ConsentPixel – Privacy · Verified

CIPA Cases

CIPA Cases: Rulings, Settlements & Deep Dives

Case-by-case coverage of the California wiretapping lawsuits reshaping website tracking — the rulings that change your risk, in plain English.

The fastest way to understand CIPA risk is to watch the cases. This category breaks down individual California Invasion of Privacy Act lawsuits and settlements against websites — who was sued, over which technology, and what the court actually decided. We cover the plaintiff wins that expand the theory, the defense wins that narrow it, and the settlements that set the going rate.

Every write-up is grounded in public court records and reputable legal reporting, and paired with our continuously updated tracker so you can see the whole landscape at a glance. The goal isn’t to alarm — it’s to show you, concretely, what separates a case that survives from one that gets dismissed. This is general information, not legal advice.

Conner v. Toyota Motor Corporation
CIPA Cases

Conner v. Toyota — CIPA “Decline Button” Tracking Case

A CIPA class action claims Toyota.com kept tracking visitors — through fingerprinting — even after they clicked “Decline” on the cookie banner. It’s the clearest test yet of a simple promise: that saying no actually stops the tracking. Here’s the theory, why fingerprinting makes the “decline” button so dangerous, and what the case signals for every site running a consent banner.

Conner v. Toyota — CIPA “Decline Button” Tracking Case Read Post »

Kimmons v. NFL Enterprises LLC
CIPA Cases

Kimmons v. NFL — 182 Trackers & Tracking After Opt-Out (CIPA)

A CIPA class action says NFL.com deployed 182 third-party trackers before a visitor could make any choice — and kept 186 running after opt-out, including canvas fingerprinting and a session recorder that allegedly captured keystrokes. It’s the most detailed “your opt-out did nothing” complaint of 2026. Here’s what forensic testing claims to have found, the legal theory behind it, and what it signals for every site with a consent banner.

Kimmons v. NFL — 182 Trackers & Tracking After Opt-Out (CIPA) Read Post »

Frasco v. Flo Health, Inc.
CIPA Cases

Frasco v. Flo Health — $59.5M Settlement + Meta’s CIPA Verdict

The period-tracking case that produced two results at once: a $59.5M settlement from Google, Flo, and Flurry — and, against the one defendant that refused to settle, the first major CIPA jury verdict in the statute’s history, finding Meta liable for capturing women’s reproductive-health data without consent. Here’s how in-app data reached advertisers, both tracks of the outcome, and why every operator collecting sensitive data should read it.

Frasco v. Flo Health — $59.5M Settlement + Meta’s CIPA Verdict Read Post »

Doe v. Wellstar Health System, Inc.
CIPA Cases

Doe v. Wellstar — $4.25M MyChart Pixel Settlement

One of Georgia’s largest health systems agreed to a $4.25M settlement after a class action alleged that Meta Pixel and Google tracking tools on its website and MyChart patient portal quietly transmitted roughly 870,000 patients’ health activity to advertisers. Here’s exactly how a patient portal leaks data, the theory that made it actionable, and what every operator — healthcare or not — should take from it.

Doe v. Wellstar — $4.25M MyChart Pixel Settlement Read Post »

GoodRx Tracking Pixel Litigation
CIPA Cases

GoodRx Tracking Pixel Litigation (FTC + Class Action) – Case Deep-Dive

GoodRx is the case that broadens the story beyond hospitals — and it is really two separate matters that are easy to confuse. One is a landmark $1.5 million FTC enforcement action, the first ever under the Health Breach Notification Rule, and it is final. The other is a private class action with a much larger headline number that a federal court has repeatedly declined to approve. Keeping them apart is the whole point.

GoodRx Tracking Pixel Litigation (FTC + Class Action) – Case Deep-Dive Read Post »

Mass General Brigham Tracking Pixel Litigation
CIPA Cases

Mass General Brigham Tracking Pixel Litigation — Case Deep-Dive

Before “pixel litigation” was a category anyone tracked, Mass General Brigham paid $18.4 million to settle a class action over cookies and tracking pixels on its public informational websites. Finalised in early 2022, it was one of the first eight-figure healthcare tracking settlements — the case that showed the plaintiffs’ bar this theory could command serious money.

Mass General Brigham Tracking Pixel Litigation — Case Deep-Dive Read Post »

Inova Health Tracking Pixel Litigation
CIPA Cases

Inova Health Tracking Pixel Litigation (Lugo v. Inova) – Case Deep-Dive

Inova Health agreed to a $3.15 million settlement over Meta and Google pixels on its public-facing websites — but the reason this case matters isn’t the number. It’s the law. The surviving claim was brought under the federal Electronic Communications Privacy Act (ECPA), and it cleared a motion to dismiss on a theory that reaches straight into HIPAA.

Inova Health Tracking Pixel Litigation (Lugo v. Inova) – Case Deep-Dive Read Post »

Penn Medicine Tracking Pixel Litigation
CIPA Cases

Penn Medicine Tracking Pixel Litigation (Mohr v. Penn) – Case Deep-Dive

Penn Medicine agreed to a settlement of up to $9.5 million over Meta and Google tracking pixels on its myPennMedicine patient portal — and the claim wasn’t brought under California’s CIPA. It was brought under Pennsylvania’s own wiretap statute. This case is the clearest proof yet that pixel-as-wiretap theory is not a California problem.

Penn Medicine Tracking Pixel Litigation (Mohr v. Penn) – Case Deep-Dive Read Post »

In re Meta Pixel Tax Filing Cases — CIPA Case Deep-Dive
CIPA Cases

In re Meta Pixel Tax Filing Cases

Meta lost the argument that it doesn’t “use” its own Pixel — then won the case anyway, on procedure. In March 2026 a federal court denied class certification after plaintiffs broadened their class definition and ran into CIPA’s one-year statute of limitations. It’s the most instructive defense win of the year, and the most dangerous one to misread.

In re Meta Pixel Tax Filing Cases Read Post »

Session Cookies vs Persistent Cookies: The Complete 2026 Guide
CIPA Cases

Session Cookies vs Persistent Cookies: The Complete 2026 Guide

The difference between session cookies vs persistent cookies comes down to one thing: how long they live. But that single distinction decides whether a cookie needs consent, how it’s regulated, and whether it puts your website at legal risk. This guide explains both types clearly — plus how sessions differ from cookies, how to view them in Chrome, and the tools that scan and audit them.

Session Cookies vs Persistent Cookies: The Complete 2026 Guide Read Post »

Podraza v. Nourish, Inc.
CIPA Cases

Podraza v. Nourish, Inc.

A federal court let both a CIPA §631 wiretap claim and a federal Wiretap Act claim survive dismissal against a telehealth provider — because the site relied on browsewrap consent that the court found inadequate. It’s one of 2026’s clearest warnings that a passive “notice on the page” is not consent.

Podraza v. Nourish, Inc. Read Post »

Ortiz v. Foris Dax, Inc. (Crypto.com)
CIPA Cases

Ortiz v. Foris Dax (Crypto.com) — CIPA Case Deep-Dive

The plaintiffs clicked “Disable All” — and, they allege, the tracking kept running anyway. A federal court dismissed their wiretapping claim but let the pen-register claim proceed, in one of the most thorough federal endorsements yet of the theory that cookies can be illegal “pen registers.” Here’s the full breakdown, and why the “Disable All” detail should worry every site with a consent banner.

Ortiz v. Foris Dax (Crypto.com) — CIPA Case Deep-Dive Read Post »

Scroll to Top