Newly filed · Retail / Beauty
Hartigan v. Ulta Salon, Cosmetics & Fragrance Inc.
S.D. California — No. 3:26-cv-04007-JO-VET
Newly filed — allegations unproven
CIPA §631 · ECPA
Date / Key Date
Filed Aug 11, 2026 · Jun 4, 2024 – date of judgment
Class Period
Jun 4, 2024 – Aug 11, 2026
Proposed class action alleging Ulta's website deployed the Meta Pixel and related trackers that intercepted the contents of visitors' communications — full URL strings and the specific products and content viewed — and transmitted them to Meta and other third parties without consent. The complaint stacks CIPA §631, the ECPA, and California constitutional privacy and intrusion-upon-seclusion claims, and alleges Ulta also aided Meta's interception. Filed by plaintiff Raeanon Hartigan for a class of California website visitors. Notably brought by Swigart Law Group and Shay Legal — firms among the most active CIPA filers — underscoring that the pixel wave has moved firmly into mainstream retail and beauty. Newly filed and unproven; Ulta has not been found liable.
Meta Pixel
Retail / beauty
§631 "contents" theory
ECPA
Settlement + Verdict · Health / Femtech
Frasco v. Flo Health, Inc.
N.D. California — No. 3:21-cv-00757-JD (Judge James Donato)
$59.5M settlement + landmark Meta jury verdict
CIPA §632
Date / Key Date
Verdict Aug 1, 2025 · final hearing Oct 29, 2026
Class Period
Nov 1, 2016 – Feb 28, 2019
The period-tracker case produced two outcomes. Google, Flo and Flurry settled for a combined $59.5M (Google $48M, Flo $8M, Flurry $3.5M). Meta refused and went to trial — and a unanimous San Francisco jury found it liable under §632 for capturing confidential reproductive-health data via its SDK without consent, the first major CIPA jury verdict in history. The court denied Meta's post-trial motions; damages not yet set.
$59.5M Settlement
Femtech
SDK tracking
Meta jury verdict
§632
Case details →Settlement · Healthcare
Doe v. Wellstar Health System, Inc.
N.D. Georgia
Settlement — awaiting approval
Pixel · consent & disclosure
Date / Key Date
Settlement motion filed Jul 22, 2026
Class Period
Feb 19, 2020 – Jul 22, 2026
$4.25M settlement covering ~870,000 patients over Meta Pixel and Google trackers on Wellstar.org and the Wellstar MyChart patient portal. A judge allowed some claims to proceed, finding Wellstar allegedly went "beyond the scope of patients' permission" — receiving enhanced advertising services rather than cash for the data. Settled without admitting wrongdoing.
$4.25M Settlement
Healthcare portal
MyChart
Meta Pixel
Google
Case details →Settlement · Healthcare
McCulley, et al. v. Banner Health
Weld County, Colorado — No. 2026CV30182
Settlement — claims open (Sep 5, 2026)
Pixel · consent & disclosure
Date / Key Date
Claim deadline Sep 5, 2026 · final approval Sep 10, 2026
Class Period
Jun 1, 2020 – Nov 22, 2023
Settlement covering roughly 1,028,000 people who logged into a Banner patient account (formerly MyBanner), over tracking tools alleged to have disclosed personal and health information to Meta and Google. Relief is disclosed per class member — a $20 payment plus a year of privacy monitoring — rather than as a single fund total; aggregate cost scales with the ~1M-person class.
$20 + 1 yr monitoring / member
Healthcare portal
~1.03M class
Meta
Google
Settlement · Behavioral health
Strong v. LifeStance Health Group, Inc.
D. Arizona — No. 2:23-cv-00682
Settlement — claims open (Sep 29, 2026)
Pixel · consent & disclosure
Date / Key Date
Prelim. approval May 12, 2026 · claims by Sep 29, 2026
Class Period
Mar 1, 2020 – Apr 30, 2023
Non-reversionary $3,027,874.44 settlement over third-party tracking tools on LifeStance's website and online booking tool, alleged to have disclosed patient information to Meta and Google. Notable for the sensitivity — LifeStance is a major outpatient mental-health provider, and the data allegedly signaled treatment for conditions like depression, PTSD and bipolar disorder. Two subclasses; settled without admitting wrongdoing.
