Blog

Michigan Court Lets Patients’ Federal Wiretap Act Claim Over Website Tracking Proceed as Pennsylvania Court Reaches the Opposite Result

Julie Rubash, General Counsel and Chief Privacy Officer
September 22, 2026

Do you want to receive these privacy recaps in your inbox each week? Subscribe here or follow us on LinkedIn.

Two courts ruled the same day on structurally identical website-tracking cases under the federal Wiretap Act, and reached opposite results on the federal claim. A Michigan court let the claim proceed against a health system; a Pennsylvania court dismissed it against a brokerage, though state wiretapping claims survived.


Keep reading for the analysis and takeaways.

United States

Michigan Court Lets Patients’ Federal Wiretap Act Claim Over Website Tracking Proceed

A Michigan judge allowed a claim under the federal Wiretap Act to proceed in Wehrle v. McLaren Health Care Corp, a putative class action brought by patients of McLaren and its subsidiary, the Karmanos Cancer Institute. Plaintiffs allege that the providers embedded the Meta Pixel, Google Analytics, Google Tag Manager, and the LinkedIn Insight Tag in their websites, sending identifiable health information (cancer-treatment searches, oncologist selections and appointment activity) to advertising platforms without consent. The Wiretap Act and unjust-enrichment claims will proceed to discovery; plaintiffs’ remaining common-law claims were dismissed.

Takeaway


The federal Wiretap Act bars intentionally intercepting an electronic communication, or procuring someone else to intercept it, which is how the operator rather than the platform ends up the defendant. But unlike the many state wiretapping laws requiring all parties to consent, such as California’s CIPA, the federal statute needs only one party to consent. In the case of interception by website pixels, the website operator can provide that consent. Therefore, under that one-party consent rule, website defendants rarely dispute that an interception occurred. Everything turns on an exception to that exception: the protection falls away where a communication is “intercepted for the purpose of committing any criminal or tortious act.” Courts’ interpretations of that exception have split into two approaches though. Under the “independent act” approach, the criminal or tortious act must be independent of the interception itself. Under the “primary purpose” approach, the exception applies only where committing a crime or tort was the “primary motivation” or “determinative factor” behind the interception.

Here the court applied both. HIPAA satisfied the first, since it makes knowingly disclosing identifiable health information for commercial advantage a crime, so the disclosure, as alleged, breached a statute apart from the Wiretap Act. On the second, defendants argued that plaintiffs’ own complaint identified advertising as the primary motivation, but the court recited that a lawful purpose does not by itself sanitize an interception also made for an illegitimate one. Profit and an intent to disclose unlawfully can coexist.

This decision is provisional though. The judge said his conclusion reflects “the state of the law as it stands today,” and that he would revisit it at summary judgment. Whether advertising so dominated that no criminal purpose was a determinative factor is a question for the evidence. In a similar Texas case, the defendant, Houston Methodist, won summary judgment on exactly that record because there was no evidence it knew it was disclosing identifiable health information. But that is not a reason to look the other way. Courts infer purpose from conduct, including ignored warnings and continued use of the audiences built from that data. And even if a provider defeats the Wiretap Act claim by showing it didn’t know what its pixels were sending, that same ignorance doesn’t insulate it from HIPAA enforcement, because HIPAA’s civil money penalties are tiered by culpability rather than gated on knowledge. So conducting a field-level inventory of what each tag sends on which pages, along with a record of who approved it, is still the defensible posture.

Pennsylvania Court Dismisses Wiretap Act Claim but Lets State Claims Proceed

A Pennsylvania judge, ruling the same day, reached the opposite result on the federal claim in Felsen v. The Vanguard Group, Inc., a case structurally identical to Wehrle v. McLaren but involving financial rather than health data. Brokerage customers allege that Vanguard let Google, Meta, and LinkedIn see the financial products they searched for, bought, and sold on its platform. The court found that plaintiffs had standing, then split the claims: it dismissed the federal Wiretap Act claim without prejudice, along with the California constitutional and common-law privacy claims, but allowed the Pennsylvania and California wiretapping claims to proceed. As in McLaren, Vanguard was undisputedly a party to the communications, so the federal claim depended on the crime-tort exception.

Takeaway


The cases did not diverge because health data is more sensitive than financial data. They diverged on the first of the two approaches described in the McLaren post. This court required an independent act, so plaintiffs had to identify a crime or tort separate from the interception itself. They listed candidates, including Gramm-Leach-Bliley and intrusion upon seclusion, but the court found they “offer no explanation as to how these torts and crimes are independent of the interception,” and their fallback that the data was later built into advertising profiles never explained what made that a crime or tort. Having failed that test, plaintiffs never reached the primary purpose question.


The difference is that the Michigan court had a choice, but this one did not. Vanguard was decided in the Eastern District of Pennsylvania, which sits in the Third Circuit, and the Third Circuit has already adopted a strict interpretation of the independent act approach, requiring “acts secondary to the acquisition of the communication.” So when plaintiffs argued that no independent act is required (an argument available where the primary purpose approach governs alone) the court called it “directly contradicted by binding Third Circuit precedent.” Facing no such binding authority, the Michigan court was free to apply both approaches. The same complaint therefore fares differently in Third Circuit jurisdictions (Pennsylvania, New Jersey and Delaware) than it would elsewhere.


However, none of this prevented the plaintiffs’ claims from proceeding under Pennsylvania’s WESCA and California’s CIPA. The crime-tort exception matters for the federal claim only because the federal statute is satisfied by one party’s consent, which the website operator can supply. Pennsylvania and California both require consent from all parties, so the operator’s own authorization is worth nothing and plaintiffs need not prove any unlawful purpose. To defend against the Pennsylvania claim, Vanguard therefore had to argue that its customer consented, through a privacy notice linked at the bottom of every page. The court could not resolve that on the pleadings, holding that Vanguard would have to prove the link was “both functional and conspicuous enough” to have been reasonably seen. It also rejected Vanguard’s argument that its tags carried only routing data, holding that search terms and trading activity are the “contents” of a communication. Both state claims therefore proceed, even though the federal claim was dismissed. So a company can win the federal argument outright and still be in litigation, which means exposure is better measured against the state wiretapping statutes than the federal standard.

A Little More Privacy, if You Please

A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.

Latest Blog Posts

California’s 2027 Privacy Bills Explained (SB 923, SB 690, and AB 2561)

September 2, 2026

SB 923, SB 690, and AB 2561 update California's...

Latest White Papers

Connecting Legal & Marketing Teams on Consent and Preferences

February 4, 2025

Break down data silos and unlock better collaboration. Marketing...

Navigating Sensitive Data in the U.S.

February 4, 2025

Download our comprehensive guide to learn how different states...

Enterprise Guide To Cookie management & Tracker List Curation

July 1, 2024

How to review the tracking tech on your websites...

Keep in touch

Sign up for our newsletter to keep up with privacy news for adtech and martech,
plus occasional company news.

Let's explore what we can do together.

We'll be in touch within 48 hours

    First name *

    Last name *

    Email address *

    Company *

    Message *

    * indicates required fields