Blog

Meta Pixel Lawsuits: What Courts Have Ruled, Case by Case (2026)

A Meta Pixel lawsuit claims that the Meta Pixel, a snippet of Meta's tracking code on a website, sent information about the site's visitors to Meta without the consent the law requires. That is the allegation.

Key Takeaways

  • 01Meta Pixel suits rely mainly on California's Invasion of Privacy Act (sections 631, 632 and 638.51), the federal Wiretap Act and the Video Privacy Protection Act. Plaintiffs have sued Meta and the companies that ran the websites.
  • 02In 2026, three federal judges denied class certification in pixel cases: the Meta tax-filing cases (March 30), Capital One (June 16) and Rack Room Shoes (September 21). The Ninth Circuit agreed to review the Capital One denial.
  • 03Settlements on the court record include Sutter Health ($21.5 million), TaxAct ($14.95 million fund), AARP ($12.5 million) and Mount Sinai ($5,256,588), each without admission of wrongdoing.
  • 04SB 690, signed September 30, 2026, takes effect January 1, 2027. From then, only the Attorney General may bring a section 638.51 pen-register or trap-and-trace claim over website or app conduct against a private actor. Section 631 and 632 claims and the $5,000-per-violation remedy remain.
  • 05Under a strict standard, our EU test observed a request to the Meta Pixel before any consent choice on 230 of 912 consent-tool sites from our sales-lead lists (25%, July 2026) and on 76 of 229 sites whose owners ran our free scanner (33%, June to July 2026). Server-side Conversions API sends are not measured.

The short answer: patients, taxpayers, credit-card applicants and video viewers have filed proposed class actions over the Pixel, mainly under the California Invasion of Privacy Act (CIPA), the federal Wiretap Act and the Video Privacy Protection Act (VPPA). Several survived motions to dismiss. Settlements on the record include Sutter Health ($21.5 million), TaxAct ($14.95 million fund), AARP ($12.5 million) and Mount Sinai ($5,256,588), all without an admission of wrongdoing. In 2026, three federal judges denied class certification in pixel cases. And California's SB 690 changes one of the theories from January 1, 2027.

As courts have summarized the complaints, the Pixel works through the visitor's browser, while Meta's Conversions API sends data from the website owner's servers. The Mount Sinai opinion puts it plainly: "Unlike the Pixel, CAPI does not cause a user's browser to transmit information directly to Facebook."

What this post is, and is not

It reports what courts, legislatures and regulators have done, and what our scanner measured. It is not legal advice and does not say whether anyone is liable. Allegations are allegations; a settlement is not a finding.

What a Meta Pixel lawsuit alleges

Among the website cases, Meta is the defendant in two consolidated federal cases in Northern California, brought by patients and taxpayers. Elsewhere the defendant ran the website: hospital systems, a tax preparer, a bank, video sites, a retailer. The AARP complaint alleged that the site shared "at least the user's Facebook Profile ID and the title of the video that the user watched" with Meta (complaint). TaxAct plaintiffs alleged that confidential tax return information went "to third parties, including Meta and Google, without permission." TaxAct denied the allegations, and both cases settled without an admission.

The laws these cases use

The main legal theories in Meta Pixel cases, as of October 2, 2026
LawWhat it requires, as courts describe itWhere it stands
CIPA section 631 (wiretap)Reading or learning a communication's contents in transit without all parties' consentSurvived Meta's motions to dismiss; lost at summary judgment in one 2025 case
CIPA section 632 (eavesdropping)Intentionally eavesdropping on or recording a confidential communication without all parties' consentJury verdict against Meta in the Flo Health app case (2025)
CIPA section 638.51 (pen register)Installing or using a pen register or trap-and-trace device without a court orderSurvived Meta's motion to dismiss (2025); from January 1, 2027, website and app claims against private actors are for the Attorney General only
CIPA remedy, section 637.2The greater of $5,000 per violation or three times actual damagesUnchanged for section 631 and 632 claims
Federal Wiretap ActOne party's consent is enough, unless the interception is for the purpose of a crime or tortCourts split at the pleading stage
VPPAA video tape service provider knowingly disclosing a consumer's identifying information and viewing historyCircuits split on who is a "consumer"; Supreme Court argument October 14, 2026
State lawsMassachusetts wiretap act; California's medical-information law (CMIA); Washington's My Health My Data ActDefense wins in Massachusetts (2024) and on CMIA claims in one 2025 case; Washington's consent rules have applied since 2024