$3.03M Settlement
Behavioral health
Booking tool
Meta
Google
Newly filed · Automotive
Conner v. Toyota Motor Corporation
L.A. County Superior Court
Newly filed — allegations unproven
CIPA §638.51
Date / Key Date
Filed Jul 15, 2026
Proposed class action alleging that after the plaintiff rejected all third-party cookies on Toyota.com, the site kept tracking her using fingerprinting — which doesn't depend on cookies — then shared data for cross-device advertising. Framed as an "outrageous privacy 'bait and switch.'" The theory targets tracking that continues after a visitor opts out. Newly filed and unproven; Toyota has not been found liable.
Fingerprinting
Tracking after "decline"
Trap & trace
Cross-device
Case details →Newly filed · Sports / Media
Kimmons v. NFL Enterprises LLC
Alameda County Superior Court — No. 26CV197596
Newly filed — allegations unproven
CIPA §631
Date / Key Date
Filed Jul 6, 2026
Forensic testing cited in the complaint alleges NFL.com ran 182 third-party trackers before any consent choice and 186 after a visitor opted out — opting out didn't reduce the tracking. It also alleges a session recorder captured keystrokes typed into input fields (order and timing, whether or not submitted) — the §631 "contents" theory in its strongest form. Newly filed and unproven.
Session replay
186 after opt-out
Keystroke capture
Canvas fingerprinting
Case details →Settlement · Healthcare
Branson v. Concord Hospital
New Hampshire — No. 217-2024-CV-00295
Settled
NH Wiretap Statute
Date / Key Date
Settled 2026
$800,000 settlement over website tracking tools alleged to have disclosed patient information to third parties — brought under New Hampshire's wiretap statute, not California's CIPA. One of a growing set of tracking cases outside California, showing the pixel-tracking theory is portable across states' wiretap laws.
$800K Settlement
Healthcare
New Hampshire
State wiretap law
Settlement · Telehealth
Lucas v. Call-On-Doc
Will County, Illinois — No. 2026LA000403
Settlement — claims open (Aug 29, 2026)
Pixel · consent & disclosure
Date / Key Date
Claim deadline Aug 29, 2026
$1.8M settlement over third-party tracking tools on the Call-On-Doc telehealth platform alleged to have disclosed users' information without consent. California account holders and appointment bookers can claim up to $20 (no proof required). Another telehealth entry in the healthcare tracking wave.
$1.8M Settlement
Telehealth
Illinois
Up to $20 / claimant
Defendant win · Online gaming
Hughes v. DraftKings
C.D. California
Voluntarily dismissed by plaintiff
CIPA §631, §638.51
Date / Key Date
Dismissed mid-July 2026
The CIPA claim against DraftKings ended with the plaintiff voluntarily dismissing the case rather than pressing on. A modest data point rather than a precedent, but a reminder that not every CIPA claim survives contact with a prepared defendant — a rare defense-side outcome in a cycle dominated by verdicts and settlements.
Online gaming
Website tracking
Voluntary dismissal
Procedural · Demand-letter ecosystem
Vivek Shah v. Crain Communications, Inc. — vexatious-litigant order
C.D. California — No. 2:26-cv-03070-RGK-CTS (Judge R. Gary Klausner)
Pre-filing order — serial filer restricted
CIPA §631(a)
A federal court declared one of the most prolific individual CIPA filers a vexatious litigant, requiring him to obtain court permission before filing new CIPA or related digital-privacy suits in the district — citing ~29 proceedings since 2021 and seven near-identical §631(a) complaints in the prior seven months. Narrow: it binds one filer, one district, prospectively, and doesn't reach arbitration or decide the merits.
Vexatious litigant
Pre-filing order
Serial plaintiff
Demand letters
Case details →Settlement · Media / News
Mirmalek v. Los Angeles Times Communications LLC (Doe v. LA Times)
C.D. California
Settlement pending — final approval
CIPA §631, §638.51
The LA Times agreed to a $3.85M settlement over claims that tracking technologies on its
website and mobile app collected California visitors' information without consent between Jan 2023 and
Dec 2025. Valid claims by May 20, 2026 eligible for pro-rata cash. Final approval hearing held June 26, 2026 —
order pending.
