Cybersecurity Policy Report, S.D. Ill.: Allegations about tailored Meta health ads form plausible basis for ECPA claims against hospital, (Oct 8, 2025)
Law Firms Mentioned:Baker & Hostetler LLP | Cohen & Malad, LLP
Organizations Mentioned:BakerHostetler | Deaconess Illinois Union County Hospital, Inc. d/b/a Deaconess Illinois Union County d/b/a Union County Hospital
By Justin Marcus Smith, J.D.
The court said it was satisfied the patient alleged capture and improper disclosure of IIHI under HIPAA such that she could invoke the ECPA crime-tort exception.
A patient’s putative class action claims against an Illinois hospital for negligence and violation of Section 2511(1) of Electronic Communications Privacy Act (ECPA or Wiretap Act), in connection with Meta’s Pixel or similar web tracking technology, survived a motion to dismiss, held the federal district court in East St. Louis, Illinois. All of the patient’s other claims failed for various reasons, so the court dismissed them without prejudice (Doe v. Deaconess Ill. Union Cty. Hosp., Inc., No. 3:24-cv-02284-NJR (N.D. Ill. Sept. 29, 2025)).
Background. A patient brought a putative class action against Deaconess Illinois Union County Hospital (hospital) for allegedly causing her protected health information (PHI) and personally identifying information (PII) to be transmitted to unauthorized third parties, including Meta Platforms, Inc. (Meta), Google, LLC (Google), DoubleClick Ads, and Microsoft Corp. (Microsoft) (collectively, the third parties) by means of website data tracking technology, e.g., Meta’s Pixel. The patient alleged the hospital, Meta, and the other third parties exploited data collected from patient internet use for profit. The patient said she saw medical advertisements in her Facebook feed about the medical conditions and symptoms she searched for and viewed on the hospital’s website.
The patient asserted the following claims:
negligence;
negligence per se;
invasion of privacy—intrusion upon seclusion;
breach of express contract;
breach of implied contract;
unjust enrichment;
breach of bailment;
violation of the Illinois Eavesdropping Statute (IES), 720 ILCS 5/14, et seq.;
violation of the Electronic Communications Privacy Act (ECPA or Wiretap Act), 18 U.S.C. § 2511(1), et seq.;
violation of ECPA, 18 U.S.C. § 2511(3)(a), for unauthorized divulgence;
violation of the Stored Communications Act (SCA), 18 U.S.C. § 2701, et seq.; and,
violation of the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, et seq.;
The patient proposed to represent a nationwide class consisting of all Deaconess hospital patients whose private information Deaconess disclosed to third parties through the Meta Pixel and related technology without authorization. The patient also proposed to represent an Illinois subclass of patients likewise defined and affected. The hospital moved to dismiss for failure to state a claim pursuant to Fed. Reg Civ. P. 12(b)(6). The court granted dismissal in part and denied dismissal in part.
Negligence claims. The negligence claims (counts i, ii) survived dismissal because Illinois recognizes negligence claims can be based on one’s emotional damages. The patient alleged embarrassment, humiliation, frustration, and emotional distress.
Invasion of privacy. The court agreed with the hospital that the patient failed to plead an intrusion for her privacy claim based on intrusion upon seclusion. The court analyzed that the Northern District of Illinois dismissed a nearly identical intrusion upon seclusion claim in Kurowski v. Rush Sys. for Health, 659 F. Supp. 3d 931, 943-44 (N.D. Ill. 2023) (Kurowski I). This basis of an intrusion upon seclusion claim is an offensive prying into a private domain of another, not the tort of publication. Disclosures of private personal information do not support a claim for unauthorized intrusion. Third parties may have invaded privacy, but Kurowski I did not impute such liability to the defendant in that matter.
The court found the Kurowski I reasoning persuasive. The hospital here was the intended recipient of the information in question, but the patient’s theory required the court to equate improper disclosure of private information with an intrusion into her private space. The court declined to do that. The court accordingly dismissed the invasion of privacy claim (count iii).
Contract claims. The court agreed with the hospital that the patient failed to allege actual damages in support of her breach of express and breach of implied contract claims. Emotional damages, risk of future harm, and loss or privacy were not pecuniary in nature. Diminution of the value of personal information was speculative. Illinois courts have questioned whether a person even holds a property right in personal information. Lost revenues and profits did not fit because the patient had a contract with the hospital for healthcare, not a profit sharing agreement about the sale of personal information. The court dismissed the patient’s contract claims (counts iv, v).
Unjust enrichment. The unjust enrichment claim (count vi) failed because it is not an independent cause of action under Illinois law. It rested here on the same conduct as the other claims the court dismissed.
