ConsentPixel – Privacy · Verified

LIVE TRACKER — UPDATED MONTHLY

CIPA Lawsuit
Tracker 2026

As of August 2026, this tracker follows **46 documented CIPA website lawsuits** — cases targeting session-replay tools, tracking pixels, and analytics scripts — with more than **$153.4M in disclosed settlements**, sourced from public court records. Updated monthly.

🗓️ Last updated: August 17, 2026 Next update: September 2026
SNAPSHOT · 2026 CA · §631 · §638.51
46
Total tracked cases
+10 since July · updated Aug 11, 2026
$153.4M+
Disclosed settlement value
incl. Flo Health $59.5M
TECHNOLOGY IMPLICATED

Which technologies are most often named in CIPA cases?

Across tracked cases, three technologies recur: session-replay tools (Hotjar, Microsoft Clarity, FullStory), advertising and analytics pixels (Meta Pixel, TikTok Pixel, Google Analytics), and live-chat widgets. Each can capture or transmit a visitor's activity before consent — the factual basis most CIPA website claims are built on.

Session recording65%
Third-party scripts15%
Forms & chat data10%
Tracking pixels10%
50K–100K
Total CIPA claims filed since 2022 (lawsuits + demand letters)
$5,000
Statutory damages per violation under California Penal Code §637.2 — no proof of harm required
$153.4M+
Publicly disclosed settlement value tracked on this page
28
US states with similar wiretapping statutes reaching websites
46
Named cases detailed on this tracker (updated monthly)

How many CIPA website lawsuits have been filed?

As of 2026, this tracker documents 46 CIPA website lawsuits — cases filed under the California Invasion of Privacy Act against sites running session-replay tools, tracking pixels, and analytics scripts, representing more than $153.4M in disclosed settlements. Counting pre-suit demand letters, total CIPA activity runs into the tens of thousands of claims since 2022. The list below shows each tracked case — filter by status or search by defendant.

Showing 0 of 0 cases

What are the most recent CIPA lawsuits?

The cases below are sorted newest-first and updated monthly from public court records, so the top rows are the most recent CIPA filings and settlements. Each links to a full breakdown of the defendant, court, technology at issue, and outcome.

Not the person who manages your site? Forward this page to your developer or agency — they're the ones who need to see which trackers fire before consent.

Newly filed · Retail / Beauty

Hartigan v. Ulta Salon, Cosmetics & Fragrance Inc.

S.D. California — No. 3:26-cv-04007-JO-VET

Newly filed — allegations unproven CIPA §631 · ECPA
Date / Key Date
Filed Aug 11, 2026 · Jun 4, 2024 – date of judgment
Class Period
Jun 4, 2024 – Aug 11, 2026

Proposed class action alleging Ulta's website deployed the Meta Pixel and related trackers that intercepted the contents of visitors' communications — full URL strings and the specific products and content viewed — and transmitted them to Meta and other third parties without consent. The complaint stacks CIPA §631, the ECPA, and California constitutional privacy and intrusion-upon-seclusion claims, and alleges Ulta also aided Meta's interception. Filed by plaintiff Raeanon Hartigan for a class of California website visitors. Notably brought by Swigart Law Group and Shay Legal — firms among the most active CIPA filers — underscoring that the pixel wave has moved firmly into mainstream retail and beauty. Newly filed and unproven; Ulta has not been found liable.

Meta Pixel Retail / beauty §631 "contents" theory ECPA

Settlement + Verdict · Health / Femtech

Frasco v. Flo Health, Inc.

N.D. California — No. 3:21-cv-00757-JD (Judge James Donato)

$59.5M settlement + landmark Meta jury verdict CIPA §632
Date / Key Date
Verdict Aug 1, 2025 · final hearing Oct 29, 2026
Class Period
Nov 1, 2016 – Feb 28, 2019

The period-tracker case produced two outcomes. Google, Flo and Flurry settled for a combined $59.5M (Google $48M, Flo $8M, Flurry $3.5M). Meta refused and went to trial — and a unanimous San Francisco jury found it liable under §632 for capturing confidential reproductive-health data via its SDK without consent, the first major CIPA jury verdict in history. The court denied Meta's post-trial motions; damages not yet set.

$59.5M Settlement Femtech SDK tracking Meta jury verdict §632
Case details →

Settlement · Healthcare

Doe v. Wellstar Health System, Inc.

