Penn Medicine Tracking Pixel Litigation
Penn Medicine agreed to a settlement of up to $9.5 million over Meta and Google tracking pixels on its myPennMedicine patient portal — and the claim wasn't brought under California's CIPA. It was brought under Pennsylvania's own wiretap statute. This case is the clearest proof yet that pixel-as-wiretap theory is not a California problem.
- Case
- Mohr, et al. v. The Trustees of the University of Pennsylvania (d/b/a Penn Medicine)
- Court
- Court of Common Pleas, Philadelphia County
- Case No.
- 230102149
- Legal theory
- Pennsylvania Wiretapping & Electronic Surveillance Control Act (WESCA), 18 Pa. Cons. Stat. § 5701 et seq.
- Class period
- Jan 23, 2021 – Jan 23, 2023 (myPennMedicine access, PA address on file)
- Class size
- ~756,723 individuals
- Tracking tech
- Meta & Google tracking pixels on the myPennMedicine patient portal
- Settlement
- Up to $9,500,000 — up to $15 per claimant
- Status (Jul 2026)
- Preliminary approval only (June 12, 2026). Final Approval Hearing set for Nov 12, 2026 — not yet finally approved.
- Defendant
- Penn Medicine — denies all allegations, no admission of wrongdoing
What the case is about
A group of plaintiffs led by Johnathon Mohr sued The Trustees of the University of Pennsylvania, which owns and operates the University of Pennsylvania Health System — Penn Medicine — alleging that it embedded third-party tracking pixels on the myPennMedicine patient portal and that those tools disclosed patients' personally identifiable information to third parties without consent.
The third parties named are the usual advertising and analytics infrastructure of the modern web: Meta (Facebook) and Google tracking pixels, along with other tracking, analytics, and advertising technologies. According to the complaint, the data collection also implicated LinkedIn, Snap, and TikTok/ByteDance. The mechanism is identical to dozens of other healthcare pixel cases: a marketing tag on a patient-facing page transmits, to an ad-tech company, the fact that a specific person interacted with a specific health system.
What distinguishes this case is not the technology. It's the law the plaintiffs used to attack it.
Most high-profile pixel cases are Californian, built on CIPA. Penn Medicine is in Philadelphia, and the claim was brought under the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) — Pennsylvania's own two-party-consent wiretap statute, 18 Pa. Cons. Stat. § 5701.
If your compliance mental model is "pixel-as-wiretap lawsuits are a California thing, and we're not in California," this case is the direct refutation. Pennsylvania is one of numerous states with an all-party (two-party) consent wiretap law, and plaintiffs' firms are now testing the same interception theory under each of them. The venue moved; the theory travelled with it.
The legal theory — a wiretap claim outside California
The operative complaint centres on a single, potent statute rather than the multi-count confidentiality stacks seen in some California cases. The core allegation:
- WESCA (18 Pa. Cons. Stat. § 5701 et seq.) — Pennsylvania's Wiretapping and Electronic Surveillance Control Act. The theory: by deploying the Meta and Google pixels on the patient portal, Penn Medicine intercepted the contents of patients' electronic communications and disclosed them to third parties, without the consent Pennsylvania's two-party-consent regime requires.
Why this is significant procedurally: the case has already survived an early merits test. After the matter was removed to federal court and then returned to the Court of Common Pleas, Penn Medicine filed Preliminary Objections — Pennsylvania's equivalent of a motion to dismiss — and on November 18, 2024, the court overruled them, allowing the WESCA theory to proceed. A wiretap-pixel claim clearing that bar under a state statute other than CIPA is precisely the precedent other plaintiffs' firms watch for.
The lesson for operators outside California is uncomfortable: the absence of CIPA in your state does not mean the absence of a wiretap theory. Pennsylvania, Florida, Washington, Massachusetts, Illinois and others have their own interception or privacy statutes, and the pixel fact pattern is portable across them.
The pixel-as-wiretap theory originated in California but does not depend on CIPA. Penn Medicine shows it succeeding past an early merits test under Pennsylvania's own statute.
Where it stands (as of July 2026)
This is the point that must be stated precisely, because it is easy to get wrong: this settlement is not final. It has received preliminary approval only.
- Settlement fund: Penn Medicine has agreed to pay up to a total of $9,500,000, covering class payments, notice and administration, attorneys' fees, and incentive awards. (Some press reports cite an "up to $9.25 million" figure; the official settlement site states an up-to-$9.5 million total.)
- Per-claimant payment: up to $15 for each Settlement Class Member who files a valid claim.