Defendant win · Leadership consulting
Rounds v. Development Dimensions International, Inc.
C.D. California
Dismissed — no leave to amend
CIPA §638.51
Dismissed without leave to amend a claim that DDI's 6Sense data-broker SDK
(geolocation, device, browser-cookie data to de-anonymize visitors) was an illegal trap-and-trace device.
Judge Carter found cookies do not satisfy §638.51, since trap-and-trace covers signaling data identifying the
source of a communication, not routine web-tracking metadata. With no plausible violation, the out-of-state
defendant had no CA minimum contacts and personal jurisdiction failed.
Case details →Defendant win · Technology
Blaker v. NetScout Systems, Inc.
LA County Superior Court, Dept. 733
Demurrer sustained — no leave to amend
CIPA §638.51
The court held CIPA's pen register / trap-and-trace provisions reach telephone
communications only — not ordinary software on a commercial website. Treated as an issue of first impression;
leaned on statutory construction and §638.52's court-order process. Dismissal with prejudice gives
operators a clean rebuttal to the pen-register theory, though it leaves §631 wiretapping and pre-consent
timing theories untouched.
Case details →Plaintiff win · Financial services
Ingraham v. Capital One Financial Corp.
Federal Court
Significant claims survived
CIPA §631
Multiple claims survived where plaintiffs alleged transmission of highly sensitive data to
third parties: employment status, citizenship, bank account type, credit approval/denial outcomes, FICO
segments, income bands, names, emails, phones. Court distinguished routine browsing-data disputes due to the
extraordinary sensitivity. Reinforces that defendants face greater difficulty challenging standing when
sensitive financial data is disclosed.
Case details →Defendant win · Cryptocurrency / Finance
Ortiz v. Foris Dax, Inc. (Crypto.com)
Federal Court
Split — §631 dismissed, §638.51 survived
CIPA §631, §638.51
§631 wiretapping claim dismissed (plaintiffs failed to describe their actual website
activities). But the §638.51 pen register claim survived in one of the most comprehensive federal analyses yet
on whether CIPA's pen register provision reaches internet tracking — concluding it does, since CA adopted
a federal pen register definition Congress expanded to internet tracking in 2001. A strong federal endorsement
of the pen register theory.
Case details →Plaintiff win · Entertainment / Events
Garcia v. Anschutz Entertainment Group (AEG)
Federal Court
Split — ECPA dismissed, §638.51 survived
CIPA §638.51, ECPA
ECPA federal claim dismissed under the party exception. CIPA pen register claim survived
because AEG's third-party cookies activated immediately on landing — before the consent banner appeared
and before any opt-out existed. The court emphasized a banner shown after tracking has begun is only a
disclosure notice, not valid consent. A warning for orgs whose trackers fire before consent interaction.
Defendant win · Streaming / Media
Diaz v. Paramount Skydance (Pluto TV)
Federal Court
Dismissed — lack of Article III standing
CIPA §631, §638.51
Dismissed for lack of Article III standing. Court drew a sharp line between genuinely
sensitive data (medical, financial, personal communications) and routine behavioural metadata from
ad-targeting pixels on a free streaming platform. Vague allegations that pixels collected 'personal
information' were insufficient — plaintiffs must identify specific sensitive data actually disclosed.
Standing framework now cited across districts as a first-line defence for non-sensitive content sites.
Plaintiff win · Telehealth / Health & wellness
Podraza v. Nourish, Inc.
N.D. Illinois
Motion to dismiss denied — case proceeds
CIPA §631, ECPA
Both the ECPA wiretapping claim and the CIPA §631 claim survived dismissal. The problem was
consent architecture: unlike Bosley (clickwrap requiring affirmative acceptance before access), Nourish relied
on browsewrap — a buried notice users were deemed to accept by visiting. Courts are increasingly hostile to
browsewrap; the court found it inadequate. The ECPA claim survived via the HIPAA crime-tort exception —
significant for health/wellness sites. Fisher Phillips called it 'the most straightforwardly bad decision
in the set for businesses.' Takeaway: browsewrap is not defensible consent; affirmative clickwrap or an
enforced CMP is the standard.
Case details →Settlement · Beauty / service business
Cumor, Dunn v. European Wax Center, Inc.
