I.T. v. ChoicePoint LLC
Trial Court Opinion
UNITED STATES DISTRICT COURT 6 WESTERN DISTRICT OF WASHINGTON AT SEATTLE I.T., et al., CASE NO. C25-00193 Plaintiffs, ORDER GRANTING IN PART AND v. DENYING IN PART DEFENDANT’S MOTION TO DISMISS CHOICEPOINT LLC d/b/a CHOICEPOINT HEALTH, Defendant.
13 Plaintiffs I.T., A.K., S.R., and M.G.1 bring this putative class action alleging Defendant ChoicePoint LLC d/b/a ChoicePoint Health (“ChoicePoint”) illegally used online tracking tools to record Plaintiffs’ use of the ChoicePoint website to seek help for drug or alcohol addiction. Dkt.
16 Nos. 1, 13. Plaintiffs further allege that ChoicePoint transmitted that information to Google and Facebook without their consent. Id. This case is one of several similar cases in the Ninth Circuit, and nationwide, against healthcare-related entities for their use of Google and Facebook tracking tools. ChoicePoint moved to dismiss the action for failure to state a claim. Dkt. No. 17). The Court finds that some of Plaintiffs’ claims are insufficiently pleaded, and will therefore grant in part Defendant’s motion. However, the Court also concludes that leave to amend is proper.
24 1 The Court granted Plaintiffs’ motion to proceed pseudonymously. Dkt. No. 8.
1 I. BACKGROUND2 2 “ChoicePoint is a medical provider specializing in addiction treatment services, including medication-assisted addiction treatment, psychiatric counseling and in-patient addiction treatment[.]” Dkt. No. 13 ¶ 9. ChoicePoint operates www.choicepointhealth.com (“the Website”), which allows “potential clients to research its programs, request an appointment, and complete an online assessment of the severity of their addiction.” Id. 7 Plaintiffs are citizens of Washington (I.T.), Indiana (S.R.), Missouri (A.K.), and Ohio (M.G.). Dkt. No. 13 ¶¶ 14, 19, 24, 30. Plaintiffs allege that ChoicePoint collected and transmitted two types of “sensitive information” about them to Google and Facebook3: (1) that website visitors “are seeking help for drug or alcohol addiction” by requesting an appointment for addiction treatment services, and (2) “the results of their online addiction evaluation[s.]” Id. ¶ 3; see also id. ¶¶ 15 (I.T.), 20 (S.R.), 25 (A.K.), 31 (M.G.). Plaintiffs explain that this collection and transfer occurs using tracking pixels.4 Id. ¶ 58. Plaintiffs allege that the Google and Facebook pixels on the Website transmitted the fact that Plaintiffs scheduled appointments with ChoicePoint to Google (id. ¶ 78) and to Facebook (id. ¶ 79) and the results of Plaintiffs’ online evaluations to Google (id. ¶¶ 76–77). Plaintiffs allege that this information was associated with their identities because the pixels connected the information with Plaintiffs’ Google or Facebook accounts and through their 2 This section assumes, in resolving the motion to dismiss, that the factual allegations in the first amended complaint (“FAC”) are true. Edmonson v. City of Martinez, 17 F. App’x 678, 679 (9th Cir. 2001).
3 The amended complaint states that Plaintiffs’ information was also sent to TikTok, Bing, Taboola, Pinterest, and Quora. Dkt. No. 13 ¶ 75. During oral argument, Plaintiffs confirmed the claims arise from ChoicePoint’s alleged transmission of information to Google and Facebook only.
22 4 “A Pixel is: ‘[A] small piece of code that will be placed into the website or ad and define [the Pixel operator’s] tracking goals such as purchases, clicks, or pageviews[.]’” Dkt. No. 13 ¶ 59 (quoting Lurking Beneath the Surface: Hidden Impacts of Pixel Tracking, FEDERAL TRADE COMMISSION-OFFICE OF TECHNOLOGY BLOG (Mar. 6, 2023), https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2023/03/lurking-beneath-surface-hidden-impacts-pixel- tracking (last visited July 16, 2025)). unique “browser fingerprints[.]”5 Id. ¶¶ 62–73, 77. Plaintiffs allege that after providing this information to ChoicePoint they “immediately began seeing targeted online advertisement for addiction treatment services.” Id. ¶¶ 18, 23, 28, 34.
4 Plaintiffs allege that ChoicePoint directly benefits by providing Plaintiffs’ information to Google and Facebook because it “receive[s] access to advertising and marketing analytics services in exchange for installing Google and Facebook Tracking Tools on their website.” Dkt. No. 13 ¶ 92. Lastly, Plaintiffs allege ChoicePoint’s Privacy Policy fails to inform consumers about its disclosures to Google and Facebook and lies about protecting consumer information by stating, “We don’t sell, trade, or give away your personal information to anyone.” Id. ¶ 82.