Our CIPA guide covers the California law itself. Washington's statute requires separate consents to collect and to share consumer health data.

Healthcare pixel cases

The flagship case, against Meta, is In re Meta Pixel Healthcare Litigation (N.D. Cal. No. 3:22-cv-03580), filed June 17, 2022. Patients of several hospital systems, which are not defendants, allege that the Pixel ran on their providers' patient portals and sent Meta health-related information.

  • December 22, 2022: the court denied a preliminary injunction while calling the allegations against Meta "troubling."
  • September 7, 2023: Meta's motion to dismiss was granted in part and denied in part, and the Wiretap Act, CIPA, contract and unjust-enrichment claims went forward. At that stage a court accepts the allegations as true.
  • June 12, 2026: class certification was argued ("Written order will follow"). On July 7 the court vacated the trial dates, citing "the time needed for that opinion" (minutes). As of October 2, 2026, the public docket showed no class-certification order.

The crime-tort split. Hospitals argue they are a party to the communication, so their own consent suffices under the Wiretap Act. Plaintiffs invoke the exception for interceptions made to commit a crime or tort, usually pointing to HIPAA. Courts let the claim proceed against HealthPartners (December 2023) and Mount Sinai (July 2024), and dismissed it against Kaiser with leave to amend (April 2024): "Violation of HIPAA was not the purpose of the alleged interception." All three rulings accepted the allegations as true.

Massachusetts. In the New England Baptist Hospital case (SJC-13542, October 24, 2024), the state's highest court held its wiretap act's word "communication" ambiguous as applied to browsing hospital web pages that, the complaints alleged, ran the Meta Pixel and Google Analytics, and reversed the denial of motions to dismiss.

Federal guidance. In June 2024 a Texas federal court vacated HHS's position that an IP address plus a visit to an unauthenticated page about specific health conditions or providers is protected health information. HHS dropped its appeal (dismissed September 4, 2024).

Healthcare tracking settlements on the court record (all without admission)
DefendantCourt and numberAmountFinal approval
Sutter HealthSacramento Super. Ct. No. 34-2019-00258072$21,500,000March 6, 2026
Advocate Aurora HealthE.D. Wis. No. 2:22-cv-01253$12,225,000July 10, 2024
Novant HealthM.D.N.C. No. 1:22-cv-00697$6,660,000June 17, 2024
HealthPartners (Group Health Plan)D. Minn. No. 0:23-cv-00267$6,000,000July 9, 2025
Mount Sinai Health SystemS.D.N.Y. No. 1:23-cv-09485$5,256,588November 4, 2025

See the approvals for Novant, HealthPartners and Mount Sinai. Kaiser's $47.5 million tracking settlement (approved July 14, 2026) is left out: the complaint, as the court quoted it, lists other vendors, not Meta.

The jury verdict against Meta involved an app. In the Flo Health app case (N.D. Cal. No. 3:21-cv-00757), a jury found on August 1, 2025 that Meta intentionally eavesdropped on or recorded plaintiffs' communications without all parties' consent under section 632 (verdict form). The case concerned data from a period-tracking app sent through Meta's SDK, not the website Pixel. Meta's post-trial motions were denied, but no judgment had been entered as of September 30, 2026. Google ($48 million), Flo ($8 million) and Flurry ($3.5 million) agreed to settle, with final approval set for hearing on October 29, 2026.

