Podraza v. Nourish, Inc.
A federal court let both a CIPA §631 wiretap claim and a federal Wiretap Act claim survive dismissal against a telehealth provider — because the site relied on browsewrap consent that the court found inadequate. It's one of 2026's clearest warnings that a passive "notice on the page" is not consent.
What the case is about
In August 2025, three plaintiffs — Arissa Podraza, Jessica Keller, and Susan Colby — filed a proposed class action against Nourish, Inc., a telehealth and nutrition-care provider, on behalf of an estimated class of more than 10,000 patients. The core allegation is one that has become the template for the 2026 litigation wave: that Nourish embedded third-party tracking technology on its website that transmitted visitors' sensitive health information to Google without consent.
What sets Podraza apart from the generic "pixel on a retail site" case is the sensitivity of the data and the nature of the defendant. This isn't a shoe store's Meta Pixel firing on a product page. It's a healthcare provider whose visitors are, by definition, disclosing health-related information — and the complaint alleges that information flowed to a third-party advertising ecosystem. That combination is exactly the fact pattern courts treat most seriously, and it is why the case survived where many browsing-metadata cases have failed.
The plaintiffs brought claims under the federal Electronic Communications Privacy Act (ECPA / Wiretap Act), the California Invasion of Privacy Act (CIPA) §631, and negligence, among others. Notably, the court did trim the complaint — several privacy and contract theories were dismissed, and the judge criticised the plaintiffs for filing what he called a "press release complaint." But on the two claims that matter most for website operators — wiretapping and CIPA — the case moves forward.
The legal theory — and why consent decided it
CIPA §631(a) prohibits reading, or attempting to read, the contents of a communication in transit without the consent of all parties. The plaintiffs' theory is the familiar one: when a website loads a third-party tracker, that tool allegedly intercepts the contents of the visitor's communication with the site — here, health-related interactions — and routes them to a third party (Google) that was not a party to the conversation. Because California is an all-party consent state, that interception is unlawful unless every party, including the visitor, consented.
So the entire case turns on one question: did the visitors consent? Nourish argued they did — through the notice on its website. And this is where the ruling becomes essential reading, because the court's answer draws the single most important line in modern tracking litigation: the difference between browsewrap and clickwrap.
Browsewrap: terms are posted somewhere on the site (often a footer link), and users are "deemed" to accept them merely by using the site. No action is required. Courts increasingly find this does not establish consent.
Clickwrap: the user must take an affirmative action — ticking a box or clicking "I agree" — before proceeding. This is far more defensible because the user demonstrably assented.
Nourish relied on browsewrap. The court found that inadequate to establish the all-party consent CIPA requires, and refused to dismiss on that basis. As Fisher Phillips summarised it, this is what makes Podraza "the most straightforwardly bad decision in the set for businesses" — the court allowed both claims to survive without the limiting factors that let other defendants distinguish their wins.
The ruling also navigated the HIPAA crime-tort exception in a way that allowed the federal wiretap claim to proceed — a point of particular concern for any healthcare or health-adjacent business, because it signals that the presence of health data can strengthen, rather than complicate, a plaintiff's wiretap theory.
Where it stands (as of July 2026)
On April 20, 2026, the court ruled on Nourish's motion to dismiss. The outcome was mixed on paper but decisively unfavourable for the defendant on the claims that carry the litigation:
- Federal Wiretap Act (ECPA) claim — survives. The court declined to dismiss, navigating the HIPAA crime-tort exception in the plaintiffs' favour.
- CIPA §631 claim — survives. The inadequate browsewrap consent meant the court would not dismiss the all-party-consent theory at the pleading stage.
- Several other privacy and contract claims — dismissed. The court trimmed the complaint and criticised its "press release" framing.
With the core claims intact, the case proceeds past the pleading stage — the point at which most defendants hope to end these lawsuits. Status is stated as of publication; consult the docket (3:25-cv-50356) for the latest.
