ConsentPixel – Privacy · Verified

CIPA Case Watch · Issue 03 — August 2026

The Year Theory Became Verdicts — And a New Frontier Opened

Last cycle, the story was a spreading defense against the pen register theory. This cycle, the ground shifted the other way — hard. A jury handed down the first major CIPA verdict in the statute's history, a $59.5M settlement landed alongside it, patient-portal settlements kept stacking up, and a brand-new theory emerged: suing companies for tracking people after they opted out. Meanwhile the "reform" headlines — SB 690 and a serial filer restricted — sound like relief but change little. Here's the Good, the Bad, and the Ugly.

CP ConsentPixel Team August 11, 2026 13 min read CIPA Case Watch · Issue 03
1st ever
Major CIPA jury verdict in the statute's history (Meta, §632)
$59.5M
Flo Health settlement (Google, Flo, Flurry) alongside the verdict
New theory
Suing for tracking that continues after a visitor opts out
Narrow
SB 690 gutted; a top filer restricted — neither lowers your real risk

The shift this cycle

For two years, CIPA litigation lived mostly at the pleading stage — motions to dismiss won or lost, theories tested but rarely resolved. This cycle, that changed. The abstract question of whether CIPA's decades-old provisions really reach modern website and app tracking got a concrete, expensive answer: yes, at least sometimes, and a jury will say so.

Three things define August 2026. First, CIPA produced its first major jury verdict — against Meta, in the Flo Health period-tracker case — proving the theory doesn't collapse at trial. Second, the settlement machine kept running, from a $59.5M femtech deal to a string of patient-portal pixel settlements. Third, a genuinely new frontier opened: lawsuits against Toyota and the NFL built on the allegation that tracking continued after a visitor declined or opted out — turning a consent banner from a shield into evidence.

We're not a law firm, and this is not legal advice. What we are is a team that tracks these decisions because each tells website operators something concrete about their risk. This issue names the trend that matters — the move from theory to verdicts — and the two "reform" stories that sound reassuring but shouldn't change what you do.

Two theories, one reminder. §631 (wiretapping) targets the contents of communications intercepted in transit; §632 targets the recording of confidential communications; §638.51 (pen register) targets addressing/routing data. This cycle's biggest events ran on §631 and §632 — the theories no pending reform touches. The pre-consent firing gap loses in every forum.
🟢 The Good — a clean defense win and a restrained filer

The Good: defendants aren't defenseless

Amid a rough cycle for operators, two developments genuinely helped the defense side — one a merits win, one procedural.

Hughes v. DraftKings

C.D. California Voluntarily dismissed §631 / §638.51
✓ Dismissed — case dropped by plaintiff
🎲 Online gaming · website tracking

The CIPA claim against DraftKings ended with the plaintiff voluntarily dismissing the case in mid-July 2026, rather than pressing on. Voluntary dismissals rarely make headlines, but they're a useful tell: when a plaintiff walks away, it often signals the claim wasn't as strong as the demand letter implied, or that the defendant's posture made it not worth pursuing.

It's a modest data point, not a precedent — but in a cycle dominated by verdicts and settlements against defendants, it's a reminder that not every CIPA claim survives contact with a prepared defendant.

✦ What this means for your site

A well-prepared defense still matters — some claims fold. But a voluntary dismissal is a litigation outcome, not a compliance strategy. The reliable way to be in this column isn't to win the fight; it's to not present the fact pattern that starts it.

Vivek Shah v. Crain Communications — vexatious-litigant order

C.D. California July 20, 2026 Pre-filing order
✓ Serial filer restricted
⚖️ Procedural · demand-letter ecosystem

A federal judge declared one of the most prolific individual CIPA filers, Vivek Shah, a vexatious litigant, requiring him to obtain court permission before filing new CIPA or related digital-privacy suits in the Central District of California. The court cited roughly 29 proceedings since 2021 and seven near-identical §631(a) complaints in the prior seven months.

It's a real signal that courts are noticing abusive filing patterns — but a narrow one. It binds one filer, in one district, prospectively, and doesn't reach arbitration demands or decide whether the underlying tracking violates CIPA.

✦ What this means for your site

Helpful if you face this specific plaintiff in this specific court — your counsel can check whether he obtained leave to file. For everyone else, it changes nothing about your exposure. We unpack exactly what the designation does (and doesn't) in our explainer on the Shah order.

A dismissal elsewhere doesn't fix what fires on your site

Every verdict and settlement this cycle started with a tracker firing before consent. See what fires on your site before the banner renders — the same thing a plaintiff scanner looks for first. About 10 seconds, no account.

Scan your site free →
🔴 The Bad — the year the bill came due

The Bad: verdicts and settlements stack up

If the Good column was thin, the Bad column was where the cycle's weight landed. This is the month CIPA stopped being theoretical.

