The Meta Pixel lawsuit is not one case but a sprawling wave of privacy litigation accusing Meta Platforms of using its website tracking code to collect sensitive personal information — medical records, tax return details, video viewing habits — and tie it to users’ Facebook and Instagram identities without consent. Since 2022, plaintiffs have filed hundreds of class actions under federal and state privacy statutes, healthcare providers have paid tens of millions to settle, and in August 2025 a San Francisco jury found Meta liable for illegally eavesdropping on users of a period-tracking app.1Lawdragon. Big Tech on Trial: Jury Finds Meta Liable for Misusing Women’s Health Data
What the Meta Pixel Is
The Meta Pixel is a snippet of JavaScript that a website operator installs in a page’s header. When a visitor loads the page, the code drops a cookie in the browser and sends data back to Meta’s servers: IP address, browser type, device information, the page viewed, and what the visitor did on the site (clicking a button, filling out a form, making a purchase, scheduling an appointment).2Hootsuite. What Is the Meta Pixel Because the Pixel matches that activity to a user’s Facebook or Instagram account through cookies, Meta can build a profile linking off-platform behavior to a social media identity, even when the user isn’t logged in.3Captain Compliance. Types of Data the Meta Pixel Collects and Retains About Website Visitors
With “advanced matching” turned on, the Pixel can also transmit names, email addresses, phone numbers, dates of birth, and physical addresses.3Captain Compliance. Types of Data the Meta Pixel Collects and Retains About Website Visitors Roughly 47% of all websites use it, with especially heavy adoption among S&P 500 companies, retailers, and financial services firms.4American Bar Association. Pixel Tools and VPPA Class Actions That footprint is why the same tool is now the subject of separate lawsuits about hospitals, tax software, and streaming video.
Healthcare Cases and Settlements
The largest coordinated case is In re Meta Pixel Healthcare Litigation, consolidated in the Northern District of California under Judge William H. Orrick (Case No. 3:22-cv-03580). Plaintiffs allege the Pixel was installed on the websites and patient portals of at least 664 hospital systems and medical providers, where it captured protected health information and transmitted it to Meta without patient consent or valid HIPAA authorization.5Cohen Milstein. In re Meta Pixel Healthcare Litigation
Meta lost two motions to dismiss. Claims proceeding include violations of the Electronic Communications Privacy Act, breach of contract, breach of the duty of good faith and fair dealing, invasion of privacy, violation of the California Comprehensive Computer Data Access and Fraud Act, and trespass to chattels. Judge Orrick rejected Meta’s argument that patients had no privacy expectation because they used publicly accessible webpages, finding they were “communicating with their healthcare providers about their healthcare needs.”6Cohen Milstein. Meta Must Keep Battling Trimmed Health Tracking Privacy Suit Plaintiffs moved for class certification in September 2025.5Cohen Milstein. In re Meta Pixel Healthcare Litigation
Individual providers have separately paid to resolve their own class actions:
- Kaiser Permanente reported an April 2024 breach affecting roughly 13.4 million members whose data went to Google, Microsoft, and Twitter through tracking tools, and agreed to a settlement worth up to $47.5 million, with a final fairness hearing scheduled for 2026.7HIPAA Journal. Kaiser Permanente Website Tracker Breach Affects 13.4 Million Individuals8ClassAction.org. Up to $47.5M Kaiser Settlement Ends Class Action Lawsuit
- Advocate Aurora Health disclosed that about 3 million patients in Illinois and Wisconsin may have had appointment details, provider names, insurance information, and MyChart messages transmitted to Meta, and settled for $12.225 million.9HotHardware. Facebook’s Meta Pixel Exposes 3 Million Patients10HIPAA Journal. Advocate Aurora Health Settles Pixel Lawsuit for $12.25 Million
- Novant Health, the first provider to send breach notification letters over the Pixel, told 1,362,296 patients their information was exposed after the code was misconfigured on its MyChart portal, and later settled for $6.6 million.11HIPAA Journal. Novant Health Notifies Patients About Unauthorized Disclosure of PHI via Meta Pixel Code on Patient Portal12HIPAA Journal. One Third of Healthcare Websites Have Meta Pixel Tracking Code
- Northwell Health’s settlement in Kaplan v. Northwell Health, Inc. received final approval in April 2026, though a notice of appeal has been filed. Subclass members who logged into a patient portal or booked appointments between 2020 and 2023 are eligible for a $15 cash payment and privacy monitoring.13NW Pixel Settlement. Kaplan v. Northwell Health Settlement