N.D. Georgia

Settlement — awaiting approval Pixel · consent & disclosure
Date / Key Date
Settlement motion filed Jul 22, 2026
Class Period
Feb 19, 2020 – Jul 22, 2026

$4.25M settlement covering ~870,000 patients over Meta Pixel and Google trackers on Wellstar.org and the Wellstar MyChart patient portal. A judge allowed some claims to proceed, finding Wellstar allegedly went "beyond the scope of patients' permission" — receiving enhanced advertising services rather than cash for the data. Settled without admitting wrongdoing.

$4.25M Settlement Healthcare portal MyChart Meta Pixel Google
Case details →

Settlement · Healthcare

McCulley, et al. v. Banner Health

Weld County, Colorado — No. 2026CV30182

Settlement — claims open (Sep 5, 2026) Pixel · consent & disclosure
Date / Key Date
Claim deadline Sep 5, 2026 · final approval Sep 10, 2026
Class Period
Jun 1, 2020 – Nov 22, 2023

Settlement covering roughly 1,028,000 people who logged into a Banner patient account (formerly MyBanner), over tracking tools alleged to have disclosed personal and health information to Meta and Google. Relief is disclosed per class member — a $20 payment plus a year of privacy monitoring — rather than as a single fund total; aggregate cost scales with the ~1M-person class.

$20 + 1 yr monitoring / member Healthcare portal ~1.03M class Meta Google

Settlement · Behavioral health

Strong v. LifeStance Health Group, Inc.

D. Arizona — No. 2:23-cv-00682

Settlement — claims open (Sep 29, 2026) Pixel · consent & disclosure
Date / Key Date
Prelim. approval May 12, 2026 · claims by Sep 29, 2026
Class Period
Mar 1, 2020 – Apr 30, 2023

Non-reversionary $3,027,874.44 settlement over third-party tracking tools on LifeStance's website and online booking tool, alleged to have disclosed patient information to Meta and Google. Notable for the sensitivity — LifeStance is a major outpatient mental-health provider, and the data allegedly signaled treatment for conditions like depression, PTSD and bipolar disorder. Two subclasses; settled without admitting wrongdoing.

$3.03M Settlement Behavioral health Booking tool Meta Google

Newly filed · Automotive

Conner v. Toyota Motor Corporation

L.A. County Superior Court

Newly filed — allegations unproven CIPA §638.51
Date / Key Date
Filed Jul 15, 2026
Class Period

Proposed class action alleging that after the plaintiff rejected all third-party cookies on Toyota.com, the site kept tracking her using fingerprinting — which doesn't depend on cookies — then shared data for cross-device advertising. Framed as an "outrageous privacy 'bait and switch.'" The theory targets tracking that continues after a visitor opts out. Newly filed and unproven; Toyota has not been found liable.

Fingerprinting Tracking after "decline" Trap & trace Cross-device
Case details →

Newly filed · Sports / Media

Kimmons v. NFL Enterprises LLC

Alameda County Superior Court — No. 26CV197596

Newly filed — allegations unproven CIPA §631
Date / Key Date
Filed Jul 6, 2026
Class Period

Forensic testing cited in the complaint alleges NFL.com ran 182 third-party trackers before any consent choice and 186 after a visitor opted out — opting out didn't reduce the tracking. It also alleges a session recorder captured keystrokes typed into input fields (order and timing, whether or not submitted) — the §631 "contents" theory in its strongest form. Newly filed and unproven.

Session replay 186 after opt-out Keystroke capture Canvas fingerprinting
Case details →

Settlement · Healthcare

Branson v. Concord Hospital

New Hampshire — No. 217-2024-CV-00295

Settled NH Wiretap Statute
Date / Key Date
Settled 2026
Class Period

$800,000 settlement over website tracking tools alleged to have disclosed patient information to third parties — brought under New Hampshire's wiretap statute, not California's CIPA. One of a growing set of tracking cases outside California, showing the pixel-tracking theory is portable across states' wiretap laws.

$800K Settlement Healthcare New Hampshire State wiretap law

Settlement · Telehealth

Lucas v. Call-On-Doc

Will County, Illinois — No. 2026LA000403

Settlement — claims open (Aug 29, 2026) Pixel · consent & disclosure
Date / Key Date
Claim deadline Aug 29, 2026
Class Period

$1.8M settlement over third-party tracking tools on the Call-On-Doc telehealth platform alleged to have disclosed users' information without consent. California account holders and appointment bookers can claim up to $20 (no proof required). Another telehealth entry in the healthcare tracking wave.

$1.8M Settlement Telehealth Illinois Up to $20 / claimant

Defendant win · Online gaming

Hughes v. DraftKings

C.D. California

Voluntarily dismissed by plaintiff CIPA §631, §638.51
Date / Key Date
Dismissed mid-July 2026
Class Period

The CIPA claim against DraftKings ended with the plaintiff voluntarily dismissing the case rather than pressing on. A modest data point rather than a precedent, but a reminder that not every CIPA claim survives contact with a prepared defendant — a rare defense-side outcome in a cycle dominated by verdicts and settlements.