Frasco v. Flo Health — the Meta jury verdict + $59.5M settlement

N.D. California Verdict Aug 1, 2025 · settlement 2026 §632
✗ Jury verdict for plaintiffs (Meta) + $59.5M settlement
🩺 Femtech · period-tracking app · SDK tracking

This is the landmark. In the period-tracker case, three defendants — Google, Flo, and Flurry — settled for a combined $59.5 million. The fourth, Meta, refused and went to trial. A unanimous San Francisco jury found Meta liable under CIPA §632 for capturing women's confidential menstruation and pregnancy data through its SDK without consent — treating the SDK as an "electronic recording device." It's the first major CIPA jury verdict in the statute's history, and the court denied Meta's post-trial motions to undo it.

Why it matters beyond femtech: the jury's reasoning — when an SDK is a recording device, what counts as consent — isn't limited to health data. And Meta itself has characterized potential exposure as reaching "multiples of billions of dollars" at $5,000 per violation under §637.2 across a certified class.

✦ What this means for your site

The "they'll never get to a jury" defense is gone. A CIPA tracking theory has now won at trial. If your site or app hands data to third-party SDKs or pixels before genuine consent, this is the fact pattern that just produced a verdict. Full breakdown in our Frasco v. Flo Health deep-dive.

The patient-portal pixel settlements — Wellstar, Banner, LifeStance

Multiple districts 2026 Pixel / consent & disclosure
✗ Settled — $4.25M · ~1M-patient class · $3.03M
🏥 Healthcare · patient portals & booking tools

The healthcare pixel wave kept breaking. Wellstar settled for $4.25M over Meta and Google trackers on its site and the Wellstar MyChart portal (~870,000 patients). Banner Health settled claims covering roughly 1,028,000 people who logged into a Banner patient account, with per-member relief. LifeStance — a major behavioral-health provider — agreed to a non-reversionary $3,027,874.44 settlement over trackers on its site and booking tool.

The through-line is the authenticated surface: trackers sitting on logged-in patient portals, where the person is identified and the activity is medical. That's the highest-risk configuration in healthcare, and the settlements keep confirming it.

✦ What this means for your site

A marketing pixel does not belong behind a login. If you run any authenticated area tied to sensitive activity — portal, account, booking, intake — keep third-party trackers off it entirely. We cover the pattern in the patient-portal pixel settlements and the single-case detail in Doe v. Wellstar.

The wiretap wave widens — Concord Hospital & Call-On-Doc

NH · Illinois 2026 State wiretap / §631-type
◐ Settled — $800K · $1.8M
🏥 Healthcare · telehealth · booking

Two smaller settlements show the theory spreading beyond California and beyond giant systems. Concord Hospital (New Hampshire) settled tracking claims for $800,000 under New Hampshire's wiretap statute; Call-On-Doc, a telehealth provider, settled for $1.8 million. Neither is enormous, but together they signal that the pixel-tracking theory is portable across states and defendant sizes.

✦ What this means for your site

This isn't a California-only or big-hospital-only problem. Other states' wiretap laws are being used the same way, so "we're not in California" isn't the protection operators sometimes assume. The underlying fix — don't fire trackers without consent — is jurisdiction-agnostic.

🟠 The Ugly — the frontier that should worry you most

The Ugly: "opt-out doesn't opt you out"

The most important development this cycle isn't a settlement figure — it's a new theory. Two high-profile suits target not tracking-without-a-banner, but tracking that allegedly continued after the visitor said no. That's a harder fact to defend and a broader net, because it turns the consent banner into evidence against the operator.

Conner v. Toyota

L.A. County Superior Court Filed July 15, 2026 §638.51 · fingerprinting
◐ Newly filed — allegations unproven
🚗 Automotive · fingerprinting after "decline"

The plaintiff alleges she rejected all third-party cookies on Toyota.com every visit — and that the site tracked her anyway, using fingerprinting that doesn't depend on cookies, then shared the data for cross-device advertising. She frames it as an "outrageous privacy 'bait and switch.'" The case is newly filed and unproven, and Toyota will contest it.

The significance is the theory: declining cookies did nothing because the tracking wasn't cookie-based. A banner that only governs cookies can't stop fingerprinting — and the gap is exactly what the complaint targets.

✦ What this means for your site

If your "decline" only clears cookies, you have this gap. Enforcement has to reach cookieless tools — fingerprinting, session recorders — too. See the Conner v. Toyota deep-dive.

Kimmons v. NFL

Alameda County Superior Court Filed July 6, 2026 §631 · session replay
◐ Newly filed — allegations unproven
🏈 Sports/media · 186 trackers after opt-out

Forensic testing cited in the complaint alleges NFL.com ran 182 third-party trackers before any consent choice and 186 after a visitor opted out — opting out didn't reduce the tracking. It also alleges a session recorder captured keystrokes typed into input fields, the order and timing of individual keys, whether or not the user hit submit. That keystroke-capture is the §631 "contents" theory in its strongest form — much harder to dismiss than a routing-data claim. Newly filed and unproven.