Tax filing and financial institutions

A July 2023 report by seven members of Congress said TaxAct, TaxSlayer and H&R Block confirmed using the Meta Pixel. In the Meta Pixel Tax Filing Cases (N.D. Cal. No. 5:22-cv-07557), where Meta is the defendant, the court denied Meta's motion to dismiss a section 638.51 pen-register claim on August 6, 2025, rejecting Meta's reading as a "loophole." On March 30, 2026 it denied class certification without prejudice: no named plaintiff had standing for the TaxAct classes, and the H&R Block classes were broader than the complaint's, exposing members to individual defenses under what the court called CIPA's one-year limitations period.

TaxAct settled its own class action (N.D. Cal. No. 3:23-cv-00830) for a $14.95 million fund plus up to $2.5 million for notice and administration. The court approved it on December 30, 2024. Objectors appealed, the Ninth Circuit heard argument on May 18, 2026, and payments wait on the outcome.

On August 19, 2026, the Connecticut Attorney General announced a $275,000 settlement with TaxAct, saying its investigation found that from 2018 to 2022 TaxAct disclosed customers' financial details, such as rounded adjusted gross income, to Meta and Google. TaxAct agreed to tag monitoring that regularly scans its site and two independent audits.

In the Capital One case (N.D. Cal. No. 3:24-cv-05985), credit-card applicants alleged their data went to Meta through the Pixel and the server-to-server Conversions API, among other vendors' tools. On June 16, 2026 the court denied class certification: what was sent for each applicant, and consent across a "diversity of disclosures," were individual questions. The Ninth Circuit agreed to review that denial on August 24.

Video sites and the VPPA

Video-site cases turn on who counts as a VPPA "consumer," and the appeals courts have split.

The VPPA "consumer" split
CourtCaseDateReading
2d Cir.NBA newsletter case, No. 23-1147October 15, 2024Broad: a free-newsletter subscriber can qualify
7th Cir.Me-TV case, No. 24-1290March 28, 2025Broad: "data can be worth more than money"
6th Cir.Paramount Global (247Sports) case, No. 23-5748April 3, 2025Narrow: the subscription must be audiovisual
D.C. Cir.Washington Newspaper Publishing case, No. 24-7022August 12, 2025Narrow, in a Meta Pixel case

The Supreme Court took the Paramount Global case (No. 25-459) and set it for argument on October 14, 2026. The question is whether "goods or services from a video tape service provider" means all of a provider's goods or services or only its audiovisual ones.

AARP's $12.5 million VPPA settlement received final approval on February 20, 2026. Patreon's $7.25 million settlement was approved on June 5, 2025.

Since August 2025: standing rulings and class-certification denials

Plaintiffs kept their claims alive against Meta at the pleading stage in 2023 and 2025. From August 2025 on, several rulings went the other way.

Defense rulings and class-certification denials since August 2025
DateCaseRuling
August 26, 2025Microsoft Clarity case (9th Cir. No. 24-14)Dismissal of a session-replay suit under Pennsylvania's wiretap act affirmed for lack of standing
October 17, 2025Eating Recovery Center (N.D. Cal. No. 3:23-cv-05561)Summary judgment for the defendant on a CIPA claim
March 30, 2026Meta Pixel Tax Filing CasesClass certification denied without prejudice
June 16, 2026Capital OneClass certification denied; under Ninth Circuit review
September 21, 2026Rack Room Shoes (N.D. Cal. No. 3:24-cv-06709)Dismissed without prejudice for lack of standing; class certification denied

Three threads run through them. Standing: the Clarity ruling found no harm "remotely similar to the 'highly offensive' interferences or disclosures that were actionable at common law." Proof about each person: the Rack Room Shoes plaintiffs conceded they lacked reliable evidence that their own communications were intercepted, and the court held that "The presence of a tracker is not a sufficient basis to draw a reasonable inference of actual tracking." The statute's wording: the Eating Recovery Center court found it undisputed that Meta did not read or attempt to learn the contents in transit, and wrote that "The language of CIPA is a total mess." Judgment was entered for the defendant on October 21, 2025. The plaintiff moved to alter it in November 2025, and we found no ruling on that motion.

