Website Tracking, AI, and Privacy Class Actions: The New Theories Plaintiffs Are Using

If you run a website — and if you are a business operating in 2026, you almost certainly do — you are operating in the middle of one of the most active litigation environments in the country. Class action plaintiffs and their attorneys have spent the last several years stress-testing old privacy statutes against new technology, and the results are consequential: hundreds of lawsuits filed annually, circuit court splits on fundamental legal questions, and exposure that can reach thousands of dollars per user per violation depending on the statute at issue.

This post explains what is actually happening in these cases, which legal theories have stuck and which have not, and what business owners should be doing about it right now. The goal is not to alarm you but to give you an accurate map of the legal landscape so you can make informed decisions about how your website is built and what tracking tools you deploy.


The Foundation: Old Statutes, New Technology

The class action theories driving this wave of litigation do not rely on new privacy laws. They rely on statutes written decades before the modern web existed, stretched by plaintiffs’ attorneys to cover behaviors those legislatures almost certainly never contemplated.

The two workhorses are the California Invasion of Privacy Act (CIPA), first enacted in 1967, and the Video Privacy Protection Act (VPPA), enacted by Congress in 1988 after a Washington D.C. reporter published Supreme Court nominee Robert Bork’s video rental history. CIPA’s wiretapping provisions, codified at Penal Code sections 631 and 632.7, make it a crime — and a civil tort — to intentionally eavesdrop upon, tap, or make a recording of a private communication without the consent of all parties. The VPPA prohibits “video tape service providers” from knowingly disclosing personally identifiable information about consumers to third parties without consent.

Neither statute was designed with embedded JavaScript tracking pixels, session replay software, or AI-powered behavioral analytics in mind. Plaintiffs argue that it does not matter what the legislature intended — the conduct fits the text, and the remedies are substantial. CIPA provides for $5,000 per violation. The VPPA provides for $2,500 per violation. In a class action with millions of website visitors, those per-violation figures compound into exposure that gets the attention of any CFO.

The litigation environment has escalated dramatically. Industry trackers observed CIPA filings jump from approximately 675 cases annually in 2024 to a projected rate exceeding 3,500 cases in 2026. Federal and state courts in California, Pennsylvania, Florida, and across the country are now routinely deciding whether your analytics stack constitutes an illegal wiretap.


Session Replay Software and the Wiretapping Theory

To understand the litigation, you first need to understand session replay software. Products like FullStory, Hotjar, and Microsoft Clarity allow website operators to record user sessions — capturing mouse movements, keystrokes, clicks, form entries, and page navigation — for the purpose of UX analysis and conversion optimization. The value proposition is real: you can watch exactly what a user did on your site, identify friction points, and improve the experience.

Plaintiffs’ attorneys noticed that this description — capturing user communications in real time and transmitting them to a third-party vendor — maps onto CIPA section 631’s prohibition on intercepting private communications. Section 631(a) prohibits any person who “by means of any machine, instrument, or contrivance, or in any other manner, intentionally taps, or makes any unauthorized connection” with any wire or reads or attempts to read the “contents” of a communication “while the same is in transit.”

The pivotal early case was Javier v. Assurance IQ, LLC, decided by the Ninth Circuit in May 2022. The plaintiff visited a website that used third-party session replay software to record his interactions, including form entries containing personal and insurance-related information. He had not consented before the recording began. The Ninth Circuit held that CIPA consent must be obtained before tracking begins — retroactive or implied consent is insufficient. That ruling launched an enormous wave of copycat litigation.

The Javier saga itself ended quietly. On remand, a district court in the Northern District of California dismissed the case in June 2023 with prejudice, finding that the claims were time-barred and that the plaintiff had not adequately alleged facts to invoke the delayed discovery doctrine. But by then, the legal theory was established and the copy-cat filings had already flooded the dockets.

How Courts Have Diverged Since Javier

The case law since 2022 has not been uniformly favorable to plaintiffs. Courts have split on several threshold issues that determine whether a CIPA session-replay claim survives.