13th Judicial Circuit, Hillsborough County, FL
Settlement pending — final approval
CIPA §631, ECPA, FSCA
European Wax Center agreed to a $5M settlement over waxcenter.com firing the Meta Pixel,
Attentive Mobile, LinkedIn and Snap tags on page load — before consent — transmitting booking-related data to
ad partners. Claims stacked CIPA §631, ECPA and Florida's FSCA. Class covers all US residents who visited
Jun 30 2023 – Apr 2 2026; browsing alone qualifies. Up to $10/claimant pro rata. Notable because the tracking
stack is the exact config on thousands of eCommerce/service sites.
Case details →Defendant win · Tax prep / Financial
In re Meta Pixel Tax Filing Cases
N.D. California
Class certification denied (MDL continues)
CIPA §631, §638.51, UCL
Plaintiffs sought to certify a far broader class at certification than the complaint
contemplated — from people whose tax-filing data appeared in Meta's systems to anyone whose any data
appeared. The court found this expansion raised individualized questions overwhelming common ones, defeating
predominance under Rule 23(b)(3). Underlying CIPA claims remain alive; the MDL continues without a certified
class for now. Standing must be proven by a preponderance at certification, not just pleading-level.
Case details →Settlement · Healthcare
In re Sutter Health Tracking Pixel Litigation
N.D. California
Settled
CIPA §631
Sutter Health agreed to a $21.5M settlement over deploying third-party tracking pixels on
its patient portal and marketing site, transmitting protected health information to vendors without patient
consent. Provides $90 per class member. Healthcare faces elevated CIPA exposure due to the sensitivity of
medical data.
Case details →Settlement · Healthcare
Doe v. Inova Health System
E.D. Virginia / C.D. California
Settled
CIPA §631
Inova Health settled for $3.1M over tracking pixels on its healthcare website transmitting
patient data to third-party vendors without HIPAA authorisation or consumer consent. Part of the broader
healthcare pixel litigation wave affecting hospitals and health systems nationwide.
Defendant win · Retail / E-commerce
Balabbo v. Wildflower Brands
LA County Superior Court
CIPA dismissed; privacy claim survives
CIPA §631, §638.51, Common law privacy
Mixed ruling. Court dismissed CIPA pen register and wiretapping claims, finding CCPA/CPRA
governs website data collection and the legislature could not have intended to criminalise under CIPA what it
regulated under CCPA. But a common law invasion of privacy claim survived — capture/transmission of credit
card and medical data could be a highly offensive intrusion. The CIPA/CCPA preemption argument gains traction.
Plaintiff win · Media / News
D'Antonio v. Cable News Network, Inc. (CNN)
S.D. New York
Motion to dismiss denied
CIPA §638.51
A SDNY judge denied CNN's motion to dismiss a CIPA class action over third-party
trackers on CNN.com. Court found Article III standing — aggregation of tracking data into comprehensive user
profiles bears a close relationship to traditional privacy torts. Rejected CNN's argument that trackers
collected only routing info rather than communication content.
Case details →Pending · Health / Media
Maghoney v. Dotdash Meredith (VeryWellHealth)
N.D. California
Active litigation — pre-discovery
CIPA §631
Plaintiff alleges he visited VeryWellHealth.com in Dec 2024, entering search terms for STI
symptoms/treatment, and that the site's advertising platform intercepted and transmitted this sensitive
health data — search terms, navigation history, device metadata — to third-party advertisers in real time
without consent. Highlights risk for health/wellness sites with search functionality.
Settlement · Gaming / Media
Shah v. Fandom Inc. (GameSpot)
N.D. California
Settled
CIPA §638.51
Fandom agreed to a $1.2M settlement over GameSpot deploying unauthorized third-party
trackers without prior consent to track California visitors. Described by commentators as 'the blueprint
for thousands of pending pixel lawsuits' — established that a consent banner dismissal without explicit
Accept is not valid consent.
Plaintiff win · Retail / E-commerce
Camplisson v. Adidas America, Inc.
S.D. California
Survived — pen register theory
CIPA §638.51
Case survived on the §638.51 pen register theory. Court noted most cases in this and other
districts recognise website-based trackers can plausibly constitute a pen register. Significant precedent for
retail e-commerce sites using standard advertising pixels; demonstrates the theory's viability even as
other courts reject it.
