Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Sept. 7, 2023

In Re Meta Pixel Healthcare Litigation

Judge
William Orrick
Docket
3:22-cv-03580
Court
U.S. District Court · Northern District of California
Pages
26
Civil ProcedureMotion to DismissContractTort
In one sentence

In John Doe v. Meta Platforms, Judge Orrick granted in part and denied in part Meta’s motion to dismiss claims about Meta Pixel’s collection of healthcare information.

Who this affects

The order affected five anonymous Facebook users who sued Meta Platforms, Inc. and other defendants. It allowed some claims to proceed and required plaintiffs to amend other claims before the case could continue on those theories.

What happened

In John Doe, et al. v. Meta Platforms, Inc., et al., five anonymous Facebook users alleged that Meta Pixel collected healthcare-related information and patient communications from healthcare-provider websites and used the information for targeted advertising. They asserted federal and California claims involving privacy, contracts, computer access, theft, and consumer protection.

The court denied Meta’s motion to dismiss the Electronic Communications Privacy Act, California Invasion of Privacy Act, breach-of-contract, good-faith-and-fair-dealing, and unjust-enrichment claims. It granted the motion with leave to amend the privacy, computer-access, negligence-per-se, trespass, larceny, unfair-competition, and Consumer Legal Remedies Act claims.

Judge Orrick ruled that plaintiffs plausibly alleged several claims but needed more detail for others, including the categories of sensitive health information allegedly captured and facts supporting certain damages, duties, false statements, and reliance. He required plaintiffs to file an amended complaint within 20 days of the order.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
In Re Meta Pixel Healthcare Litigation · No. 3:22-cv-03580
Judge
William Orrick
Date
Sept. 7, 2023

Background

Five Facebook users proceeded anonymously because of the sensitive nature of the litigation. They alleged that their healthcare providers installed Meta Pixel on patient portals and that the Pixel transmitted information to Meta, including information that revealed their status as patients and the contents of patient communications. They alleged that Meta monetized the information for targeted advertising and violated federal and California law, as well as Meta’s own policies.

The consolidated complaint asserted 13 claims: breach of contract; breach of the duty of good faith and fair dealing; violation of the Electronic Communications Privacy Act (ECPA), also called the Wiretap Act; violation of the California Invasion of Privacy Act (CIPA); intrusion upon seclusion; invasion of privacy under the California Constitution; negligence per se; trespass to chattels; violation of California’s Unfair Competition Law (UCL); violation of the California Consumer Legal Remedies Act (CLRA); larceny; violation of California’s Comprehensive Computer Data Access and Fraud Act (CDAFA); and unjust enrichment. Meta moved to dismiss every claim under Rule 12(b)(6), which requires dismissal when a complaint does not plausibly state a claim for relief.

ECPA claim

The court denied Meta’s motion to dismiss the ECPA claim. The ECPA prohibits unauthorized interception of electronic communications. The court held that plaintiffs adequately alleged that Meta intentionally intercepted the contents of their electronic communications using the Pixel.

The court rejected Meta’s argument that plaintiffs could not allege intent because third-party developers selected and configured the Pixel and Meta had policies and filters intended to prevent the receipt of sensitive information. Whether Meta intended to receive the information, what steps it took to prevent receipt, and whether its filtering tools worked involved factual questions that could not be resolved on a motion to dismiss.

The court also held that plaintiffs adequately alleged the interception of protected “content,” including login buttons and descriptive URLs that could reveal the substance of a healthcare communication. Finally, the court rejected Meta’s argument that the healthcare providers’ installation of the Pixel established consent as a matter of law. Whether the providers actually consented depended on what Meta disclosed, how Meta described and trained providers about the Pixel, and how the providers understood its operation.

CIPA claim

The court denied Meta’s motion to dismiss the CIPA claim. It rejected Meta’s argument that CIPA could not apply because the named plaintiffs were not California residents. Plaintiffs plausibly alleged that the design, marketing, and implementation of the Pixel and Meta’s terms occurred in California. The court did not decide or foreclose broader choice-of-law issues.

The court also held that plaintiffs adequately alleged intent under CIPA for the same reasons supporting the ECPA claim. Their allegations that Meta’s disclosures and filtering efforts did not prevent the transfer of sensitive information were sufficient at the pleading stage. Plaintiffs also adequately alleged that information was sent to or received from California because they alleged that Meta was headquartered there and designed and carried out the tracking scheme there. The court further concluded that Pixel software could qualify as a “device” under the CIPA provision at issue.