The “real-time interception” problem. CIPA section 631 requires that communication be intercepted while in transit. In Torres v. Prudential Financial, Inc. (decided in April 2025), a California federal court granted summary judgment against the plaintiff on this precise ground. The court found that session replay software does not intercept data “in transit” because the information becomes readable only after transmission and reassembly — the software is reading stored data, not tapping a live wire. This is a significant defense that has succeeded.

The party exception. Another recurring defense is that the website operator cannot “eavesdrop” on communications to which it is already a party. Courts have applied this reasoning to dismiss CIPA claims where the website deployed its own first-party chat feature. If you are a party to the conversation, you are not wiretapping it. The Ninth Circuit affirmed this reasoning in Thomas v. Papa John’s (June 2025), holding that a party to a conversation cannot be held liable for eavesdropping on its own conversation.

The third-party vendor problem. The party exception does not extend to genuinely independent third-party vendors. In Mikulsky v. Bloomingdale’s, LLC, decided by the Ninth Circuit in June 2025, the court reversed a district court dismissal and held that the plaintiff had plausibly alleged that Bloomingdale’s “aided, agreed with, employed, or conspired with” a session replay vendor to intercept the contents of her communications — including names, addresses, credit card information, and product selections — in real time. The court accepted that session replay software can capture “contents” rather than mere “record data” when it records substantive inputs like billing information and product choices. Critically, the Ninth Circuit also confirmed that any company operating a website accessible to California users can face CIPA liability even without a physical presence in the state.

The practical takeaway from this conflicting case law is not reassurance — it is uncertainty. Whether your use of session replay survives a CIPA challenge depends heavily on how the vendor’s technology processes data, what information is captured, and what disclosures you make before the session begins. That uncertainty costs money to litigate even when you ultimately win.


The VPPA and Tracking Pixels: A Law About Videotapes Reaches the Internet

The Video Privacy Protection Act is, at its core, a statute about protecting your right to rent movies without the government or your nosy neighbors finding out. Its application to modern web analytics required significant doctrinal stretching, but plaintiffs found a credible theory: if a website operator deploys Meta Pixel or a similar tool, and that pixel transmits to Meta both (a) information identifying the user and (b) information about which videos the user watched on the website, the disclosure arguably falls within the VPPA’s prohibition on disclosing “personally identifiable information” about a “consumer” to a third party.

The VPPA defines “personally identifiable information” to include information that “identifies a person as having requested or obtained specific video materials or services from a video tape service provider.” When a user watches a video on a website and the Meta Pixel fires to report that event to Meta along with the user’s Facebook ID — which is sufficient to identify the individual — plaintiffs argue that is exactly what the statute prohibits.

The “Consumer” Definition Battle

The most contested legal question in VPPA litigation is who qualifies as a “consumer” entitled to sue. The statute defines “consumer” as any person “who rents, purchases, or subscribes to goods or services from a video tape service provider.” Plaintiffs have argued aggressively that someone who signs up for a company’s email newsletter — creating a subscriber relationship — qualifies, even if the newsletter has nothing to do with video content.

Courts have divided sharply. In Salazar v. NBA (Second Circuit, October 2024), the court adopted a broad reading and held that a “consumer” is not limited to consumers of video content. Someone who provides an email address to receive a newsletter from a website that also hosts video content is a “consumer” for VPPA purposes. That decision dramatically expanded potential liability for any media company, news organization, sports franchise, or business that both operates a newsletter and embeds video content.

The Sixth Circuit reached the opposite conclusion in Salazar v. Paramount Global (April 2025), holding that the statutory term “goods or services” must be read in context — it refers to audio-visual goods and services, not any goods or services offered by a company that also happens to stream video. A person who signed up for a Paramount email newsletter did not, on that basis alone, become a “consumer” protected by the VPPA.

This split is heading to the Supreme Court. On January 26, 2026, the Court granted certiorari in Salazar v. Paramount Global. Until the Court decides the case, companies face genuine uncertainty about their VPPA exposure if they operate a newsletter signup and embed any video content on their websites.

The Second Circuit also drew a line in Solomon v. Flipps Media, Inc. (May 2025), affirming dismissal of a VPPA class action on separate grounds, suggesting that not every pixel disclosure of user identity plus video-viewing behavior will automatically survive scrutiny.


