The Split Sharpens — And the Pixel Theory Goes National
Last cycle was about verdicts. This one is about division. A California federal court let some tracking claims against Wayfair proceed while tossing others in the same order; a $3.85M settlement won final approval — then drew an appeal; and the pen-register theory keeps winning for defendants in one courtroom while §631 wiretapping claims survive in the next. Meanwhile the tracking-pixel theory spread past California's borders — into a Colorado hospital suit and beauty retail. Here's the Good, the Bad, and the Ugly.
In this issue
The shift this cycle
If last cycle proved CIPA claims can reach a jury, this cycle proved how unevenly they land. The clearest example arrived on August 13, when a Central District of California judge ruled on Wayfair's motion to dismiss and split the difference cleanly: the pen-register theory was dismissed, but the §631 wiretapping claim and a trap-and-trace theory were allowed to proceed — all in the same order. That single ruling is the whole state of CIPA law in miniature.
Three threads define this cycle. First, the pen-register theory keeps losing for defendants who challenge it head-on — a genuine bright spot for operators. Second, the §631 "contents" theory keeps surviving, and it reached a new vertical: beauty retail, with a proposed class action against Ulta. Third, the pixel theory stopped being a California-only story — a Colorado hospital was sued over the same Meta Pixel fact pattern, on different legal grounds, showing the underlying argument travels even where CIPA can't.
We're not a law firm, and this is not legal advice. We track these decisions because each tells website operators something concrete about their exposure. This issue names the trend that matters — a hardening split that leaves the pre-consent firing problem exactly where it's always been: unprotected in every forum.
The Good: the pen-register theory keeps failing
For operators, the most reliable defense trend of 2026 held firm this cycle: when defendants challenge the "pen register / trap-and-trace" theory directly, courts increasingly reject it. Two data points reinforced that.
Limas v. Wayfair LLC — pen-register claim dismissed
In Limas v. Wayfair, the plaintiff alleged Wayfair ran tracking tools tied to TikTok, Meta, Pinterest, Snapchat, X, and Reddit, and argued those tools were both pen registers and trap-and-trace devices under §638.51. The court dismissed the pen-register half without leave to amend — the plaintiff didn't rebut Wayfair's argument that a recent state appellate decision, Smith v. LoanDepot.com (Cal. Ct. App., Apr. 2026), forecloses the theory.
That's the good news for operators: a growing line of authority now treats the pen-register label as a poor fit for ordinary website software. When a defendant makes the argument squarely, this theory is increasingly a loser.
The pen-register theory is the most defensible to fight — but notice what didn't get dismissed (see The Bad). A win on one theory in the same order that lets another proceed isn't a defense you'd choose to rely on. The reliable position is not presenting the fact pattern at all.
Smith v. LoanDepot.com — the appellate anchor
The reason Wayfair's pen-register claim fell is that defendants now have state appellate authority to point to. Smith v. LoanDepot.com is the decision courts are increasingly citing to foreclose the theory that everyday website trackers are "pen registers." Its value is durability: a Court of Appeal ruling carries far more weight than a single trial judge's order, and it's now doing exactly that work across new cases.
The caveat: California appellate courts are still preparing to rule on the broader question of whether CIPA reaches website tracking at all — with the closely watched Variety Media pen-register appeal drawing a tentative ruling in late August — tentative, not final, so the picture could shift again.
Your counsel now has real appellate footing against the pen-register theory — worth knowing if you face a §638.51 claim. But this authority does nothing for §631 wiretapping claims, which is where the real volume and the surviving cases sit.
SB 690 clears the legislature — the pen-register theory loses ground in Sacramento too
Passed both houses · awaiting the GovernorThe defense trend wasn't only judicial this cycle. On the final days of the session (late August 2026), the California Legislature passed SB 690 — the first meaningful CIPA reform in years — and sent it to Governor Newsom, who has until roughly the end of September to sign or veto it. If signed, it would remove the private right of action for the pen-register / trap-and-trace theory (§638.51) on websites, leaving that claim enforceable only by the Attorney General, and would apply retroactively to certain pending §638.51 claims within a two-year window tied to a January 1, 2027 operative date.
Be precise about what it does not do, because the headlines overstate it: SB 690 leaves §631 wiretapping and §632 recording claims completely untouched — and §631 is the provision behind most Meta Pixel, session-replay, and chatbot suits. The likely result isn't fewer cases; it's the same cases reframed as §631 claims. As of publication SB 690 has passed but is not yet law — the Governor's decision is the thing to watch.
Don't deprioritize remediation on the strength of SB 690. Even if signed, it narrows one theory while the most expensive one — §631, at $5,000 per violation under Cal. Penal Code §637.2 — survives intact. Your exposure doesn't disappear; it moves.
