Hanson v. Sanford Health Corp.
Robert Hanson, on behalf of himself and all others similarly situated v. Sanford Health Corp.
- Patrick Schiltz
- 0:25-cv-03129
- U.S. District Court · District of Minnesota
- 15
Counsel of record per CourtListener. Firm names are approximate and have been consolidated across spelling variants.
Judge Schiltz granted in part and denied in part Sanford Health Corp.'s motion to dismiss in Hanson v. Sanford Health Corp., dismissing two privacy claims but allowing four others to proceed.
Current and prospective patients who used Sanford Health Corp.'s website and may have had their browsing activity tracked and shared with third-party advertisers, as well as healthcare organizations that deploy third-party tracking tools on their websites and assert privacy protections in public disclosures.
What happened
In Hanson v. Sanford Health Corp. (No. 25-CV-3129), plaintiff Robert Hanson sued Sanford Health Corp. on behalf of himself and a proposed class, alleging that Sanford used tracking tools — including Meta's Pixel — on its website to collect and share users' information with third parties like Meta, Snapchat, and Google, without adequate disclosure. Hanson, a Sanford patient who searched for his doctor on the Sanford website before back surgery, claims he later received targeted ads related to back and spine issues. He brought six claims; Sanford moved to dismiss five of them.
The court dismissed Hanson's claim for intrusion upon seclusion because that tort requires an unauthorized intrusion into private affairs, and Hanson voluntarily gave his information to Sanford — the wrong is in Sanford's disclosure to third parties, not in any intrusion. The court also dismissed Hanson's claim under the Minnesota Health Records Act, finding that a search on Sanford's publicly accessible website — which requires no login and is open to anyone — does not produce a 'health record' under Minnesota law, because the information could only allow someone to infer Hanson was a patient, and mere inference is insufficient under the statute.
Judge Patrick J. Schiltz denied the motion as to Hanson's remaining claims: a federal electronic communications privacy claim (finding that Sanford's alleged HIPAA violation could trigger the statute's crime/tort exception), a Minnesota deceptive trade practices claim, a Minnesota consumer fraud claim, and a sixth claim not subject to the motion. The court also declined without prejudice to strike Hanson's proposed class definition at this stage, leaving that issue for later proceedings. Counts I and IV were dismissed with prejudice and on the merits.
The detailed version
- Hanson v. Sanford Health Corp. · No. 0:25-cv-03129
- Patrick Schiltz
- Sept. 4, 2026
Background
Sanford Health Corp. is described in the complaint as the largest rural health system in the United States, operating hospitals, clinics, and senior-care communities. Sanford maintains a public website where users can search for doctors and locations, research medical services, and access care. Sanford deploys tracking tools on its website, including the Meta Pixel — a snippet of code that tracks user activity and sends data to Meta, which uses it to build profiles for targeted advertising. Sanford also deploys similar tools from at least ten other third-party companies, including Snapchat and Google.
Sanford's website contains a Privacy Statement representing that it does not share personal information with unrelated third parties except as required by law, and that contracted third parties are obligated not to misuse the information.
Plaintiff Robert Hanson is a current Sanford patient who visited the "Doctors" page on Sanford's website before back surgery to search for information about his doctor. After using the site, Hanson alleges he began receiving targeted advertisements from third parties relating to back and spine issues. Hanson filed a putative class action — a lawsuit filed on behalf of oneself and a proposed group of similarly situated people — asserting six claims. Sanford moved to dismiss five of them under Federal Rule of Civil Procedure 12(b)(6), which allows dismissal when a complaint fails to state a legally plausible claim.
Standard of Review
Under Rule 12(b)(6), the court accepts all factual allegations as true and draws reasonable inferences in the plaintiff's favor. The complaint must raise a right to relief above the speculative level and state a claim that is plausible on its face.
Count I — Intrusion Upon Seclusion: GRANTED (Dismissed With Prejudice)
Hanson's complaint labeled this claim "Invasion of Privacy," but the court and the parties understood it as an intrusion upon seclusion claim. Under Minnesota law, this tort requires: (a) an intrusion; (b) that is highly offensive to a reasonable person; and (c) into a matter in which the person has a legitimate expectation of privacy.
The court held that Hanson's allegations describe a disclosure, not an intrusion. Hanson voluntarily provided information to Sanford; Sanford then allegedly shared it with third parties. Minnesota law holds that a plaintiff who voluntarily disclosed information to a defendant cannot maintain an intrusion-upon-seclusion claim, and the defendant's later unauthorized sharing of that information does not supply the missing element of intrusion.
Hanson argued that his expectation that Sanford would keep the information private distinguished his case, but the court rejected this, noting that expectation of privacy is already built into the third element of the tort and does not convert a disclosure into an intrusion. Hanson's comparison to a Minnesota Court of Appeals case involving a defendant who altered a medical-release form to obtain unauthorized information was rejected as inapposite because that case involved an actual unauthorized act of obtaining information — a true intrusion — not merely a disclosure of voluntarily provided data. This claim was dismissed with prejudice and on the merits.