10 Plaintiffs filed this case on January 30, 2025. Dkt. No. 1. After ChoicePoint moved to dismiss (Dkt. No. 9), Plaintiffs filed the first amended complaint (“FAC”) under Federal Rule of Civil Procedure 15(a)(1)(B). Dkt. No. 13. Plaintiffs assert eight6 causes of action: common law invasion of privacy, breach of fiduciary duty, negligence, breach of implied contract, unjust enrichment, violation of the Electronic Communications Privacy Act (“ECPA”), violations of the Ohio Consumer Sales Practices Act (“OCSPA”), violations of the Indiana Deceptive Consumer Sales Act (“IDCSA”), and violations of the Washington Consumer Protection Act (“CPA”). Id. ¶¶ 156–255.
18 ChoicePoint moved to dismiss the FAC under Federal Rule of Civil Procedure 12(b)(6), arguing each cause of action fails to state a claim. Dkt. No. 17. Plaintiffs responded (Dkt. No. 21), ChoicePoint replied (Dkt. No. 22), and the Court heard oral argument (Dkt. No. 24). The matter is ripe for the Court’s consideration.
5 A “browser fingerprint” is a “combination of [a user’s] device and browser characteristics” that is “often unique.”
23 Dkt. No. 13 ¶ 73.
6 In response to ChoicePoint’s motion to dismiss the FAC, Plaintiffs agreed to the dismissal of their claims for breach of confidence and the Washington Privacy Act. Dkt. No. 21 at 24 n.8.
1 II. ANALYSIS A. Subject Matter Jurisdiction 3 The Court has subject matter jurisdiction over this putative class action under 28 U.S.C. § 4 1332 because ChoicePoint is a citizen of New Jersey (Dkt. No. 13 ¶ 35), the putative classes each include at least one member that is not a citizen of New Jersey (id. ¶¶ 14, 19, 24, 30), the amount in controversy exceeds $5 million (id. ¶ 36), and each putative class would exceed 100 members (id. ¶¶ 36, 147). 28 U.S.C. § 1332(d)(2), (5), (10).
8 B. Legal Standard 9 In evaluating a motion to dismiss under Rule 12(b)(6), a court examines the complaint to determine whether, assuming the facts alleged are true, the plaintiff has stated “a claim to relief that is plausible on its face.” Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007)). A claim is plausible if “the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id. Consistent with the authority cited in the parties’ briefing,7 the Court applies Washington law to the state-law claims and the CPA claim, federal law to the ECPA claim, Ohio law to the OCSPA claim, and Indiana law to the IDCSA claim. See Brewer v. Dodson Aviation, 447 F. Supp. 18 2d 1166, 1175 (W.D. Wash. 2006) (explaining the “presumptive local law” of Washington applies unless there is an actual conflict between Washington’s laws and the laws of another state); In re MCG Health Data Sec. Issue Litig., No. 2:22-CV-849-RSM-DWC, 2023 WL 3057428, at *2 (W.D. Wash. Mar. 27, 2023) (applying Washington state law to common law claims and “the law Even though three Plaintiffs are not Washington residents and ChoicePoint is not based in Washington, neither party performs a choice of law analysis.
1 of the state wherein each state statutory claim arises”), report and recommendation adopted, 2023 2 WL 4131746 (W.D. Wash. June 22, 2023).
3 C. The Court Can Consider the Privacy Policy.
4 “Generally, district courts may not consider material outside the pleadings when assessing the sufficiency of a complaint.” Khoja v. Orexigen Therapeutics, Inc., 899 F.3d 988, 998 (9th Cir. 2018). Here, both parties rely on ChoicePoint’s Privacy Policy (Dkt. No. 25), a document outside the pleadings, to support their arguments.8 Plaintiffs allege the Privacy Policy promises that ChoicePoint does not “sell, trade, or give away your personal information to anyone.” Dkt. No. 13 ¶ 82. Plaintiffs rely on this language to support their implied contract claim (Dkt. No. 21 at 15–16) and claims for violations of state consumer protection laws (id. at 21–23). And ChoicePoint argues the Privacy Policy explains and warns Plaintiffs about each act of which they now complain, undermining the implied contract claim (Dkt. No. 17 at 21–23) and the ECPA claim (id. at 27).