✦ What this means for your site

Two lessons: opt-outs must actually stop trackers, and session replay must stay off input fields. The 186-after-opt-out number is measurable from the outside by anyone. See the Kimmons v. NFL deep-dive, and our piece on why decline has to mean decline.

The patterns: what's changed, what hasn't

Two "reform" stories this cycle sound like relief and aren't. Read together with the verdicts above, they show why a better legal or legislative climate doesn't lower your actual risk.

DevelopmentSounds likeActually does
SB 690 (amended July 2026)"California is fixing CIPA"Gutted from a broad exemption to a narrow one: gives the AG exclusive authority over §638.51 pen register claims. Leaves §631 and §632 private claims — the ones behind the Flo verdict and NFL suit — fully intact. Not law yet.
Shah vexatious-litigant order"The demand-letter wave is ending"Restricts one filer, one district, prospectively. Doesn't reach arbitration or decide the merits. The ecosystem of other filers is untouched.
Meta §632 jury verdictProves the theory wins at trial. This is the development that actually moved risk — against operators.
"After opt-out" theoryExpands liability from "no banner" to "banner that didn't work," a broader and harder-to-defend net.

The honest read: the defense and legislative news is narrow and uncertain, while the plaintiff news — a verdict, a new theory — is concrete and expansive. For a full breakdown of the bill, see SB 690 explained.

What to do right now — based on this cycle

1

Block non-essential trackers until genuine consent

Nothing non-essential — cookie-based or cookieless — should load or transmit before a visitor affirmatively agrees. This is the exact fact pattern behind the Flo verdict and every settlement in the Bad column above.

2

Make "decline" actually work — including cookieless tools

The Toyota and NFL suits target opt-outs that didn't stop fingerprinting and session recorders. Enforce the opt-out across every non-essential tracker, not just the cookie-based ones — that's the new frontier this cycle opened.

3

Keep trackers off authenticated and sensitive surfaces

Patient portals, account areas, booking tools, checkout, and intake forms are where the portal settlements and the §631 keystroke theory live. A marketing pixel doesn't belong behind a login or on a sensitive page.

4

Log the consent you obtain

The 2026 rules increasingly require you to show an opt-out was honored, not just claim it. A timestamped record of who consented, to what, and when is what answers a "bait and switch" allegation before it becomes a settlement.

The take from August 2026: theory became verdict

For two years, the open question was whether CIPA's old provisions really reach modern tracking. This cycle answered it: a jury said yes, a settlement machine kept paying, and a new "after opt-out" theory widened the target. The abstract became concrete, and it moved against operators.

The two reassuring stories — SB 690's narrowing and a serial filer restrained — are real but small, and they don't touch the theories that actually won. A better defense climate and a pending bill are not the same as a lower actual risk.

The move that protects you in any court, under any bill, is unchanged: don't fire trackers before consent, make opt-out stop everything, keep session replay off sensitive fields, and document what you obtain. Everything in the Bad and Ugly columns above is a variation on the same failure — and it's a failure you can simply not have.

We'll publish the next CIPA Case Watch covering the developments of September 2026 — including any post-trial movement on the Meta verdict's damages, and whether SB 690 clears the legislature before the deadline. For the full, continuously updated case database, see our CIPA Lawsuit Tracker.

Is your site firing before consent — or after opt-out?

No verdict, settlement, or bill fixes a tracker that fires before the banner renders or after a visitor declines. Run the same scan a plaintiff firm would — in about 10 seconds.

Free site scan →
CP

ConsentPixel Research Team

CIPA Litigation Research & Case Analysis

The ConsentPixel — Privacy · Verified research team monitors CIPA case filings, decisions, and settlements to translate legal developments into practical guidance for website owners. CIPA Case Watch publishes monthly. All case summaries are sourced from public court records and legal reporting. This series does not constitute legal advice.

Legal disclaimer: This article is published for informational purposes only and does not constitute legal advice. Case summaries are based on publicly available court records and legal reporting, including analysis published by Bloomberg Law, Labaton Keller Sucharow, HIPAA Journal, Courthouse News Service, the National Law Review, Duane Morris LLP, and CIPAWorld. Conner v. Toyota and Kimmons v. NFL Enterprises are newly filed complaints; the allegations described are unproven and neither defendant has been found liable. Settlements are resolved without admissions of wrongdoing. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. SB 690 is a pending bill, not law. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel; it is not a HIPAA product and does not make any website "HIPAA compliant." CIPA litigation is fact-specific and rapidly evolving; for advice on your situation, consult a qualified privacy attorney.

Scroll to Top