- Preliminary approval: June 12, 2026.
- Final Approval Hearing: scheduled for November 12, 2026, at 2:00 p.m. EST, via Zoom. Until the court rules at that hearing, the settlement is proposed, not final — and the date can move.
- Claim deadline: September 16, 2026. Exclusion/objection deadline: September 1, 2026.
- Class Counsel: Philip L. Fraietta and Alec M. Leslie of Bursor & Fisher, P.A., and Scott R. Drury of Drury Legal, LLC. Class Counsel may seek up to $3,700,000 in fees.
- Class representatives may seek incentive awards of up to $5,000 each (up to $2,500 for two of them), subject to court approval.
Penn Medicine denies all of the plaintiffs' claims and maintains it engaged in no wrongdoing, agreeing to settle to avoid the expense, burden, and uncertainty of continued litigation. No court has decided the merits.
The most quietly significant part of this settlement isn't the money — it's the prospective relief. Penn Medicine states it is not currently using the Meta pixel on pennmedicine.org, and under the settlement its Web Governance Committee will assess the use of analytics and advertising technologies on the site. For the next two years, Penn Medicine agrees it will not use analytics and advertising technologies on pennmedicine.org unless that committee determines the use is consistent with applicable law.
Read that plainly: a major health system has, in effect, agreed to route all website analytics and ad-tech through a governance gate for two years. When remediation looks like a moratorium, the cost of the underlying tags was never just the settlement fund — it was the marketing capability itself.
Would a plaintiff firm find pixels on your portal pages?
Penn Medicine's exposure sat on a patient-portal page. See which trackers fire before consent on your site, in about 10 seconds — including on login and account pages. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then a 14-day free trial, no credit card, from $8.99/mo
How Penn Medicine fits the 2026 landscape
This case is one node in a large, coordinated wave of healthcare pixel litigation. The macro context is stark: since 2023, US healthcare organisations have paid a reported $100M+ across roughly 19 analysed pixel cases, and the consolidated In re Meta Pixel Healthcare Litigation reportedly gathers dozens of hospital-system defendants. The Markup's 2022 investigation found the Meta Pixel on 33 of the 100 largest US health systems. Penn Medicine is not an outlier — it is a representative data point in a systemic pattern.
What Penn adds to that pattern specifically:
| Factor | Typical California pixel case | Penn Medicine (Mohr) |
|---|---|---|
| Governing law | CIPA (Cal. Penal Code § 631) | WESCA (18 Pa.C.S. § 5701) |
| Venue | California | Pennsylvania |
| Surface at issue | Public or portal pages | myPennMedicine patient portal |
| Class size | Varies | ~756,723 |
| Early merits test | Motion to dismiss | Preliminary Objections overruled (Nov 2024) |
| Status | Varies | Preliminary approval; final hearing Nov 2026 |
Why this case matters for website operators
First: the wiretap theory is not California-specific. This is the generalisable lesson. Operators outside California often assume pixel-as-wiretap litigation can't reach them. Penn Medicine — brought under Pennsylvania's WESCA, surviving early objections — shows the same interception theory being deployed under a different state's statute. All-party-consent states each provide a potential vehicle.
Second: patient portals are a top-risk surface. As with Sutter Health, the exposure attached to a patient-portal page. A page that reveals someone is a patient of a specific provider carries the same context-sensitivity whether it sits behind CIPA or WESCA. The tags on it are the risk.
Third: the class runs back years. The class period begins in January 2021, and the conduct alleged predates most organisations' awareness of pixel litigation. Tags installed and forgotten become the basis of a present-day claim across three-quarters of a million people.
Fourth: remediation can cost more than the settlement. The two-year governance restriction on pennmedicine.org's analytics and ad tech is a real operational cost — the kind of constraint that outlasts the cheque.
What this means for your site
The failure pattern here is preventable with technical controls, not legal ones:
- Don't assume your state is safe. If you operate outside California, identify whether your state has an all-party-consent wiretap or privacy statute. Many do, and the pixel theory is being tested under them. The safe posture is the same everywhere.
- Treat portal and login pages as sensitive surfaces. Any page whose loading implies a status — patient, member, applicant — should carry no third-party marketing tags before consent.
- Block before consent, everywhere. Meta and Google pixels, and similar tools, should not fire until the visitor affirmatively agrees. The alleged interception only happens if the tag loads.
- Inventory inherited tags. A class period starting in 2021 means tags added years ago — often by people no longer at the organisation — are the live risk. You cannot control a tracker you don't know is running.