Online gaming Website tracking Voluntary dismissal

Procedural · Demand-letter ecosystem

Vivek Shah v. Crain Communications, Inc. — vexatious-litigant order

C.D. California — No. 2:26-cv-03070-RGK-CTS (Judge R. Gary Klausner)

Pre-filing order — serial filer restricted CIPA §631(a)
Date / Key Date
Order Jul 20, 2026
Class Period

A federal court declared one of the most prolific individual CIPA filers a vexatious litigant, requiring him to obtain court permission before filing new CIPA or related digital-privacy suits in the district — citing ~29 proceedings since 2021 and seven near-identical §631(a) complaints in the prior seven months. Narrow: it binds one filer, one district, prospectively, and doesn't reach arbitration or decide the merits.

Vexatious litigant Pre-filing order Serial plaintiff Demand letters
Case details →
Settlement · Media / News

Mirmalek v. Los Angeles Times Communications LLC (Doe v. LA Times)

C.D. California
Settlement pending — final approval CIPA §631, §638.51
Date / key date
2026-06-26
Class period
Jan 2023 – Dec 2025

The LA Times agreed to a $3.85M settlement over claims that tracking technologies on its website and mobile app collected California visitors' information without consent between Jan 2023 and Dec 2025. Valid claims by May 20, 2026 eligible for pro-rata cash. Final approval hearing held June 26, 2026 — order pending.

$3.85M SettlementNews websiteWeb trackersTripleLiftGumGum
Defendant win · Leadership consulting

Rounds v. Development Dimensions International, Inc.

C.D. California
Dismissed — no leave to amend CIPA §638.51
Date / key date
2026-03-11
Class period

Dismissed without leave to amend a claim that DDI's 6Sense data-broker SDK (geolocation, device, browser-cookie data to de-anonymize visitors) was an illegal trap-and-trace device. Judge Carter found cookies do not satisfy §638.51, since trap-and-trace covers signaling data identifying the source of a communication, not routine web-tracking metadata. With no plausible violation, the out-of-state defendant had no CA minimum contacts and personal jurisdiction failed.

Defendant winTrap & tracePersonal jurisdictionCookies / SDK
Case details →
Defendant win · Technology

Blaker v. NetScout Systems, Inc.

LA County Superior Court, Dept. 733
Demurrer sustained — no leave to amend CIPA §638.51
Date / key date
2026-05-27
Class period

The court held CIPA's pen register / trap-and-trace provisions reach telephone communications only — not ordinary software on a commercial website. Treated as an issue of first impression; leaned on statutory construction and §638.52's court-order process. Dismissal with prejudice gives operators a clean rebuttal to the pen-register theory, though it leaves §631 wiretapping and pre-consent timing theories untouched.

Defendant winPen registerTrap & traceFirst impressionTelephone-only
Case details →
Plaintiff win · Financial services

Ingraham v. Capital One Financial Corp.

Federal Court
Significant claims survived CIPA §631
Date / key date
2026-05-22
Class period

Multiple claims survived where plaintiffs alleged transmission of highly sensitive data to third parties: employment status, citizenship, bank account type, credit approval/denial outcomes, FICO segments, income bands, names, emails, phones. Court distinguished routine browsing-data disputes due to the extraordinary sensitivity. Reinforces that defendants face greater difficulty challenging standing when sensitive financial data is disclosed.

Plaintiff winFinancial dataSensitive dataApplication dataThird-party transmission
Case details →
Defendant win · Cryptocurrency / Finance

Ortiz v. Foris Dax, Inc. (Crypto.com)

Federal Court
Split — §631 dismissed, §638.51 survived CIPA §631, §638.51
Date / key date
2026-05-21
Class period

§631 wiretapping claim dismissed (plaintiffs failed to describe their actual website activities). But the §638.51 pen register claim survived in one of the most comprehensive federal analyses yet on whether CIPA's pen register provision reaches internet tracking — concluding it does, since CA adopted a federal pen register definition Congress expanded to internet tracking in 2001. A strong federal endorsement of the pen register theory.

Mixed rulingPen registerThird-party trackingInternet tracking theory
Case details →
Plaintiff win · Entertainment / Events

Garcia v. Anschutz Entertainment Group (AEG)

Federal Court
Split — ECPA dismissed, §638.51 survived CIPA §638.51, ECPA
Date / key date
2026-05-05
Class period

ECPA federal claim dismissed under the party exception. CIPA pen register claim survived because AEG's third-party cookies activated immediately on landing — before the consent banner appeared and before any opt-out existed. The court emphasized a banner shown after tracking has begun is only a disclosure notice, not valid consent. A warning for orgs whose trackers fire before consent interaction.

