Health Law Daily Wrap Up, GENERAL HEALTH CARE NEWS—E.D. Cal.: United Healthcare secures dismissal of putative class action over website tracking technologies, (Aug 25, 2026)
Law Firms Mentioned:Hogan Lovells Cadwalader US LLP | Potter Handy, LLP
Organizations Mentioned:AARP | Raido Fund Ltd. | Surgis Management Services, Inc. | United Healthcare Services, Inc.
By Ravindra Kumar Singh, B.L.
Medicare plan browsing and device-tracking data did not reveal sufficiently sensitive health information to establish a concrete privacy injury for Article III standing.
United Healthcare Services, Inc. (UHC) has secured dismissal with prejudice of a putative class action alleging that third-party tracking technologies on its website unlawfully collected and transmitted users' information. A federal district court in California concluded that a website visitor still failed to establish Article III standing after amending her complaint to identify the tracking technologies and information allegedly collected while she researched Medicare supplement coverage. Her clicks, ZIP code, device identifiers, and other browsing data did not disclose sensitive medical information comparable to the privacy interests traditionally protected at common law. Because counsel acknowledged that no additional factual allegations could cure the standing deficiency, the court dismissed the action without further leave to amend (Magliocca v. United Healthcare Services, Inc., No. 2:25-cv-3388-WBS-SCR (E.D. Cal. Aug. 19, 2026)).
Website tracking. The dispute arose from UHC's use of third-party tracking technologies on its website. The visitor initially sued in California state court, asserting claims under the California Invasion of Privacy Act (CIPA), the federal Electronic Communications Privacy Act (ECPA), the California Computer Data Access and Fraud Act (CDAFA), and the California Constitution. UHC removed the putative class action to federal court and obtained dismissal of the original complaint because the visitor had not alleged a constitutionally sufficient injury-in-fact. The court permitted amendment.
The amended complaint provided considerably more detail about the visitor's interaction with UHC's website. In July 2025, she allegedly followed a Facebook advertisement to research Medicare supplement coverage, entered her ZIP code, viewed plans available in Yuba County, selected Plan G and an AARP-endorsed Medicare option, and clicked to learn more about the plan. She did not enroll or begin the enrollment process.
According to the amended allegations, UHC deployed 155 third-party trackers, including 47 cookies, 19 canvas fingerprints, and a session recorder. The technologies allegedly captured information including page URLs and titles, clickstream events, ZIP-code-associated location signals, plan-selection information, persistent identifiers, browser and device identifiers, mouse movements, scrolling, and keystrokes. The visitor also alleged that the tracking resulted in targeted advertisements for UHC and other health insurance offerings appearing on other websites and social-media platforms.
Privacy injury. Those additional allegations did not establish a concrete injury sufficient for Article III standing. Although an intangible invasion of privacy can qualify as an injury in fact, the asserted harm must bear a close relationship to a harm traditionally recognized as actionable.
The Ninth Circuit's decision in Popa v. Microsoft Corporation, 153 F.4th 784 (9th Cir. 2025), was central to the analysis. There, collection of routine website interaction data, including mouse movements, clicks, keystrokes, URLs, and other electronic communications, did not establish standing where no embarrassing, invasive, or otherwise private information was collected. Such activity was more comparable to a store clerk observing shoppers than to the highly offensive intrusion or disclosure traditionally actionable at common law.
The amended complaint did not bridge that gap. Despite the sophistication and number of tracking technologies allegedly deployed, the information collected from the visitor's interaction with the website revealed little more than an interest in an AARP-endorsed Medicare insurance plan available within a particular ZIP code. The session-recording allegations likewise identified no input revealing medical conditions, treatment, medical history, physician information, appointments, or other individualized health information. The only information the visitor personally entered was her ZIP code.
Health information. Characterizing the browsing activity as reflecting "private health-insurance interests and financial-coverage preferences" did not transform it into sensitive health information. The court distinguished the alleged tracking from cases involving detailed profiles assembled through extensive online and offline monitoring.
In In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589 (9th Cir. 2020), for example, the Ninth Circuit recognized a privacy injury where tracking could compile a detailed profile of an individual's likes, dislikes, interests, and habits over a significant period. Here, by contrast, the alleged tracking involved a single visit to UHC's website and generic browsing of publicly available insurance information.
Nor did the visitor's selection of an AARP-endorsed Medicare plan sufficiently disclose sensitive age-related information. She did not provide a birth date or other specific demographic information, and a person researching such coverage could have been doing so for a relative rather than for herself. Inferring sensitive personal information from such a generic search would therefore be speculative.
The court also distinguished cases involving searches directly related to medical care. As explained in Harrill v. Emmanuel Medical Center, No. 23-cv-1672, 2025 WL 1635428 (E.D. Cal. June 9, 2025), searches concerning healthcare services may reveal sensitive medical information when they concern matters such as physicians, medical conditions, appointments, patient portals, or personalized health information. Nothing comparable was alleged here. The information captured remained non-sensitive browsing activity on a single website.
The amended complaint's separate assertion of monetary loss also did not establish standing because it remained conclusory and unsupported by facts describing any actual economic injury.
Having again found no concrete injury, the court lacked jurisdiction to reach the merits of the CIPA, ECPA, CDAFA, and California constitutional privacy claims. Because counsel represented at the hearing that no further factual allegations could be added to cure the standing deficiencies, another opportunity to amend was unwarranted.
Accordingly, UHC's motion to dismiss the first amended complaint was granted, and the putative class action was dismissed with prejudice.
The case is No. 2:25-cv-3388-WBS-SCR.
Judge: Shubb, W.
Attorneys: James Michael Treglio (Potter Handy, LLP) for Joanne Magliocca. Adam A. Cooke, PHV (Hogan Lovells Cadwalader US LLP) for United Healthcare Services, Inc.
Companies: United Healthcare Services, Inc.
Cases: CaseDecisions FederalLegislation GeneralNews CyberPrivacyFeed DataPrivacy CaliforniaNews