Pixel class action lawsuits are privacy cases accusing websites of secretly sharing visitor data — including health details, tax information, and video-viewing history — with third parties like Meta through small snippets of tracking code embedded on their pages. The suits have hit hospitals, tax preparers, sports leagues, streaming platforms, news outlets, and retailers, producing settlements in the millions, a wave of appellate rulings, and a Video Privacy Protection Act question now before the U.S. Supreme Court.
What a Tracking Pixel Does
The Meta Pixel is a piece of JavaScript that website operators install to record what visitors do on a page — clicks, page loads, form submissions — and send that information back to Meta’s advertising platform. Roughly 47 percent of websites used the tool as of early 2024, making it one of the most widely deployed trackers on the internet.
The lawsuits started when plaintiffs discovered how much the pixel was capturing in sensitive contexts. On hospital sites, it allegedly recorded appointment details, patient portal logins, and health conditions. On tax-preparation sites, it reportedly transmitted financial information. On media sites, it shared video titles alongside identifiers like Facebook IDs. The core claim across every context is the same: personal data flowed to Meta without users being told and without their consent.
The Healthcare Litigation Against Meta
The largest healthcare case is In re Meta Pixel Healthcare Litigation, pending in the Northern District of California before Judge William H. Orrick. Plaintiffs allege Meta deployed its pixel on at least 664 hospital and medical-provider websites, intercepting patient communications — including interactions marketed as “secure” — and redirecting the data to Meta for advertising, all without valid HIPAA authorization.
The case has cleared two rounds of motions to dismiss. In September 2023, the court let claims proceed under the federal Electronic Communications Privacy Act and for breach of contract. In January 2024, it added claims for invasion of privacy, violations of California’s Comprehensive Computer Data Access and Fraud Act, and trespass to chattels. Meta had argued that publicly accessible webpages carry no privacy protection; the court rejected that. Plaintiffs moved for class certification in September 2025.
Hospital Pixel Settlements
While the main MDL against Meta continues, individual hospitals have settled their own pixel suits. If you were a patient at one of these systems, the eligibility windows and deadlines vary:
- In re Advocate Aurora Health Pixel Litigation settled for $12,225,000, with individual payments capped at $50. The reported breach affected roughly three million patients. The final fairness hearing was held in March 2024, and Advocate Aurora removed the Meta Pixel, Google Analytics, and similar tools from its websites and patient portal.
- In re The Christ Hospital Pixel Litigation settled for a fund between $4,500,000 and $7,000,000. Eligible class members — patients who used the hospital’s portal or mobile app, or submitted health forms between December 2018 and January 2023 — could claim at least $37.50 plus a year of privacy monitoring. The claim deadline was October 23, 2025.
- Smith v. Loyola University Medical Center, a $2,665,264 settlement, received preliminary approval in May 2025 with a final approval hearing set for September 2025. The hospital agreed to stop using tracking technologies without prominent disclosures.
- Warren v. Pomona Valley Hospital Medical Center settled for $600,000, covering patients who visited the hospital’s website and logged into the patient portal between January 2019 and December 2022. A final fairness hearing was set for January 2026.
- Kaplan v. Northwell Health, Inc. offered patients who used the FollowMyHealth portal or booked appointments through the hospital’s website a $15 cash payment and 12 months of privacy monitoring, with a broader subclass receiving monitoring only. Final approval was issued April 23, 2026, but a notice of appeal has been filed, so the settlement’s fate is not yet certain.
Not every hospital defendant lost. Palomar Health, a California public hospital district, won dismissal in August 2024 after a San Diego court found the plaintiff had failed to meet pre-filing requirements under California’s Government Claims Act and that sovereign immunity shielded the public entity from money damages.
The Video Privacy Protection Act Wave
Outside healthcare, the dominant theory driving pixel class actions is the Video Privacy Protection Act. The VPPA is a 1988 federal statute originally passed to prevent disclosure of video rental records, inspired by a reporter’s publication of Supreme Court nominee Robert Bork’s rental history. It bars “video tape service providers” from knowingly disclosing consumers’ personally identifiable information without consent, and it authorizes statutory damages of at least $2,500 per violation, plus punitive damages and attorneys’ fees.
Plaintiffs’ firms adapted the statute to the pixel era. The argument: any website hosting video content is a “video tape service provider,” and a tracking pixel that sends a viewer’s Facebook ID together with a video title to Meta is an unauthorized disclosure of PII. The theory has produced roughly 200 cases per year recently, with at least 28 filed in the first two months of 2025 alone. Defendants include the NBA, the NFL, Zillow, DraftKings, Paramount Global, GameStop, the Toledo Blade newspaper, Pearson Education, and the TED Foundation.
The Supreme Court Case
Courts have split on who counts as a “consumer” under the VPPA, and the Supreme Court is now going to sort it out. The Second Circuit, in Salazar v. National Basketball Association, adopted a broad reading: a website user who signs up for a newsletter and watches videos qualifies, even if the newsletter itself is not audiovisual content. The Sixth Circuit went the other way in Salazar v. Paramount Global, holding in April 2025 that a consumer must subscribe to goods or services “in the nature of video cassette tapes or similar audio visual materials.” The Seventh Circuit sided with the broad reading; the D.C. Circuit sided with the narrow one.