A dismissal on one theory doesn't fix what fires on your site
Every surviving claim this cycle started with a tracker firing before consent. See what fires on your site before the banner renders — the same thing a plaintiff scanner looks for first. About 10 seconds, no account.
Scan your site free →The Bad: the wiretapping theory keeps surviving
For every pen-register win, the §631 "contents" theory kept advancing — and this cycle it reached a mainstream consumer brand.
Limas v. Wayfair LLC — §631 & trap-and-trace survive
The same Wayfair order that dismissed the pen-register claim let the §631(a) wiretapping claim and a trap-and-trace theory proceed. On trap-and-trace, Wayfair argued the device must capture incoming impulses while the trackers captured data outgoing from users — but the court said Wayfair was looking at the wrong recipient: the question wasn't whether the communication was incoming to Wayfair.
This is the pattern operators should internalise: the theories that survive are the ones about intercepting the contents and routing of a visitor's communications — and detailed allegations about multi-platform tracking are increasingly enough to clear a motion to dismiss.
Winning the pen-register argument doesn't end the case if §631 survives alongside it. A defendant running six ad-tech trackers still faces discovery and settlement pressure on the surviving claims. The trackers firing before consent are what generate every one of these theories.
Hartigan v. Ulta Beauty — Meta Pixel class action
A proposed class action alleges Ulta's website deployed the Meta Pixel and related trackers that intercepted the contents of visitors' communications — full URL strings and the specific products and content viewed — and transmitted them to Meta and other third parties without consent. Filed by plaintiff Raeanon Hartigan for a class of California website visitors dating to June 2024, the complaint stacks CIPA §631, the ECPA, and California constitutional privacy and intrusion-upon-seclusion claims, and alleges Ulta aided Meta's interception. Notably, it's brought by Swigart Law Group and Shay Legal — among the most active CIPA filers. Separately, a distinct Ulta matter on session-replay tracking drew an August ruling that the company's privacy policy alone was not enough to establish CIPA consent — a reminder that passive "by continuing to browse" notice does not meet the affirmative-consent standard.
The allegations are unproven and Ulta has not been found liable. What makes the filing notable isn't novelty — it's the vertical: the pixel wave has moved firmly into mainstream beauty and retail, where the Meta Pixel is nearly universal.
If you run the Meta Pixel and serve California visitors, this is your fact pattern. The Ulta complaint isn't exotic — it's the standard §631 "contents" theory applied to a routine retail tracking setup. The differentiator between a defendant and a bystander is whether the pixel fires before consent. This is general information, not legal advice.
The Ugly: the split gets messier, and the theory travels
The genuinely uncertain developments this cycle are the ones that resist a clean "good" or "bad" reading — a settlement that's approved but frozen, and a pixel suit in a state where CIPA doesn't even apply.
Mirmalek v. Los Angeles Times — $3.85M approved, then appealed
The LA Times won final approval of a $3.85M class settlement over three ad-tech trackers (TripleLift, GumGum, Audiencerate) that allegedly collected visitor data without consent — brought, notably, on the pen-register theory. Then an appeal was filed, and payouts are stayed until it resolves.
Here's why it lands in the Ugly column: the settlement rewards the same §638.51 pen-register theory that defendants are successfully dismissing elsewhere (see Wayfair, LoanDepot). A company paid $3.85M to resolve a theory another company just defeated at the pleading stage weeks later. That's not a coherent risk signal — it's the split personified, and it means settlement math can't be reduced to "which theory is winning this month."
Don't read the pen-register dismissals as "you're safe." The LA Times shows a company can still pay millions on a theory that's losing in other courtrooms — because settlement pressure comes from cost and uncertainty, not from which way the last ruling went. The only stable variable you control is whether trackers fire before consent.
Miller v. UCHealth — the pixel theory crosses state lines
A proposed class action alleges UCHealth deployed the Meta Pixel on its "Find a Doctor" feature and possibly its patient portal, capturing users' condition and symptom searches along with identifying details, and sending that to Meta without consent. Filed by Larimer County resident Patrick Miller in federal court in Denver, the complaint is built on HIPAA and privacy grounds — not CIPA (Colorado isn't a CIPA jurisdiction). As in several of these suits, Meta is not named; the website operator is the sole defendant.
We're including it here precisely because it isn't a CIPA case. It's the same Meta-Pixel-on-a-health-site fact pattern that drives the California wave — reproduced in a state with no wiretapping analog, on entirely different legal theories. The allegations are unproven and UCHealth has not been found liable.
"We don't have California traffic" is not the shield it used to be. The pixel-tracking theory is portable — it reappears under HIPAA, under other states' wiretap laws, and under consumer-protection statutes. The underlying trigger is identical everywhere: sensitive data sent to a third party before the visitor agreed. ConsentPixel — Privacy · Verified is the detection and state-law consent layer for that trigger; it is not a HIPAA product and does not make any site "HIPAA compliant." This is general information, not legal advice.
