
Disclaimer: The information in this post is for general informational purposes only and does not constitute legal advice. I am not a lawyer. Please consult a licensed attorney for guidance on your specific situation.
Healthcare marketers are accustomed to complying with regulatory requirements from HIPAA to GDPR to ADA; however, a number of health systems and other organizationals have recently been caught off guard by lawsuits claiming violation of wiretapping laws, most commonly the California Invasion of Privacy Act (CIPA).
What is CIPA?
The California Invasion of Privacy Act (CIPA) was enacted in 1967 to address growing concerns about the ability to unlawfully eavesdrop on private communications through the use of emerging technologies. The original law was designed to penalize the use of technologies such as landline wiretaps and recording devices to record private conversations; however, the law has been expanded multiple times in the decades that followed to include cordless phones and cell phones.
How does CIPA apply to website tracking technology?
In recent years, there has been a surge in lawsuits about tracking technologies on healthcare websites, especially those from Meta and Google Analytics. These lawsuits have centered around the accusation that by providing IP address to third parties without permission on sensitive pages like a request an appointment page.
Now that healthcare marketers have found ways to protect their organizations against such claims by removing tracking pixels from sensitive pages and other tactics, consumer privacy attorneys and their clients have looked for other avenues to sue organizations for their use of tracking pixels.
Proponents of applying CIPA to website tracking technologies argue that by collecting IP address and website traffic without explicit consent from website users, these tracking technologies act as “pen registers.” A pen register is a device or process that records the dialing or routing of communications but not the contents of the communication.
These lawsuits can apply to any organization marketing to residents of the state of California.
How are courts reacting to these lawsuits?
While initial lawsuits date back to the early 2000’s, the recent flood of lawsuits didn’t begin until around 2022. And the courts’ reaction to such lawsuits has been inconsistent at best indicating a high level of legal uncertainty that will need to be further litigated before healthcare organizations will have clarity.
For example, Greenley v. Kochava concluded tracking pixels could constitude “pen register” or “trap and trace” devices while Sanchez v. Cars.com, Inc. and Aviles v. LiveRamp, Inc. concluded the opposite.
Are there any examples of CIPA lawsuits impacting healthcare organizations?
There are many examples of how these lawsuits have impacted healthcare organizations. While this list is not exhaustive, it covers a plethora of organization types, legal arguments, and outcomes:
- Cole v. Quest Diagnostics
- Doe v. Eating Recovery Center
- Frasco v. Flo Health
- Hodges v. GoodRX Holdings
- John Doe v. Meta (while Meta isn’t a healthcare organization, the lawsuits claims relate to information collected from the websites of healthcare organizations)
- J.S. v. Spring Fertility Holdings, Meta, and LinkedIn
- Wright v. TrueCare
How can healthcare organizations protect themselves from CIPA lawsuits?
While these cases play out in the courts and healthcare marketers wait on clear direction about if and how CIPA applies to modern tracking technologies, we must be vigilant to protect our organizations from the financial risks associated with such lawsuits. The following actions should be considered:
- Consult a qualified attorney
- Implement a cookie consent tool
- Review Privacy Policy and Terms of Use pages for needed updates
- Review tracking vendor configuration for needed updates such as IP anonymization
- Consider server-side analytics and tracking tools
- Document privacy practices and decisions

