For three years the most productive area of American privacy litigation has been tracking pixels on health and wellness websites. The theory is straightforward and, to most people who hear it, obviously correct: you go to your insurer’s site, you search for an oncologist, and a third-party script quietly ships that search to an advertising company.
Two rulings this summer suggest the theory is running into structural limits that have nothing to do with whether the conduct is bad.
The Blue Shield ruling
A federal judge dismissed claims against Blue Shield of California arising from Google Analytics and the Meta Pixel running on its website.
The reasoning is the part that matters. Most of these cases are pleaded under state wiretapping and eavesdropping statutes — California’s CIPA is the workhorse — because those statutes carry statutory damages and don’t require proving individualized harm. But wiretapping statutes are written around the act of interception. Someone has to intercept a communication.
The court’s conclusion: Blue Shield did not intercept anything. Blue Shield is a party to the communication — you were talking to Blue Shield. Embedding a script that lets someone else listen is not the same act as listening. Under this reading, the entities that actually received and processed the data — Google and Meta — are the ones that could theoretically be liable on an interception theory.
This is not a ruling that the conduct was fine. It is a ruling that the plaintiffs sued the wrong defendant.
Why that’s a problem in practice
Suing Google and Meta directly for pixel-collected health data is a materially harder case than suing the hospital or the insurer, for reasons that are mostly about litigation economics rather than merits.
The website operator is a single defendant with a defined set of pages, a discoverable tag manager configuration, and a clear record of what scripts it deployed and when. The class is definable: everyone who visited these pages during this window.
The platform is a defendant with billions of users, receiving pixel fires from millions of sites, with terms of service that push liability back onto the site operator, arbitration provisions where they can be enforced, and an argument that it processed the data as a service provider at the site’s direction under contractual terms that prohibit sending health data in the first place. Meta’s position in these cases has consistently been that it told sites not to send sensitive categories and filtered what it could detect.
So the ruling creates a gap. The party with the practical control over what gets sent is not the party the wiretapping statute reaches. The party the statute reaches has the resources and the contractual posture to make the case enormously expensive.
The Illinois ruling
Weeks later, an Illinois federal judge handed the Blue Cross Blue Shield Association a win on most claims in a case brought over federal employees’ use of its website. The holding: searches for doctors and symptoms did not amount to protected health information.
This one deserves care, because the reasoning is narrower than the headline suggests. The question was not whether searching for an oncologist reveals something sensitive about you — of course it does. The question was whether that search falls within the specific statutory definition of protected health information that the plaintiffs’ claims depended on.
PHI under HIPAA is individually identifiable health information created or received by a covered entity relating to an individual’s health condition, care, or payment. A search query on a provider-directory page is not, on a strict reading, a record of your condition or your care. It is a record of what you looked up.
The distinction is legally coherent and practically absurd. Everyone in the ad-tech supply chain treats a symptom search as health data, because it is the most valuable kind of signal they can get — it is forward-looking, high-intent, and predicts spending. The industry’s own segment taxonomies are built on exactly this inference. A legal definition that excludes it is a definition that has fallen out of sync with how the data is actually used.
What’s actually happening
Put the two rulings together and the shape is clear.
Health-adjacent browsing generates data that is treated as health data by every commercial actor who touches it, and is not treated as health data by the statutes written to protect health data. And the statutes that would reach the conduct — wiretapping laws — attach to the wrong party in the chain.
This is what happens when you regulate by sector. HIPAA regulates covered entities handling records. It was written in 1996 for a world of charts, claims, and clearinghouses. It has almost nothing to say about a JavaScript tag on a public-facing marketing page, and courts applying it faithfully will keep producing results like these.
Meanwhile the FTC’s Health Breach Notification Rule — which does reach non-HIPAA health apps and has been used effectively — depends on enforcement priorities that shift with administrations, and the current Commission’s attention is elsewhere.
What still works
Not all of this is bleak, and the litigation wave has produced real change even where individual cases have failed.
Direct-to-platform theories still have life where plaintiffs can show the platform knowingly ingested sensitive categories rather than merely receiving what a site sent.
State comprehensive privacy laws increasingly define “sensitive data” to include health information inferred from behavior, not just health records. That is the right definition, and it is spreading — Washington’s My Health My Data Act, with its private right of action, remains the most aggressive version and has not been meaningfully narrowed.
Consumer health data laws are the growth area precisely because they were drafted after this problem was visible.
What you can do about it today
Since the legal system is not going to protect this for you in the near term:
-
Use a browser that blocks trackers by default. Firefox with Enhanced Tracking Protection set to Strict, Brave, or Safari with cross-site tracking prevention. This blocks the Meta Pixel and most analytics on health sites outright.
-
Install uBlock Origin if your browser supports it. It is the single most effective privacy tool available to a non-technical user and it costs nothing.
-
Do symptom and provider searches in a private window, or better, in a separate browser profile that carries no logged-in identity. The pixel is far less useful without a cookie tying it to your Facebook or Google account.
-
Do not log into your insurer’s portal in the same browser session as your social media accounts. The correlation is the whole product.
-
If you are in Washington, Nevada, or Connecticut, you have consumer health data rights that go well beyond HIPAA. Washington’s law lets you sue. Use it.
-
Check your insurer’s site yourself. Open developer tools, watch the network tab, filter for
facebook.comorgoogle-analytics.com. It takes ninety seconds and tells you exactly what is being sent. Screenshots of that are what class actions are built from.
The pattern
The pixel litigation wave was never going to be the durable fix. It was a workaround — plaintiffs’ lawyers reaching for whatever statute had teeth, because the statute that should have applied was written before the conduct existed.
Workarounds get narrowed. That is what courts do to theories stretched past their drafting. What these two rulings say is not “this is fine.” What they say is: if you want health browsing data protected, someone has to pass a law that protects health browsing data. Twenty states now have comprehensive privacy laws. The number that squarely cover this is much smaller.


