Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • DOGE Copied ‘Entire Country’s’ Social Security Data to ‘High-Risk’ Database, Whistleblower Says
    • D. Idaho: Health Insurance administrator prevails over its accidental data breach victims
    • EU Establishes Emergency Fund for Major Cyber Incidents
    • Polish Bank Fined Over GDPR Violations
    • U.K.’s ICO Seeks Input on Data Protection Complaint Procedures
    • Wash. App.: Privacy Act claim against Seattle Children's Hospital over website tracking dismissed
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Wash. App.: Privacy Act claim against Seattle Children's Hospital over website tracking dismissed, (Aug 26, 2025)

    Law Firms Mentioned:Davis Wright Tremaine LLP | Tousley Brain Stephens PLLC
    Organizations Mentioned:Davis Wright Tremaine, LLP | Seattle Children's Hospital | Tousley Brain Stephens, PLLC

    By Wendy Biddle, J.D.

    “Click-and-search navigation” of the hospital’s public website does not constitute a Privacy Act violation.

    The Washington Court of Appeals affirmed a trial court's dismissal of a putative class action lawsuit against Seattle Chil ...

    By Wendy Biddle, J.D.

    “Click-and-search navigation” of the hospital’s public website does not constitute a Privacy Act violation.

    The Washington Court of Appeals affirmed a trial court's dismissal of a putative class action lawsuit against Seattle Children's Hospital (SCH) involving allegations that the hospital's use of Meta's Pixel tracking technology violated the state's privacy act. The appellate court held that plaintiffs' website navigation activities did not constitute "private communication" under RCW 9.73.030(1)(a) ( Baker v. Seattle Children’s Hospital , No. 86461-1-I (Wash. App. Aug. 18, 2025)).

    Background. The lawsuit centered on SCH's implementation of Meta Platforms Inc.'s Pixel software on its public website at www.seattlechildrens.org. According to the complaint, Pixel is designed to track user activity by capturing clicks, text searches, page views, and webpage addresses visited by users. SCH utilized this information to support its advertising efforts.

    The technology operates by sharing tracked data with Meta, often linking website activity to users' Facebook accounts through first-party and third-party cookies. When users are logged into Facebook while browsing SCH's website, Pixel transmits cookies to Meta that allow the company to connect website activity data to specific Facebook accounts. Even for users without Facebook accounts or those not logged in, Pixel transmits activity data with unique identifiers that Meta can use to link current or future Facebook accounts to the browsing activity.

    The three named plaintiffs used SCH's public website to search for various health-related information. One searched for medical conditions and symptoms for her minor daughter, another looked for information about medical conditions and healthcare providers for her minor son, and the other searched for urgent care facility hours.

    The plaintiffs argued that their website activities constituted "private communication" under Washington's privacy act and that SCH's deployment of Pixel technology amounted to unlawful interception of their sensitive health information. They specifically characterized their HTTP requests (electronic communications sent from browsers to website servers) as protected communications under the statute. The plaintiffs defined their intercepted activities as including HTTP requests that ask SCH's website to retrieve specific information, such as lists of urgent care locations or healthcare providers with particular specializations. They alleged that these requests and the corresponding responses constituted private communications that were unlawfully intercepted without their consent.

    SCH moved to dismiss the complaint, which the trial court granted. The plaintiffs subsequently appealed.

    Appeal. Washington's privacy act prohibits intercepting or recording private communications transmitted by telephone, telegraph, radio, or other devices between two or more individuals without obtaining consent from all participants. To establish a violation under RCW 9.73.030(1)(a), plaintiffs must demonstrate four elements: a private communication transmitted by a device that was intercepted or recorded using a device designed to record and/or transmit, without consent of all parties to the private communication.

    The court focused primarily on whether the plaintiffs' website activities constituted "communication" under the statute. The court noted that the Washington Supreme Court has adopted the dictionary definition of communication as "the act of imparting or transmitting" or "facts or information communicated."

    The court relied heavily on State v. Riley, 846 P.2d 1365 (Wash. Sup. Ct. 1993), where the Washington Supreme Court held that a line trap tracing computer hacking activity did not record communication under the privacy act because it merely recorded a phone number rather than an exchange of information between parties. The Riley decision distinguished between devices that capture one-way information versus those that record exchanges between multiple parties.

    The court also referenced State v. Roden, 321 P.3d 1183 (Wash. Sup. Ct. 2014) which addressed text messaging and distinguished back-and-forth communications that plainly fall under privacy act protection from simple informational statements. The Roden court emphasized that protected communications typically involve exchanges that affect multiple parties and involve multiple invasions of privacy.

    The appellate court concluded that the plaintiffs' complaint failed to allege that they navigated SCH's website to transmit messages to or exchange information with another party. Instead, the court found that plaintiffs merely clicked and entered search terms to retrieve publicly displayed information and webpages. The court distinguished the plaintiffs' activities from the back-and-forth messaging protected by the privacy act, noting that SCH's alleged interception of click-and-search activity did not affect other parties or involve multiple invasions of privacy. The court emphasized that under the plain terms of RCW 9.73.030(1)(a), actual communication must occur to support a viable privacy act claim.

    Rejecting the plaintiffs' argument for a broad interpretation of the privacy act to encompass website navigation, the court stated: "Because plaintiffs do not plead facts to establish that communication occurred on SCH's public website under the plain terms of RCW 9.73.030(1)(a), we conclude their claim must fail."

    The case is No. 86461-1-I.

    Judge: Coburn, L.

    Attorneys: Kim D. Stephens (Tousley Brain Stephens PLLC) for Carly Baker. Fred B. Burnside (Davis Wright Tremaine LLP) for Seattle Children’S Hospital.

    Cases: CaseDecisions StateLegislation GCNNews GeneralNews CyberPrivacyFeed DataPrivacy WashingtonNews DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use