14 The Court can consider the Privacy Policy (Dkt. No. 25) as incorporated by reference in the FAC. Dkt. No. 13 ¶¶ 82 n.45, 85, 133, 161, 172; United States v. Ritchie, 342 F.3d 903, 908 (9th Cir. 2003). But apart from a conclusory allegation that Plaintiffs “relied” upon the Privacy Policy (Dkt. No. 13 ¶ 133), there are no allegations in the FAC that any Plaintiff read the Privacy Policy at any point in their interactions with ChoicePoint. See In re Meta Pixel Tax Filing Cases, 724 F. Supp. 3d 987, 1001 (N.D. Cal. 2024) (taking judicial notice of submitted terms of service but stating, “[t]he Court cannot conclude from Meta’s submission that this was the version in effect during the period relevant to plaintiffs’ claims, or that plaintiffs ever assented to the terms ChoicePoint also provides their Terms of Service (Dkt. No. 25-1) but does not rely on that document or its language as a basis to dismiss any claims. See generally Dkt. Nos. 17, 22. Accordingly, the Court does not consider the Terms of Service.
1 therein”). Moreover, the circumstances surrounding where and how any Plaintiff could have viewed the Privacy Policy have not been alleged and thus are not before the Court. Accordingly, as detailed below, the Privacy Policy is not dispositive of any claim at this stage of the litigation.
4 D. Plaintiffs Adequately Allege Disclosure of Personally Identifiable Information and Protected Health Information.
Before analyzing each cause of action, the Court addresses ChoicePoint’s threshold argument that none of Plaintiffs’ claims are cognizable because Plaintiffs do not connect the transmitted survey results and appointment confirmation with an individual’s name, date of birth, or social security number. ChoicePoint cites no authority for the proposition that only those identifiers are sufficiently personally identifiable to support Plaintiffs’ claims. Further, Plaintiffs do allege that their survey results were connected to them individually through their Google and/or Facebook accounts (Dkt. No. 13 ¶¶ 62–73) and that each Plaintiff was logged into their Google and Facebook accounts when they accessed the Website (id. ¶¶ 17, 22, 27, 33). Plaintiffs also provide screenshots demonstrating this connection through _cid, _sid, and _fbp cookies. Dkt. No. ¶¶ 77–79. ChoicePoint does not address these allegations, and other courts have found such allegations sufficient to connect pixel information with individuals. See, e.g., Gaige v. Exer Holding Co., LLC, No. 2:24-cv-06099-AH-(AJRx), 2025 WL 559719, at *4 (C.D. Cal. Mar. 2, 2025) (finding Facebook User IDs and IP addresses associated with the disclosed information to be sufficiently personally identifiable).
While not raised as a threshold issue by ChoicePoint, the Court finds it prudent to also address here the argument that the disclosed information is not protected health information (“PHI”) or individually identifiable health information (“IIHI”) as defined by the Health Insurance Portability and Accountability Act (“HIPAA”). This analysis is relevant for both the breach of fiduciary duty claim and the ECPA claim. Dkt. No. 17 at 17–18, 25–26. Under HIPAA, IIHI is “any information” that “is created or received by a health care provider” and “relates to the past, present, or future physical or mental health or condition of an individual, [or] the provision of health care to an individual” and “with respect to which there is a reasonable basis to believe that the information can be used to identify the individual.” 42 U.S.C. § 1320d(6). Here, ChoicePoint “is a medical provider specializing in addiction treatment services” and each Plaintiff requested an appointment with ChoicePoint through the Website. Dkt. No. 17 at 12. Courts have found public searches for physicians by particular specialty sufficient to allege information “about a present medical condition and the provision of medical care covered by HIPAA.” Cousin v. Sharp Healthcare, 702 F. Supp. 3d 967, 973 (S.D. Cal. 2023). Likewise, the results of Plaintiffs’ addiction survey are plausibly PHI when coupled with Plaintiffs’ requests for appointments. See Nienaber v. Overlake Hosp. Med. Ctr., No. 2:23-cv-01159-TL, 2025 WL 692097, at *6 (W.D.
12 Wash. Mar. 4, 2025) (hereinafter “Nienaber II”) (“[T]he additional disclosure of Plaintiff’s patient status with Defendant makes her other interactions with Defendant’s website, such as searching for particular physicians or researching specific medical conditions, clearly related to the provision of healthcare by Defendant to Plaintiff.”).
16 Accordingly, for purposes of a motion to dismiss, Plaintiffs have adequately alleged the transmission of personally identifiable information (“PII”) and PHI.
18 E. The Motion to Dismiss the Negligence Claim Is Granted.
In Washington, the elements of a negligence claim are “the existence of a duty, a breach thereof, a resulting injury, and proximate causation between the breach and the resulting injury.”
Michaels v. CH2M Hill, Inc., 257 P.3d 532, 542 (Wash. 2011). “[A]ctual loss or damage is an essential element[.]” Krottner v. Starbucks Corp., 406 F. App’x 129, 131 (9th Cir. 2010) (quoting Gazija v. Nicholas Jerns Co., 543 P.2d 338, 341 (Wash. 1975)). Plaintiffs argue the alleged “violation of a privacy right” is sufficient to support negligence damages. Dkt. No. 21 at 13.
