Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • FTC Intends to Police Retailers’ Use of ‘Surveillance Pricing’
    • D. Mass.: Most Meta Pixel, Google Analytics website tracking privacy claims against hospital survive dismissal
    • Financial Regulator Urged to Close Gap Exploited by Cyber Thieves
    • Latvian Regulator Outlines Methodology of Response to Personal Data Leaks
    • Nonprofit Appeals Denial of Cybersecurity Pilot Program Funding
    • Power Inverters Eligible for Clean-Energy Tax Credits Removed From FCC’s Covered List
    • TCPA, Fax, Robocall Petitions Deemed ‘Moot’ by FCC Bureau
    • U.K. Privacy Agency Highlights Parental Concerns About Children’s Online Activities
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, D. Mass.: Most Meta Pixel, Google Analytics website tracking privacy claims against hospital survive dismissal, (Aug 20, 2026)

    Law Firms Mentioned:McDermott Will & Schulte LLP | Shapiro Haber & Urmy LLP
    Organizations Mentioned:Apex Silver Mines, Ltd. | Beth Israel Deaconess Medical Center | Beth Israel Deaconess Medical Center, Inc. | McDermott Will & Emery, LLP | Shapiro Haber & Urmy, LLP | Wintherix, LLC

    By Justin Marcus Smith, J.D.

    The hospital waived arguments that might have distinguished the consumer as a non-patient under Massachusetts law.

    A consumer who was not a patient of a hospital sufficiently pleaded putative class action claims for invasion of privacy, breach of impl ...

    By Justin Marcus Smith, J.D.

    The hospital waived arguments that might have distinguished the consumer as a non-patient under Massachusetts law.

    A consumer who was not a patient of a hospital sufficiently pleaded putative class action claims for invasion of privacy, breach of implied contract, and other claims in connection with allegations that the hospital used Meta and Google website tracking technologies to disclose personal health information (PHI) without consent and contrary to representations, held the federal district court in Boston, Massachusetts. As for the invasion of privacy claim, the court held the consumer’s communications about her search for providers and specific medical procedures for herself constituted medical information of a highly intimate or personal nature under state law. The hospital waived a potential distinction that the consumer was not a patient. Based on the same allegations, the Electronic Communications Privacy Act (ECPA) claim also survived the hospital’s motion to dismiss because the crime-tort exception to one-party consent did not apply. The breach of fiduciary duty claim survived because hospitals have a professional duty not to disclose PHI without consent. Massachusetts courts have repeatedly recognized a fiduciary relationship between hospitals and patients, and the hospital again waived a potential distinction that the consumer was not a patient. The consumer otherwise alleged sufficient facts to infer a plausible fiduciary relationship based on placement of trust and confidence. The consumer also sufficiently pleaded the elements of a negligence claim and a claim for breach of implied contract insofar as the hospital allegedly disclosed the consumer’s PHI to Meta and Google. The equitable cause of action for unjust enrichment could proceed in parallel for now. Breach of confidence was the only claim that did not survive the hospital’s dismissal motion because no precedent supported it as an independent claim. The court accordingly denied dismissal in part, but granted dismissal in part only as to the breach of confidence claim (Vita v. Beth Israel Deaconess Medical Center, Inc., No. 1:25-cv-11383-JEK (D. Mass. Aug. 14, 2026)).

    Background. A consumer brought a putative class action against a medical center (hospital) for the unconsented disclosure of patient medical information and private medical information of users of the hospital website. The consumer alleged the hospital installed Meta Pixel and Google Analytics user tracking technology on its public website to intercept user communications and then transmit the collected confidential information to Meta Platforms, Inc. (Meta) and Google LLC (Google). The consumer, while not a patient of the hospital, alleged the hospital misused confidential medical information collected from her use of the website, including her use of the “Find a Doctor” feature for providers and searches for information about treatment for herself and her husband, despite certain alleged assurances of confidentiality. She also said she regularly used the website to access her husband’s private medical records through the patient portal. Meta and Google, meanwhile, allegedly directed website owners to disclose the use of collected data.