- Keep an auditable consent log. Timestamped proof of affirmative consent is the record that shortens a two-party-consent dispute.
ConsentPixel — Privacy · Verified blocks Meta, Google, and other third-party trackers at the browser level until the visitor consents — on every page, including portal and login screens — and logs each decision. It also surfaces the tags you inherited but never inventoried, which is where cases like this begin.
Frequently asked questions
What is the Penn Medicine tracking pixel lawsuit about?
It is a class action, Mohr, et al. v. The Trustees of the University of Pennsylvania (d/b/a Penn Medicine), Case No. 230102149, in the Court of Common Pleas of Philadelphia County. The plaintiffs allege that Penn Medicine deployed Meta and Google tracking pixels and other analytics and advertising technologies on the myPennMedicine patient portal, and that those tools disclosed patients' personally identifiable information to third parties without consent, in violation of the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa. Cons. Stat. § 5701 et seq. Penn Medicine denies all allegations and maintains it did nothing wrong.
How much is the Penn Medicine settlement, and is it final?
Penn Medicine has agreed to pay up to a total of $9,500,000, with each class member who files a valid claim receiving a cash payment of up to $15. Importantly, the settlement is not yet final. It received preliminary approval on June 12, 2026, and the Final Approval Hearing is scheduled for November 12, 2026, at 2:00 p.m. EST via Zoom. Until the court rules at that hearing, the settlement remains proposed, and the hearing date can be postponed. Some press reports cite an "up to $9.25 million" figure, but the official settlement site states an up-to-$9.5 million total.
What law did the Penn Medicine case use — is this a CIPA case?
No, it is not a CIPA case. Unlike the many California pixel lawsuits brought under the California Invasion of Privacy Act, the Penn Medicine claim was brought under Pennsylvania's own wiretap statute — the Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa. Cons. Stat. § 5701 et seq. Pennsylvania is an all-party (two-party) consent state, and the theory is that the tracking pixels intercepted patients' communications without the required consent. This is significant because it shows the pixel-as-wiretap theory is not confined to California; it can be pursued under other states' interception statutes. The Pennsylvania court overruled Penn Medicine's Preliminary Objections in November 2024, allowing the claim to proceed.
Who is included in the Penn Medicine settlement class?
The Settlement Class is defined as all persons who, between January 23, 2021, and January 23, 2023, accessed the myPennMedicine patient portal and had a Pennsylvania address on file at the time of access. That class is estimated at approximately 756,723 individuals. Class members who wish to receive a payment must submit a valid claim form by the September 16, 2026 deadline; the exclusion and objection deadline is September 1, 2026. This is a summary of the settlement notice, not legal advice — class members should review the official settlement site for their specific options.
What is Penn Medicine changing about its website?
The settlement includes prospective (non-monetary) relief. Penn Medicine states it is not currently using the Meta pixel on pennmedicine.org, and under the settlement its Web Governance Committee will assess the implementation and use of analytics and advertising technologies on the website. While continuing to deny liability, Penn Medicine agreed that for the next two years it will not use analytics and advertising technologies on pennmedicine.org unless the Web Governance Committee determines that such use is consistent with applicable law. In practical terms, that routes website analytics and ad tech through a governance review for two years.
What should my website do to avoid a claim like this?
Treat any page whose mere loading implies a private status — patient portals, login pages, account pages — as a sensitive surface that carries no third-party marketing tags before consent. Block Meta, Google, and similar trackers until the visitor affirmatively agrees, audit tags you may have inherited years ago, and keep a timestamped consent log. Crucially, don't assume you're safe because you're outside California: many states have their own all-party-consent wiretap statutes, and the same pixel theory is being tested under them, as Penn Medicine shows. This is general information, not legal advice.
Related cases & reading
Sources
- Official settlement website, UPHSPixelSettlement.com (administered by Epiq) — Mohr, et al. v. The Trustees of the University of Pennsylvania, No. 230102149 (Phila. Cnty. Ct. Com. Pl.); FAQ, class definition, monetary and prospective relief, and hearing/deadline dates.
- Settlement Agreement (fully executed 4-7-26), via UPHSPixelSettlement.com / ClassAction.org — release terms, class representatives, and procedural history (removal, remand, Preliminary Objections overruled Nov 18, 2024).
- ClassAction.org, "Up to $9.25M Penn Medicine Settlement Resolves Lawsuit Over Alleged Disclosure of Patient Info" (July 2026).
- Class notice and long-form notice (LFN), UPHSPixelSettlement.com — class size and incentive-award terms.