Mixed rulingConsent banner gapPen registerPre-consent firingThird-party cookies
Defendant win · Streaming / Media

Diaz v. Paramount Skydance (Pluto TV)

Federal Court
Dismissed — lack of Article III standing CIPA §631, §638.51
Date / key date
2026-04-20
Class period

Dismissed for lack of Article III standing. Court drew a sharp line between genuinely sensitive data (medical, financial, personal communications) and routine behavioural metadata from ad-targeting pixels on a free streaming platform. Vague allegations that pixels collected 'personal information' were insufficient — plaintiffs must identify specific sensitive data actually disclosed. Standing framework now cited across districts as a first-line defence for non-sensitive content sites.

Defendant winAdvertising pixelsStandingStreaming platform
Plaintiff win · Telehealth / Health & wellness

Podraza v. Nourish, Inc.

N.D. Illinois
Motion to dismiss denied — case proceeds CIPA §631, ECPA
Date / key date
2026-04-20
Class period

Both the ECPA wiretapping claim and the CIPA §631 claim survived dismissal. The problem was consent architecture: unlike Bosley (clickwrap requiring affirmative acceptance before access), Nourish relied on browsewrap — a buried notice users were deemed to accept by visiting. Courts are increasingly hostile to browsewrap; the court found it inadequate. The ECPA claim survived via the HIPAA crime-tort exception — significant for health/wellness sites. Fisher Phillips called it 'the most straightforwardly bad decision in the set for businesses.' Takeaway: browsewrap is not defensible consent; affirmative clickwrap or an enforced CMP is the standard.

Plaintiff winBrowsewrap vs clickwrapHealth / wellnessECPA crime-tort exceptionConsent architecture
Case details →
Settlement · Beauty / service business

Cumor, Dunn v. European Wax Center, Inc.

13th Judicial Circuit, Hillsborough County, FL
Settlement pending — final approval CIPA §631, ECPA, FSCA
Date / key date
2026-07-15
Class period
Jun 30 2023 – Apr 2 2026

European Wax Center agreed to a $5M settlement over waxcenter.com firing the Meta Pixel, Attentive Mobile, LinkedIn and Snap tags on page load — before consent — transmitting booking-related data to ad partners. Claims stacked CIPA §631, ECPA and Florida's FSCA. Class covers all US residents who visited Jun 30 2023 – Apr 2 2026; browsing alone qualifies. Up to $10/claimant pro rata. Notable because the tracking stack is the exact config on thousands of eCommerce/service sites.

$5M SettlementBeauty / service businessMeta PixelLinkedInSnap
Case details →
Defendant win · Tax prep / Financial

In re Meta Pixel Tax Filing Cases

N.D. California
Class certification denied (MDL continues) CIPA §631, §638.51, UCL
Date / key date
2026-03-30
Class period

Plaintiffs sought to certify a far broader class at certification than the complaint contemplated — from people whose tax-filing data appeared in Meta's systems to anyone whose any data appeared. The court found this expansion raised individualized questions overwhelming common ones, defeating predominance under Rule 23(b)(3). Underlying CIPA claims remain alive; the MDL continues without a certified class for now. Standing must be proven by a preponderance at certification, not just pleading-level.

Defendant winTax filing portalMeta PixelClass certificationFinancial data
Case details →
Settlement · Healthcare

In re Sutter Health Tracking Pixel Litigation

N.D. California
Settled CIPA §631
Date / key date
2026-04-01
Class period

Sutter Health agreed to a $21.5M settlement over deploying third-party tracking pixels on its patient portal and marketing site, transmitting protected health information to vendors without patient consent. Provides $90 per class member. Healthcare faces elevated CIPA exposure due to the sensitivity of medical data.

$21.5M SettlementHealthcare portalMeta PixelGoogle AnalyticsThird-party pixels
Case details →
Settlement · Healthcare

Doe v. Inova Health System

E.D. Virginia / C.D. California
Settled CIPA §631
Date / key date
2026-04-01
Class period

Inova Health settled for $3.1M over tracking pixels on its healthcare website transmitting patient data to third-party vendors without HIPAA authorisation or consumer consent. Part of the broader healthcare pixel litigation wave affecting hospitals and health systems nationwide.