How Podraza fits the 2026 landscape
2026's CIPA rulings have been famously split. Many cases are dismissed at the threshold because plaintiffs allege only generic browsing metadata — courts increasingly demand specific, sensitive data before finding a concrete injury (as in Ortiz v. Crypto.com, where the wiretap claim failed for lack of specificity). Others reject the pen-register theory outright (as in Rounds v. DDI).
Podraza lands on the opposite side of that split — and shows exactly which factors push a case there:
| Factor | Cases that get dismissed | Podraza v. Nourish |
|---|---|---|
| Data sensitivity | Generic browsing metadata | Sensitive health information |
| Injury pleaded | Vague "personal information" | Specific health data to Google |
| Consent architecture | Clickwrap / affirmative accept | Browsewrap — found inadequate |
| Defendant type | Retail / general content | Telehealth provider |
| Result | Dismissed, often w/ prejudice | Claims survive — proceeds |
The pattern is unmistakable: sensitive data + weak consent = a case that survives. If your site handles anything health-adjacent and relies on a passive notice, you are on the wrong side of this line.
Why this case matters for website operators
Every CIPA case teaches one lesson especially clearly. Podraza's is about consent architecture. It's not enough to have a privacy notice or a cookie policy somewhere on the page. The court drew a bright line: consent that a user is merely "deemed" to give by visiting is not the affirmative, all-party consent CIPA demands. A banner nobody has to interact with — or worse, a footer link — is browsewrap dressed up.
The second lesson is about timing and sensitivity. Nourish is a telehealth provider, so the data at issue was inherently sensitive, and the trackers allegedly fired without any affirmative gate. That is the highest-risk configuration in the entire CIPA landscape: sensitive data, third-party recipient, no real consent. Healthcare, wellness, mental-health, and even fitness or nutrition sites should read this case as directed squarely at them.
What this means for your site
The good news is that the failure in Podraza is entirely preventable, and the fix is technical, not legal. The court punished a passive notice paired with trackers that fired anyway. The defensible posture is the mirror image:
- Block first, ask second. Non-essential trackers — analytics, ad pixels, session replay — should not fire until the visitor makes an affirmative choice. This is the single most important control, and it's exactly what browsewrap lacks.
- Require affirmative consent (clickwrap, not browsewrap). The visitor must do something — click Accept — before non-essential tracking begins. "Deemed" consent is the failure mode this case punishes.
- Treat health-adjacent data as radioactive. If your site touches health, wellness, or medical topics, assume the strictest scrutiny and never let third-party tools receive that data pre-consent.
- Keep an auditable consent log. Timestamped proof of each visitor's affirmative choice is your evidence that you had real, all-party consent — the thing Nourish couldn't show.
ConsentPixel — Privacy · Verified is built for exactly this: it blocks third-party trackers at the browser level until the visitor affirmatively consents, turning the browsewrap failure mode into a defensible clickwrap posture, and logging every decision. The gap that kept Podraza alive is the gap it's designed to close.
Worried your site has this exposure?
Scan free in about 10 seconds to see every tracker firing on your site — including the ones loading before any affirmative consent, the exact gap this ruling punishes. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What is Podraza v. Nourish about?
What did the court decide?
Why did the CIPA and wiretap claims survive?
What's the difference between browsewrap and clickwrap consent?
How can my website avoid this outcome?
Sources
- Podraza et al v. Nourish, Inc., No. 3:25-cv-50356 (N.D. Ill.) — docket via CourtListener / RECAP and Justia Dockets.
- Law.com Radar, "Podraza v. Nourish, Inc." — filing summary (class of 10,000+ patients; Siri & Glimstad).
- Law360, "Podraza et al v. Nourish, Inc." — report on the court declining to cut wiretap and negligence claims.
- Fisher Phillips LLP, "The Good, the Bad, and the Ugly: What 7 Recent Court Decisions Tell You About Today's Website Privacy Liability" (May 2026) — analysis of the April 20 ruling, browsewrap holding, and HIPAA crime-tort exception.
All facts drawn from public court records and legal reporting. Status stated as of publication (July 2026); dockets update over time.