2 ChoicePoint argues Plaintiffs’ allegations of actual damages are insufficient and the Court agrees.
3 Washington courts find allegations of actual damages in the form of decreased value in private information to be sufficient when that information is “misappropriated for illegal purposes” like identity theft or increased spam calls. Nunley v. Chelan-Douglas Health Dist., 558 P.3d 513, 523–28 (Wash. Ct. App. 2024) (finding “a person’s means of identification, PII and PHI, can have value and conceivably that value can be diminished or destroyed when their identities are misappropriated for illegal purposes”).
9 In response to ChoicePoint’s motion, Plaintiffs argue that their allegations of a general “invasion of privacy” are sufficient to state a claim for damages under a negligence theory. Dkt.
11 No. 21 at 13. But Plaintiffs’ authority in support of this position is inapposite. Id. at 14 (citing White v. Twp. of Winthrop, 116 P.3d 1034, 1039 (Wash. Ct. App. 2005) (discussing damages under the tort of invasion of privacy); and K.S. v. City of Puyallup, No. 13-5926 RJB, 2014 WL 6071016, at *6–7 (W.D. Wash. Nov. 13, 2014) (finding issues of fact as to whether an invasion of privacy caused damages, but not stating that invasion of privacy alone is a form of cognizable negligence damages)). As in Nienaber II, Plaintiffs “cite[] no support for the proposition that loss of privacy alone can constitute damages for a negligence claim under Washington law.” 2025 WL 692097, at *7.
19 ChoicePoint also challenges Plaintiffs’ “diminution of value” theory of damages. Dkt. No. 17 at 19–20. Plaintiffs do not respond to this argument. Dkt. No. 21 at 13–14. The Court finds that Plaintiffs do allege their information has value (Dkt. No. 13 ¶¶ 94–98), but only make a conclusory allegation that a disclosure diminishes the information’s value (id. ¶ 99). Thus, Plaintiffs do not allege sufficient facts to support this theory of damages.
24 Because the FAC fails to state a valid claim for negligence, the Court dismisses this claim.
1 F. The Motion to Dismiss the Breach of Fiduciary Duty Claim Is Denied.
2 In Washington, a breach of fiduciary duty claim has four elements: “(1) existence of a duty owed, (2) breach of that duty, (3) resulting injury, and (4) that the claimed breach proximately caused the injury.” Priv. Client Fiduciary Corp. v. Chopra, No. 22-CV-00436-LK, 2023 WL 5 2372917, at *6 (W.D. Wash. Mar. 6, 2023) (quoting Micro Enhancement Int’l, Inc. v. Coopers & Lybrand, LLP, 40 P.3d 1206, 1217 (Wash. Ct. App. 2002)). Plaintiffs allege that a fiduciary duty arose “within the scope of Defendant’s relationship with its patients, potential patients and former patients[.]” Dkt. No. 13 ¶ 181. ChoicePoint argues this claim fails because “[t]here is no allegation that Plaintiffs ever became customers or patients of ChoicePoint.” Dkt. No. 17 at 18.
10 In Nienaber II, after observing that no Washington court had addressed “a breach-of- fiduciary claim against a healthcare provider for the disclosure of private information,” the court applied non-Washington authority finding “a confidential and fiduciary duty may arise when a patient trusts the healthcare provider defendant with their confidential health information.” 2025 14 WL 692097, at *12 (citation modified). Although the doctor/patient relationship was clearer in Nienaber II, where the defendant was a hospital, the Court finds that at this stage of the case, the reasoning in Nienaber II also applies here. Plaintiffs allege ChoicePoint was acting as a “medical provider” and that they used the Website to access ChoicePoint’s medical services, including scheduling appointments (Dkt. No. 13 ¶¶ 15, 20, 25, 31), and that in doing so Plaintiffs provided their PHI to ChoicePoint creating a fiduciary duty. See supra Section II(D); Dkt. No. 13 ¶ 9; see A.J. v. LMND Med. Grp., Inc., No. 23-cv-03288-RFL, 2024 WL 4579143, at *4 (N.D. Cal. Oct.
21 25, 2024) (finding allegations sufficient to support a breach of fiduciary claim where “Plaintiffs allege that they entrusted their private medical information to Lemonaid, acting as a healthcare provider, for the purpose of receiving medical care, participating in health assessments, and receiving health-related services” (citation modified)). ChoicePoint’s argument that a disclosure on the Website “makes clear that the Website does not provide medical advice and is for informational purposes only” (Dkt. No. 22 at 3–4) does not undermine the sufficiency of Plaintiff’s allegations because there are no allegations that Plaintiffs saw (or should have seen) this disclaimer.