In January 2026, the Supreme Court granted certiorari in Salazar v. Paramount Global to decide whether “goods or services from a video tape service provider” covers all of a provider’s offerings or only audiovisual ones. Oral argument is expected in the October 2026 term, with a decision anticipated in early 2027. The Court denied certiorari in the NBA’s case in December 2025, so the Second Circuit’s broad ruling stands in that jurisdiction for now.
What Counts as PII
Even plaintiffs who clear the “consumer” question face a second fight over whether pixel data is personally identifiable information. In Solomon v. Flipps Media, Inc., the Second Circuit held that video titles and Facebook IDs transmitted as raw computer code are not PII, because an “ordinary person” could not use them to identify someone’s viewing habits without specialized technological assistance. The court reinforced that reasoning in Hughes v. NFL, rejecting arguments that tools like ChatGPT could bridge the gap. Other courts have gone the other way: a Southern District of New York judge ruled in Collins v. Pearson Education that a Facebook ID does qualify as PII.
Wiretap and State Privacy Claims
Pixel plaintiffs also invoke state wiretapping laws, arguing the pixel intercepts communications in real time without consent. Results have been uneven.
California’s Invasion of Privacy Act has been the busiest state battleground, in part because CIPA authorizes $5,000 per violation and does not require proof of actual harm. Plaintiffs have pursued both traditional wiretapping theories and “pen register” claims. In the Meta Pixel tax-filing cases, a court denied Meta’s motion to dismiss, finding the pixel plausibly worked as a real-time data collection tool. But courts dismissed similar CIPA claims in Price v. Headspace and Kishnani v. Royal Caribbean Cruises in 2025, holding that tracking pixels do not fall within the statute’s scope. California’s proposed SB 690 would amend CIPA to explicitly exempt commercially necessary, CCPA-compliant data collection from the statute’s private right of action.
In Pennsylvania, federal courts have largely rejected claims under the state’s Wiretapping and Electronic Surveillance Control Act. In Heaven v. Prime Hydration LLC and Ingrao v. Addshoppers, Inc., courts dismissed WESCA claims for lack of Article III standing, reasoning that ordinary browsing does not constitute private information creating actionable harm. The Ninth Circuit reinforced that trend in Popa v. Microsoft Corp. in August 2025, holding that tracking mouse movements, clicks, and page scrolling is not “highly offensive” enough to constitute concrete injury. The court compared the practice to “a store clerk’s observing shoppers” and held that a bare statutory violation without real-world harm does not confer federal standing.
Massachusetts went further the other direction. Its Supreme Judicial Court ruled in Vita v. New England Baptist Hospital that using third-party tracking technologies like Google Analytics and the Meta Pixel does not violate the state’s Wiretap Act at all.
The Tax-Filing Case
A separate line of pixel litigation targeted tax-preparation websites. In In re Meta Pixel Tax Filing Cases, plaintiffs alleged Meta illegally collected sensitive financial data from tax-filing platforms through the pixel. In April 2026, Judge P. Casey Pitts of the Northern District of California denied class certification, finding the proposed classes “significantly” broad and holding that certification would require “extensive individual inquiries,” particularly around statute-of-limitations defenses. The court also rejected injunctive relief because no named plaintiff showed a likelihood of future injury, noting a lack of evidence that data was collected from any plaintiff after 2023.
Regulatory Actions
Federal regulators have moved alongside private litigants. The FTC brought two prominent enforcement actions against digital health platforms sharing data through tracking pixels:
- GoodRx paid a $1.5 million fine for violating the Health Breach Notification Rule by disclosing prescription and telehealth data to advertising companies without consent.
- BetterHelp paid $7.8 million to consumers after the FTC alleged the company shared mental health data for advertising purposes in violation of Section 5 of the FTC Act.
Both companies were barred from sharing health information for targeted advertising going forward. The FTC launched an Office of Technology in February 2023 to build internal capacity for these investigations.
On the HIPAA side, the HHS Office for Civil Rights issued a bulletin in December 2022 stating that tracking technologies collecting protected health information — including IP addresses linked to specific health condition pages — must comply with HIPAA’s Privacy, Security, and Breach Notification Rules. In July 2023, OCR and the FTC jointly sent warning letters to approximately 130 hospital systems and telehealth providers about the risks of embedding tracking technologies. In June 2024, a federal court in the Northern District of Texas vacated the portion of the HHS bulletin addressing unauthenticated public webpages in American Hospital Association v. Becerra, ruling that HHS had exceeded its authority under HIPAA. HHS filed a notice of appeal but withdrew it in August 2024.
What’s Still Open
Several major questions remain unresolved. The Supreme Court’s decision in Salazar v. Paramount Global will determine whether the VPPA reaches anyone who interacts with a video-hosting website or only subscribers of audiovisual content, a ruling that could sustain or collapse hundreds of pending claims. The healthcare MDL against Meta continues toward class certification. California’s SB 690 could reshape CIPA claims, and the Ninth Circuit’s Popa decision has raised the bar for proving concrete injury in federal pixel cases across the western states. Hospitals and healthcare systems, in the meantime, continue settling individual cases rather than risk trial.