$3.1M SettlementHealthcare portalMeta Pixel
Defendant win · Retail / E-commerce

Balabbo v. Wildflower Brands

LA County Superior Court
CIPA dismissed; privacy claim survives CIPA §631, §638.51, Common law privacy
Date / key date
2026
Class period

Mixed ruling. Court dismissed CIPA pen register and wiretapping claims, finding CCPA/CPRA governs website data collection and the legislature could not have intended to criminalise under CIPA what it regulated under CCPA. But a common law invasion of privacy claim survived — capture/transmission of credit card and medical data could be a highly offensive intrusion. The CIPA/CCPA preemption argument gains traction.

Mixed rulingSession replayE-commerceCCPA preemptionCommon law privacy
Plaintiff win · Media / News

D'Antonio v. Cable News Network, Inc. (CNN)

S.D. New York
Motion to dismiss denied CIPA §638.51
Date / key date
2026
Class period

A SDNY judge denied CNN's motion to dismiss a CIPA class action over third-party trackers on CNN.com. Court found Article III standing — aggregation of tracking data into comprehensive user profiles bears a close relationship to traditional privacy torts. Rejected CNN's argument that trackers collected only routing info rather than communication content.

Plaintiff winNews websiteData broker matchingAdvertising trackers
Case details →
Pending · Health / Media

Maghoney v. Dotdash Meredith (VeryWellHealth)

N.D. California
Active litigation — pre-discovery CIPA §631
Date / key date
2025
Class period

Plaintiff alleges he visited VeryWellHealth.com in Dec 2024, entering search terms for STI symptoms/treatment, and that the site's advertising platform intercepted and transmitted this sensitive health data — search terms, navigation history, device metadata — to third-party advertisers in real time without consent. Highlights risk for health/wellness sites with search functionality.

PendingHealth search termsAd platform tracking
Settlement · Gaming / Media

Shah v. Fandom Inc. (GameSpot)

N.D. California
Settled CIPA §638.51
Date / key date
2025-12-01
Class period

Fandom agreed to a $1.2M settlement over GameSpot deploying unauthorized third-party trackers without prior consent to track California visitors. Described by commentators as 'the blueprint for thousands of pending pixel lawsuits' — established that a consent banner dismissal without explicit Accept is not valid consent.

$1.2M SettlementGaming websitePen register trackersConsent blueprint
Plaintiff win · Retail / E-commerce

Camplisson v. Adidas America, Inc.

S.D. California
Survived — pen register theory CIPA §638.51
Date / key date
2025-11-18
Class period

Case survived on the §638.51 pen register theory. Court noted most cases in this and other districts recognise website-based trackers can plausibly constitute a pen register. Significant precedent for retail e-commerce sites using standard advertising pixels; demonstrates the theory's viability even as other courts reject it.

Plaintiff winMeta PixelTracking pixelsPen register
Case details →
Defendant win · Media / News

Khamooshi v. Politico LLC

N.D. California
Dismissed — lack of standing CIPA §638.51
Date / key date
2025-10-02
Class period

§638.51 pen register claim dismissed for lack of Article III standing. Collection of generic device/browser metadata — IP addresses, device type, browser version — did not constitute the 'embarrassing, invasive, or otherwise private' info needed for concrete injury. Popa v. Microsoft standing framework applied. Metadata alone is insufficient.

Defendant winBrowser metadataAnalytics trackersStanding
Plaintiff win · Retail / E-commerce

Mikulsky v. Bloomingdale's

Ninth Circuit
Reversed dismissal — proceeds CIPA §631
Date / key date
2025-06-20
Class period

Ninth Circuit reversed dismissal. Court found plaintiffs adequately alleged FullStory intercepted the 'contents' of communications — names, addresses, credit card info entered at checkout — while in transit, not merely post-transmission. Real-time interception satisfied by FullStory's keystroke and form capture. Now in discovery.

Plaintiff winFullStoryE-commerce checkoutReal-time interception
Case details →
Defendant win · Food / E-commerce

Thomas v. Papa John's International

Ninth Circuit
Dismissal affirmed CIPA §631
Date / key date
2025-06-18
Class period

Ninth Circuit affirmed dismissal. Papa John's was a party to its own visitors' communications — a party cannot eavesdrop on its own conversation. The direct party exception under §631 bars direct liability. But the court noted plaintiff hadn't pleaded aiding-and-abetting against FullStory specifically, leaving that avenue open — and plaintiffs have since pivoted to it.

Defendant winFullStoryRestaurant / E-commerceParty exceptionAiding-and-abetting
Pending · Travel / Transport

Washington v. Flixbus, Inc.