The HIPAA Dimension: Pixels on Healthcare Websites

The intersection of tracking pixels and healthcare is where the legal exposure becomes most acute. Beginning in December 2022, HHS’s Office for Civil Rights issued guidance concluding that HIPAA-covered entities — hospitals, health systems, medical practices, mental health platforms, telehealth services — that deploy third-party tracking pixels on their patient-facing websites may be violating HIPAA’s Privacy Rule when those pixels transmit protected health information (PHI) to vendors like Meta or Google.

The concern is straightforward. A patient who visits a hospital’s “schedule an appointment” page, clicks through the oncology department, and then logs into the patient portal has transmitted information that, in combination with the tracking data collected by the pixel, reveals health-related facts about that person. OCR’s position was that this constitutes an unauthorized disclosure of PHI.

In July 2023, HHS OCR and the FTC sent warning letters to approximately 130 hospitals flagging “serious privacy and security risks” from these tracking deployments. Separately, plaintiffs’ attorneys filed dozens of class actions. A class action in the Northern District of California consolidated as In re Meta Pixel Healthcare Litigation survived Meta’s second motion to dismiss in January 2024, with Judge William Orrick allowing the case to proceed on the theory that Meta’s pixel intercepted and transmitted protected patient information.

The regulatory picture became more complicated in mid-2024. The American Hospital Association sued HHS to challenge the OCR bulletin, and a federal judge sided with the AHA in June 2024, finding that portions of the OCR guidance exceeded the agency’s statutory authority. HHS announced it would not appeal. That decision limits OCR’s direct enforcement posture — but it does not extinguish the private class action theory, which does not depend on the OCR bulletin.

For healthcare businesses, the upshot is this: even if HIPAA enforcement on tracking pixels is more constrained than the 2022 OCR guidance suggested, the private class action exposure under CIPA, VPPA, the federal Electronic Communications Privacy Act, and state wiretap statutes remains real and active. Covered entities should not interpret the AHA litigation victory as permission to re-deploy pixels on authenticated patient portals.


AI-Generated Profiling as an Aggravating Factor

The newest layer on top of the pixel and session-replay theories is the role of artificial intelligence. As more companies deploy AI-powered customer analytics, behavioral targeting, and customer service automation, plaintiffs have begun adding AI-specific allegations to their privacy claims.

The theory takes several forms. First, plaintiffs allege that AI tools are not passive collectors of behavioral data — they actively analyze, categorize, and profile users based on that data, creating inferences about intent, preferences, and identity that go beyond what the raw event data would reveal. When CIPA plaintiffs allege that a session replay vendor “reads” or “uses” the intercepted communications, the AI processing argument is that the vendor’s AI systems consume and derive value from the captured data in ways that amplify the intrusion beyond a simple data pipe.

Second, AI conversation intelligence tools — products that listen to customer service calls, transcribe them, and use AI to analyze sentiment, sales opportunities, and compliance — have become their own litigation category. In a class action filed against Heartland Dental and RingCentral in July 2025, plaintiffs alleged wiretap violations stemming from RingCentral’s AI product that listened to, analyzed, and transcribed patient calls without patient consent. In Taylor v. ConverseNow Technologies, a federal court in the Northern District of California allowed a CIPA class action to proceed against an AI-powered phone order system deployed by Domino’s, declining to dismiss the claim that the AI intercepted and recorded calls without the callers’ consent.

Third, AI profiling creates a VPPA aggravation theory: if a pixel transmits video-watching behavior to a third party that then uses AI to build a detailed behavioral profile of that user, plaintiffs argue the “disclosure” is more damaging — and thus warrants heightened scrutiny — than a simple event log transmission.

The AI angle does not, by itself, create new causes of action under existing statutes. But it does two things that matter for litigation: it makes damages allegations more credible (a detailed AI-generated profile is more concretely harmful than a click log), and it potentially implicates additional AI-specific legislation that is moving through state legislatures. Businesses that use any AI-powered analytics, sales intelligence, or call monitoring tools should treat those deployments with the same caution they apply to session replay and pixel tracking.


The Multi-State Exposure Problem

California gets the most attention because CIPA is well-established and aggressively litigated. But businesses operating nationally — which is virtually every business with a public-facing website — face exposure under analogous statutes in Pennsylvania, Florida, and potentially other states.

Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA) is one of the strictest surveillance statutes in the country. Like CIPA, it requires all-party consent for the interception of electronic communications. Plaintiffs have filed WESCA class actions asserting that tracking pixels on Pennsylvania-accessible websites constitute unlawful interception. A Pennsylvania federal court remanded one such case to state court in 2025 after finding that the particular plaintiff — whose “searches for drink flavors” were captured — had not alleged an injury sufficient to establish federal Article III standing. That ruling is a standing victory for defendants, not a ruling that WESCA does not apply to pixel tracking.

Florida’s Security of Communications Act (FSCA) is similarly structured. In W.W. v. Orlando Health, Inc., a federal court denied Orlando Health’s motion to dismiss an FSCA claim, holding that the plaintiff had adequately alleged that electronic communications captured by Meta and Google pixels on the patient portal were “contents” under the statute. That decision opens the door to Florida-based tracking pixel litigation in a way that was less certain before.

In addition to these state-specific wiretap statutes, businesses face potential exposure under the federal Electronic Communications Privacy Act (ECPA), which also prohibits the intentional interception of wire and electronic communications. ECPA claims are harder to bring than CIPA claims — the statute has more carve-outs — but they have appeared in multi-count pixel and session-replay complaints.

The multi-state problem is structurally difficult. A company that configures its website with certain tracking tools for California compliance may still be deploying those tools to Pennsylvania and Florida visitors under those states’ all-party-consent requirements. A national website effectively needs to meet the most restrictive applicable standard, or it needs to deploy geolocation-based consent logic that adjusts consent requirements by user location.


High-Risk Tools and Integrations

Several categories of tools and integrations create elevated exposure based on the litigation landscape as it currently stands.

Session replay software (FullStory, Hotjar, Microsoft Clarity, Mouseflow, Heap) remains the core category for CIPA section 631 claims. The risk is highest when the tool captures form inputs, credit card numbers, addresses, or other substantive content beyond navigation metadata. After Mikulsky v. Bloomingdale’s, even companies that previously received dismissals should reassess.

Meta Pixel is the primary target of both VPPA claims (video content + newsletter subscriber combinations) and HIPAA-related claims for healthcare businesses. The pixel’s behavior — transmitting user identification data alongside event data to Meta — is well-documented and provides plaintiffs with a concrete disclosure to point to in a complaint.

Google Analytics, Google Ads, and Google Tag Manager have appeared in multiple complaints alongside Meta Pixel. A federal court in 2025 allowed claims under CIPA and the federal Wiretap Act to proceed against Google based on allegations that these products intercepted user health information from a medical website.

AI-powered call analytics and conversation intelligence tools (including RingCentral AI, Gong, Chorus, and similar products integrated into customer-facing phone lines) are now an emerging target, as the Taylor v. ConverseNow and Heartland Dental/RingCentral cases illustrate.

Chatbots with third-party backends carry CIPA exposure when the back-end infrastructure is operated by a vendor that is genuinely independent from the website operator. The party exception to CIPA — which protects the website operator from claims it eavesdropped on its own conversations — may not protect the third-party vendor who processes the chat data.

Email newsletter signup forms combined with embedded video create the subscriber-plus-video-content combination that the Second Circuit held sufficient to establish VPPA consumer status in Salazar v. NBA. Any business with a subscription email list and video on its website should treat this combination as a current risk until the Supreme Court resolves the circuit split.


Practical Compliance: What to Do

The volume and uncertainty of this litigation does not mean that compliance is impossible. It means that thoughtful, documented choices about your tracking stack reduce your risk substantially, and that certain baseline measures are no longer optional.

A consent management platform (CMP) is the primary technical control for managing consent to tracking. A well-implemented CMP presents users with a clear notice about what tracking technologies your site uses and obtains their affirmative consent before those technologies fire. The baseline requirement from Javier v. Assurance IQ — that CIPA consent must occur before tracking begins — is exactly what a properly configured CMP addresses.

Critically, the CMP must actually block tracking scripts from executing until consent is received. A banner that pops up while pixels are already firing in the background is not compliant consent management — it is a lawsuit waiting to happen. The technical implementation matters as much as the design.