Other providers sued include MedStar Health System, UCSF and Dignity Health, Northwestern Memorial Hospital, WakeMed, Cedars-Sinai, and New York-Presbyterian, which paid $300,000 to settle with the New York Attorney General.12HIPAA Journal. One Third of Healthcare Websites Have Meta Pixel Tracking Code
The Flo Health Jury Verdict
On August 1, 2025, a San Francisco jury found Meta liable under the California Invasion of Privacy Act for eavesdropping on users of the Flo period-tracking app. The jury concluded that Meta’s software development kit embedded in the app recorded users’ answers about pregnancy goals and menstrual details without consent.1Lawdragon. Big Tech on Trial: Jury Finds Meta Liable for Misusing Women’s Health Data
Meta argued it never intended to collect health data and had told developers not to send it. Plaintiffs countered with internal Meta documents, including a 2018 warning from a Meta engineer, and testimony from Meta VP and Associate General Counsel for Privacy Steve Satterfield, who acknowledged the company benefited from app event data. CIPA carries statutory damages of $5,000 per violation, and Meta has acknowledged that total damages could run into “multiples of billions of dollars.” Co-defendant Flo Health settled during trial; Meta has signaled it will seek to overturn the verdict.14Bloomberg Law. Meta’s Health Privacy Trial Loss Spotlights Power of Wiretapping
Tax Preparation Cases
A December 2022 class action (Doe et al. v. Meta Platforms, Inc., No. 3:22-cv-07557) alleges that H&R Block, TaxAct, and TaxSlayer embedded the Pixel, letting Meta collect taxpayer names, email addresses, adjusted gross incomes, filing statuses, refund amounts, and dependent information. The case brings claims under the Electronic Communications Privacy Act, CIPA, and California’s Unfair Competition Law.15ClassAction.org. H&R Block, TaxAct, TaxSlayer Quietly Transmit Sensitive User Information to Meta
The court denied Meta’s motion to dismiss, rejecting the company’s argument that it didn’t “install or use” the Pixel and calling Meta’s reading of the pen-register statute a “loophole” for intrusive technology.16Courthouse News Service. In re Meta Pixel Tax Filing Cases Order In March 2026, however, Judge P. Casey Pitts denied class certification. Plaintiffs could not show Meta had actually received their data from specific tax-filing sites, no named plaintiff demonstrated collection since 2023, and generic metadata like IP addresses did not necessarily reveal sensitive financial information.17Law360. Facebook Users Lose Cert Bid in Tax Data Collection Fight
Missouri Attorney General Andrew Bailey separately sued H&R Block, TaxSlayer, and TaxAct in July 2023, alleging violations of the Missouri Merchandising Practices Act for sharing taxpayer data with Meta and Google despite contrary promises in their privacy policies.18Missouri Attorney General. Attorney General Bailey Files Suit Against Tax Preparation Companies
Video Privacy Protection Act Filings
The 1988 Video Privacy Protection Act has produced the largest volume of Meta Pixel filings. Plaintiffs argue that websites hosting video content violate the VPPA when the Pixel transmits viewing habits and Facebook IDs to Meta without written consent. Statutory damages of at least $2,500 per violation make these cases costly. More than 80 were filed in 2023, and filings continued at roughly 200 per year through early 2025.4American Bar Association. Pixel Tools and VPPA Class Actions
AARP settled one such case for $12.5 million and agreed to cease or limit Pixel operations on its website.19The Recorder. AARP Reaches $12.5M Settlement in Meta Pixel Privacy Class Action
Where a VPPA claim can succeed now depends on the court. In July 2025, the Second Circuit ruled in Solomon v. Flipps Media, Inc. that video titles and Facebook IDs transmitted in code are not “personally identifiable information” under the VPPA, because an ordinary person cannot interpret the underlying code without technical help. The court reinforced that reading in Hughes v. National Football League, rejecting the argument that tools like ChatGPT could “translate” the transmissions.20Morgan Lewis. Second Circuit Shuts the Door on Meta Pixel VPPA Claims Pixel-based VPPA claims are effectively closed inside the Second Circuit but continue elsewhere.
The California Wiretap and Pen Register Theories
The California Invasion of Privacy Act is doing much of the legal work. Section 631 prohibits unauthorized wiretapping and Section 632 prohibits eavesdropping on confidential communications; both carry $5,000 in statutory damages per violation without a separate showing of injury.21WilmerHale. Year in Review: 2024 Web Tracking Litigation and Enforcement The Flo verdict was a Section 632 win.