S.D. California
Motion to dismiss denied CIPA §631
Date / key date
2025-06-05
Class period

Motion to dismiss denied. Case proceeds on claims that Flixbus's website chat tool intercepted customer communications and transmitted them to a third-party vendor without disclosure or consent. Adds to a growing body where integrated chat tools with third-party backends create viable §631 exposure distinct from first-party chat.

PendingChat tool (third-party backend)Travel website
Defendant win · Financial services

Torres v. Prudential Financial, Inc.

N.D. California
Summary judgment for defendant CIPA §631
Date / key date
2025-04-17
Class period

Summary judgment for the defendant. Court held §631 requires evidence a party actually read or attempted to read communication contents while in transit — mere data capture during a session is insufficient. Session replay that reassembles data only after transmission does not satisfy real-time interception. One of the most significant defendant-friendly rulings — narrows §631 liability substantially.

Defendant winSession replay softwareFinancial portalReal-time interception
Defendant win · Automotive / E-commerce

Rodriguez v. Autotrader.com, Inc.

C.D. California
Dismissed with prejudice — standing CIPA §638.51
Date / key date
2025-04-04
Class period

Dismissed with prejudice for lack of standing. Court was skeptical of tester-style pleading — a plaintiff who visits specifically to document a CIPA violation cannot claim injury when her expectations were met. Courts increasingly scrutinise whether serial plaintiffs suffered genuine harm, applying stricter Article III analysis. Significant for serial plaintiff cases.

Defendant winAutomotive marketplaceStandingSerial plaintiff
Pending · Health / Femtech

Frasco v. Flo Health, Inc.

N.D. California
Class certification granted CIPA §632
Date / key date
2025
Class period

Class action certified in 2025. A California subclass certified for claims under §632 (confidential communications). Involves a health-tracking app that allegedly shared sensitive reproductive health data with advertising platforms. One of the first CIPA class certifications in femtech — may set precedent for health app developers and their analytics integrations.

PendingHealth tracking appMeta PixelAnalytics§632
Case details →
Plaintiff win · Retail / E-commerce

Saleh v. Nike, Inc.

C.D. California
Survived dismissal — in discovery CIPA §631
Date / key date
2024
Class period

Court found FullStory could be characterised as a third-party eavesdropper rather than a tool of Nike. Focus was on the real-time nature of the data capture — FullStory receiving keystrokes and interactions as they occur, not after the session. Survived dismissal on the aiding-and-abetting theory under §631.

Plaintiff winFullStoryE-commerceAiding-and-abetting
Case details →
Plaintiff win · Sports / Media

Heerde v. Learfield Communications

C.D. California
Survived dismissal CIPA §631
Date / key date
2024
Class period

Court found a viable CIPA theory where search terms typed on a university athletics site were transmitted in real time to third-party vendors via analytics scripts. The real-time transmission of content (the search query) distinguished it from passive data collection. Survived on aiding-and-abetting. Significant for sites with search + analytics.

Plaintiff winSearch terms capturedAnalytics pixelsAiding-and-abetting
Pending · Ad tech / Data broker

Greenley v. Kochava, Inc.

S.D. California
Ongoing — leading precedent CIPA §638.51
Date / key date
2023
Class period

Foundational case establishing that an SDK embedded in apps could constitute a pen register under CIPA. Court rejected the argument that an SDK was categorically not a pen register. Opened the door to claims against advertising SDKs, fingerprinting, and cross-site tracking. Still considered the most important §638.51 precedent in website tracking litigation.

PendingMobile SDKDevice fingerprintingPen registerLeading precedent
Case details →
Defendant win · Health / SaaS

Graham v. Noom, Inc.

N.D. California
Dismissed — party exception CIPA §631
Date / key date
2024
Class period

Court found FullStory was a direct party to communications when recording sessions, not a third-party interceptor. As a service provider integrated into Noom's infrastructure and operating as Noom's agent, the party exception applied. Illustrates how vendor configuration and contractual relationship significantly affect the outcome.

Defendant winFullStoryHealth / wellness appParty exception
Defendant win · Retail / E-commerce

Licea v. Old Navy (Gap Inc.)

C.D. California
Dismissed — party exception CIPA §631
Date / key date
2024
Class period

Court ruled Old Navy could not eavesdrop on its own chat communications — it was a party, not a third-party interceptor. Live chat deployed by the website owner itself falls under the party exception. Important for first-party chat/customer service tools. Plaintiffs have since focused on third-party chat providers (Intercom, Drift, Zendesk) to avoid this exception.

Defendant winLive chat widgetRetail websiteParty exception
Defendant win · Retail / E-commerce

Byars v. Hot Topic, Inc.