Case details →Defendant win · Media / News
Khamooshi v. Politico LLC
N.D. California
Dismissed — lack of standing
CIPA §638.51
§638.51 pen register claim dismissed for lack of Article III standing. Collection of generic
device/browser metadata — IP addresses, device type, browser version — did not constitute the
'embarrassing, invasive, or otherwise private' info needed for concrete injury. Popa v. Microsoft
standing framework applied. Metadata alone is insufficient.
Plaintiff win · Retail / E-commerce
Mikulsky v. Bloomingdale's
Ninth Circuit
Reversed dismissal — proceeds
CIPA §631
Ninth Circuit reversed dismissal. Court found plaintiffs adequately alleged FullStory
intercepted the 'contents' of communications — names, addresses, credit card info entered at
checkout — while in transit, not merely post-transmission. Real-time interception satisfied by
FullStory's keystroke and form capture. Now in discovery.
Case details →Defendant win · Food / E-commerce
Thomas v. Papa John's International
Ninth Circuit
Dismissal affirmed
CIPA §631
Ninth Circuit affirmed dismissal. Papa John's was a party to its own visitors'
communications — a party cannot eavesdrop on its own conversation. The direct party exception under §631 bars
direct liability. But the court noted plaintiff hadn't pleaded aiding-and-abetting against FullStory
specifically, leaving that avenue open — and plaintiffs have since pivoted to it.
Pending · Travel / Transport
Washington v. Flixbus, Inc.
S.D. California
Motion to dismiss denied
CIPA §631
Motion to dismiss denied. Case proceeds on claims that Flixbus's website chat tool
intercepted customer communications and transmitted them to a third-party vendor without disclosure or
consent. Adds to a growing body where integrated chat tools with third-party backends create viable §631
exposure distinct from first-party chat.
Defendant win · Financial services
Torres v. Prudential Financial, Inc.
N.D. California
Summary judgment for defendant
CIPA §631
Summary judgment for the defendant. Court held §631 requires evidence a party actually read
or attempted to read communication contents while in transit — mere data capture during a session is
insufficient. Session replay that reassembles data only after transmission does not satisfy real-time
interception. One of the most significant defendant-friendly rulings — narrows §631 liability substantially.
Defendant win · Automotive / E-commerce
Rodriguez v. Autotrader.com, Inc.
C.D. California
Dismissed with prejudice — standing
CIPA §638.51
Dismissed with prejudice for lack of standing. Court was skeptical of tester-style pleading
— a plaintiff who visits specifically to document a CIPA violation cannot claim injury when her expectations
were met. Courts increasingly scrutinise whether serial plaintiffs suffered genuine harm, applying stricter
Article III analysis. Significant for serial plaintiff cases.
Pending · Health / Femtech
Frasco v. Flo Health, Inc.
N.D. California
Class certification granted
CIPA §632
Class action certified in 2025. A California subclass certified for claims under §632
(confidential communications). Involves a health-tracking app that allegedly shared sensitive reproductive
health data with advertising platforms. One of the first CIPA class certifications in femtech — may set
precedent for health app developers and their analytics integrations.
Case details →Plaintiff win · Retail / E-commerce
Saleh v. Nike, Inc.
C.D. California
Survived dismissal — in discovery
CIPA §631
Court found FullStory could be characterised as a third-party eavesdropper rather than a
tool of Nike. Focus was on the real-time nature of the data capture — FullStory receiving keystrokes and
interactions as they occur, not after the session. Survived dismissal on the aiding-and-abetting theory under
§631.
Case details →Plaintiff win · Sports / Media
Heerde v. Learfield Communications
C.D. California
Survived dismissal
CIPA §631
Court found a viable CIPA theory where search terms typed on a university athletics site
were transmitted in real time to third-party vendors via analytics scripts. The real-time transmission of
content (the search query) distinguished it from passive data collection. Survived on aiding-and-abetting.
Significant for sites with search + analytics.
Pending · Ad tech / Data broker
Greenley v. Kochava, Inc.
S.D. California
Ongoing — leading precedent
CIPA §638.51
Foundational case establishing that an SDK embedded in apps could constitute a pen register
under CIPA. Court rejected the argument that an SDK was categorically not a pen register. Opened the door to
claims against advertising SDKs, fingerprinting, and cross-site tracking. Still considered the most important
§638.51 precedent in website tracking litigation.