For healthcare businesses, the CMP must integrate with HIPAA compliance controls. Any tool that could transmit PHI must be gated behind a HIPAA-compliant authorization process, not merely a generic cookie consent banner.

Conduct Vendor Due Diligence and Review Data Processing Agreements

Your liability under CIPA and similar statutes often turns on what your vendor does with data once it receives it. Under the theory articulated in Mikulsky v. Bloomingdale’s, a website operator can be liable for “aiding” a third-party vendor’s interception even if the operator itself did not directly capture the data. Your data processing agreements with session replay vendors, analytics providers, and AI tool vendors should clearly specify what data is collected, how it is processed, how long it is retained, and what restrictions apply to the vendor’s use.

Review your vendor list with an eye toward which tools are capturing communication contents — form inputs, chat messages, voice recordings — versus which are capturing metadata. The former category carries substantially higher litigation risk.

Implement Data Minimization Practices

Session replay software typically comes with configuration options to mask or exclude sensitive fields. Credit card numbers, Social Security numbers, health information fields, and password inputs should be excluded from recording by default. The Mikulsky court specifically noted that the complaint alleged capture of “names, addresses, credit card information, and product selections” — exactly the kind of information that data minimization configuration would have excluded.

Similarly, review your pixel configurations. Meta Pixel’s “Advanced Matching” features, which send hashed user identification data, increase VPPA and CIPA exposure relative to a more basic pixel configuration. The additional targeting precision may not be worth the legal risk.

If you are sued, your ability to demonstrate that you had a functioning consent mechanism that operated before any tracking began, that your privacy policy accurately described your data collection practices, and that users had a meaningful opportunity to decline is your primary defense. Document everything. Retain records of consent deployments, policy updates, and vendor configurations.

For businesses in the healthcare space, document your analysis of whether each tracking tool could potentially transmit PHI, and maintain records of any business associate agreements with analytics vendors that access patient data.

Watch the Legislative Landscape

California SB 690, which would have created a “commercial business purpose” carve-out limiting CIPA’s application to standard website analytics, unanimously passed the California Senate in June 2025 but stalled in the Assembly and was designated a two-year bill. It is eligible for reconsideration in the 2026 legislative session. If it passes, it would substantially narrow the CIPA wiretapping theory for standard analytics deployments — but it has not passed yet, and CIPA liability remains in full force through at least the end of 2026. Do not defer compliance on the expectation of legislative relief.

The Supreme Court’s resolution of the VPPA consumer definition question in Salazar v. Paramount Global will also be significant. If the Court adopts the Sixth Circuit’s narrower reading — limiting “consumers” to subscribers of audio-visual content — many pending VPPA pixel cases would collapse. If the Court adopts the Second Circuit’s broader reading, the existing exposure would be confirmed and potentially expanded.


Conclusion

Website tracking litigation is not a niche privacy concern. It has become one of the most active class action categories in federal and state courts, driven by a combination of aggressive plaintiff-side litigation, genuinely ambiguous case law, and technology deployments that most businesses set up without full legal review.

The underlying legal theories — that session replay software “wiretaps” user communications, that tracking pixels “disclose” video-watching behavior in violation of a 1988 videotape rental law, that AI call analytics constitutes unlawful interception — would have seemed far-fetched ten years ago. Courts have found them at least colorable, and settlements regularly reach into the millions.

Your immediate priorities are straightforward: audit your tracking stack, deploy a consent management platform that actually blocks scripts before consent is received, review data processing agreements with your analytics vendors, and apply data minimization controls to session replay and pixel configurations. If you operate in healthcare, those steps are not optional — they are baseline compliance under multiple overlapping regulatory regimes.

The legal landscape will continue shifting. The Supreme Court will rule on VPPA. California’s legislature may narrow CIPA. Courts will continue issuing conflicting decisions on the real-time interception requirement and the party exception. What will not shift is the basic reality that businesses deploying sophisticated tracking tools without meaningful consent mechanisms are presenting plaintiffs with viable class action theories. Getting ahead of that is substantially cheaper than litigating it.


This post is for general informational purposes only and does not constitute legal advice. If you have specific questions about your website’s privacy compliance, you should consult with a qualified attorney.



Leave a Reply