breach-of-contract claim based on allegations that Google promised to collect only health information that users chose to provide.

The court was less persuaded by the allegations concerning people who did not hold Google accounts. It said the plaintiffs appeared not to have adequately alleged that information connected to the “cid” cookie could be tied to personally identifying information.

The court also discussed intent under the Federal Wiretap Act and California Penal Code section 631. It said the relevant question for this lawsuit is whether Google intended to receive communications containing private health information that it could link to a particular, identifiable person. The court said it was plausible to infer that Google intended to receive such communications before 2023, but expressed skepticism that the plaintiffs could ultimately prove that point.

For conduct after Google’s 2023 disclosure, the court said the allegations did not support an inference that Google intended to receive linkable personal health information. The disclosure told providers not to use Google’s products on pages that might relate to health-care services and might be covered by federal health-privacy law. The court also said any allegation that the disclosure was part of a plot to continue collecting the information would be subject to a heightened pleading requirement for allegations of fraud, which the plaintiffs had not nearly satisfied.

Order and next steps

The court did not issue a final ruling on the claims. Instead, it requested supplemental briefing. Google must file its brief within seven days of the order, the plaintiffs must respond within fourteen days, and Google may reply within twenty-one days. The parties’ initial submissions may not exceed fifteen pages, and Google’s reply may not exceed ten pages.

Because this order requests further briefing and states only tentative views, it does not grant or deny a motion, dismiss a claim, or finally resolve the case.

The authoritative version

Read the full 6-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.