Bailment. The court held breach of bailment also did not apply because the hospital never received “exclusive possession” of the disputed information. No one can have exclusive possession of another person’s information. The court found the patient’s analogy of a car left at an auto repair shop, with the owner retaining a key, unpersuasive because it was too different from data sharing. The court dismissed the patient’s breach of bailment claim (count vii).
IES. The court agreed with the hospital that the patient could not proceed with her IES (Illinois Eavesdropping Statute) claim under 720 ILCS 5/14-2(a)(2) because she did not allege the capture or interception of an “oral communication.” The claim also failed under section 14-2(a)(3) because the hospital was a party to the communication in question. The court dismissed the IES claim (count viii) accordingly.
ECPA. The court found the patient’s § 2511(1) ECPA claim survived dismissal. Like the IES claim, the party exception applied to the ECPA (Wiretap Act) claim under 18 U.S.C. § 2511(1). However, the Wiretap Act had a “crime-tort” exception to the party exception. The hospital advanced three arguments against applying it.
First, the hospital said the crime or tort in question must be independent of the communication interception. Second, it said the recording of data must have been done with the specific purpose of harming the patient. Third, it preemptively argued the contents of the allegedly intercepted communications were not individually identifiable health information (IIHI) under the Health Insurance Portability and Accountability Act (HIPAA).
As to the third argument about HIPAA IIHI, the court acknowledged the patient’s search history and even the “conditions” and “symptoms” she researched were not necessarily related to her. They could have pertained to someone else, but even so, the court concluded the patient sufficiently alleged improper disclosure of her IIHI. The disputed information might have been related to her health. According to the complaint, Meta allegedly could and did match the information it received from the hospital to the patient’s Facebook ID, such that she began seeing personally-tailored online ads about treatments for the specific conditions she researched on the hospital’s website. The court said it was therefore satisfied the patient alleged the capture and improper disclosure of IIHI to third parties; therefore, she could invoke the crime-tort exception to sustain her ECPA claim.
The hospital argued that even if it captured the patient’s IIHI, the criminal or tortious activity was not independent of its interception under ECPA. The court agreed there must be a “secondary act” that triggers the crime-tort exception to reimpose liability on a party to the communication, and here, it found the patient alleged the hospital proceeded in two steps: it allegedly captured the patient’s PHI and PII with web trackers; then it disclosed that information to third parties.
Next, the hospital argued its only goal was to improve its marketing, which did not harm the patient. The court easily rejected that because the patient alleged a HIPAA violation in the process. For these reasons, the court found the patient’s § 2511(1) ECPA claim (count ix) survived dismissal.
ECPA § 2511(3)(a) and SCA. The court held the hospital had the better argument, pertinent to the patient’s ECPA § 2511(3)(a) and SCA (Stored Communications Act) claims, that it was not in the business of providing electronic communications services. The court did not agree with the patient’s contention that the majority of Illinois courts have recognized that making a website available to the public amounts to providing an electronic communications service. None of the cases the patient cited supported that conclusion. They all denied dismissal on other grounds. The preponderance of authority appeared to support the hospital’s position that healthcare providers are not in the business of providing electronic communications services. The court accordingly dismissed the patient’s ECPA § 2511(3)(a) and SCA claims (counts x, xi).
CFAA. The court agreed with the hospital that the patient did not state a claim under the CFAA (Computer Fraud and Abuse Act) because the complaint did not suggest the hospital exceeded its authorized access to her computer. The Supreme Court decision in Van Buren v. United States, 593 U.S. 374, 379 (2021) favored the hospital. The phrase “not entitled to so obtain” under 18 U.S.C. § 1030(e)(6) was best read to refer to information that a person was not entitled to obtain while otherwise using a computer with authorization. The patient’s complaint was that the hospital had no authorized access to disclose her data, but that did not fit with the CFAA requirement that the wrongdoer use a computer in order to exceed authorized access. The patient provided information to the hospital, and that information was not “off limits.” That was a fatal defect on the CFAA claim (count xii), so the court dismissed it.
The case is No. 3:24-cv-02284-NJR.
Judge: Rosenstengel, N.
Attorneys: Lynn A. Toops (Cohen & Malad, LLP) for Jane Doe. Paul G. Karlsgodt (Baker & Hostetler LLP) for Deaconess Illinois Union County Hospital, Inc. d/b/a Deaconess Illinois Union County d/b/a Union County Hospital.
Companies: Deaconess Illinois Union County Hospital, Inc. d/b/a Deaconess Illinois Union County d/b/a Union County Hospital
Cases: CaseDecisions ConfidentialityNews CyberPrivacyFeed EHRNews HIPAANews DataPrivacy LitigationEnforcement IllinoisNews DataSecurity