Case details →Defendant win · Health / SaaS
Graham v. Noom, Inc.
N.D. California
Dismissed — party exception
CIPA §631
Court found FullStory was a direct party to communications when recording sessions, not a
third-party interceptor. As a service provider integrated into Noom's infrastructure and operating as
Noom's agent, the party exception applied. Illustrates how vendor configuration and contractual
relationship significantly affect the outcome.
Defendant win · Retail / E-commerce
Licea v. Old Navy (Gap Inc.)
C.D. California
Dismissed — party exception
CIPA §631
Court ruled Old Navy could not eavesdrop on its own chat communications — it was a party,
not a third-party interceptor. Live chat deployed by the website owner itself falls under the party exception.
Important for first-party chat/customer service tools. Plaintiffs have since focused on third-party chat
providers (Intercom, Drift, Zendesk) to avoid this exception.
Defendant win · Retail / E-commerce
Byars v. Hot Topic, Inc.
C.D. California
Dismissed — party exception
CIPA §631
The chat tool was found to be an extension of the business itself — not an independent
third-party interceptor — so the party exception applied. Lawsuit dismissed. Reinforces that integrated chat
tools operating as the business's own agent do not create §631 liability, unlike third-party vendors that
independently receive and process communication data.
Defendant win · Health / Consumer
Sisti v. Bosley, Inc.
C.D. California
Dismissed with prejudice
CIPA §631
Complete dismissal with prejudice. Widely cited by Fisher Phillips and others as the
definitive template for defensible consent configuration: clickwrap requiring affirmative acceptance before
access. The counter-example to Nourish's browsewrap — Bosley's affirmative clickwrap defeated the
claims entirely.
Settlement · Healthcare
In re Advocate Aurora Health Pixel Litigation
U.S. District Court, E.D. Wisconsin
Settled — final approval
Federal Wiretap Act
Paid $12.25M to settle a consolidated class action covering ~2.5M patients — one of the
largest exposed populations in the healthcare pixel wave; the litigation began with the health system’s own
self-reported breach to HHS.
Case details →Settlement · Healthcare
John Doe & Jane Doe v. Partners Healthcare System, Inc. (Mass General Brigham)
Suffolk Superior Court, MA (BLS) — No. 1984CV01651-BLS1
Settled
Common-law invasion of privacy
The $18.4M settlement that helped start the healthcare pixel wave — an eight-figure payout
over cookies and pixels on public hospital websites, finalised in early 2022, before the wave.
Case details →Settlement · Healthcare
Mohr, et al. v. The Trustees of the University of Pennsylvania (Penn Medicine)
Court of Common Pleas, Philadelphia County — No. 230102149
Settlement pending — final approval (Nov 2026)
Pennsylvania WESCA, 18 Pa. Cons. Stat.…
Up-to-$9.5M settlement over Meta and Google pixels on the myPennMedicine patient portal —
brought under Pennsylvania’s WESCA wiretap law, not California’s CIPA. Preliminary approval; final hearing Nov
12, 2026.
Case details →Settlement · Telehealth / Mental health
In the Matter of BetterHelp, Inc. (FTC action)
U.S. Federal Trade Commission (administrative) — File No. 2023169
FTC settlement — final (2023)
Section 5 of the FTC Act
The online-therapy firm paid $7.8M to settle FTC charges that it shared users’ mental-health
intake data with Facebook, Snapchat and others for advertising; the first FTC action to return funds for
health data, plus a ban on sharing health data for ads.
Case details →Settlement · Pharmacy / Consumer health
GoodRx — FTC action + Doe v. GoodRx Holdings, Inc. (class action)
U.S. FTC (via DOJ) + N.D. Cal. — No. 3:23-cv-00501
FTC settled ($1.5M); class action denied approval
FTC Health Breach Notification Rule + …
Two matters: a landmark $1.5M FTC action (first-ever Health Breach Notification Rule
enforcement, final) and a separate private class action the court has twice declined to approve ($25M→$32M
proposals). Prescription data shared via Meta, Google, Criteo pixels and SDKs.
Case details →