5 While this claim may ultimately fail on its merits, accepting Plaintiffs’ allegations as true, as the Court must, the Court finds Plaintiffs have sufficiently pleaded that ChoicePoint owed them a fiduciary duty. As ChoicePoint only challenges this element, the Court denies the motion to dismiss the breach of fiduciary duty claim.
9 G. The Motion to Dismiss the Invasion of Privacy Claim Is Granted.
In Washington, an invasion of privacy by publication claim9 “requires publicizing the private affairs of another if the matter publicized would be highly offensive to a reasonable person.” Fisher v. State ex rel. Dep’t of Health, 106 P.3d 836, 840 (Wash. Ct. App. 2005) (citing Reid v. Pierce County, 961 P.2d 333, 338 (Wash. 1998)). For this tort, publicizing “means that the matter is made public, by communicating it to the public at large, or to so many persons that the matter must be regarded as substantially certain to become one of public knowledge.” Emeson v. Dep’t of Corr., 376 P.3d 430, 442 (Wash. Ct. App. 2016) (citing RESTATEMENT (SECOND) OF TORTS § 652D cmt. a. (AM. L. INST. 1977)). Plaintiffs allege that their information was shared with Google and Facebook and that Plaintiffs then “began seeing targeted online advertisements for addiction treatment services.” Dkt. No. 13 ¶¶ 18, 23, 28, 34. ChoicePoint argues Plaintiffs fail to allege their information was publicized or that its publication would be highly offensive. Dkt.
21 No. 17 at 15–17. The Court agrees that Plaintiffs fail to allege their information was communicated to the “public at large” sufficient to support a claim for invasion of privacy.
9 Although the FAC labels the invasion of privacy claim as “intrusion upon seclusion[,]” Plaintiffs confirmed at oral argument that their claim is for invasion of privacy by publication. Dkt. No. 13 at 44.
1 Two recent decisions in this district have dismissed invasion of privacy by publication claims on similar facts. First, in Nienaber v. Overlake Hospital Medical Center, the court dismissed the invasion of privacy by publication claim because “[t]he disclosure of PHI or PII to Facebook and Google” did not meet the standard for publication to the “public at large[.]” 733 F. 5
1 Accordingly, Plaintiffs fail to allege their information was published and the invasion of privacy claim must be dismissed.
3 H. The Motion to Dismiss the Implied Contract Claim Is Granted.
4 “To prevail on a breach of implied contract claim, a plaintiff must demonstrate that [an] implied contract exists based on the acts of the parties involved and in light of the surrounding circumstances.” Nienaber II, 2025 WL 692097, at *10. At the motion to dismiss stage, this requires allegations of an offer, acceptance to the terms of that offer, the acceptance is communicated to the offeror, a mutual intent to contract, and a meeting of the minds of the parties.
9 Krottner, 406 F. App’x at 131. Plaintiffs allege they entered an implied contract with ChoicePoint through ChoicePoint’s promises in its Privacy Policy (Dkt. No. 21 at 15) and by providing “their Sensitive Information to Defendant in exchange for services” (Dkt. No. 13 ¶ 194). Both theories fail.
13 First, the existence of the Privacy Policy does not advance Plaintiffs’ claim when Plaintiffs do not allege that they reviewed the Privacy Policy before providing their information to ChoicePoint. See Dkt. No. 13 ¶¶ 14–34; Krottner, 406 F. App’x at 131 (finding plaintiffs’ attempt to characterize documents as an implied contract fails where they did not allege that they reviewed the documents, considered them an offer, or accepted the offer). Plaintiffs’ sole conclusory allegation that they “relied on the statements made by Defendant, including in its Privacy Policy” (Dkt. No. 13 ¶ 133) is insufficient, especially when Plaintiffs also allege that reading such privacy policies is “practically impossible” (id. ¶ 57).
21 Second, simply alleging Plaintiffs provided information in exchange for services is insufficient to support the existence of an implied contract because “the services giving rise to the contract must be rendered under such circumstances as to indicate that the person rendering them expected to be paid therefore[.]” Nienaber I, 733 F. Supp. 3d at 1091 (cleaned up). Plaintiff does not allege any such circumstances.
3 The Court therefore dismisses the implied contract claim.
4 I. The Motion to Dismiss the Unjust Enrichment Claim Is Denied.
5 To state a claim for unjust enrichment, Plaintiffs must show that: (1) Plaintiffs conferred a benefit upon ChoicePoint, (2) at Plaintiffs’ expense, and (3) the circumstances make it unjust for ChoicePoint to retain the benefit without payment. Young v. Young, 191 P.3d 1258, 1262 (Wash. 2008). ChoicePoint’s sole argument for dismissing the unjust enrichment claim is that “the enrichment must relate to two parties to a transaction.” Dkt. No. 17 at 24 (citing MCG Health Data, 2023 WL 3057428, at *5–6). This is not an element of unjust enrichment and ChoicePoint misreads the authority it cites.