A newer theory relies on CIPA Section 638.51, which bars installing a “pen register” or “trap and trace” device without a court order. Plaintiffs argue tracking pixels function as pen registers because they capture routing and addressing information like IP addresses.16Courthouse News Service. In re Meta Pixel Tax Filing Cases Order Courts have split. Some allow the claim; others have thrown it out on the grounds that IP addresses carry no reasonable expectation of privacy or that treating every website pixel as a pen register would “criminalize normal internet behavior.”22FKKS. Pixel Tracking Litigation California state courts rejected the theory in early 2025 in Sanchez v. Cars.com and Aviles v. LiveRamp.23Byte Back Law. 2025 Update: Website Tracking Litigation and Enforcement
Two other rulings have cut against plaintiffs. The Third Circuit held in Cole v. Quest Diagnostics that a third-party pixel provider is a “direct recipient” of browser communications rather than an illegal interceptor, and in Lakes v. Ubisoft a California federal court dismissed wiretap claims after finding the plaintiff had consented by interacting with a cookie banner, creating an account, and making purchases.24Inside Class Actions. 2025 Website Wiretapping Roundup
Regulators and Congress
Federal enforcement has focused on companies that deployed the Pixel rather than on Meta itself. The FTC fined GoodRx $1.5 million in February 2023 for sharing sensitive health information with Facebook and other third parties, penalized BetterHelp $7.8 million the next month for sharing mental health data for advertising, and fined the telehealth company Cerebral $7 million in April 2024 for disclosing information on more than 3 million users to Meta and TikTok.25Freshpaint. A Timeline of Events Around Tracking Technologies in Healthcare
The HHS Office for Civil Rights issued guidance in December 2022 warning that using tracking technologies on healthcare websites may violate HIPAA, and in July 2023 the OCR and FTC jointly sent warning letters to nearly 130 healthcare organizations.12HIPAA Journal. One Third of Healthcare Websites Have Meta Pixel Tracking Code
On Capitol Hill, a July 2023 report led by Senator Elizabeth Warren concluded that Meta and major tax preparation companies had “recklessly” shared taxpayer financial data. Co-signed by Senators Wyden, Blumenthal, Duckworth, Sanders, and Whitehouse, and Representative Porter, it was referred to the IRS, the Treasury Inspector General, the DOJ, and the FTC.26The Markup. Congressional Report Finds Meta and Tax Prep Companies Recklessly Shared Taxpayers’ Data In October 2024, lawmakers followed up with a letter urging the DOJ to act against TaxSlayer, H&R Block, TaxAct, and Ramsey Solutions, noting the IRS Inspector General had found those companies’ consent statements failed to comply with Treasury regulations governing disclosure of tax return information.27Legal Dive. DOJ Urged to Probe Tax Companies’ Pixel Use
How Meta Is Defending the Cases
Represented by Gibson Dunn & Crutcher across most Pixel matters, Meta has argued that its terms of service explicitly prohibit third-party websites from sending sensitive information through the Pixel, placing the blame for misuse on the sites that deploy it. The company has also challenged whether plaintiffs can prove Meta actually received their specific sensitive data, arguing that generic metadata like IP addresses is not a concrete injury.28Gibson Dunn. Gibson Dunn Secures Denial of Class Certification for Meta Platforms in Pixel Privacy Litigation
Results have been mixed. Motions to dismiss failed in the healthcare and tax-filing cases. The class certification denial in the tax case was a significant win, resting on the argument that individual inquiries into what data was collected from each plaintiff would swamp common questions. The VPPA argument that encoded Pixel transmissions cannot be read by ordinary people prevailed at the Second Circuit. The most damaging loss was Frasco, where a jury rejected Meta’s position that it lacked the intent to eavesdrop.20Morgan Lewis. Second Circuit Shuts the Door on Meta Pixel VPPA Claims
In its SEC filings, Meta has disclosed multiple putative class actions over its receipt of information from third-party websites via business tools, noting the cases “are in different stages” and that some motions to dismiss have been denied while others have been granted.29SEC. Meta Platforms Annual Report The Flo verdict has also fueled industry lobbying behind California Senate Bill 690, which would exempt commercial business purposes from CIPA liability.14Bloomberg Law. Meta’s Health Privacy Trial Loss Spotlights Power of Wiretapping
Who May Be Affected
If you used a hospital patient portal, scheduled care through a provider’s website, filed taxes online with H&R Block, TaxAct, or TaxSlayer, or watched video content on a site that ran the Pixel, you may fall within one of the existing class definitions. Named settlements have already opened claims for members of Kaiser Permanente, Advocate Aurora Health, Novant Health, Northwell Health, and AARP audiences, with deadlines and payment amounts set by each settlement website. Eligibility usually turns on whether you had a Facebook or Instagram account and used the covered service during a specific window, most commonly between 2020 and 2023. Check the individual settlement site tied to the provider or company you used to see whether a claim is still open and what proof is required.