    The consumer initially brought her suit in state court in 2023 asserting a single claim under the Massachusetts Wiretap Act, M.G.L. c. 272, § 99. After the state court held that statute did not prohibit the hospital’s conduct, the consumer filed an amended complaint under the Electronic Communications Privacy Act (ECPA), 18 U.S.C. § 2511, and several state-law claims. The hospital invoked federal question jurisdiction and removed the case to federal district court.

    The consumer asserted claims in a second amended complaint (SAC) for violation of ECPA; invasion of privacy in violation of M.G.L. c. 214, § 1B (Section 1B); breach of fiduciary duty; negligence; breach of confidence; breach of contract; and unjust enrichment. The consumer sought to represent a class of Massachusetts residents who similarly accessed the hospital website from February 25, 2020, to the date the hospital removed the website tracking technologies. The hospital filed a Fed. R. Civ. P. 12(b)(6) motion to dismiss for failure to state a claim.

    Privacy invasion. Applying precedents, the court held the consumer’s communications about her search for providers and specific medical procedures for herself constituted medical information of a highly intimate or personal nature under Section 1B. The hospital argued the information it allegedly shared with Meta and Google was de minimis under the state invasion of privacy law because the information was not of a highly personal or intimate nature. However, the court noted that Massachusetts courts have repeatedly declined to dismiss similar claims for comparable invasions of privacy. The hospital, meanwhile, waived at this stage whether those cases might be factually distinct insofar as the instant consumer was not a patient.

    The hospital’s next argument was that it had a legitimate marketing interest, including the promotion of targeted advertising, in sharing the consumer’s confidential information with Google and Meta. However, the court said the hospital had raised a question of fact here which could not be resolved on a motion to dismiss. The consumer adequately alleged an invasion of privacy claim under Section 1B.

    ECPA. The court held the SAC sufficiently alleged that the hospital acted with the purpose of committing a tortious act in violation of Section 1B, which also qualified as a violation of ECPA under the crime-tort exception to the ECPA one-party consent rule. Under ECPA, all agreed that the hospital was a party to the communications at issue in this case; however, the ECPA one-party consent-to-intercept rule has a crime-tort exception. The consumer relied on the crime-tort exception to hold the hospital liable under ECPA.

    The court found the consumer plausibly alleged that the hospital intentionally intercepted her website communications for the purpose of committing a tortious act in violation of ECPA, i.e., the impropriety of disclosing PHI without consent. The alleged tort consisted of the hospital affirmatively misleading the consumer that it was only collecting data on an aggregated, anonymized basis, and that it would not share any information received with any outside parties, and that it did these things to advance its own financial self-interest. The court ruled this was enough, at this early stage, to infer the impropriety of PHI disclosure without consent.

    The court continued that the allegations that the hospital installed the tracking technologies for marketing and commercial gain, which might be lawful purposes, did not preclude the possibility that the data collection was also done for a tortious or unlawful purpose. Again, this involved a fact question unfit for resolution at the pleading stage.

    The court noted the consumer also adequately alleged that the hospital’s tortious purpose was separate and independent of the act of the recording. Some courts have held that the common law privacy claim of intrusion upon seclusion cannot satisfy ECPA’s tortious intent requirement because it is a tort that occurs through the act of interception itself. Here, the consumer alleged the hospital acted with the purpose of violating the Section 1B state statute when it intercepted her communications containing confidential medical information, but this did not occur through interception itself. Rather, the purpose was the use of the acquired communications, unconsented disclosure to Meta and Google. Interception was distinct from the plan to disclose; therefore, the crime-tort exception applied to the ECPA one-party consent rule.

    The hospital attempted to argue that the tracking technologies were not a “device” under ECPA because it used them in the ordinary course of its business. Though undefined in the statute, the First Circuit has held that a “device” must be part of “routine” practice. The court ruled this an affirmative defense not clearly made out on the face of the pleadings. The hospital did not suggest it used Meta Pixel and Google Analytics routinely. The consumer alleged, to the contrary, that the technologies were not necessary to the hospital running its website and that it had no legitimate reason to falsely promise privacy and then, without notice, share users’ medical information with Meta and Google. The SAC did not leave the ECPA claim facially barred under the business-use exception.