12 In MCG Health Data, the court dismissed an unjust enrichment claim explaining 13 Plaintiffs’ allegations are insufficient to show a claim for unjust enrichment.
Plaintiffs do not allege that they entered into a transaction with MCG Health.
14 Rather, Plaintiffs allege Plaintiffs’ medical provider entities contracted with MCG Health to provide services to the medical providers. Plaintiffs also do not allege 15 facts showing they conferred a benefit to MCG Health. Again, the medical providers sought a service and provided payment for that service. Because Plaintiffs 16 failed to allege a transaction between Plaintiffs and MCG Health, Plaintiffs have failed to plead an unjust enrichment claim. 2023 WL 3057428, at *6. The term “transaction” as used in MCG Health does not require allegations that Plaintiffs “pay monies to Defendant” to support an unjust enrichment claim, as ChoicePoint argues. Dkt. No. 17 at 24. Instead, MCG Health requires Plaintiffs to have conferred a benefit directly on ChoicePoint, which Plaintiffs sufficiently allege. See Dkt. No. 13 ¶¶ 5–8, 92– 93, 202; see Nienaber II, 2025 WL 692097, at *11 (providing PII and PHI to defendant provides “a benefit upon Defendant for purposes of her unjust enrichment claim”). ChoicePoint’s sole argument for dismissing the unjust enrichment claim fails. Thus, the motion to dismiss the unjust enrichment claim is denied.
3 J. The Motion to Dismiss the ECPA Claim Is Denied.
4 The ECPA “prohibits a person from intentionally using or disclosing to any other person ‘the contents’ of an intercepted electronic communication.” Castillo, 2024 WL 4785136, at *4 (quoting 18 U.S.C. § 2511(1)(c)–(d)). The ECPA contains an exception for the parties to the communication, unless the communication is “intercepted for the purpose of committing any criminal or tortious act[.]” 18 U.S.C. § 2511(2)(d).
9 Plaintiffs allege ChoicePoint violated ECPA when it “intercepted Plaintiffs’ and Class Members’ electronic communications via the Pixels, which tracked, stored, and unlawfully disclosed Plaintiffs’ and Class Members’ Private Information to third parties such as Google.”
12 Dkt. No. 13 ¶ 220. ChoicePoint argues this claim fails because (1) Plaintiffs consented to the disclosure of their information via the Privacy Policy, (2) Plaintiffs fail to allege the content of any communications were intercepted, and (3) there is not an underlying criminal or tortious purpose to the alleged interceptions. Dkt. No. 17 at 25–28. For the following reasons, the Court finds these arguments unpersuasive.
17 First, regarding consent, Plaintiffs do not allege they saw or reviewed the Privacy Policy.
18 Accordingly, because Plaintiffs’ allegations do not suggest that they could have consented to ChoicePoint’s disclosure, the consent argument fails.
20 Second, ChoicePoint argues that under In re Zynga Privacy Litigation, 750 F.3d 1098 (9th Cir. 2014), the survey results and appointment requests allegedly transmitted to Google and Facebook are not “the contents of an intercepted electronic communication” for purposes of ECPA. Dkt. No. 17 at 27. Zynga does not support ChoicePoint’s argument. In that case, the Ninth Circuit held “that under ECPA, the term ‘contents’ refers to the intended message conveyed by the communication, and does not include record information regarding the characteristics of the message that is generated in the course of the communication.” 750 F.3d at 1106. The decision went on to hold that a “referrer header” that includes “the user’s Facebook ID and the address of the webpage from which the user’s HTTP request to view another webpage was sent” was not the “contents” of a communication under ECPA. Id. at 1107.
6 But, as many other courts have found, the information Plaintiffs allege was intercepted by ChoicePoint here—that Plaintiffs sought an appointment for addiction treatment services and the outcome of their online assessment—does constitute the “contents” of the communication under ECPA, as defined by Zynga, because that information constitutes the substance, purpose, and meaning of the message. See, e.g., Doe v. Tenet Healthcare Corp., No. 1:23-cv-01106-DC-CKD, __ F. Supp. 3d __, 2025 WL 1635956, at *13 (E.D. Cal. June 9, 2025) (finding “detailed URLs disclosed to Meta included a combination of PHI and PII, such as health information (appointments, medical conditions, diagnoses, treating physicians) and IP addresses, [Facebook] IDs, and device identifiers” were ECPA “contents,” as applied to the California Invasion of Privacy Act); Zarif v. Hwareh.com, Inc., No. 23-cv-0565-BAS-DEB, __ F. Supp. 3d __, 2025 WL 16 486317, at *7 (S.D. Cal. Feb. 13, 2025) (holding “searches for prescription medication” concern the “substance, purport, or meaning of that communication” for ECPA purposes); Castillo, 2024 18 WL 4785136, at *5 (URLs related to searches for a specific prescription constitute ECPA “contents”). Plaintiffs sufficiently allege the “contents” of their communications were intercepted.