The counter-signals: the Flo Health verdict, the Ninth Circuit's review of Capital One, and an Attorney General settlement that requires tag monitoring.

What SB 690 changes, and what it does not

Governor Newsom signed SB 690 on September 30, 2026 (Chapter 976, Statutes of 2026; bill text). It sets no date of its own, so under the California Constitution it takes effect January 1, 2027.

From then, only the Attorney General may bring a section 638.51 pen-register or trap-and-trace action under section 637.2 against a private actor over conduct on a website or app. SB 690 does not change section 631 or 632, or the $5,000-per-violation remedy for those claims. The new section 637.2(d)(2) reads: "The amendments to this section by Senate Bill No. 690 of the 2025-26 Regular Session apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation."

The Assembly Privacy Committee's analysis called the pen-register statute "a poster child for abusive lawsuits," and the Governor's signing message says "additional work in this area is needed."

What our scans show about the Meta Pixel

Our free compliance scanner loads a website in a real browser and records its network requests. Two censuses report the Meta Pixel on its own, under a strict standard: any request to the Pixel observed before a consent choice counts. It is a behavioral test, not one any court above applied.

Requests to the Meta Pixel observed in our scans (EU test)
CohortBefore any consent choiceAfter the scanner clicked Reject
Per-consent-tool census: 912 sites running one of four widely used consent tools, from our sales-lead lists (not a random sample), scanned July 19 to 20, 2026230 of 912 (25%)26 of 741 sites where Reject was clickable (3.5%)
State census: 229 sites whose owners ran our free scanner, June 21 to July 14, 202676 of 229 (33%)11 of 70 sites where Reject was clickable (16%)

In our Reject-All cookie study (6,964 cookie observations on 791 sites), of 304 cookie observations with Meta's pixel host (connect.facebook.net) in the write stack, 115 (37.8%) were still in the browser after Reject All. The unit is cookies, not sites.

How to read these numbers:

  • Every per-tracker figure in our studies, before consent and after Reject, comes from the scanner's EU test: a fresh browser in Frankfurt, Germany, visiting each site for the first time. Our scanner also loads each site from San Francisco, but none of our per-tracker figures comes from that US visit, so we have no US rate for any tracker.
  • It cannot see data a website's own servers send to another company, such as events sent through Meta's Conversions API, and it does not count requests to the website's own domain, so tracking relayed through the site's own server is not in these figures.
  • It records where each request went and when, not what the request contained or why it was made. It does not send a Global Privacy Control signal, so GPC honoring and US opt-out flows are not measured.
  • The two censuses differ in population and in their after-Reject definitions, so 16% against 3.5% is not a trend or a comparison of consent tools. No census carries an industry tag, so we have no healthcare rate.

None of this says any site broke a law or could be sued. It says what a browser observed. Methods are in the per-consent-tool census and the state census.

Looking for settlement money?

Each class settlement here has a court-approved administrator, and the court's orders set who qualifies and when. Two administrator sites were live on October 2, 2026: TaxAct's, which says payments "are delayed until all appeals are resolved," and AARP's, which says payments were issued on April 13, 2026. Several older settlement domains have lapsed, so start from the court docket. We do not estimate payments.

Frequently Asked Questions

How we checked these records

We checked every case, statute and regulator action here against a primary record on October 1 and 2, 2026; several were still pending.

See what your site sends before a consent choice

Our free compliance scanner loads your page in a real browser from the EU and the US, clicks Reject in one visit and Accept in another, and reports the third-party requests it observed. Full compliance, no compromise.