    Next, the hospital attempted to argue that its alleged disclosures to Meta and Google did not qualify as ECPA “contents.” The broad ECPA definition of contents encompasses personally identifiable information (PII), like party name, date of birth, and medical condition. The hospital argued the consumer did not plead disclosure of confidential information because mere web browsing could not identify an individual or the individual’s PHI, but the court said that ignored the details of the pleading. The consumer alleged disclosure of requests for information about particular conditions and treatments. The alleged details qualified as ECPA contents.

    Fiduciary breach. The court held the consumer sufficiently pleaded a breach of fiduciary duty claim against the hospital. The hospital contended that a hospital, unlike a physician, does not owe a fiduciary duty to patients. However, the court noted that hospitals, as part of the medical profession, indeed have a professional duty not to disclose PHI without consent. Massachusetts courts have repeatedly recognized a fiduciary relationship between hospitals and patients. The hospital again waived a potential distinction that the consumer was not a patient, and the consumer otherwise alleged sufficient facts to infer a plausible fiduciary relationship based on placement of trust and confidence.

    The hospital maintained that the consumer still failed to allege breach of that duty or causally connected damages, but the court found that did not follow from the facts alleged about secret and unauthorized PHI, including searches for providers and specific medical procedures, to Meta and Google. The consumer sought compensatory damages for injuries in the form of unauthorized transmission of confidential information; receipt of unwanted targeted advertisements based on that improperly intercepted and disclosed information; loss of benefit of the bargain in not obtaining compensation for use of the information; and a reduction in substantial value of such information. Taken together, the allegations sufficiently stated a breach of fiduciary duty claim.

    Negligence. The consumer stated a plausible claim for negligence. The district court cited how the Massachusetts Supreme Judicial Court (SJC) has explained that the Massachusetts legislature favors confidentiality of medical facts. The legislature enacted a statute limiting the availability of hospital records. The fact that other hospitals may have also used Meta Pixel and Google Analytics was no defense. The consumer also alleged harm. The allegations sufficiently pleaded the necessary duty, breach, causation, and damages elements of a negligence claim.

    The hospital invoked the economic loss doctrine. Purely economic losses are usually unrecoverable in tort or strict liability actions without personal injury or property damage, but the court said Massachusetts courts have not applied the economic loss doctrine to fiduciary negligence claims. Since the court already found the hospital a plausible fiduciary, the economic loss doctrine could not apply at this stage.

    Confidence breach. The court agreed with the hospital that Massachusetts law does not recognize an independent claim for breach of confidence. The court declined to infer that such a claim exists where there was no binding precedent for it. The court dismissed the breach of confidence claim accordingly.

    Contract breach. The consumer plausibly alleged that the hospital breached an implied contract by disclosing her confidential medical information to Meta and Google. The hospital facially agreed not to disclose the disputed information to third parties, without consent, in exchange for the consumer submitting it.

    The hospital’s arguments for dismissal were unpersuasive. The consumer did not need to allege that the hospital assented to the implied contract. The consumer also pleaded consideration. There was no reason to dismissal the claim for breach of implied contract at this stage.

    Unjust enrichment. The SAC plausibly stated an equitable cause of action for unjust enrichment by alleging that the hospital knowingly profited from the consumer’s medical information without consent. Contrary to the hospital’s assertion, the alleged benefits received were sufficiently measurable. While damages for breach of contract and unjust enrichment are mutually exclusive, the court said it was accepted practice to permit both theories to proceed at the pleading stage. The court further explained it was premature to presuppose a valid underlying express contract.

    The case is No. 1:25-cv-11383-JEK.

    Judge: Kobick, J.

    Attorneys: Patrick J. Vallely (Shapiro Haber & Urmy LLP) for Kathleen Vita. David Q. Gacioch (McDermott Will & Schulte LLP) for Beth Israel Deaconess Medical Center, Inc.

    Companies: Beth Israel Deaconess Medical Center, Inc.

    Cases: CaseDecisions StateLegislation EHRNews GeneralNews HealthReformNews HIPAANews CyberPrivacyFeed DataPrivacy MassachusettsNews DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use