C.D. California
Dismissed — party exception CIPA §631
Date / key date
2024
Class period

The chat tool was found to be an extension of the business itself — not an independent third-party interceptor — so the party exception applied. Lawsuit dismissed. Reinforces that integrated chat tools operating as the business's own agent do not create §631 liability, unlike third-party vendors that independently receive and process communication data.

Defendant winChat toolParty exception
Defendant win · Health / Consumer

Sisti v. Bosley, Inc.

C.D. California
Dismissed with prejudice CIPA §631
Date / key date
2026-05-01
Class period

Complete dismissal with prejudice. Widely cited by Fisher Phillips and others as the definitive template for defensible consent configuration: clickwrap requiring affirmative acceptance before access. The counter-example to Nourish's browsewrap — Bosley's affirmative clickwrap defeated the claims entirely.

Defendant winClickwrapConsent templateDismissed with prejudice
Settlement · Healthcare

In re Advocate Aurora Health Pixel Litigation

U.S. District Court, E.D. Wisconsin
Settled — final approval Federal Wiretap Act
Date / key date
Final approval Jul 10, 2024
Class period
Oct 24, 2017 – Oct 22, 2022

Paid $12.25M to settle a consolidated class action covering ~2.5M patients — one of the largest exposed populations in the healthcare pixel wave; the litigation began with the health system’s own self-reported breach to HHS.

$12.22M SettlementHealthcareMeta PixelGoogle AnalyticsMyChart
Case details →
Settlement · Healthcare

John Doe & Jane Doe v. Partners Healthcare System, Inc. (Mass General Brigham)

Suffolk Superior Court, MA (BLS) — No. 1984CV01651-BLS1
Settled Common-law invasion of privacy
Date / key date
Final approval Jan 20, 2022
Class period
May 23, 2016 – Jul 31, 2021

The $18.4M settlement that helped start the healthcare pixel wave — an eight-figure payout over cookies and pixels on public hospital websites, finalised in early 2022, before the wave.

$18.4M SettlementHealthcareinvasion of privacyMetaGoogle
Case details →
Settlement · Healthcare

Mohr, et al. v. The Trustees of the University of Pennsylvania (Penn Medicine)

Court of Common Pleas, Philadelphia County — No. 230102149
Settlement pending — final approval (Nov 2026) Pennsylvania WESCA, 18 Pa. Cons. Stat.…
Date / key date
Final Approval Hearing Nov 12, 2026
Class period
Jan 23, 2021 – Jan 23, 2023

Up-to-$9.5M settlement over Meta and Google pixels on the myPennMedicine patient portal — brought under Pennsylvania’s WESCA wiretap law, not California’s CIPA. Preliminary approval; final hearing Nov 12, 2026.

$9.5M SettlementHealthcareWESCAPennsylvaniapatient portal
Case details →
Settlement · Telehealth / Mental health

In the Matter of BetterHelp, Inc. (FTC action)

U.S. Federal Trade Commission (administrative) — File No. 2023169
FTC settlement — final (2023) Section 5 of the FTC Act
Date / key date
Order final Jul 2023; refunds to ~800k began 2024
Class period
~2017 – 2020 (conduct)

The online-therapy firm paid $7.8M to settle FTC charges that it shared users’ mental-health intake data with Facebook, Snapchat and others for advertising; the first FTC action to return funds for health data, plus a ban on sharing health data for ads.

$7.8M SettlementFTCSection 5mental healthtelehealth
Case details →
Settlement · Pharmacy / Consumer health

GoodRx — FTC action + Doe v. GoodRx Holdings, Inc. (class action)

U.S. FTC (via DOJ) + N.D. Cal. — No. 3:23-cv-00501
FTC settled ($1.5M); class action denied approval FTC Health Breach Notification Rule + …
Date / key date
FTC final Feb 2023; class-action approval denied Jan 16, 2026
Class period

Two matters: a landmark $1.5M FTC action (first-ever Health Breach Notification Rule enforcement, final) and a separate private class action the court has twice declined to approve ($25M→$32M proposals). Prescription data shared via Meta, Google, Criteo pixels and SDKs.

$1.5M SettlementFTCHBNRSection 5class action
Case details →
Stay current

Get notified when a new CIPA case is filed

This tracker updates as courts rule. Get the important changes — new filings, dismissals, settlements — in your inbox, so you know when the risk shifts.

Free · the case-law digest, not marketing spam · unsubscribe any time

For agencies & web studios

Your clients are already Googling this page. Here's how to serve it — and bill for it.

Every business owner reading this tracker is a site you might build or manage. The exposure on this page is your clients' exposure — and CIPA remediation, monitoring, and reporting is a productizable, recurring service. Three ways to start:

01 — Audit

Client-portfolio risk report

Scan every client domain you manage and get a per-site, white-label-ready CIPA risk report — see which client sites fire trackers before consent, in one pass.

