JOHN DOE I, et al., Plaintiffs, v. GOOGLE LLC, Defendant.
Case No. 23-cv-02431-VC
UNITED STATES DISTRICT COURT NORTHERN DISTRICT OF CALIFORNIA
March 20, 2025
ORDER REQUESTING FURTHER BRIEFING Re: Dkt. No. 164
1. One of the things that makes this case so tricky is the lack of a clear overlap between the conduct the plaintiffs complain about in this case and some of the statutes they invoke. As the Court understands it, this lawsuit is and always has been focused on Google‘s receipt of private health information that can be linked to an identifiable person. Dkt. No. 159, Second Amend. Compl. ¶¶ 1, 21. But some of the statutory provisions invoked by the plaintiffs are broader—they cover the intentional interception of any communication without the consent of one party (or both parties) to the communication. It was probably a wise choice for the plaintiffs to focus their lawsuit in this fashion, but it makes it difficult to apply concepts like intent from statutes like the Federal Wiretap Act and CIPA (and from the case law interpreting those statutes). In any event, given the subject matter of the lawsuit, the focus here must be on whether the plaintiffs have adequately alleged that Google has obtained their private health information in a way that enables Google to actually identify them and link the information to them.
At least one cookie—the gid cookie—seems to collect information that, when a website interaction involves Google account holders, can link that website interaction to those account holders in a way that identifies them. The plaintiffs allege that this cookie generates and then transmits a unique identifier assigned to a website user when that user is logged into a Google service on the same browser. The plaintiffs further allege that this identifier can be tied to that user‘s Google account. Based on this, it appears reasonable to infer that Google, which obviously knows the personal information that users input to create their Google accounts, can use the gid cookie to tie information that came from the health providers’ webpages to a specific person. On the Court‘s understanding, when a specific action happens on a webpage with these cookies enabled, there will be several types of cookies that contain different data. Some of those cookies may end up sending health information, and when that transmission also includes the gid cookie with a specific gid identifier attached, Google is collecting health information about a particular, identifiable Google account holder. The plaintiffs allege that this health information then becomes included in Google‘s “digital dossier” on that person. If this cannot be inferred from the allegations in the SAC, Google should explain why, with reference to the SAC and materials that can properly be considered at this stage.
3. Breach of Contract: For the reasons discussed above, it appears that the plaintiffs may have stated a claim based on allegations that Google collected communications about private health information between patients and providers that could be linked to Google account holders through the cookies tied to users’ accounts, after promising to collect only health information that Google account holders chose to provide. See Second Amend. Compl. ¶¶ 96–101; Dkt. No. 159-4 at 5; Dkt. No. 159-5. It appears that a reasonable person reading Google‘s Privacy Policy could conclude that Google promised to only collect health information after consent by users and that the health information at issue here was covered by that promise. Dkt. No. 158-14 at 19.
4. Intent: The Federal Wiretap Act applies when a person “intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept, any wire, oral, or electronic communication.”
Section 631 of CIPA applies when someone “willfully and without the consent of all parties to the communication . . . reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit.”
As mentioned at the outset, this lawsuit seeks to hold Google liable for intercepting communications about private health information that Google can link to a particular, identifiable individual. Therefore, it doesn‘t matter (at least for purposes of this lawsuit) whether Google intended to intercept other types of communications. If Google intended to intercept communications that contained no private health information, that wouldn‘t matter. And even if Google intended to intercept communications about private health information (which it denies), that wouldn‘t matter for purposes of this suit if Google couldn‘t link the information to a particular, identifiable person.
The plaintiffs may indeed have adequately alleged that Google, prior to publication of its 2023 HIPAA disclosure, intended to receive private health information that it could link to individual Google account holders. We know, of course, that Google intended to receive communications between website visitors to health provider pages and health providers
In contrast, following Google‘s new HIPAA disclosure in 2023, it would not be reasonable to infer from the allegations in the SAC that Google intended to receive personal health information that could be linked to identifiable Google account holders. In that disclosure, Google told providers not to use Google‘s products on any page that may be related to the provision of health care services and are likely to be covered by HIPAA. This, as the Court understands it, would prevent the gid cookie from sending personal health information in a way that would allow Google to link it to identifiable Google account holders because the cookie would not be on any page containing personal health information. Although at times the plaintiffs seem to suggest that the new 2023 disclosure was just part of a plot by Google to keep getting the type of health information that is the focus of this lawsuit, that allegation would be governed by Rule 9(b), and the plaintiffs have not come close to satisfying the Rule 9(b) standard. Indeed, as mentioned above, it seems questionable that the plaintiffs will be able to prove that Google intended to receive these types of communications even before 2023.
Google‘s primary job in its supplemental brief, then, is to explain why the above analysis
Google‘s brief should be filed no later than 7 days from this order, the plaintiff‘s response should be filed no later than 14 days from this order, and Google may reply no later than 21 days from this order. The parties’ initial submissions should not exceed fifteen pages, and Google‘s reply should not exceed 10 pages.
IT IS SO ORDERED.
Dated: March 20, 2025
VINCE CHHABRIA
United States District Judge