The patterns: what's changed, what hasn't
Strip away the individual rulings and three patterns define this cycle — two new, one stubbornly constant.
| Development this cycle | What it changes | Your exposure |
|---|---|---|
| Pen-register theory keeps losing (Wayfair, LoanDepot) | A defensible argument against §638.51 claims, now with appellate backing | Lower — if that's the only theory pled |
| §631 "contents" theory keeps surviving (Wayfair, Ulta) | The high-volume theory clears motions to dismiss on detailed tracking allegations | Unchanged — the main risk |
| Settlement approved but appealed (LA Times $3.85M) | Shows companies still pay on theories losing elsewhere; settlement ≠ merits | Cost-driven, not theory-driven |
| Beauty/retail joins the wave (Ulta) | Mainstream Meta-Pixel setups are now targets, not just healthcare/media | Higher for retail operators |
| Theory goes national (UCHealth, Colorado) | Same pixel fact pattern reappears under HIPAA / other states' laws | Portable beyond California |
| The pre-consent firing gap | Nothing — it's the trigger under every theory, in every forum | The constant across all cases |
| SB 690 passed the legislature (awaiting Governor) | Would strip the private right of action for §638.51 pen-register claims — but only if signed, and §631 stays intact | Watch — not yet law; §631 exposure unchanged |
| Defense also landed clean wins (Chrysler, food banks, UnitedHealthcare) | Standing and party-exception dismissals show prepared defendants still prevail | Lower — with genuine consent architecture |
The throughline is unchanged from every prior issue: whichever theory is winning this month, they all begin at the same place — a tracker that transmits a visitor's activity to a third party before the visitor consented. The pen-register defense might spare you one claim; it does nothing about the §631 claim filed alongside it, or the same fact pattern refiled in Colorado under HIPAA.
What to do right now
None of this changes the practical playbook — it sharpens why it matters. Four steps, in order.
Find what fires before consent
Every surviving claim this cycle — Wayfair §631, Ulta, UCHealth — starts with a tracker transmitting before the visitor agreed. Scan your site to see exactly what loads pre-consent, the way a plaintiff scanner would.
Treat the Meta Pixel as the highest-risk tag
The Ulta and UCHealth suits both turn on it. If you run the Meta Pixel, confirm it doesn't fire — and doesn't transmit URL or form data — until consent. This is the single most-litigated tracker of 2026.
Don't rely on your jurisdiction
UCHealth shows the theory travels. Whether you have California traffic or not, block non-essential trackers until consent and honour opt-out signals — the standard that holds under CIPA, HIPAA-adjacent claims, and every state wiretap law.
Keep the proof
Settlements like the LA Times turn on what a site actually did. A timestamped, page-scoped consent log is what lets you show a tracker was gated — the evidence that a privacy policy alone can't provide.
The take
This cycle's headline isn't a verdict or a number — it's a widening split. The pen-register theory is losing; the §631 wiretapping theory is winning; a settlement got approved on a theory that's failing elsewhere; and the whole fact pattern jumped state lines into a jurisdiction where CIPA doesn't apply. If you're trying to time your risk to "which theory is ahead," this cycle is the argument against that entire approach.
Because underneath the divergence, every one of these cases — the survivor, the settlement, the out-of-state copy — traces to the same millisecond: a tracker firing before consent. That's the one variable you control, and it's the one that's dispositive in every forum.
We'll publish the next CIPA Case Watch covering October 2026 — including any ruling in the California appellate pen-register case, and whether the LA Times appeal moves. For the full, continuously updated case database, see our CIPA Lawsuit Tracker.
Is your site firing before consent?
No ruling, settlement, or bill fixes a tracker that fires before the banner renders. Run the same scan a plaintiff firm would — in about 10 seconds.
Free site scan →Legal disclaimer: This article is published for informational purposes only and does not constitute legal advice. Case summaries are based on publicly available court records and legal reporting, including analysis published by the National Law Review, Spencer Fane LLP, Law360, Loeb & Loeb LLP, Klein Moynihan Turco LLP, Top Class Actions, and the Denver Post (via HealthExec and Daily Hodl). Hartigan v. Ulta Beauty and Miller v. UCHealth are newly filed complaints; the allegations described are unproven and neither defendant has been found liable. Limas v. Wayfair is a motion-to-dismiss ruling, not a final judgment. The LA Times settlement was resolved without any admission of wrongdoing and is under appeal. The $5,000-per-violation figure, where referenced, reflects statutory damages under California Penal Code §637.2. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel; it is not a HIPAA product and does not make any website "HIPAA compliant." CIPA and website-tracking litigation are fact-specific and rapidly evolving; for advice on your situation, consult a qualified privacy attorney.