Run a portfolio scan →
02 — Partner

Agency program

Manage 5+ client sites? Multi-domain plans, one dashboard for your whole book, white-label options, and margin on every site you protect.

See the agency program →
03 — Stay current

CIPA Case Watch for agencies

The rulings that change your clients' risk, sent monthly — built for the person who has to keep 10+ sites defensible, not just one.

Get the agency digest →
Why agencies: one client letter means the whole portfolio shares the exposure — and the remediation retainer.
Context · pending legislation

Watching SB 690. A pending California bill, SB 690, would — if passed — remove the private right of action for CIPA's pen-register / trap-and-trace provisions (§§638.50–.51), leaving enforcement to the Attorney General and leaving §631 wiretapping and §632 recording claims intact. It would also apply retroactively to certain pending §638.51 claims within a two-year window tied to a Jan 1, 2027 operative date. As of August 2026 SB 690 has not passed — it sits on the Assembly Appropriations suspense file with an Aug 31, 2026 deadline and could still fail. Cases on this tracker remain live; we'll update if the bill's status changes. This is general information, not legal advice.

⚠️Legal Disclaimer

ConsentPixel is not a legal source of reference and does not provide legal advice. This tracker is compiled from publicly available court records and legal reporting for general informational purposes only. Case details, outcomes, and figures may change over time and should be independently verified. Nothing on this page creates an attorney–client relationship. For advice about your specific situation, please consult a qualified attorney.

For agencies

CIPA Case Watch — agency digest

The rulings that change client risk, monthly — for the person keeping 10+ sites defensible. Tell us how many client sites you manage and we'll tailor it.

The site-count field self-segments your list — 5+ routes to the agency-plan nurture track.

FAQ

CIPA lawsuit tracker — frequently asked questions

Common questions about CIPA website lawsuits, settlements, and the technologies driving them.

Which companies have been sued under CIPA?

Defendants span retail and e-commerce, media and streaming, healthcare, finance, and technology — from national brands to mid-market websites. Every tracked defendant is listed above with its court, the technology implicated, and current case status.

How much are CIPA settlements and statutory damages?

Under California Penal Code §637.2, CIPA allows statutory damages of $5,000 per violation, or three times actual damages — whichever is greater. Disclosed settlements across the cases on this tracker exceed $153.4M. Actual outcomes vary widely by case, class size, and the technology involved.

What is CIPA (the California Invasion of Privacy Act)?

CIPA is a California wiretapping and eavesdropping statute (California Penal Code §630 et seq.). In website litigation, plaintiffs argue that trackers which record or transmit a visitor's interactions without prior consent amount to unlawful "wiretapping" or use of a "pen register." The two sections most cited against websites are §631 and §638.51.

What is the difference between CIPA §631 and §638.51?

§631 is CIPA's wiretapping provision — the theory that a tracker intercepts the contents of a visitor's communication. §638.51 concerns "pen registers" and "trap and trace" devices — the theory that a tracker captures identifying metadata about a visitor. Many recent website cases plead both, and courts have split on each. See our CIPA §631 explainer for the detail.

Does CIPA only apply in California?

CIPA is a California statute, but claims can reach websites outside California when California residents are affected. Separately, more than two dozen US states have their own wiretapping or privacy laws, and plaintiffs are testing similar theories under them. This is general information, not legal advice.

What is a CIPA demand letter?

A CIPA demand letter is a pre-litigation notice from a plaintiff's firm alleging that a website's trackers violate CIPA, inviting settlement before a lawsuit is filed. A large share of CIPA activity begins this way; the tracker above focuses on filed cases and their outcomes.

How can I tell if my website is at risk of a CIPA claim?

CIPA website claims turn on trackers firing before a visitor consents. The practical check is to see which third-party trackers — session replay, ad pixels, chat widgets — load on your site pre-consent. You can run a free scan to see exactly what fires before consent on your pages.

Are these CIPA cases settlements or active lawsuits?

The tracker includes a mix: finalized settlements, plaintiff and defendant wins on motions, and active/pending cases. Use the filters above — Settlements, Plaintiff wins, Defendant wins, Pending — to view each category.

How often is this CIPA lawsuit tracker updated?

The tracker is updated monthly from public court records. New settlements and rulings are added as they're reported, and each entry reflects the latest known status.

Not legal advice. This tracker and FAQ aggregate publicly available court-record information for general educational purposes only and do not constitute legal advice. Case details change; verify against primary sources and consult a qualified attorney about your specific situation.

Scroll to Top