California Pixel-Wiretap Rulings Split the Same Week: Blue Shield Claim Dismissed, BlueChew Claims Advance

California Pixel-Wiretap Rulings Split the Same Week: Blue Shield Claim Dismissed, BlueChew Claims Advance
Two Northern District of California judges issued website tracking-pixel wiretap rulings within days of each other in July 2026, and they cut in opposite directions. One dismissed a federal Wiretap Act claim against Blue Shield of California. The other let state wiretap claims against Google and Meta proceed.
Information last verified on July 23, 2026. Both decisions are motion-to-dismiss rulings, not final judgments, and both cases remain active.
Jurisdiction scope: These rulings apply the federal Wiretap Act (18 U.S.C. 2510-2522) and California and other state wiretap statutes as interpreted in the U.S. District Court for the Northern District of California. California's own eavesdropping law, the California Invasion of Privacy Act (CIPA), is a separate state statute from the federal Wiretap Act. This is general legal information, not legal advice.
What Happened
Both cases involve the same technology: small pieces of tracking code, often called pixels, that website operators embed to send visitor activity to advertising and analytics companies such as Meta and Google. The legal question in each case was whether loading that code onto a health-related website amounts to an illegal interception of the visitor's communications.
On July 10, 2026, Judge Yvonne Gonzalez Rogers of the Northern District of California dismissed the federal Wiretap Act claim in a proposed class action against Blue Shield of California, captioned Doe I v. California Physicians' Service dba Blue Shield of California (No. 4:25-cv-03925). The plaintiffs alleged that Blue Shield embedded the Meta Pixel and Google Analytics on its website and that those tools disclosed enrollees' health-related browsing to Meta and Google.
The court dismissed the federal Wiretap Act count with leave to amend, meaning the plaintiffs may file a revised complaint. According to reporting on the order, the court acknowledged that the alleged disclosure of medical information could be serious and analogous to a traditional privacy harm. The claim failed on a narrower point: the complaint itself attributed the actual interception to Google and Meta, not to Blue Shield. The federal Wiretap Act, the court reasoned, does not create a private claim against a defendant merely for procuring, facilitating, or aiding another party's interception, and there is no general aiding-and-abetting liability under the statute.
Days later, in mid-July 2026, a separate Northern District of California case moved the opposite way. In M.D. v. Google LLC and Meta Platforms Inc., a proposed class action over tracking pixels on the telehealth site BlueChew (operated by Dermacare), the court largely denied Google's and Meta's motions to dismiss. Legal-press coverage placed the decision the week of July 14, 2026.
That case is before Judge Araceli Martinez-Olguin, who had dismissed an earlier version of the complaint on September 23, 2025. This time, the court allowed most of the amended claims to proceed. A central defense argument was consent: Meta contended that users agreed to be tracked by accepting its privacy policy. The court rejected the idea that a general, boilerplate privacy policy establishes the specific, informed consent the wiretap statutes require, treating consent as a fact question that cannot be resolved on a motion to dismiss. The practical result is that Google and Meta, the pixel providers themselves, now face discovery rather than an early exit.
One point deserves emphasis, because the two cases are easy to conflate. The Blue Shield ruling turned on the federal Wiretap Act. The BlueChew ruling rested on state wiretap and privacy law, including the California Invasion of Privacy Act and comparable state statutes, not the federal Wiretap Act. They are related legal theories, but they are not the same statute, and each has its own tests.

What the Law Actually Says
The federal Wiretap Act, part of the Electronic Communications Privacy Act, is codified at 18 U.S.C. 2510 through 2522. Its core prohibition, in 18 U.S.C. 2511, bars intentionally intercepting the contents of an electronic communication. The statute also allows a private lawsuit by a person whose communications are unlawfully intercepted.
Two features of that statute drove the Blue Shield result. First, the Act targets the party that intercepts. Courts have consistently declined to read a broad procurement or aiding-and-abetting theory into the private right of action, so a defendant that merely enabled someone else's interception is not automatically on the hook. Second, the statute contains a party exception in 18 U.S.C. 2511(2)(d): a party to the communication does not violate the Act unless the interception is done to commit a crime or tort. A website operator is generally treated as a party to the visitor's communication with its own site, which is why claims that pin the interception on the site operator itself often struggle. When the plaintiffs' own theory placed the interception with Google and Meta, the claim against Blue Shield as a procurer had no statutory home.
State wiretap laws can operate differently, which is why the BlueChew case survived on separate ground. California's CIPA, at Penal Code sections 631 and 632, reaches a third party that secretly records or reads a communication in transit, and California courts have allowed CIPA theories against pixel and tracking-technology providers who are not parties to the communication. Consent is a defense under both the federal and state schemes, but it must be actual and informed. The BlueChew court's refusal to treat a boilerplate privacy policy as blanket consent reflects a recurring theme: consent is usually a fact question, and generic policy language rarely resolves it at the pleading stage. California's separate California data privacy laws and its broader recording and eavesdropping rules add further layers that a federal Wiretap Act analysis does not address.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Read together, the two rulings are less contradictory than they first appear. They turn on two variables that run through nearly all pixel-tracking litigation: the identity of the alleged interceptor, and the quality of any consent.
When the defendant is the first-party website operator, as Blue Shield was, the federal Wiretap Act's structure works against the plaintiff. The operator is a party to the communication, and the statute does not readily punish a party for handing data to a third party's tool. That is a doctrinal problem, not a factual one, which is why the Blue Shield plaintiffs received leave to amend rather than a clean win for the insurer. They may try to reframe their theory, and the underlying claims remain live.