Privacy and intrusion claims

The court granted the motion to dismiss the California constitutional privacy and intrusion-upon-seclusion claims, with leave to amend. It held that plaintiffs plausibly alleged that the conduct occurred in or came from California and that they had a reasonable expectation of privacy in their medical communications. But the complaint did not identify the specific personal or private information that each named plaintiff shared with a healthcare provider and reasonably believed Meta received.

The court required plaintiffs to amend these claims to describe the types or categories of sensitive health information allegedly provided through their devices and captured by Meta. The court stated that the description could be general enough to protect plaintiffs’ specific privacy interests.

CDAFA claim

The court granted Meta’s motion to dismiss the CDAFA claim, with leave to amend. CDAFA permits a civil action by an individual who suffered statutory “damage or loss.” The court rejected plaintiffs’ theories that their inability to use computers to communicate with healthcare providers in the future or the diminished value of their information constituted an actionable loss under the allegations then before the court.

Plaintiffs could amend to allege a different theory involving impairment of their computing devices. The court also limited any further amended CDAFA claim to the two subsections plaintiffs addressed in opposition: sections 502(c)(1) and 502(c)(8). Whether plaintiffs could allege a qualifying loss or damage would also affect whether the Pixel could qualify as a prohibited computer contaminant under the statute.

Contract claims

The court denied Meta’s motion to dismiss the breach-of-contract and related breach-of-the-duty-of-good-faith-and-fair-dealing claims. Meta argued that a limitation-of-liability provision in its Terms of Service barred the claims. The court declined to dismiss them because plaintiffs sought nominal damages and restitution and alleged intentional conduct. The court noted that Meta could later seek to limit the types of damages available, including damages beyond nominal damages, at summary judgment or another appropriate stage.

The court also held that the contractual promises identified in Meta’s Privacy Policy and Terms of Service were sufficiently definite. Plaintiffs plausibly alleged that Meta failed to require partners to have the right to share health information, failed to use its systems and teams to prevent unauthorized acquisition, and did not take appropriate action despite allegedly knowing that its filters were ineffective.

Unjust enrichment

The court denied Meta’s motion to dismiss the unjust-enrichment claim. Under California law, unjust enrichment is treated as a quasi-contract claim. The court held that plaintiffs could plead it as an alternative to their express-contract claim at this stage and that they had alleged that their legal remedies were inadequate.

Negligence per se, trespass, and larceny

The court granted the motion to dismiss the negligence-per-se claim, with leave to amend. Negligence per se is a doctrine that may allow a statutory violation to help establish the duty of care in a negligence claim, but plaintiffs still had to allege the basic elements of negligence. The court concluded that HIPAA, the federal health-privacy statute identified by plaintiffs, could not supply the required state-law duty under the authorities it followed. Plaintiffs could amend to identify a state-law source of the duty.

The court granted the motion to dismiss the trespass-to-chattels claim, with leave to amend. Plaintiffs alleged that Meta placed a tracking cookie on their devices and reduced the value of their devices by making them reluctant to use those devices to communicate with healthcare providers. But they did not allege that the cookie impaired device operation, such as by reducing storage or battery life, or that Meta’s conduct affected the devices’ functionality.

The court granted the motion to dismiss the larceny claim, with leave to amend. Plaintiffs alleged theft by false pretenses under California law, but they did not clearly identify the specific false representations Meta made to them or facts showing that they transferred their information in reliance on those representations.

UCL and CLRA claims

The court granted the motion to dismiss the UCL claim, with leave to amend. A UCL claim requires an economic injury involving lost money or property. The court held that plaintiffs had not separately alleged a sufficient benefit-of-the-bargain theory or a specific monetary or economic loss. Their allegations about the diminished value of their data were inconsistent with their contention that they did not want Meta or anyone else to possess their individually identifiable health information.

The court also granted the motion to dismiss the CLRA claim, with leave to amend. Plaintiffs based that claim on alleged misrepresentations that Meta required its partners to have rights to collect, use, and share users’ information. Meta argued that Rule 9(b), which requires fraud-based claims to be pleaded with particularity, required plaintiffs to allege that they saw and relied on the statements. Plaintiffs did not address that argument. The court dismissed the claim with leave to amend so plaintiffs could plead facts regarding reliance on the alleged misrepresentations.

Disposition

Judge William H. Orrick concluded that Meta’s motion was denied regarding the ECPA, CIPA, breach-of-contract, and unjust-enrichment claims. The motion was granted with leave to amend regarding the privacy, CDAFA, negligence-per-se, trespass, larceny, UCL, and CLRA claims. Plaintiffs were ordered to file an amended complaint within 20 days of the order.

The authoritative version

Read the full 26-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.