Magliocca v. United Healthcare Services, Inc.
Summary
A Baird Holm LLP post reports that the U.S. District Court for the Eastern District of California dismissed a putative class action against UnitedHealthcare on March 31, 2026, finding the plaintiff failed to allege a concrete injury and thus lacked standing under the cited statutes. The court relied on recent case law (including Popa v. Microsoft) to explain what types of tracked information might meet the concrete-injury threshold, and granted the plaintiff leave to amend.
Litigation Status
Procedural Posture
Putative class action alleging use of third-party trackers on UnitedHealthcare's website; defendant moved to dismiss; court dismissed for lack of standing. Plaintiff was granted the opportunity to amend the complaint.
Reported Holding
The district court found the plaintiff lacked standing because the complaint failed to allege a concrete injury under the cited statutes (CIPA, ECPA, CDAFA, and the California Constitution), and granted the defendant's motion to dismiss. The court analyzed recent case law, including Popa v. Microsoft, in assessing what sorts of tracked information could support a concrete injury.
What the Court Decided
The court granted UnitedHealthcare's motion to dismiss the putative class action for lack of standing because the plaintiff did not allege a concrete injury from the website's use of third-party tracking technologies.
What the Court Did Not Decide
The court did not resolve the merits of whether the tracking practices were actionable under the cited statutes because dismissal was based on lack of alleged concrete injury; it also did not make a definitive ruling that the tracking at issue was or was not highly offensive or privacy-invasive on the merits.
Significance
Generally viewed as defense-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- third-party tracking technologies
- cookies
- pixels
- session replay / collection of mouse movements, clicks, keystrokes
Statutes Invoked
Claims Asserted
- California Invasion of Privacy Act (CIPA)
- Electronic Communications Privacy Act (ECPA)
- California Computer Data Access and Fraud Act (CDAFA)
- California Constitution
What This Matter May Mean for Website Operators
California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice. Our scanner tests these behaviors empirically.
The reported outcome direction at the standing stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website