Publication

July 8, 2026
|
2 minute read
|

Veradigm Ruling Highlights Website Tracker and Wiretap Litigation Risk

A recent ruling from the Northern District of Illinois underscores why companies should know exactly what tracking technologies are embedded in their websites, portals, apps, and online platforms.

In Doe v. Veradigm LLC, Judge Mary M. Rowland denied Veradigm’s motion to dismiss a putative class action alleging that Veradigm improperly disclosed patients’ protected health information to Google through tracking technologies on password-protected patient portals. The court accepted the plaintiffs’ allegations as true at the pleading stage and held that the claims under the federal Electronic Communications Privacy Act, the California Invasion of Privacy Act, and Illinois negligence law could proceed. 

Plaintiffs claim Veradigm used Google digital marketing tools, including Google Analytics, on authenticated patient portals, despite alleged Google warnings not to use Google Analytics on HIPAA-covered authenticated pages. Plaintiffs further allege that the tools transmitted information to Google, including IP addresses, device identifiers, account numbers, URLs, searches for specific conditions, login activity, and actions taken inside patient portals. 

The court held that plaintiffs plausibly alleged disclosure of PHI because each plaintiff identified specific portal activity related to medical conditions and alleged that they later received advertisements related to those conditions. The court distinguished cases where plaintiffs alleged only generalized portal activity or patient status without enough detail about what was disclosed. 

The decision also reflects broader wiretap-litigation risk. On the federal ECPA claim, Veradigm argued that it was a party to the communications and therefore could not be liable. The court held that the plaintiffs plausibly invoked the Wiretap Act’s crime-tort exception, based on allegations that Veradigm unlawfully disclosed individually identifiable health information in violation of HIPAA. 

The court also allowed the CIPA claims to proceed, including the claim under California’s pen register provision. The court noted that CIPA has increasingly been invoked, with mixed results, to challenge third-party software that records website activity, and it followed what it described as the overwhelming majority of courts concluding that third-party internet trackers can meet CIPA’s technical pen register requirements at the pleading stage. 

The takeaway is practical: tracking technologies are not just marketing tools. They are litigation targets. Companies should inventory all pixels, cookies, analytics scripts, session replay tools, chat tools, SDKs, tag managers, and advertising technologies deployed across websites, portals, mobile apps, and subdomains. They should confirm what data those tools collect, where it goes, whether sensitive or authenticated user activity is involved, whether vendors are using the data for their own purposes, and whether disclosures, consent flows, opt-out mechanisms, and contracts accurately describe actual data flows.

The strongest defense is operational accuracy: know what is embedded, remove what is unnecessary, restrict tracking in sensitive environments, align notices with reality, and document governance before plaintiffs or regulators do the mapping for you.

 

The strongest defense is operational accuracy: know what is embedded, remove what is unnecessary, restrict tracking in sensitive environments, align notices with reality, and document governance before plaintiffs or regulators do the mapping for you.

Related People