Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Jan. 29, 2024

In Re Meta Pixel Healthcare Litigation

Judge
William Orrick
Docket
3:22-cv-03580
Court
U.S. District Court · Northern District of California
Pages
11
Civil ProcedureMotion to Dismiss
In one sentence

In re Meta Healthcare Pixel Litigation: Judge Orrick denied Meta’s dismissal and strike motions, except plaintiffs abandoned one claim.

Who this affects

The ruling affects the plaintiffs asserting privacy, CDAFA, and trespass claims against Meta Platform, Inc.; those claims were allowed to proceed past the pleading stage, while the plaintiffs’ CLRA claim was voluntarily withdrawn.

What happened

In In re Meta Healthcare Pixel Litigation, plaintiffs alleged that Meta’s Pixel collected sensitive information sent to healthcare providers without consent. After an earlier order allowed amendments, plaintiffs amended their privacy, computer-access, and trespass claims; they did not reassert negligence per se, larceny, or unfair-competition claims.

Meta argued that the amended allegations were insufficient, including because some information was sent through publicly accessible webpages. Plaintiffs also alleged that the Pixel placed a cookie on their devices, used device resources, slowed communications, and transmitted information without permission. Plaintiffs voluntarily withdrew their claim under California’s Consumers Legal Remedies Act.

Judge William H. Orrick denied Meta’s motion to dismiss the remaining claims and denied its motion to strike part of the proposed class definition. The court ruled that the privacy, California computer-access, and trespass allegations were sufficient to proceed at the pleading stage, while noting that discovery could show the alleged device impacts were too small to support the trespass claim. The claims involving health information from Hey Favor were left in the separate Hey Favor case.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
In Re Meta Pixel Healthcare Litigation · No. 3:22-cv-03580
Judge
William Orrick
Date
Jan. 29, 2024

Background

In an earlier order, the court granted Meta Platform, Inc.’s motion to dismiss several claims with permission to amend, including claims involving privacy, California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), negligence per se, trespass, larceny, California’s Unfair Competition Law, and California’s Consumers Legal Remedies Act (CLRA). In the First Amended Consolidated Class Action Complaint, plaintiffs did not reassert the negligence per se, larceny, or Unfair Competition Law claims. They amended and reasserted their privacy, CDAFA, trespass, and CLRA claims. Plaintiffs voluntarily withdrew the CLRA claim. Meta again moved to dismiss, and separately moved to strike part of the proposed class definition.

Privacy and intrusion claims

The court had previously required plaintiffs to identify the general types or categories of sensitive health information they had provided to healthcare providers through their devices. Plaintiffs identified health conditions for which they sought treatment, along with examples of queries, appointment requests, and other communications with healthcare providers. The court held that these allegations were sufficient at the pleading stage because they generally identified sensitive information that Meta plausibly collected through its Pixel.

Meta argued that the claims failed because some information was transmitted through publicly accessible URLs that did not require users to log in. The court declined to dismiss the claims on that basis. It distinguished an earlier decision involving general health information available to the public, explaining that plaintiffs here alleged that the Pixel captured information connecting particular users to particular healthcare providers and indicating that users were about to log in to patient portals. The court held that communications with healthcare providers through publicly available webpages did not, by itself, foreclose the privacy claims. Whether the circumstances ultimately amounted to an actionable invasion of privacy would depend on the totality of the circumstances and could be evaluated as the case proceeded.

CDAFA claims

CDAFA is a California statute governing unauthorized access to or use of computer data, systems, and networks. The court had previously dismissed plaintiffs’ CDAFA claim because they had not adequately alleged impairment of their devices or that the Pixel was a contaminant that usurped the normal operation of their devices.

In the amended complaint, plaintiffs alleged that Meta occupied storage space on their devices without authorization, slowed the devices, used their computer resources, and profited from the data. The court held that these allegations identified a measurable impact and were sufficient at this stage. The court also found sufficient allegations under CDAFA section 502(c)(1), including that the Pixel usurped normal device operation, secretly placed the _fbp cookie on devices, and redirected data to Meta. The court stated that Meta could renew its argument that mere copying or use of data is insufficient if discovery showed no alteration to plaintiffs’ data or devices.

The court also found sufficient allegations under section 502(c)(8), which concerns knowingly introducing a computer contaminant. Plaintiffs alleged that the Pixel recorded and transmitted information, tracked website visitors’ actions, was disguised as a first-party cookie, and usurped the normal operation of users’ devices. The court held that these allegations were sufficient to allege that the Pixel transmitted information without permission. Whether Meta had the required intent was left for later evidentiary proceedings.

Trespass to chattels

Trespass to chattels is a claim alleging wrongful interference with personal property. The court had previously dismissed this claim because plaintiffs had not alleged an effect on the functionality of their devices. In the amended complaint, plaintiffs alleged that the _fbp cookie occupied measurable storage, Meta’s code used measurable device resources and slowed devices, and the resulting delays increased webpage loading time. They sought nominal damages and damages for lost storage and time.

The court explained that California law requires some appreciable damage or impairment for this type of claim. Unlike the temporary computer-resource use discussed in the cited precedent, the alleged cookies remained on devices until discovered or removed and continued using storage and resources. The court held that the alleged measurable reduction in available storage was sufficient to allow the claim to proceed. It described the issue as a close question and noted that discovery and expert testimony might later establish that the alleged impact was too minor to satisfy the legal standard. Meta’s motion to dismiss the trespass claim was denied.

Motion to strike and disposition

Meta moved to strike paragraph 357 of the amended complaint, which excluded from the proposed class health information obtained from Hey Favor, Inc. Meta sought to have those claims included in this case in connection with its pending motion to sever claims in the separate Hey Favor action. The court denied the motion to strike and stated that the claims against Meta in the Hey Favor action would remain there and proceed with the claims against the other defendants in that case. The court also stated that it would later determine the appropriate structure of any certified class or classes.

Judge William H. Orrick denied Meta’s motion to dismiss, except that plaintiffs had voluntarily abandoned the CLRA claim. He also denied Meta’s motion to strike.

The authoritative version

Read the full 11-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.