20 Third, ChoicePoint relies on the fact that it is a party to the communications to argue that it is exempt from ECPA liability for its use of the communications here. But Plaintiffs’ allegations invoke the crime-tort exception to the exemption for parties to the communications: they allege ChoicePoint disclosed their communications with intent to violate HIPAA. Dkt. No. 13 ¶¶ 100– 127, 227. ChoicePoint argues that the alleged HIPAA violation and the ECPA violation are one and the same and thus the HIPAA-related allegations are insufficient to independently invoke the crime-tort exception. Dkt. No. 17 at 25–26. Multiple courts have rejected this argument, concluding that an intent to disclose or use private information in violation of HIPAA is distinct from the interception of the private information. See R.S. v. Prime Healthcare Servs., Inc., No. 5:24-cv-00330-ODW (SPx), 2025 WL 103488, at *6 (C.D. Cal. Jan. 13, 2025) (“R.S. asserts that the violation stems from Prime Healthcare’s intentional disclosure of the collected Private Information, which constitutes a ‘further impropriety’ independent and separate from Prime Healthcare’s interception.” (quoting Weston v. Lefiti, No. 24-541, 2024 WL 4579237, at *2 (9th Cir. Oct. 25, 2024))); Castillo, 2024 WL 4785136, at *5 (“The Court concludes that alleging a defendant intercepted data to use the data in violation of criminal or tort laws suffices to invoke the crime-tort exception.”); Gaige, 2025 WL 559719, at *5; K.L. v. Legacy Health, No. 3:23-cv- 1886-SI, 2024 WL 4794657, at *6 (D. Or. Nov. 14, 2024). Plaintiffs sufficiently allege that ChoicePoint’s intent to disclose their information in violation of HIPAA is a separate act from the interception of their data.
15 ChoicePoint also argues the private information here is not subject to HIPAA because Plaintiffs’ “information [was] provided through a public website accessible to anyone as opposed to a private patient portal.” Dkt. No. 17 at 26. But whether the PHI was provided through a public webpage or patient portal is “immaterial” and courts have found information that identifies an individual and relates to a health condition can support the HIPAA crime-tort exception for ECPA liability, regardless of whether a webpage was publicly accessible. See Castillo, 2024 WL 21 4785136, at *7 (“Costco may have collected data that ‘relates to’ Plaintiffs’ individualized health conditions even though they do not allege that their data were collected while they were logged into their patient portals.”). Here, Plaintiffs scheduled appointments with ChoicePoint, which specializes in addiction treatment services, and that combination of information is HIPAA- protected. See supra, Section II(D).
3 Again, while this claim may ultimately fail on the merits, the Court finds that the ECPA claim has been adequately pleaded.
5 K. The Motion to Dismiss the OCSPA and the IDCSA Claims Is Granted.
6 In Ohio, “[n]o supplier shall commit an unfair or deceptive act or practice in connection with a consumer transaction.” OHIO REV. CODE ANN. § 1345.02(A). The OCSPA defines “consumer transaction” as “a sale, lease, assignment, award by chance, or other transfer of an item of goods, a service, a franchise, or an intangible, to an individual for purposes that are primarily personal, family, or household, or solicitation to supply any of these things.” OHIO REV. CODE ANN. § 1345.01(A). Similarly, in Indiana, “[a] supplier may not commit an unfair, abusive, or deceptive act, omission, or practice in connection with a consumer transaction.” IND. CODE § 24- 5-0.5-3(a). The IDCSA defines “consumer transaction” as “a sale, lease, assignment, award by chance, or other disposition of an item of personal property, real property, a service, or an intangible[.]” IND. CODE § 24-5-0.5-2(a)(1). Thus, a “consumer transaction” is required to state a claim under the OCSPA or the IDCSA. See Ferron v. Zoomego, Inc., 276 F. App’x 473, 475 (6th Cir. 2008) (OCSPA); IUE-CWA Loc. 901 v. Spark Energy, LLC, 440 F. Supp. 3d 969, 975 (N.D. Ind. 2020) (IDCSA).
19 ChoicePoint argues Plaintiffs fail to sufficiently allege a consumer transaction and the Court agrees. Dkt. No. 17 at 29–31. For both claims, Plaintiffs allege: “Defendant’s advertisement of, and statements made to solicit [Plaintiffs] to contract to receive its addiction rehabilitation services through its Website, including in its Privacy Policy, are ‘consumer transactions[.]’” Dkt.