Count II — Electronic Communications Privacy Act: DENIED
The federal Electronic Communications Privacy Act (ECPA), 18 U.S.C. § 2511, prohibits intentional interception of electronic communications. A party to a communication is ordinarily exempt. However, the "crime/tort exception" removes that exemption if the party intercepted the communication for the purpose of committing a crime or tort under federal or state law.
Sanford argued it was a party to the communications and that the crime/tort exception did not apply because its motive was commercial, not tortious. The court disagreed. Hanson alleged that Sanford's disclosure of his information to Meta and other third parties violated the Health Insurance Portability and Accountability Act (HIPAA). Sanford did not argue at this stage that no HIPAA violation occurred. The court held that a pecuniary motive does not defeat the crime/tort exception, since monetary gain is a common motive for criminal acts. The court also rejected Sanford's argument that Hanson failed to allege a tort or crime distinct from the interception itself, finding that the alleged HIPAA violation arose from the disclosure — a separate act from the interception. The motion to dismiss this claim was denied.
Count III — Minnesota Uniform Deceptive Trade Practices Act: DENIED
The Minnesota Uniform Deceptive Trade Practices Act (MUDTPA), Minn. Stat. § 325D.43 et seq., prohibits misrepresentations about the characteristics or quality of goods or services. Only injunctive relief (a court order to stop conduct) is available — not money damages. Hanson alleged that Sanford's Privacy Statement falsely represented that it would protect his information and not share it with unrelated third parties.
Sanford raised four arguments for dismissal, all rejected:
Particularity Under Rule 9(b) Federal Rule 9(b) requires fraud-based claims to be pleaded with particularity — specifying the time, place, content, and details of the alleged misrepresentations. The court held that Hanson satisfied this standard by identifying Sanford's published website privacy policies as the alleged misrepresentations and describing his doctor-search visit in anticipation of back surgery. Precise dating was not required for ongoing corporate representations posted on a public website.
Standing to Seek Injunctive Relief Sanford argued Hanson lacked standing because he did not allege a likelihood of future harm. The court disagreed, finding it plausible that Hanson faces ongoing harm from further misuse of already-disclosed data and potential future disclosures, citing a comparable recent district court decision.
Causal Nexus Sanford argued Hanson failed to allege that the targeted ads he received came from Sanford's disclosures rather than some other source. The court rejected this, finding that the sequence of events — website search, Sanford's transmission of data to third parties, followed by targeted ads on the same medical topic — was sufficient at the pleading stage.
Adequacy of Website Disclosures Sanford argued its website was not deceptive because it disclosed use of tracking tools. The court found this unavailing because the same Privacy Statement also represented that Sanford does not share personal information with unrelated third parties except as required by law — a statement Hanson alleges is false. The motion to dismiss this claim was denied.
Count IV — Minnesota Health Records Act: GRANTED (Dismissed With Prejudice)
The Minnesota Health Records Act (MHRA), Minn. Stat. § 144.291 et seq., imposes liability for negligent or intentional release of a patient's "health record." A "health record" must relate to the past, present, or future physical or mental health, care, or payment for care of a "patient" — defined as a person who has received health care services for treatment or examination of a medical, psychiatric, or mental condition.
The court held that information generated by Hanson's search on Sanford's publicly accessible website — open to anyone without login — cannot constitute a "health record" because it does not reveal that the user is a patient. The court acknowledged that one might infer from a healthcare website search that the user is a patient, but under Minnesota case law, information from which patient status can only be inferred does not qualify as a "health record." The court distinguished a Minnesota Court of Appeals decision where a provider directly disclosed that a specific person was a hospitalized patient — no inference was needed there. This claim was dismissed with prejudice and on the merits.
Count V — Minnesota Consumer Fraud Act: DENIED
Sanford made the same causal-nexus argument against Hanson's claim under the Minnesota Consumer Fraud Act (MCFA), Minn. Stat. § 325F.69, as it made against the MUDTPA claim. The court rejected it for the same reasons and denied the motion to dismiss this claim.
Class Allegations
Sanford asked the court to strike Hanson's proposed class definition as a "fail-safe" class — a class defined in a way that would automatically exclude anyone who loses on the merits. The court declined to rule on this without prejudice, finding the issue better addressed at the class-certification stage after discovery and full briefing.
Disposition
The motion to dismiss was granted in part and denied in part. Counts I (intrusion upon seclusion) and IV (Minnesota Health Records Act) were dismissed with prejudice and on the merits. The motion was denied in all other respects.
Read the full 15-page opinion on CourtListener, the free public archive maintained by the Free Law Project.