When the defendant is the third-party pixel provider, as Google and Meta were in the BlueChew case, the analysis shifts. A company that is not a party to the communication cannot invoke the party exception, so the litigation moves to consent, and consent is fact-intensive. A privacy policy buried in a footer is a weak substitute for the specific, informed agreement these statutes contemplate, and courts have been increasingly willing to say so at the motion-to-dismiss stage. Because the BlueChew claims rest on state law, they also sidestep the federal procurement problem entirely.
We are not predicting how either case ends. Both are at the motion-to-dismiss stage, and surviving a motion to dismiss is not the same as proving a violation. What the pairing shows is a maturing body of law that sorts pixel cases by structure rather than by headline, and that outcome depends heavily on which statute a plaintiff invokes and against whom.
How This Affects You
Pixel-tracking wiretap litigation is about whether embedding third-party advertising or analytics code on a website, especially a health, insurance, or telehealth site, discloses a visitor's activity in a way the law treats as interception without consent. These are civil class actions, not criminal cases, and the current wave centers on how tracking data flows to companies like Meta and Google.
If you visited a health-related site and are wondering whether your data was shared, these rulings do not resolve that for any individual. A motion-to-dismiss decision addresses whether a lawsuit may proceed, not whether any particular person was harmed or is owed anything. Separately, some pixel-tracking matters have led to settlements, such as the Allina Health pixel-tracking settlement and the Duke MyChart pixel settlement, each with its own eligibility terms and deadlines set by a court-appointed administrator. Nothing here is individualized legal advice, and this article does not tell you whether you have a claim.
This is general legal information, not legal advice. Wiretap and privacy law is fact-specific and varies by jurisdiction and by statute, and both cases discussed here are ongoing. For advice about your situation, consult a licensed attorney in your state.
Last updated: 2026-07-23. This is a developing story; details verified as of 2026-07-23.
Frequently Asked Questions
What did the court decide in the Blue Shield of California pixel case?
On July 10, 2026, Judge Yvonne Gonzalez Rogers of the Northern District of California dismissed the federal Wiretap Act claim against Blue Shield of California in Doe I v. California Physicians' Service (No. 4:25-cv-03925). The dismissal came with leave to amend, so the plaintiffs may file a revised complaint. It was not a final judgment and did not end the case.
Why was the federal Wiretap Act claim against Blue Shield dismissed?
The court reasoned that the complaint attributed the actual interception to Google and Meta rather than to Blue Shield, and that the federal Wiretap Act does not create a private claim against a defendant merely for procuring or facilitating another party's interception. There is no general aiding-and-abetting liability under the statute's private right of action.
Does the dismissal mean Blue Shield won the case?
No. A dismissal with leave to amend means the plaintiffs may try again with a revised complaint. It resolves how the current version of the claim was pleaded, not whether Blue Shield ultimately violated any law. The matter remains an active case in the Northern District of California.
What happened in the BlueChew case involving Google and Meta?
In M.D. v. Google LLC and Meta Platforms Inc., a Northern District of California judge largely denied Google's and Meta's motions to dismiss claims that tracking pixels on the telehealth site BlueChew captured users' prescription and identifying data without consent. Legal press reported the decision the week of July 14, 2026. As a result, the pixel providers face discovery rather than an early dismissal.
Is the BlueChew ruling a federal Wiretap Act decision?
No, and this is an important distinction. The surviving BlueChew claims rest on state wiretap and privacy law, including the California Invasion of Privacy Act and comparable state statutes, not the federal Wiretap Act. That is one reason the case avoided the procurement problem that defeated the federal claim against Blue Shield.
Why did the consent defense fail in the BlueChew case?
Google and Meta argued that users consented to tracking by agreeing to a privacy policy. The court declined to treat a general, boilerplate privacy policy as the specific, informed consent the wiretap statutes require, and it treated consent as a fact question that cannot be resolved on a motion to dismiss. Consent may still be litigated later in the case.
How is California's CIPA different from the federal Wiretap Act?
The federal Wiretap Act (18 U.S.C. 2510-2522) is a federal statute, and its private right of action generally targets the party that intercepts, with a party exception for those involved in the communication. California's Invasion of Privacy Act (Penal Code sections 631 and 632) is a separate state law that reaches third parties who secretly read or record a communication in transit. The two use different tests, which is why one claim can fail while the other proceeds.
What is a tracking pixel, and why does it raise wiretap questions?
A tracking pixel is a small piece of code a website embeds to send data about a visitor's activity to an advertising or analytics company. Plaintiffs argue that on sensitive sites, such as health or telehealth pages, this can transmit protected information to a third party without proper consent, which they frame as an unlawful interception under federal or state wiretap law.
Sources and References
- Doe I v. California Physicians' Service dba Blue Shield of California, No. 4:25-cv-03925 (N.D. Cal.), docket(courtlistener.com)
- 18 U.S.C. 2511, federal Wiretap Act interception prohibition and private right of action(uscode.house.gov).gov
- California Penal Code section 631, California Invasion of Privacy Act (CIPA)(leginfo.legislature.ca.gov).gov
- Federal Wiretap Act claim against Blue Shield dismissed by US federal judge (context)(mlex.com)
- Google, Meta must face privacy lawsuit over BlueChew trackers, US judge rules (context)(mlex.com)
- Google, Meta Beat BlueChew Users' Privacy Suit, For Now (September 2025 dismissal, context)(news.bloomberglaw.com)