23 No. 13 ¶¶ 241, 247. But Plaintiffs do not allege they saw any advertisements or that ChoicePoint made any statements to them. Dkt. No. 13 ¶¶ 14–34. And as explained above, no Plaintiff alleges they saw the Privacy Policy. Moreover, Plaintiffs cite no authority suggesting that the mere existence of a website, even if it operates “as marketing for a company’s services,” constitutes a solicitation that would create a “consumer transaction” for the purposes of either statute. Dkt. No. 21 at 21. In support of this argument, Plaintiffs cite only an agreed order entered for settlement purposes that does not include any relevant analysis. See id. (citing State ex rel. Dewine v. Classmates, Inc., No. 15CV004418, 2015 Ohio Misc. LEXIS 14991, at *14 (Ct. Com. Pl. June 5, 2015)). Accordingly, the OCSPA and the IDCSA claims fail because Plaintiffs fail to allege any consumer transactions.
9 L. The Motion to Dismiss the Washington CPA Claim Is Granted.
10 The Washington CPA prohibits “unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce[.]” WASH. REV. CODE § 19.86.020. “To prevail on a CPA claim, ‘the plaintiff must prove (1) an unfair or deceptive act or practice, (2) occurring in trade or commerce, (3) affecting the public interest, (4) injury to a person’s business or property, and (5) causation.’” Gray v. Amazon.com, Inc., 653 F. Supp. 3d 847, 857 (W.D. Wash. 2023) (quoting Panag v. Farmers Ins. Co. of Washington, 204 P.3d 885, 889 (Wash. 2009)), aff’d, No. 23-35377, 2024 WL 2206454 (9th Cir. May 16, 2024).
17 Plaintiffs allege ChoicePoint violated the CPA by (1) “[f]alsely promising that it would keep confidential and not disclose” their sensitive information, (2) “[f]ailing to inform” Plaintiffs that it would disclose their information to “third parties in exchange for advertising and marketing services[,]” and (3) “[s]urreptitiously collecting and sharing” Plaintiffs’ information with third parties. Dkt. No. 13 ¶ 252. ChoicePoint challenges the sufficiency of Plaintiffs’ alleged unfair acts, causation, and injury. Dkt. No. 17 at 32–33.
23 First, ChoicePoint argues “Plaintiffs fail to plead any detail as to when ChoicePoint ‘falsely promised’ it would keep Plaintiffs’ Sensitive Information confidential and not disclose it to any third parties.” Dkt. No. 17 at 32. The Court agrees with ChoicePoint that Plaintiffs’ allegation of a false promise fails to identify an unfair act because it is based on the Privacy Policy that no Plaintiff alleges to have seen. See Dkt. No. 21 at 23 (Plaintiffs arguing the Privacy Policy as the basis for the false promise).
5 Second, regarding the failure to inform Plaintiffs about the tracking and the “surreptitious collecting and sharing[,]” ChoicePoint argues “Plaintiffs have also not properly plead [sic] causation in that their alleged injury would not have occurred but for ChoicePoint’s allegedly unfair or deceptive acts.” Dkt. No. 17 at 32. Plaintiffs did not respond to this argument in their briefing. See Dkt. No. 21 at 23–24. Due to this failure to respond, and the lack of clear causation allegations (Dkt. No. 13 ¶¶ 251–254), the Court agrees with ChoicePoint and finds Plaintiffs have failed to allege facts supporting the causation element of their CPA claim. Thus, the Court need not address ChoicePoint’s remaining arguments for dismissing the CPA claim.
13 For these reasons, the Court grants the motion to dismiss the CPA claim.
14 M. The Court Will Grant Leave to Amend.
15 As explained in this order, the Court finds multiple deficiencies in some of Plaintiffs’ claims. If a complaint fails to state a plausible claim, “[a] district court should grant leave to amend even if no request to amend the pleading was made, unless it determines that the pleading could not possibly be cured by the allegation of other facts.” Lopez v. Smith, 203 F.3d 1122, 1130 (9th Cir. 2000) (quoting Doe v. United States, 58 F.3d 494, 497 (9th Cir. 1995)). The Court does not find the deficiencies in Plaintiffs’ claims “could not possibly” be cured, thus the Court grants leave to amend.
22 III. CONCLUSION 23 For these reasons, the Court GRANTS IN PART and DENIES IN PART Defendant’s motion to dismiss. Dkt. No. 17.
1 Defendant’s motion is GRANTED as to Plaintiffs’ claims for invasion of privacy, breach of an implied contract, negligence, and violations of the OCSPA, IDCSA, and CPA, which are dismissed with leave to amend.
4 Defendant’s motion is DENIED as to Plaintiffs’ ECPA, breach of fiduciary duty, and unjust enrichment claims.
6 Plaintiffs may file an amended complaint by September 26, 2025.
7 Dated this 29th day of August, 2025.
A Kymberly K. Evanson 10 United States District Judge
Case-law data current through December 31, 2025. Source: CourtListener bulk data.